Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

268 advisories

Loading
n8n: Public API Execution Retry Authorization Bypass Moderate
GHSA-h3jj-5f3v-3685 was published for n8n (npm) Jun 16, 2026
ksw9722 Credited to ksw9722
Duplicate Advisory: Internal/webchat command auth could inherit ownerAllowFrom wildcard state Moderate
GHSA-r2fx-hp6p-pgrm was published for openclaw (npm) Jun 16, 2026 withdrawn
Nest: Middleware Bypass on Fastify via Trailing Slash High
CVE-2026-54281 was published for @nestjs/platform-fastify (npm) Jun 15, 2026
a-tt-om Credited to a-tt-om and kamilmysliwiec kamilmysliwiec kamilmysliwiec
Duplicate Advisory: OpenClaw: QQBot pre-dispatch slash commands could skip allowFrom checks High
GHSA-35c7-4r45-9gv3 was published for openclaw (npm) Jun 13, 2026 withdrawn
Budibase: Basic app users can exfiltrate stored REST datasource auth by rewriting datasource base URL High
CVE-2026-48152 was published for @budibase/server (npm) Jun 12, 2026
whrit Credited to whrit
FUXA Vulnerable to Unauthenticated Remote Code Execution via Script Test Mode Authorization Bypass High
CVE-2026-43947 was published for fuxa-server (npm) May 26, 2026
AbdrrahimDahmani Credited to AbdrrahimDahmani
FUXA has an unauthenticated arbitrary tag value disclosure via /api/getTagValue High
CVE-2026-43946 was published for fuxa-server (npm) May 26, 2026
anyzy2003 Credited to anyzy2003
FUXA Vulnerable to Pre-auth RCE via Path Manipulation & Configuration Injection High
CVE-2026-43945 was published for @frangoteam/fuxa (npm) May 26, 2026
ud444ng Credited to ud444ng
NocoDB: OAuth Token Scope Not Enforced at ACL Layer Allows Scope Escalation Low
CVE-2026-46549 was published for nocodb (npm) May 21, 2026
ik0z Credited to ik0z
axsharma Credited to axsharma and 0xmagic0 0xmagic0 0xmagic0
offset Credited to offset
offset Credited to offset
Duplicate Advisory: OpenClaw: Hook mapping templates could bypass hook session-key opt-in Moderate
GHSA-9j32-3m66-mc4m was published for openclaw (npm) May 11, 2026 withdrawn
Duplicate Advisory: OpenClaw: Owner-enforced commands could accept wildcard channel senders as command owners Low
GHSA-p3pv-c954-9m6f was published for openclaw (npm) May 11, 2026 withdrawn
Next.js has a Middleware / Proxy bypass in Pages Router applications using i18n High
CVE-2026-44573 was published for next (npm) May 11, 2026
bugbunny-research Credited to bugbunny-research
Backstage: Catalog unprocessed read endpoints allow authenticated cross-owner data access without permission checks Moderate
CVE-2026-44374 was published for @backstage/plugin-catalog-backend-module-unprocessed (npm) May 6, 2026
Duplicate Advisory: OpenClaw: Matrix room control-command authorization no longer trusts DM pairing-store entries High
GHSA-79rr-5c85-xvw3 was published for openclaw (npm) May 6, 2026 withdrawn
Auth.js SDK has Improper Permission Checking High
CVE-2026-42280 was published for auth0-js (npm) May 6, 2026
Clerk has an authorization bypass when combining organization, billing, or reverification checks High
CVE-2026-42349 was published for @clerk/astro (npm) Apr 30, 2026
OpenClaw: Paired-device pairing actions were not limited to the caller device Low
GHSA-xrq9-jm7v-g9h7 was published for openclaw (npm) Apr 25, 2026
Hinotoi-agent Credited to Hinotoi-agent
OpenClaw: Feishu card actions could misclassify DMs and skip dmPolicy Moderate
GHSA-72q8-jcmc-97wx was published for openclaw (npm) Apr 25, 2026
zsxsoft Credited to zsxsoft, KeenSecurityLab, and qclawer KeenSecurityLab KeenSecurityLab
qclawer qclawer
OpenClaw: Assistant media route missed scope enforcement for trusted-proxy authorization Low
CVE-2026-41908 was published for openclaw (npm) Apr 25, 2026
Kherrisan Credited to Kherrisan
ProTip! Advisories are also available from the GraphQL API