GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,608
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
26 advisories
Filter by severity
OpenClaw: BlueBubbles sender policy could match mutable conversation identifiers
Low
CVE-2026-53860
was published
for
openclaw
(npm)
Jun 18, 2026
NocoDB: OAuth Token Scope Not Enforced at ACL Layer Allows Scope Escalation
Low
CVE-2026-46549
was published
for
nocodb
(npm)
May 21, 2026
Duplicate Advisory: OpenClaw: Owner-enforced commands could accept wildcard channel senders as command owners
Low
GHSA-p3pv-c954-9m6f
was published
for
openclaw
(npm)
May 11, 2026
•
withdrawn
OpenClaw: Paired-device pairing actions were not limited to the caller device
Low
GHSA-xrq9-jm7v-g9h7
was published
for
openclaw
(npm)
Apr 25, 2026
OpenClaw: Assistant media route missed scope enforcement for trusted-proxy authorization
Low
CVE-2026-41908
was published
for
openclaw
(npm)
Apr 25, 2026
Duplicate Advisory: OpenClaw: Discord Slash Commands Bypass Group DM Channel Allowlist
Low
GHSA-qgp3-3rj7-qqq4
was published
for
openclaw
(npm)
Apr 24, 2026
•
withdrawn
Duplicate Advisory: OpenClaw: Assistant media route missed scope enforcement for trusted-proxy authorization
Low
GHSA-qgx9-6px9-7p75
was published
for
openclaw
(npm)
Apr 23, 2026
•
withdrawn
OpenClaw: Gateway plugin HTTP `auth: gateway` widens identity-bearing `operator.read` requests into runtime `operator.write`
Low
CVE-2026-42429
was published
for
openclaw
(npm)
Apr 9, 2026
OpenClaw: Discord Component Interaction Misclassifies Group DM as Direct Message
Low
CVE-2026-41341
was published
for
openclaw
(npm)
Apr 3, 2026
OpenClaw: Discord Slash Commands Bypass Group DM Channel Allowlist
Low
CVE-2026-41348
was published
for
openclaw
(npm)
Apr 3, 2026
OpenClaw: MSTeams thread history bypasses sender allowlist via Graph API
Low
CVE-2026-41365
was published
for
openclaw
(npm)
Apr 2, 2026
OpenClaw: Matrix thread root and reply context bypass sender allowlist
Low
CVE-2026-41376
was published
for
openclaw
(npm)
Apr 2, 2026
Duplicate Advisory: OpenClaw's MS Teams sender allowlist bypass when route allowlist is configured and sender allowlist is empty
Low
GHSA-xg59-f45v-9r9j
was published
for
openclaw
(npm)
Mar 31, 2026
•
withdrawn
OpenClaw: Google Chat Authz Bypass via Group Policy Rebinding with Mutable Space displayName
Low
CVE-2026-35617
was published
for
openclaw
(npm)
Mar 29, 2026
OpenClaw: Nextcloud Talk room allowlist matched colliding room names instead of stable room tokens
Low
CVE-2026-35624
was published
for
openclaw
(npm)
Mar 26, 2026
OpenClaw: Tlon settings empty-allowlist reconciliation bypassed intended revocation
Low
CVE-2026-35649
was published
for
openclaw
(npm)
Mar 26, 2026
OpenClaw may have stale policy enforcement for queued node actions
Low
CVE-2026-35648
was published
for
openclaw
(npm)
Mar 26, 2026
Duplicate Advisory: OpenClaw Node system.run approval context-binding weakness in approval-enabled host=node flows
Low
GHSA-cjq8-m7wj-xmq9
was published
for
openclaw
(npm)
Mar 21, 2026
•
withdrawn
Duplicate Advisory: Signal group allowlist authorization bypass via DM pairing-store leakage
Low
GHSA-r849-826x-wgqm
was published
for
openclaw
(npm)
Mar 19, 2026
•
withdrawn
OpenClaw: system.run wrapper-depth boundary could skip shell approval gating
Low
CVE-2026-27183
was published
for
openclaw
(npm)
Mar 9, 2026
Mercurius's queryDepth limit bypassed for WebSocket subscriptions
Low
CVE-2026-30241
was published
for
mercurius
(npm)
Mar 6, 2026
OpenClaw has cross-account DM pairing authorization bypass via unscoped pairing store access
Low
CVE-2026-32067
was published
for
openclaw
(npm)
Mar 4, 2026
OpenClaw Node system.run approval context-binding weakness in approval-enabled host=node flows
Low
CVE-2026-32058
was published
for
openclaw
(npm)
Mar 2, 2026
OpenClaw has Signal group allowlist authorization bypass via DM pairing-store leakage
Low
CVE-2026-31991
was published
for
openclaw
(npm)
Mar 2, 2026
OpenClaw Google Chat spoofing access with allowlist authorized mutable email principal despite sender-ID mismatch
Low
GHSA-chm2-m3w2-wcxm
was published
for
clawdbot
(npm)
Feb 17, 2026
ProTip!
Advisories are also available from the
GraphQL API