GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,347
Maven
5,000+
npm
5,000+
NuGet
1,042
pip
5,000+
Pub
13
RubyGems
1,122
Rust
1,498
Swift
61
Unreviewed advisories
All unreviewed
5,000+
52 advisories
Filter by severity
SvelteKit vulnerable to Cross-Site Request Forgery
High
CVE-2023-29003
was published
for
@sveltejs/kit
(npm)
Apr 4, 2023
Denial of Service in http-proxy
High
GHSA-6x33-pw7p-hmpq
was published
for
http-proxy
(npm)
Sep 4, 2020
KaTeX missing normalization of the protocol in URLs allows bypassing forbidden protocols
Moderate
CVE-2024-28246
was published
for
katex
(npm)
Mar 25, 2024
Babel vulnerable to arbitrary code execution when compiling specifically crafted malicious code
Critical
CVE-2023-45133
was published
for
@babel/traverse
(npm)
Oct 16, 2023
Improper Validation of Query Parameters in Auth0 Next.js SDK
Low
CVE-2025-67716
was published
for
@auth0/nextjs-auth0
(npm)
Dec 10, 2025
FUXA Affected by a Path Traversal Sanitization Bypass
High
CVE-2026-25951
was published
for
fuxa-server
(npm)
Feb 10, 2026
OpenClaw is vulnerable to validation bypass through GNU long-option abbreviations in allowlist mode
Critical
CVE-2026-28363
was published
for
openclaw
(npm)
Feb 27, 2026
OpenClaw's system.run allowlist approval parsing missed PowerShell encoded-command wrappers
Moderate
GHSA-3h2q-j2v4-6w5r
was published
for
openclaw
(npm)
Mar 9, 2026
OpenClaw's tools.exec.safeBins sort long-option abbreviation bypass can skip exec approval in allowlist mode
High
CVE-2026-32059
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw's exec allow-always can be bypassed via unrecognized multiplexer shell wrappers (busybox/toybox sh -c)
Moderate
CVE-2026-22175
was published
for
openclaw
(npm)
Mar 2, 2026
Duplicate Advisory: OpenClaw macOS companion app (beta): allowlist parsing mismatch for system.run shell chains
Moderate
GHSA-5326-6f73-m96w
was published
for
openclaw
(npm)
Mar 19, 2026
•
withdrawn
OpenClaw macOS companion app (beta): allowlist parsing mismatch for system.run shell chains
Low
CVE-2026-31993
was published
for
openclaw
(npm)
Mar 2, 2026
OpenClaw safeBins stdin-only bypass via sort output and recursive grep flags
Low
CVE-2026-31996
was published
for
openclaw
(npm)
Feb 19, 2026
Duplicate Advisory: allowlist exec-guard bypass via env -S
High
GHSA-x742-88jj-7hv9
was published
for
openclaw
(npm)
Mar 19, 2026
•
withdrawn
OpenClaw has allowlist exec-guard bypass via env -S
Moderate
CVE-2026-31992
was published
for
openclaw
(npm)
Mar 3, 2026
In OpenClaw, manually adding sort to tools.exec.safeBins could bypass allowlist approval via --compress-program
Moderate
CVE-2026-32010
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw: fetch-guard forwards custom authorization headers across cross-origin redirects
High
CVE-2026-32913
was published
for
openclaw
(npm)
Mar 9, 2026
OpenClaw exec allowlist safeBins short-option bypass could permit arbitrary file write
Moderate
CVE-2026-32017
was published
for
openclaw
(npm)
Mar 3, 2026
Duplicate Advisory: OpenClaw's complex interpreter pipelines could skip exec script preflight validation
Moderate
GHSA-rf75-g96h-j3rm
was published
for
openclaw
(npm)
Apr 2, 2026
•
withdrawn
OpenClaw's complex interpreter pipelines could skip exec script preflight validation
Moderate
CVE-2026-34425
was published
for
openclaw
(npm)
Apr 6, 2026
Unhead has a hasDangerousProtocol() bypass via leading-zero padded HTML entities in useHeadSafe()
Moderate
CVE-2026-39315
was published
for
unhead
(npm)
Apr 9, 2026
Duplicate Advisory: OpenClaw: Windows media loaders accepted remote-host file URLs before local path validation
Moderate
GHSA-8h8f-7cxm-m38j
was published
for
openclaw
(npm)
Apr 2, 2026
•
withdrawn
Directus: Open Redirect via Parser Bypass in OAuth2/SAML Authentication Flow
Moderate
CVE-2026-35410
was published
for
directus
(npm)
Apr 4, 2026
Flowise: Airtable_Agent Code Injection Remote Code Execution Vulnerability
Critical
CVE-2026-41265
was published
for
flowise
(npm)
Apr 18, 2026
Flowise: CSV Agent Prompt Injection Remote Code Execution Vulnerability
Critical
CVE-2026-41264
was published
for
flowise
(npm)
Apr 21, 2026
ProTip!
Advisories are also available from the
GraphQL API