GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
70
GitHub Actions
52
Go
3,904
Maven
5,000+
npm
5,000+
NuGet
967
pip
5,000+
Pub
13
RubyGems
1,062
Rust
1,374
Swift
54
Unreviewed advisories
All unreviewed
5,000+
1,266 advisories
Filter by severity
Duplicate Advisory: `OpenClaw: session_status` let sandboxed subagents access parent or sibling session state
Critical
GHSA-hh43-q692-2xmq
was published
for
openclaw
(npm)
Mar 29, 2026
•
withdrawn
mppx has multiple payment bypass and griefing vulnerabilities
Critical
GHSA-8x4m-qw58-3pcx
was published
for
mppx
(npm)
Mar 29, 2026
OpenClaw: Silent privilege escalation via gateway shared-auth reconnect
Critical
GHSA-fqw4-mph7-2vr8
was published
for
openclaw
(npm)
Mar 27, 2026
OpenClaw: Gateway Backend Reconnect lets Non-Admin Operator Scopes Self-Claim operator.admin
Critical
CVE-2026-35663
was published
for
openclaw
(npm)
Mar 27, 2026
Handlebars.js has JavaScript Injection via AST Type Confusion
Critical
CVE-2026-33937
was published
for
handlebars
(npm)
Mar 27, 2026
OpenClaw Gateway: RCE and Privilege Escalation from operator.pairing to operator.admin via device.pair.approve
Critical
CVE-2026-35639
was published
for
openclaw
(npm)
Mar 26, 2026
Convict has Prototype Pollution via startsWith() function
Critical
CVE-2026-33864
was published
for
convict
(npm)
Mar 26, 2026
Convict has prototype pollution via load(), loadFile(), and schema initialization
Critical
CVE-2026-33863
was published
for
convict
(npm)
Mar 26, 2026
n8n: Prototype Pollution in XML and GSuiteAdmin node parameters lead to RCE
Critical
CVE-2026-33696
was published
for
n8n
(npm)
Mar 26, 2026
n8n has Multiple Remote Code Execution Vulnerabilities in Merge Node AlaSQL SQL Mode
Critical
CVE-2026-33660
was published
for
n8n
(npm)
Mar 25, 2026
node-tesseract-ocr is vulnerable to OS Command Injection through unsanitized recognize() function parameter
Critical
CVE-2026-26832
was published
for
node-tesseract-ocr
(npm)
Mar 25, 2026
thumbler allows OS Command Injection
Critical
CVE-2026-26833
was published
for
thumbler
(npm)
Mar 25, 2026
textract is vulnerable to OS Command Injection
Critical
CVE-2026-26831
was published
for
textract
(npm)
Mar 25, 2026
pdf-image has an OS Command Injection Vulnerability through its pdfFilePath parameter
Critical
CVE-2026-26830
was published
for
pdf-image
(npm)
Mar 25, 2026
jsrsasign: Incomplete Comparison Allows DSA Private Key Recovery via Biased Nonce Generation
Critical
CVE-2026-4599
was published
for
jsrsasign
(npm)
Mar 23, 2026
Duplicate Advisory: OpenClaw: WebSocket shared-auth connections could self-declare elevated scopes
Critical
GHSA-x49q-fhhm-r9jf
was published
for
openclaw
(npm)
Mar 20, 2026
•
withdrawn
MCP Connect has unauthenticated remote OS command execution via /bridge endpoint
Critical
GHSA-wvr4-3wq4-gpc5
was published
for
mcp-bridge
(npm)
Mar 19, 2026
ApostropheCMS has Arbitrary File Write (Zip Slip / Path Traversal) in Import-Export Gzip Extraction
Critical
CVE-2026-32731
was published
for
@apostrophecms/import-export
(npm)
Mar 18, 2026
jsPDF has HTML Injection in New Window paths
Critical
CVE-2026-31938
was published
for
jspdf
(npm)
Mar 17, 2026
OpenClaw: WebSocket shared-auth connections could self-declare elevated scopes
Critical
CVE-2026-22172
was published
for
openclaw
(npm)
Mar 13, 2026
Apollo Federation vulnerable to prototype pollution via incomplete key sanitization
Critical
CVE-2026-32621
was published
for
@apollo/federation-internals
(npm)
Mar 13, 2026
OneUptime ClickHouse SQL Injection via Aggregate Query Parameters
Critical
CVE-2026-32306
was published
for
oneuptime
(npm)
Mar 13, 2026
Locutus vulnerable to RCE via unsanitized input in create_function()
Critical
CVE-2026-32304
was published
for
locutus
(npm)
Mar 13, 2026
OpenClaw: Pairing-scoped device tokens could mint `operator.admin` and reach node RCE
Critical
GHSA-4jpw-hj22-2xmc
was published
for
openclaw
(npm)
Mar 13, 2026
OpenClaw: Plugin subagent routes could bypass gateway authorization with synthetic admin scopes
Critical
CVE-2026-32916
was published
for
openclaw
(npm)
Mar 13, 2026
ProTip!
Advisories are also available from the
GraphQL API