Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

39 advisories

Loading
@samanhappy/mcphub: SSE Endpoint Accepts Arbitrary Username from URL Path Without Authentication, Enabling User Impersonation Critical
GHSA-wf8q-wvv8-p8jf was published for @samanhappy/mcphub (npm) May 14, 2026
ibrahmsql Credited to ibrahmsql
SillyTavern has Authentication Bypass via SSO Header Injection Critical
CVE-2026-44649 was published for sillytavern (npm) May 12, 2026
kirakira-dev Credited to kirakira-dev
Duplicate Advisory: OpenClaw: MCP loopback owner context is derived from server-issued bearer tokens High
GHSA-35vf-vw9f-q3cr was published for openclaw (npm) May 6, 2026 withdrawn
OpenClaw: MCP loopback owner context is derived from server-issued bearer tokens High
CVE-2026-44118 was published for openclaw (npm) May 4, 2026
VladimirEliTokarev Credited to VladimirEliTokarev
Duplicate Advisory: OpenClaw: Google Chat app-url webhook auth accepted non-deployment add-on principals Moderate
GHSA-hgwr-wr8h-rxm7 was published for openclaw (npm) Apr 10, 2026 withdrawn
LobeHub: Unauthenticated authentication bypass on `webapi` routes via forgeable `X-lobe-chat-auth` header Moderate
CVE-2026-39411 was published for @lobehub/lobehub (npm) Apr 8, 2026
13ernkastel Credited to 13ernkastel
Electron: Service worker can spoof executeJavaScript IPC replies Moderate
CVE-2026-34778 was published for electron (npm) Apr 3, 2026
zpbrent Credited to zpbrent
OpenClaw: Forwarding header spoofing bypasses gateway.trustedProxies origin detection Moderate
CVE-2026-35656 was published for openclaw (npm) Mar 26, 2026
lintsinghua Credited to lintsinghua
OpenClaw: Google Chat app-url webhook auth accepted non-deployment add-on principals Moderate
CVE-2026-35622 was published for openclaw (npm) Mar 26, 2026
Duplicate Advisory: OpenClaw's gateway tokenless Tailscale auth applied to HTTP routes High
GHSA-qwmf-95r9-gx9x was published for openclaw (npm) Mar 21, 2026 withdrawn
h3 has a middleware bypass with one gadget High
CVE-2026-33131 was published for h3 (npm) Mar 18, 2026
hibwyli Credited to hibwyli
OpenClaw Loopback CDP probe can leak Gateway token to local listener Moderate
CVE-2026-22174 was published for openclaw (npm) Mar 3, 2026
tdjackey Credited to tdjackey
OpenClaw's gateway tokenless Tailscale auth applied to HTTP routes Moderate
CVE-2026-32045 was published for openclaw (npm) Mar 3, 2026
zpbrent Credited to zpbrent
OpenClaw: Node reconnect metadata spoofing could bypass platform-based node command policy High
CVE-2026-32014 was published for openclaw (npm) Mar 3, 2026
76embiid21 Credited to 76embiid21
n8n has Webhook Forgery on Zendesk Trigger Node Moderate
GHSA-38c7-23hj-2wgq was published for n8n (npm) Feb 26, 2026
nkoorty Credited to nkoorty and jjjutla jjjutla jjjutla
n8n: Webhook Forgery on Github Webhook Trigger Moderate
GHSA-mqpr-49jj-32rc was published for n8n (npm) Feb 26, 2026
simonkoeck Credited to simonkoeck
Hono is Vulnerable to Authentication Bypass by IP Spoofing in AWS Lambda ALB conninfo High
CVE-2026-27700 was published for hono (npm) Feb 25, 2026
EdamAme-x Credited to EdamAme-x
OpenClaw Telegram allowlist authorization accepted mutable usernames Moderate
CVE-2026-28480 was published for clawdbot (npm) Feb 18, 2026
vincentkoc Credited to vincentkoc
vincentkoc Credited to vincentkoc
Nextcloud Talk allowlist bypass via actor.name display name spoofing Critical
CVE-2026-28474 was published for @openclaw/nextcloud-talk (npm) Feb 17, 2026
MegaManSec Credited to MegaManSec
OpenClaw has a Matrix allowlist bypass via displayName and cross-homeserver localpart matching Moderate
CVE-2026-28471 was published for openclaw (npm) Feb 17, 2026
MegaManSec Credited to MegaManSec
OpenClaw optional voice-call plugin: webhook verification may be bypassed behind certain proxy configurations High
CVE-2026-28465 was published for @clawdbot/voice-call (npm) Feb 17, 2026
0x5t Credited to 0x5t
FUXA Unauthenticated Remote Code Execution in Node-RED Integration Critical
CVE-2026-25938 was published for fuxa-server (npm) Feb 10, 2026
wodzen Credited to wodzen
n8n's Missing Stripe-Signature Verification Allows Unauthenticated Forged Webhooks Moderate
CVE-2026-21894 was published for n8n (npm) Jan 7, 2026
nkoorty Credited to nkoorty, jjjutla, and geckosecurity jjjutla jjjutla
geckosecurity geckosecurity
ProTip! Advisories are also available from the GraphQL API