GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
70
GitHub Actions
52
Go
3,904
Maven
5,000+
npm
5,000+
NuGet
967
pip
5,000+
Pub
13
RubyGems
1,062
Rust
1,374
Swift
54
Unreviewed advisories
All unreviewed
5,000+
39 advisories
Filter by severity
@samanhappy/mcphub: SSE Endpoint Accepts Arbitrary Username from URL Path Without Authentication, Enabling User Impersonation
Critical
GHSA-wf8q-wvv8-p8jf
was published
for
@samanhappy/mcphub
(npm)
May 14, 2026
SillyTavern has Authentication Bypass via SSO Header Injection
Critical
CVE-2026-44649
was published
for
sillytavern
(npm)
May 12, 2026
Duplicate Advisory: OpenClaw: MCP loopback owner context is derived from server-issued bearer tokens
High
GHSA-35vf-vw9f-q3cr
was published
for
openclaw
(npm)
May 6, 2026
•
withdrawn
OpenClaw: MCP loopback owner context is derived from server-issued bearer tokens
High
CVE-2026-44118
was published
for
openclaw
(npm)
May 4, 2026
Duplicate Advisory: OpenClaw: Google Chat app-url webhook auth accepted non-deployment add-on principals
Moderate
GHSA-hgwr-wr8h-rxm7
was published
for
openclaw
(npm)
Apr 10, 2026
•
withdrawn
LobeHub: Unauthenticated authentication bypass on `webapi` routes via forgeable `X-lobe-chat-auth` header
Moderate
CVE-2026-39411
was published
for
@lobehub/lobehub
(npm)
Apr 8, 2026
Electron: Service worker can spoof executeJavaScript IPC replies
Moderate
CVE-2026-34778
was published
for
electron
(npm)
Apr 3, 2026
OpenClaw: Gateway chat.send ACP-only provenance guard could be bypassed by client identity spoofing
High
CVE-2026-41299
was published
for
openclaw
(npm)
Mar 31, 2026
OpenClaw: Forwarding header spoofing bypasses gateway.trustedProxies origin detection
Moderate
CVE-2026-35656
was published
for
openclaw
(npm)
Mar 26, 2026
OpenClaw: Google Chat app-url webhook auth accepted non-deployment add-on principals
Moderate
CVE-2026-35622
was published
for
openclaw
(npm)
Mar 26, 2026
Duplicate Advisory: OpenClaw's gateway tokenless Tailscale auth applied to HTTP routes
High
GHSA-qwmf-95r9-gx9x
was published
for
openclaw
(npm)
Mar 21, 2026
•
withdrawn
h3 has a middleware bypass with one gadget
High
CVE-2026-33131
was published
for
h3
(npm)
Mar 18, 2026
OpenClaw Loopback CDP probe can leak Gateway token to local listener
Moderate
CVE-2026-22174
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw's gateway tokenless Tailscale auth applied to HTTP routes
Moderate
CVE-2026-32045
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw: Node reconnect metadata spoofing could bypass platform-based node command policy
High
CVE-2026-32014
was published
for
openclaw
(npm)
Mar 3, 2026
n8n has Webhook Forgery on Zendesk Trigger Node
Moderate
GHSA-38c7-23hj-2wgq
was published
for
n8n
(npm)
Feb 26, 2026
n8n: Webhook Forgery on Github Webhook Trigger
Moderate
GHSA-mqpr-49jj-32rc
was published
for
n8n
(npm)
Feb 26, 2026
Hono is Vulnerable to Authentication Bypass by IP Spoofing in AWS Lambda ALB conninfo
High
CVE-2026-27700
was published
for
hono
(npm)
Feb 25, 2026
OpenClaw Telegram allowlist authorization accepted mutable usernames
Moderate
CVE-2026-28480
was published
for
clawdbot
(npm)
Feb 18, 2026
OpenClaw Google Chat spoofing access with allowlist authorized mutable email principal despite sender-ID mismatch
Low
GHSA-chm2-m3w2-wcxm
was published
for
clawdbot
(npm)
Feb 17, 2026
Nextcloud Talk allowlist bypass via actor.name display name spoofing
Critical
CVE-2026-28474
was published
for
@openclaw/nextcloud-talk
(npm)
Feb 17, 2026
OpenClaw has a Matrix allowlist bypass via displayName and cross-homeserver localpart matching
Moderate
CVE-2026-28471
was published
for
openclaw
(npm)
Feb 17, 2026
OpenClaw optional voice-call plugin: webhook verification may be bypassed behind certain proxy configurations
High
CVE-2026-28465
was published
for
@clawdbot/voice-call
(npm)
Feb 17, 2026
FUXA Unauthenticated Remote Code Execution in Node-RED Integration
Critical
CVE-2026-25938
was published
for
fuxa-server
(npm)
Feb 10, 2026
n8n's Missing Stripe-Signature Verification Allows Unauthenticated Forged Webhooks
Moderate
CVE-2026-21894
was published
for
n8n
(npm)
Jan 7, 2026
ProTip!
Advisories are also available from the
GraphQL API