GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
44
GitHub Actions
46
Go
3,272
Maven
5,000+
npm
5,000+
NuGet
867
pip
4,521
Pub
12
RubyGems
1,007
Rust
1,194
Swift
51
Unreviewed advisories
All unreviewed
5,000+
27,583 advisories
Filter by severity
Concrete CMS vulnerable to Remote Code Execution by stored PHP object injection
High
CVE-2026-3452
was published
for
concrete5/concrete5
(Composer)
Mar 4, 2026
Concrete CMS vulnerable to Cross-Site Request Forgery (CSRF)
Low
CVE-2026-2994
was published
for
concrete5/concrete5
(Composer)
Mar 4, 2026
OpenClaw's serialize sandbox registry writes to prevent races and delete-rollback corruption
Moderate
CVE-2026-32018
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw's Node role device-identity bypass allows unauthorized node.event injection
Moderate
CVE-2026-32001
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw's commands.allowFrom sender authorization accepted conversation identifiers via ctx.From
High
GHSA-2ch6-x3g4-7759
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw has Windows Lobster shell fallback command injection in constrained fallback path
Moderate
CVE-2026-31995
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw's Zalo group sender allowlist bypass permits unauthorized GROUP dispatch
Moderate
GHSA-534w-2vm4-89xr
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw has Canvas route hardening for mixed-trust deployments
Moderate
GHSA-cjv3-m589-v3rx
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw's exec allowlist wrapper analysis did not unwrap env/shell dispatch chains
High
CVE-2026-27566
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw's typed sender-key matching for toolsBySender prevents identity-collision policy bypass
Moderate
CVE-2026-32039
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw's Signal reaction-only status events could, in limited cases, be enqueued before access checks
Moderate
GHSA-792q-qw95-f446
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw's sandbox bind validation could bypass allowed-root and blocked-path checks via symlink-parent missing-leaf paths
High
CVE-2026-27523
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw: Zip extraction symlink traversal could write outside destination
High
GHSA-jxrq-8fm4-9p58
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw's Nextcloud Talk webhook replay could trigger duplicate inbound processing
Moderate
CVE-2026-28449
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw's tools.exec.safeBins generic fallback allowed interpreter-style inline payload execution in allowlist mode
Low
GHSA-8mf7-vv8w-hjr2
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw's Synology Chat dmPolicy=allowlist failed open on empty allowedUserIds, allowing unauthorized agent dispatch
Moderate
CVE-2026-31998
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw reuses the gateway auth token in the owner ID prompt hashing fallback
Low
GHSA-v6x2-2qvm-6gv8
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw hook transform path containment missed symlink-resolved escapes
High
GHSA-659f-22xc-98f2
was published
for
openclaw
(npm)
Mar 3, 2026
In OpenClaw, manually adding sort to tools.exec.safeBins could bypass allowlist approval via --compress-program
High
CVE-2026-32010
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw has a BlueBubbles group allowlist mismatch via DM pairing-store fallback
Moderate
CVE-2026-32006
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw's voice-call Twilio replay dedupe now bound to authenticated webhook identity
Low
GHSA-gcj7-r3hg-m7w6
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw has multiple E2E/test Dockerfiles that run all processes as root
High
GHSA-w7j5-j98m-w679
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw has exec allowlist/safeBins policy-runtime mismatch via env -S wrapper interpretation
Moderate
GHSA-796m-2973-wc5q
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw: Microsoft Teams media fetch paths bypass shared SSRF guard model
Low
GHSA-7qf6-h84j-8fq4
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw's browser-origin WebSocket auth hardening gap could enable loopback password brute-force chains
Moderate
CVE-2026-32025
was published
for
openclaw
(npm)
Mar 3, 2026
ProTip!
Advisories are also available from the
GraphQL API