Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

28,576 advisories

Loading
OpenClaw: Native prompt image auto-load did not honor tools.fs.workspaceOnly in sandboxed runs High
GHSA-9f72-qcpw-2hxc was published for openclaw (npm) Mar 3, 2026
tdjackey Credited to tdjackey
OpenClaw's non-default safeBins sort configuration can bypass intended allowlist approval constraints Moderate
CVE-2026-22169 was published for openclaw (npm) Mar 3, 2026
tdjackey Credited to tdjackey
zpbrent Credited to zpbrent
OpenClaw's gateway tokenless Tailscale auth applied to HTTP routes Moderate
CVE-2026-32045 was published for openclaw (npm) Mar 3, 2026
zpbrent Credited to zpbrent
allsmog Credited to allsmog
DOMPurify contains a Cross-site Scripting vulnerability Moderate
CVE-2025-15599 was published for dompurify (npm) Mar 3, 2026
DOMPurify contains a Cross-site Scripting vulnerability Moderate
CVE-2026-0540 was published for dompurify (npm) Mar 3, 2026
swils23 Credited to swils23, cure53, and caverav cure53 cure53
caverav caverav
allsmog Credited to allsmog
Temporary path handling could write outside OpenClaw temp boundary Moderate
CVE-2026-32026 was published for openclaw (npm) Mar 3, 2026
tdjackey Credited to tdjackey
OpenClaw: Chrome --no-sandbox disabled OS-level browser sandbox in sandbox browser container Moderate
CVE-2026-32046 was published for openclaw (npm) Mar 3, 2026
TerminalsandCoffee Credited to TerminalsandCoffee
OpenClaw's MSTeams attachment redirect handling could bypass configured media host allowlists High
CVE-2026-32037 was published for openclaw (npm) Mar 3, 2026
tdjackey Credited to tdjackey
OpenClaw's hook transform module path allows traversal and arbitrary JavaScript module loading High
CVE-2026-28393 was published for openclaw (npm) Mar 3, 2026
akhmittra Credited to akhmittra
OpenClaw has command injection via Windows shell fallback in Lobster tool execution High
CVE-2026-32000 was published for openclaw (npm) Mar 3, 2026
allsmog Credited to allsmog
OpenClaw's Telegram message_reaction authorization bypass allows unauthorized system-event injection High
GHSA-qj22-xqjr-v83v was published for openclaw (npm) Mar 3, 2026
tdjackey Credited to tdjackey
OpenClaw has allowlist exec-guard bypass via env -S Moderate
CVE-2026-31992 was published for openclaw (npm) Mar 3, 2026
tdjackey Credited to tdjackey
Wagtail Vulnerable to Cross-site Scripting in simple_translation admin interface Moderate
CVE-2026-28223 was published for wagtail (pip) Mar 3, 2026
GCXWLP Credited to GCXWLP, RealOrangeOne, and gasman RealOrangeOne RealOrangeOne
gasman gasman
Wagtail Vulnerable to Cross-site Scripting in TableBlock class attributes Moderate
CVE-2026-28222 was published for wagtail (pip) Mar 3, 2026
GCXWLP Credited to GCXWLP, RealOrangeOne, and gasman RealOrangeOne RealOrangeOne
gasman gasman
BentoML Vulnerable to Arbitrary File Write via Symlink Path Traversal in Tar Extraction High
CVE-2026-27905 was published for bentoml (pip) Mar 3, 2026
q1uf3ng Credited to q1uf3ng
Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS attack High
CVE-2026-27601 was published for underscore (npm) Mar 3, 2026
ByamB4 Credited to ByamB4 and jgonggrijp jgonggrijp jgonggrijp
OpenSTAManager affected by unauthenticated privilege escalation via modules/utenti/actions.php Critical
CVE-2026-27012 was published for devcode-it/openstamanager (Composer) Mar 3, 2026
RunProgram Credited to RunProgram
Froxlor has Admin-to-Root Privilege Escalation via Input Validation Bypass + OS Command Injection Critical
CVE-2026-26279 was published for froxlor/froxlor (Composer) Mar 3, 2026
Moonster8282 Credited to Moonster8282
OpenSTAManager Affected by XSS in modifica_iva.php via righe parameter Moderate
CVE-2026-24415 was published for devcode-it/openstamanager (Composer) Mar 3, 2026
lukasz-rybak Credited to lukasz-rybak
Rancher Backup Operator pod's logs leak S3 tokens Moderate
CVE-2025-62879 was published for github.com/rancher/backup-restore-operator (Go) Mar 3, 2026
OpenViking contains a Path Traversal vulnerability High
CVE-2026-28518 was published for openviking (pip) Mar 3, 2026
Django vulnerable to Uncontrolled Resource Consumption High
CVE-2026-25673 was published for Django (pip) Mar 3, 2026
ProTip! Advisories are also available from the GraphQL API