Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

5,241 advisories

Loading
Claude Code has a Workspace Trust Dialog Bypass via Repo-Controlled Settings File High
CVE-2026-33068 was published for @anthropic-ai/claude-code (npm) Mar 19, 2026
Duplicate Advisory: Command Injection via unescaped environment assignments in Windows Scheduled Task script generation Moderate
GHSA-82gw-wqw6-r2cf was published for openclaw (npm) Mar 19, 2026 withdrawn
Duplicate Advisory: Signal group allowlist authorization bypass via DM pairing-store leakage Low
GHSA-r849-826x-wgqm was published for openclaw (npm) Mar 19, 2026 withdrawn
Duplicate Advisory: ACPX Windows wrapper shell fallback allowed cwd injection in specific paths Moderate
GHSA-h36m-2vh5-x699 was published for openclaw (npm) Mar 19, 2026 withdrawn
Duplicate Advisory: Exec allowlist wrapper analysis did not unwrap env/shell dispatch chains High
GHSA-3846-mfvc-xwpf was published for openclaw (npm) Mar 19, 2026 withdrawn
Duplicate Advisory: web_search citation redirect SSRF via private-network-allowing policy Moderate
GHSA-44c9-4rg5-qjgq was published for openclaw (npm) Mar 19, 2026 withdrawn
Duplicate Advisory: allowlist exec-guard bypass via env -S High
GHSA-x742-88jj-7hv9 was published for openclaw (npm) Mar 19, 2026 withdrawn
Duplicate Advisory: OpenClaw's system.run allowlist bypass via shell line-continuation command substitution Moderate
GHSA-xrgv-34cc-q765 was published for openclaw (npm) Mar 19, 2026 withdrawn
Duplicate Advisory: OpenClaw's allow-always wrapper persistence could bypass future approvals and enable command execution High
GHSA-pfv5-rpcw-x34x was published for openclaw (npm) Mar 19, 2026 withdrawn
Duplicate Advisory: OpenClaw: stageSandboxMedia destination symlink traversal can overwrite files outside sandbox workspace Moderate
GHSA-2cwr-f5hx-gg3w was published for openclaw (npm) Mar 19, 2026 withdrawn
Duplicate Advisory: OpenClaw's Node system.run approval hardening wrapper semantic drift can execute unintended local scripts Moderate
GHSA-g87j-gm7p-6vw2 was published for openclaw (npm) Mar 19, 2026 withdrawn
Duplicate Advisory: OpenClaw: WebSocket shared-auth connections could self-declare elevated scopes Moderate
GHSA-5rp4-cwgh-gvwq was published for openclaw (npm) Mar 19, 2026 withdrawn
Duplicate Advisory: OpenClaw macOS companion app (beta): allowlist parsing mismatch for system.run shell chains Moderate
GHSA-5326-6f73-m96w was published for openclaw (npm) Mar 19, 2026 withdrawn
Duplicate Advisory: OpenClaw's Nextcloud Talk webhook replay could trigger duplicate inbound processing Moderate
GHSA-866c-wwm5-4rj7 was published for openclaw (npm) Mar 19, 2026 withdrawn
Duplicate Advisory: OpenClaw has Windows Lobster shell fallback command injection in constrained fallback path Moderate
GHSA-8px5-2gfr-7ph6 was published for openclaw (npm) Mar 19, 2026 withdrawn
Duplicate Advisory: safeBins stdin-only bypass via sort output and recursive grep flags Low
GHSA-ggm6-h3mx-cmmp was published for openclaw (npm) Mar 19, 2026 withdrawn
Budibase Unrestricted Server-Side Request Forgery (SSRF) via REST Datasource Query Preview High
CVE-2026-33226 was published for budibase (npm) Mar 18, 2026
da7om85 Credited to da7om85
Parse Server leaks protected fields via LiveQuery afterEvent trigger High
CVE-2026-33163 was published for parse-server (npm) Mar 18, 2026
mtrezza Credited to mtrezza
ApostropheCMS has Arbitrary File Write (Zip Slip / Path Traversal) in Import-Export Gzip Extraction Critical
CVE-2026-32731 was published for @apostrophecms/import-export (npm) Mar 18, 2026
0xEr3n Credited to 0xEr3n
ApostropheCMS MFA/TOTP Bypass via Incorrect MongoDB Query in Bearer Token Middleware High
CVE-2026-32730 was published for apostrophe (npm) Mar 18, 2026
0xkakash1 Credited to 0xkakash1
NotChatbot WebChat has a stored cross-site scripting (XSS) vulnerability Moderate
CVE-2026-30048 was published for @developer.notchatbot/webchat (npm) Mar 18, 2026
socket.io allows an unbounded number of binary attachments High
CVE-2026-33151 was published for socket.io-parser (npm) Mar 18, 2026
x4cc3 Credited to x4cc3 and darrachequesne darrachequesne darrachequesne
ProTip! Advisories are also available from the GraphQL API