GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
44
GitHub Actions
46
Go
3,270
Maven
5,000+
npm
5,000+
NuGet
867
pip
4,517
Pub
12
RubyGems
998
Rust
1,194
Swift
51
Unreviewed advisories
All unreviewed
5,000+
5,241 advisories
Filter by severity
Claude Code has a Workspace Trust Dialog Bypass via Repo-Controlled Settings File
High
CVE-2026-33068
was published
for
@anthropic-ai/claude-code
(npm)
Mar 19, 2026
Duplicate Advisory: Command Injection via unescaped environment assignments in Windows Scheduled Task script generation
Moderate
GHSA-82gw-wqw6-r2cf
was published
for
openclaw
(npm)
Mar 19, 2026
•
withdrawn
Duplicate Advisory: Synology Chat dmPolicy=allowlist failed open on empty allowedUserIds, allowing unauthorized agent dispatch
High
GHSA-jqpf-vj28-9v7r
was published
for
openclaw
(npm)
Mar 19, 2026
•
withdrawn
Duplicate Advisory: Signal group allowlist authorization bypass via DM pairing-store leakage
Low
GHSA-r849-826x-wgqm
was published
for
openclaw
(npm)
Mar 19, 2026
•
withdrawn
Duplicate Advisory: ACPX Windows wrapper shell fallback allowed cwd injection in specific paths
Moderate
GHSA-h36m-2vh5-x699
was published
for
openclaw
(npm)
Mar 19, 2026
•
withdrawn
Duplicate Advisory: Exec allowlist wrapper analysis did not unwrap env/shell dispatch chains
High
GHSA-3846-mfvc-xwpf
was published
for
openclaw
(npm)
Mar 19, 2026
•
withdrawn
Duplicate Advisory: web_search citation redirect SSRF via private-network-allowing policy
Moderate
GHSA-44c9-4rg5-qjgq
was published
for
openclaw
(npm)
Mar 19, 2026
•
withdrawn
Duplicate Advisory: allowlist exec-guard bypass via env -S
High
GHSA-x742-88jj-7hv9
was published
for
openclaw
(npm)
Mar 19, 2026
•
withdrawn
Duplicate Advisory: OpenClaw's system.run allowlist bypass via shell line-continuation command substitution
Moderate
GHSA-xrgv-34cc-q765
was published
for
openclaw
(npm)
Mar 19, 2026
•
withdrawn
Duplicate Advisory: OpenClaw: system.run approvals did not bind PATH-token executable identity, enabling post-approval executable rebind
Moderate
GHSA-q86m-697p-h7fh
was published
for
openclaw
(npm)
Mar 19, 2026
•
withdrawn
Duplicate Advisory: OpenClaw's allow-always wrapper persistence could bypass future approvals and enable command execution
High
GHSA-pfv5-rpcw-x34x
was published
for
openclaw
(npm)
Mar 19, 2026
•
withdrawn
Duplicate Advisory: OpenClaw: stageSandboxMedia destination symlink traversal can overwrite files outside sandbox workspace
Moderate
GHSA-2cwr-f5hx-gg3w
was published
for
openclaw
(npm)
Mar 19, 2026
•
withdrawn
Duplicate Advisory: OpenClaw's Node system.run approval hardening wrapper semantic drift can execute unintended local scripts
Moderate
GHSA-g87j-gm7p-6vw2
was published
for
openclaw
(npm)
Mar 19, 2026
•
withdrawn
Duplicate Advisory: OpenClaw: WebSocket shared-auth connections could self-declare elevated scopes
Moderate
GHSA-5rp4-cwgh-gvwq
was published
for
openclaw
(npm)
Mar 19, 2026
•
withdrawn
Duplicate Advisory: OpenClaw macOS companion app (beta): allowlist parsing mismatch for system.run shell chains
Moderate
GHSA-5326-6f73-m96w
was published
for
openclaw
(npm)
Mar 19, 2026
•
withdrawn
Duplicate Advisory: OpenClaw's Nextcloud Talk webhook replay could trigger duplicate inbound processing
Moderate
GHSA-866c-wwm5-4rj7
was published
for
openclaw
(npm)
Mar 19, 2026
•
withdrawn
Duplicate Advisory: OpenClaw Windows Scheduled Task script generation allowed local command injection via unsafe cmd argument handling
Moderate
GHSA-5gqg-mqh5-2v39
was published
for
openclaw
(npm)
Mar 19, 2026
•
withdrawn
Duplicate Advisory: OpenClaw has Windows Lobster shell fallback command injection in constrained fallback path
Moderate
GHSA-8px5-2gfr-7ph6
was published
for
openclaw
(npm)
Mar 19, 2026
•
withdrawn
Duplicate Advisory: safeBins stdin-only bypass via sort output and recursive grep flags
Low
GHSA-ggm6-h3mx-cmmp
was published
for
openclaw
(npm)
Mar 19, 2026
•
withdrawn
Budibase Unrestricted Server-Side Request Forgery (SSRF) via REST Datasource Query Preview
High
CVE-2026-33226
was published
for
budibase
(npm)
Mar 18, 2026
Parse Server leaks protected fields via LiveQuery afterEvent trigger
High
CVE-2026-33163
was published
for
parse-server
(npm)
Mar 18, 2026
ApostropheCMS has Arbitrary File Write (Zip Slip / Path Traversal) in Import-Export Gzip Extraction
Critical
CVE-2026-32731
was published
for
@apostrophecms/import-export
(npm)
Mar 18, 2026
ApostropheCMS MFA/TOTP Bypass via Incorrect MongoDB Query in Bearer Token Middleware
High
CVE-2026-32730
was published
for
apostrophe
(npm)
Mar 18, 2026
NotChatbot WebChat has a stored cross-site scripting (XSS) vulnerability
Moderate
CVE-2026-30048
was published
for
@developer.notchatbot/webchat
(npm)
Mar 18, 2026
socket.io allows an unbounded number of binary attachments
High
CVE-2026-33151
was published
for
socket.io-parser
(npm)
Mar 18, 2026
ProTip!
Advisories are also available from the
GraphQL API