Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

1,634 advisories

Loading
Hono Vulnerable to Cookie Attribute Injection via Unsanitized domain and path in setCookie() Moderate
CVE-2026-29086 was published for hono (npm) Mar 4, 2026
TarPeg007 Credited to TarPeg007
Hono Vulnerable to SSE Control Field Injection via CR/LF in writeSSE() Moderate
CVE-2026-29085 was published for hono (npm) Mar 4, 2026
TarPeg007 Credited to TarPeg007
OpenClaw: BlueBubbles (optional plugin) pairing/allowlist mismatch when allowFrom is empty Moderate
GHSA-jwf4-8wf4-jf2m was published for openclaw (npm) Mar 4, 2026
tdjackey Credited to tdjackey
OpenClaw Vulnerable to Local File Exfiltration via MCP Tool Result MEDIA: Directive Injection Moderate
GHSA-jjgj-cpp9-cvpv was published for openclaw (npm) Mar 4, 2026
NucleiAv Credited to NucleiAv
tdjackey Credited to tdjackey
OpenClaw has incomplete IPv4 special-use SSRF blocking in web fetch guard Moderate
GHSA-4rqq-w8v4-7p47 was published for openclaw (npm) Mar 4, 2026
princeeismond-dot Credited to princeeismond-dot
OpenClaw has agent avatar symlink traversal in gateway session metadata Moderate
GHSA-9mph-4f7v-fmvh was published for openclaw (npm) Mar 4, 2026
jiseoung Credited to jiseoung
OpenClaw has SSRF guard bypass via IPv6 transition over ISATAP Moderate
GHSA-8cp7-rp8r-mg77 was published for openclaw (npm) Mar 4, 2026
zpbrent Credited to zpbrent
CKEditor 5 has Cross-site Scripting (XSS) in the HTML Support package Moderate
CVE-2026-28343 was published for @ckeditor/ckeditor5-html-support (npm) Mar 4, 2026
OpenClaw's serialize sandbox registry writes to prevent races and delete-rollback corruption Moderate
GHSA-gq83-8q7q-9hfx was published for openclaw (npm) Mar 3, 2026
kexinoh Credited to kexinoh
OpenClaw's Node role device-identity bypass allows unauthorized node.event injection Moderate
GHSA-rv2q-f2h5-6xmg was published for openclaw (npm) Mar 3, 2026
tdjackey Credited to tdjackey
OpenClaw has Windows Lobster shell fallback command injection in constrained fallback path Moderate
GHSA-fg3m-vhrr-8gj6 was published for openclaw (npm) Mar 3, 2026
tdjackey Credited to tdjackey
OpenClaw's Zalo group sender allowlist bypass permits unauthorized GROUP dispatch Moderate
GHSA-534w-2vm4-89xr was published for openclaw (npm) Mar 3, 2026
tdjackey Credited to tdjackey
OpenClaw has Canvas route hardening for mixed-trust deployments Moderate
GHSA-cjv3-m589-v3rx was published for openclaw (npm) Mar 3, 2026
NucleiAv Credited to NucleiAv
OpenClaw's typed sender-key matching for toolsBySender prevents identity-collision policy bypass Moderate
GHSA-wpph-cjgr-7c39 was published for openclaw (npm) Mar 3, 2026
jiseoung Credited to jiseoung
OpenClaw's Signal reaction-only status events could, in limited cases, be enqueued before access checks Moderate
GHSA-792q-qw95-f446 was published for openclaw (npm) Mar 3, 2026
tdjackey Credited to tdjackey
OpenClaw's Nextcloud Talk webhook replay could trigger duplicate inbound processing Moderate
GHSA-r9q5-c7qc-p26w was published for openclaw (npm) Mar 3, 2026
aristorechina Credited to aristorechina
tdjackey Credited to tdjackey
OpenClaw has a BlueBubbles group allowlist mismatch via DM pairing-store fallback Moderate
GHSA-25pw-4h6w-qwvm was published for openclaw (npm) Mar 3, 2026
tdjackey Credited to tdjackey
OpenClaw has exec allowlist/safeBins policy-runtime mismatch via env -S wrapper interpretation Moderate
GHSA-796m-2973-wc5q was published for openclaw (npm) Mar 3, 2026
jiseoung Credited to jiseoung
OpenClaw's browser-origin WebSocket auth hardening gap could enable loopback password brute-force chains Moderate
GHSA-jmmg-jqc7-5qf4 was published for openclaw (npm) Mar 3, 2026
luz-oasis Credited to luz-oasis
AnthonyDiSanti Credited to AnthonyDiSanti and vincentkoc vincentkoc vincentkoc
OpenClaw has a workspace-only sandbox guard mismatch for @-prefixed absolute paths Moderate
GHSA-27cr-4p5m-74rj was published for openclaw (npm) Mar 3, 2026
tdjackey Credited to tdjackey
OpenClaw has stored XSS in exported session HTML viewer via markdown/raw-HTML rendering Moderate
GHSA-r294-2894-92j3 was published for openclaw (npm) Mar 3, 2026
allsmog Credited to allsmog
ProTip! Advisories are also available from the GraphQL API