Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

1,740 advisories

Loading
Directus version number disclosure Moderate
CVE-2024-27296 was published for directus (npm) Mar 1, 2024
Nteract Remote Code Execution vulnerability Moderate
CVE-2024-22891 was published for nteract (npm) Mar 1, 2024
OpenClaw's avatar symlink traversal can expose out-of-workspace local files Moderate
CVE-2026-32024 was published for openclaw (npm) Mar 3, 2026
tdjackey Credited to tdjackey
tdjackey Credited to tdjackey
OpenClaw has allowlist exec-guard bypass via env -S Moderate
CVE-2026-31992 was published for openclaw (npm) Mar 3, 2026
tdjackey Credited to tdjackey
h3 has an observable timing discrepancy in basic auth utils Moderate
CVE-2026-33129 was published for h3 (npm) Mar 18, 2026
simonkoeck Credited to simonkoeck
SSRF in @aborruso/ckan-mcp-server via base_url allows access to internal networks Moderate
CVE-2026-33060 was published for @aborruso/ckan-mcp-server (npm) Mar 18, 2026
abcgco Credited to abcgco
OpenClaw Vulnerable to HTML injection via unvalidated image MIME type in data-URL interpolation Moderate
CVE-2026-32040 was published for openclaw (npm) Mar 3, 2026
allsmog Credited to allsmog
OpenClaw: Browser control startup could continue unauthenticated after auth bootstrap failure Moderate
CVE-2026-32041 was published for openclaw (npm) Mar 2, 2026
tdjackey Credited to tdjackey
OpenClaw's Node role device-identity bypass allows unauthorized node.event injection Moderate
CVE-2026-32001 was published for openclaw (npm) Mar 3, 2026
tdjackey Credited to tdjackey
AnthonyDiSanti Credited to AnthonyDiSanti and vincentkoc vincentkoc vincentkoc
luz-oasis Credited to luz-oasis
OpenClaw exec allowlist safeBins short-option bypass could permit arbitrary file write Moderate
CVE-2026-32017 was published for openclaw (npm) Mar 3, 2026
FailButWin Credited to FailButWin and Redgrave961 Redgrave961 Redgrave961
OpenClaw has encoded-path auth bypass in plugin `/api/channels` route classification Moderate
CVE-2026-32004 was published for openclaw (npm) Mar 3, 2026
tdjackey Credited to tdjackey
OpenClaw: Discord DM reaction ingress missed dmPolicy/allowFrom checks in restricted setups Moderate
CVE-2026-32028 was published for openclaw (npm) Mar 3, 2026
tdjackey Credited to tdjackey
OpenClaw has pre-auth webhook body parsing that can enable unauthenticated slow-request DoS Moderate
CVE-2026-32011 was published for openclaw (npm) Mar 3, 2026
GCXWLP Credited to GCXWLP
OpenClaw DM pairing-store identities could satisfy group allowlist authorization Moderate
CVE-2026-32027 was published for openclaw (npm) Mar 3, 2026
tdjackey Credited to tdjackey
Temporary path handling could write outside OpenClaw temp boundary Moderate
CVE-2026-32026 was published for openclaw (npm) Mar 3, 2026
tdjackey Credited to tdjackey
Vulnogram contains a stored cross-site scripting vulnerability in comment hypertext handling Moderate
CVE-2026-32774 was published for vulnogram (npm) Mar 16, 2026
restriction Credited to restriction
restriction Credited to restriction
Parse Server has a protected field change detection oracle via LiveQuery watch parameter Moderate
CVE-2026-33429 was published for parse-server (npm) Mar 20, 2026
restriction Credited to restriction and mtrezza mtrezza mtrezza
PDFME has SSRF via Unvalidated URL Fetch in `getB64BasePdf` When `basePdf` Is Attacker-Controlled Moderate
GHSA-pgx6-7jcq-2qff was published for @pdfme/common (npm) Mar 20, 2026
restriction Credited to restriction
PDFME has XSS via Unsanitized i18n Label Injection into innerHTML in multiVariableText propPanel Moderate
GHSA-xgx4-2wgv-4jhm was published for @pdfme/schemas (npm) Mar 20, 2026
restriction Credited to restriction
ProTip! Advisories are also available from the GraphQL API