GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
47
GitHub Actions
48
Go
3,378
Maven
5,000+
npm
5,000+
NuGet
881
pip
4,573
Pub
13
RubyGems
1,013
Rust
1,205
Swift
51
Unreviewed advisories
All unreviewed
5,000+
1,171 advisories
Filter by severity
Duplicate Advisory: `OpenClaw: session_status` let sandboxed subagents access parent or sibling session state
Critical
GHSA-hh43-q692-2xmq
was published
for
openclaw
(npm)
Mar 29, 2026
•
withdrawn
OpenClaw has a CWD `.env` environment variable injection which bypasses host-env policy and allows config takeover
Critical
GHSA-8rh7-6779-cjqq
was published
for
openclaw
(npm)
Apr 1, 2026
OpenClaw's incomplete host env sanitization blocklist allows supply-chain redirection via package-manager env overrides
Critical
GHSA-j7p2-qcwm-94v4
was published
for
openclaw
(npm)
Mar 31, 2026
parse-server has cloud function validator bypass via prototype chain traversal
Critical
CVE-2026-34532
was published
for
parse-server
(npm)
Mar 31, 2026
textract is vulnerable to OS Command Injection
Critical
CVE-2026-26831
was published
for
textract
(npm)
Mar 25, 2026
thumbler allows OS Command Injection
Critical
CVE-2026-26833
was published
for
thumbler
(npm)
Mar 25, 2026
MikroORM is vulnerable to SQL Injection via specially crafted object
Critical
CVE-2026-34220
was published
for
@mikro-orm/core
(npm)
Mar 29, 2026
NocoBase Affected by Sandbox Escape to RCE via console._stdout Prototype Chain Traversal in Workflow Script Node
Critical
CVE-2026-34156
was published
for
@nocobase/plugin-workflow-javascript
(npm)
Mar 30, 2026
n8n has Multiple Remote Code Execution Vulnerabilities in Merge Node AlaSQL SQL Mode
Critical
CVE-2026-33660
was published
for
n8n
(npm)
Mar 25, 2026
jsrsasign: Incomplete Comparison Allows DSA Private Key Recovery via Biased Nonce Generation
Critical
CVE-2026-4599
was published
for
jsrsasign
(npm)
Mar 23, 2026
mppx has multiple payment bypass and griefing vulnerabilities
Critical
GHSA-8x4m-qw58-3pcx
was published
for
mppx
(npm)
Mar 29, 2026
OpenClaw: Silent privilege escalation via gateway shared-auth reconnect
Critical
GHSA-fqw4-mph7-2vr8
was published
for
openclaw
(npm)
Mar 27, 2026
OpenClaw: Gateway Backend Reconnect lets Non-Admin Operator Scopes Self-Claim operator.admin
Critical
GHSA-9hjh-fr4f-gxc4
was published
for
openclaw
(npm)
Mar 27, 2026
Handlebars.js has JavaScript Injection via AST Type Confusion
Critical
CVE-2026-33937
was published
for
handlebars
(npm)
Mar 27, 2026
node-tesseract-ocr is vulnerable to OS Command Injection through unsanitized recognize() function parameter
Critical
CVE-2026-26832
was published
for
node-tesseract-ocr
(npm)
Mar 25, 2026
pdf-image has an OS Command Injection Vulnerability through its pdfFilePath parameter
Critical
CVE-2026-26830
was published
for
pdf-image
(npm)
Mar 25, 2026
OpenClaw Gateway: RCE and Privilege Escalation from operator.pairing to operator.admin via device.pair.approve
Critical
GHSA-hf68-49fm-59cq
was published
for
openclaw
(npm)
Mar 26, 2026
Convict has Prototype Pollution via startsWith() function
Critical
CVE-2026-33864
was published
for
convict
(npm)
Mar 26, 2026
Convict has prototype pollution via load(), loadFile(), and schema initialization
Critical
CVE-2026-33863
was published
for
convict
(npm)
Mar 26, 2026
n8n: Prototype Pollution in XML and GSuiteAdmin node parameters lead to RCE
Critical
CVE-2026-33696
was published
for
n8n
(npm)
Mar 26, 2026
ZDI-CAN-19105: Parse Server literalizeRegexPart SQL Injection
Critical
CVE-2024-27298
was published
for
parse-server
(npm)
Mar 1, 2024
agent-js: Insecure Key Generation in `Ed25519KeyIdentity.generate`
Critical
CVE-2024-1631
was published
for
@dfinity/auth-client
(npm)
Feb 21, 2024
OpenClaw gateway agents.files symlink escape allowed out-of-workspace file read/write
Critical
CVE-2026-32013
was published
for
openclaw
(npm)
Mar 2, 2026
CpenClaw's ACPX Windows wrapper shell fallback allowed cwd injection in specific paths
Critical
CVE-2026-31999
was published
for
openclaw
(npm)
Mar 2, 2026
ProTip!
Advisories are also available from the
GraphQL API