Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

1,187 advisories

Loading
Dag-Rui Credited to Dag-Rui
rtvkiz Credited to rtvkiz
fasrm Credited to fasrm and SociableSteve SociableSteve SociableSteve
Axios npm Supply Chain Incident Impacting @usebruno/cli Critical
CVE-2026-34841 was published for @usebruno/cli (npm) Apr 2, 2026
AntAISecurityLab Credited to AntAISecurityLab
SandboxJS: Sandbox integrity escape Critical
CVE-2026-34208 was published for @nyariv/sandboxjs (npm) Apr 3, 2026
fancymalware Credited to fancymalware
OpenClaw: Plugin subagent routes could bypass gateway authorization with synthetic admin scopes Critical
CVE-2026-32916 was published for openclaw (npm) Mar 13, 2026
tdjackey Credited to tdjackey
Duplicate Advisory: OpenClaw: Plugin subagent routes could bypass gateway authorization with synthetic admin scopes Critical
GHSA-phgf-3849-rgjq was published for openclaw (npm) Mar 31, 2026 withdrawn
Duplicate Advisory: OpenClaw: Unrecognized script runners could bypass `system.run` approval integrity Critical
GHSA-rwwx-25m7-ww73 was published for openclaw (npm) Mar 29, 2026 withdrawn
Budibase: Unauthenticated Remote Code Execution via Webhook Trigger and Bash Automation Step Critical
CVE-2026-35216 was published for @budibase/server (npm) Apr 4, 2026
da7om85 Credited to da7om85
Signal K Server: Privilege Escalation by Admin Role Injection via /enableSecurity Critical
CVE-2026-33950 was published for signalk-server (npm) Apr 3, 2026
VashuVats Credited to VashuVats
Budibase: Server-Side Request Forgery via REST Connector with Empty Default Blacklist Critical
CVE-2026-31818 was published for @budibase/backend-core (npm) Apr 3, 2026
Moonster8282 Credited to Moonster8282
Better Auth Has Two-Factor Authentication Bypass via Premature Session Caching (session.cookieCache) Critical
GHSA-xg6x-h9c9-2m83 was published for better-auth (npm) Apr 3, 2026
TriDecent Credited to TriDecent
OpenClaw: Sandbox escape via TOCTOU race in remote FS bridge readFile Critical
GHSA-9p3r-hh9g-5cmg was published for openclaw (npm) Apr 3, 2026
AntAISecurityLab Credited to AntAISecurityLab
OpenClaw: Heartbeat context inheritance bypasses sandbox via senderIsOwner escalation Critical
GHSA-g5cg-8x5w-7jpm was published for openclaw (npm) Apr 2, 2026
AntAISecurityLab Credited to AntAISecurityLab
Axios supply chain attack - dependency in @lightdash/cli may resolve to compromised axios versions Critical
GHSA-3hfp-gqgh-xc5g was published for @lightdash/cli (npm) Apr 2, 2026
Payload has Unvalidated Input in Password Recovery Endpoints Critical
CVE-2026-34751 was published for @payloadcms/graphql (npm) Apr 1, 2026
wsk3r Credited to wsk3r
Duplicate Advisory: `OpenClaw: session_status` let sandboxed subagents access parent or sibling session state Critical
GHSA-hh43-q692-2xmq was published for openclaw (npm) Mar 29, 2026 withdrawn
tdjackey Credited to tdjackey
tdjackey Credited to tdjackey
parse-server has cloud function validator bypass via prototype chain traversal Critical
CVE-2026-34532 was published for parse-server (npm) Mar 31, 2026
mtrezza Credited to mtrezza and bugbunny-research bugbunny-research bugbunny-research
textract is vulnerable to OS Command Injection Critical
CVE-2026-26831 was published for textract (npm) Mar 25, 2026
thumbler allows OS Command Injection Critical
CVE-2026-26833 was published for thumbler (npm) Mar 25, 2026
MikroORM is vulnerable to SQL Injection via specially crafted object Critical
CVE-2026-34220 was published for @mikro-orm/core (npm) Mar 29, 2026
lukas-eu Credited to lukas-eu
NocoBase Affected by Sandbox Escape to RCE via console._stdout Prototype Chain Traversal in Workflow Script Node Critical
CVE-2026-34156 was published for @nocobase/plugin-workflow-javascript (npm) Mar 30, 2026
onurcangnc Credited to onurcangnc
ProTip! Advisories are also available from the GraphQL API