Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

350 advisories

Loading
OpenClaw: Zalo replay dedupe cache could suppress events across authenticated webhook targets Low
GHSA-fqrj-m88p-qf3v was published for openclaw (npm) Apr 7, 2026
nexrin Credited to nexrin
OpenClaw: Gateway operator.write Can Reach Admin-Class Telegram Config and Cron Persistence via send Low
GHSA-767m-xrhc-fxm7 was published for openclaw (npm) Apr 7, 2026
zpbrent Credited to zpbrent
tdjackey Credited to tdjackey
Duplicate Advisory: OpenClaw: Unavailable local auth SecretRefs could fall through to remote credentials in local mode Low
GHSA-vm29-7mq3-9jrg was published for OpenClaw (npm) Mar 31, 2026 withdrawn
Electron: Crash in clipboard.readImage() on malformed clipboard image data Low
CVE-2026-34781 was published for electron (npm) Apr 7, 2026
frostb1ten Credited to frostb1ten
Parse Server: File upload Content-Type override via extension mismatch Low
CVE-2026-35200 was published for parse-server (npm) Apr 4, 2026
offset Credited to offset and mtrezza mtrezza mtrezza
Electron: Use-after-free in offscreen shared texture release() callback Low
CVE-2026-34764 was published for electron (npm) Apr 3, 2026
daffainfo Credited to daffainfo
Electron: Unquoted executable path in app.setLoginItemSettings on Windows Low
CVE-2026-34768 was published for electron (npm) Apr 3, 2026
Electron: USB device selection not validated against filtered device list Low
CVE-2026-34766 was published for electron (npm) Apr 3, 2026
OpenClaw: Voice-call Plivo replay mutates in-process callback origin before replay rejection Low
GHSA-89r3-6x4j-v7wf was published for openclaw (npm) Apr 2, 2026
zsxsoft Credited to zsxsoft and KeenSecurityLab KeenSecurityLab KeenSecurityLab
OpenClaw affected by SSRF via unguarded image download in fal provider Low
CVE-2026-34504 was published for openclaw (npm) Apr 1, 2026
AntAISecurityLab Credited to AntAISecurityLab
zsxsoft Credited to zsxsoft and KeenSecurityLab KeenSecurityLab KeenSecurityLab
@elgentos/magento2-dev-mcp vulnerable to command injection Low
CVE-2026-5603 was published for @elgentos/magento2-dev-mcp (npm) Apr 6, 2026
@nor2/heim-mcp vulnerable to command injection Low
CVE-2026-5602 was published for @nor2/heim-mcp (npm) Apr 6, 2026
fast-filesystem-mcp is vulnerable to command injection through handleGetDiskUsage function Low
CVE-2026-5327 was published for fast-filesystem-mcp (npm) Apr 2, 2026
a11y-mcp: Server-Side Request Forgery (SSRF) vulnerability in A11yServer function Low
CVE-2026-5323 was published for a11y-mcp (npm) Apr 2, 2026
Signal K Server: Arbitrary Prototype Read via `from` Field Bypass Low
CVE-2026-35038 was published for signalk-server (npm) Apr 3, 2026
VashuVats Credited to VashuVats
cyjhhh Credited to cyjhhh
OpenClaw: Tlon Startup Migration Rehydrates Empty-Array Revocations From File Config Low
GHSA-3pm9-5j7m-59vc was published for openclaw (npm) Apr 3, 2026
smaeljaish771 Credited to smaeljaish771
OpenClaw: Telnyx Webhook Replay Detection Bypass via Base64 Signature Re-encoding Low
GHSA-37v6-fxx8-xjmx was published for openclaw (npm) Apr 3, 2026
AntAISecurityLab Credited to AntAISecurityLab
TeleJSON: DOM XSS via unsanitised constructor name in `new Function()` Low
GHSA-ccgf-5rwj-j3hv was published for telejson (npm) Apr 2, 2026
Niccolo10 Credited to Niccolo10
OpenClaw: Security Scan Failure Does Not Block Plugin Installation (Fail-Open) Low
GHSA-cwq8-6f96-g3q4 was published for openclaw (npm) Apr 2, 2026
davidluzsilva Credited to davidluzsilva
OpenClaw: MSTeams thread history bypasses sender allowlist via Graph API Low
GHSA-chfm-xgc4-47rj was published for openclaw (npm) Apr 2, 2026
AntAISecurityLab Credited to AntAISecurityLab
OpenClaw: Matrix thread root and reply context bypass sender allowlist Low
GHSA-rg8m-3943-vm6q was published for openclaw (npm) Apr 2, 2026
AntAISecurityLab Credited to AntAISecurityLab
ProTip! Advisories are also available from the GraphQL API