Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

1,633 advisories

Loading
Flowise Vulnerable to PII Disclosure on Unauthenticated Forgot Password Endpoint Moderate
GHSA-jc5m-wrp2-qq38 was published for flowise (npm) Mar 5, 2026
tenbbughunters Credited to tenbbughunters
Flowise has Insufficient Password Salt Rounds Moderate
GHSA-x2g5-fvc2-gqvp was published for flowise (npm) Mar 5, 2026
kolega-ai-dev Credited to kolega-ai-dev
Fastify's Missing End Anchor in "subtypeNameReg" Allows Malformed Content-Types to Pass Validation Moderate
CVE-2026-3419 was published for fastify (npm) Mar 5, 2026
TarPeg007 Credited to TarPeg007, jsumners, mcollina, and UlisesGascon jsumners jsumners
mcollina mcollina UlisesGascon UlisesGascon
Mercurius: Incorrect Content-Type parsing can lead to CSRF attack Moderate
CVE-2025-64166 was published for mercurius (npm) Mar 5, 2026
simone-sanfratello Credited to simone-sanfratello
Hono Vulnerable to Cookie Attribute Injection via Unsanitized domain and path in setCookie() Moderate
CVE-2026-29086 was published for hono (npm) Mar 4, 2026
TarPeg007 Credited to TarPeg007
Hono Vulnerable to SSE Control Field Injection via CR/LF in writeSSE() Moderate
CVE-2026-29085 was published for hono (npm) Mar 4, 2026
TarPeg007 Credited to TarPeg007
OpenClaw: BlueBubbles (optional plugin) pairing/allowlist mismatch when allowFrom is empty Moderate
GHSA-jwf4-8wf4-jf2m was published for openclaw (npm) Mar 4, 2026
tdjackey Credited to tdjackey
OpenClaw Vulnerable to Local File Exfiltration via MCP Tool Result MEDIA: Directive Injection Moderate
GHSA-jjgj-cpp9-cvpv was published for openclaw (npm) Mar 4, 2026
NucleiAv Credited to NucleiAv
tdjackey Credited to tdjackey
OpenClaw has incomplete IPv4 special-use SSRF blocking in web fetch guard Moderate
GHSA-4rqq-w8v4-7p47 was published for openclaw (npm) Mar 4, 2026
princeeismond-dot Credited to princeeismond-dot
OpenClaw has agent avatar symlink traversal in gateway session metadata Moderate
GHSA-9mph-4f7v-fmvh was published for openclaw (npm) Mar 4, 2026
jiseoung Credited to jiseoung
OpenClaw has SSRF guard bypass via IPv6 transition over ISATAP Moderate
GHSA-8cp7-rp8r-mg77 was published for openclaw (npm) Mar 4, 2026
zpbrent Credited to zpbrent
CKEditor 5 has Cross-site Scripting (XSS) in the HTML Support package Moderate
CVE-2026-28343 was published for @ckeditor/ckeditor5-html-support (npm) Mar 4, 2026
OpenClaw's serialize sandbox registry writes to prevent races and delete-rollback corruption Moderate
GHSA-gq83-8q7q-9hfx was published for openclaw (npm) Mar 3, 2026
kexinoh Credited to kexinoh
OpenClaw's Node role device-identity bypass allows unauthorized node.event injection Moderate
GHSA-rv2q-f2h5-6xmg was published for openclaw (npm) Mar 3, 2026
tdjackey Credited to tdjackey
OpenClaw has Windows Lobster shell fallback command injection in constrained fallback path Moderate
GHSA-fg3m-vhrr-8gj6 was published for openclaw (npm) Mar 3, 2026
tdjackey Credited to tdjackey
OpenClaw's Zalo group sender allowlist bypass permits unauthorized GROUP dispatch Moderate
GHSA-534w-2vm4-89xr was published for openclaw (npm) Mar 3, 2026
tdjackey Credited to tdjackey
OpenClaw has Canvas route hardening for mixed-trust deployments Moderate
GHSA-cjv3-m589-v3rx was published for openclaw (npm) Mar 3, 2026
NucleiAv Credited to NucleiAv
OpenClaw's typed sender-key matching for toolsBySender prevents identity-collision policy bypass Moderate
GHSA-wpph-cjgr-7c39 was published for openclaw (npm) Mar 3, 2026
jiseoung Credited to jiseoung
OpenClaw's Signal reaction-only status events could, in limited cases, be enqueued before access checks Moderate
GHSA-792q-qw95-f446 was published for openclaw (npm) Mar 3, 2026
tdjackey Credited to tdjackey
OpenClaw's Nextcloud Talk webhook replay could trigger duplicate inbound processing Moderate
GHSA-r9q5-c7qc-p26w was published for openclaw (npm) Mar 3, 2026
aristorechina Credited to aristorechina
tdjackey Credited to tdjackey
OpenClaw has a BlueBubbles group allowlist mismatch via DM pairing-store fallback Moderate
GHSA-25pw-4h6w-qwvm was published for openclaw (npm) Mar 3, 2026
tdjackey Credited to tdjackey
OpenClaw has exec allowlist/safeBins policy-runtime mismatch via env -S wrapper interpretation Moderate
GHSA-796m-2973-wc5q was published for openclaw (npm) Mar 3, 2026
jiseoung Credited to jiseoung
ProTip! Advisories are also available from the GraphQL API