GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
46
GitHub Actions
48
Go
3,343
Maven
5,000+
npm
5,000+
NuGet
881
pip
4,550
Pub
12
RubyGems
1,013
Rust
1,203
Swift
51
Unreviewed advisories
All unreviewed
5,000+
321 advisories
Filter by severity
Parse Server has an MFA single-use token bypass via concurrent authData login requests
Low
CVE-2026-34224
was published
for
parse-server
(npm)
Mar 29, 2026
Trix is vulnerable to XSS through JSON deserialization bypass in drag-and-drop (Level0InputController)
Low
GHSA-53p3-c7vp-4mcc
was published
for
action_text-trix
(RubyGems)
Mar 29, 2026
Handlebars.js has a Property Access Validation Bypass in container.lookup
Low
GHSA-442j-39wm-28r2
was published
for
handlebars
(npm)
Mar 29, 2026
Parse Server: MFA recovery code single-use bypass via concurrent requests
Low
CVE-2026-33624
was published
for
parse-server
(npm)
Mar 24, 2026
h3: Missing Path Segment Boundary Check in `mount()` Causes Middleware Execution on Unrelated Prefix-Matching Routes
Low
CVE-2026-33490
was published
for
h3
(npm)
Mar 20, 2026
Nodemailer has SMTP command injection due to unsanitized `envelope.size` parameter
Low
GHSA-c7w3-x93f-qmm8
was published
for
nodemailer
(npm)
Mar 26, 2026
OpenClaw: Tlon settings empty-allowlist reconciliation bypassed intended revocation
Low
GHSA-pw7h-9g6p-c378
was published
for
openclaw
(npm)
Mar 26, 2026
Astro: Remote allowlist bypass via unanchored matchPathname wildcard
Low
CVE-2026-33769
was published
for
astro
(npm)
Mar 26, 2026
Next.js: null origin can bypass dev HMR websocket CSRF checks
Low
CVE-2026-27977
was published
for
next
(npm)
Mar 17, 2026
@grackle-ai/server JSON.parse lacks try-catch logic in its gRPC Service AdapterConfig Handling
Low
GHSA-8g29-8xwr-qmhr
was published
for
@grackle-ai/server
(npm)
Mar 25, 2026
@grackle-ai/server has a Missing Secure Flag on Session Cookie
Low
GHSA-5j35-xr4g-vwf4
was published
for
@grackle-ai/server
(npm)
Mar 25, 2026
@grackle-ai/server: Unescaped Error String in renderPairingPage() HTML Template
Low
GHSA-7q9x-8g6p-3x75
was published
for
@grackle-ai/server
(npm)
Mar 25, 2026
Duplicate Advisory: OpenClaw Node system.run approval context-binding weakness in approval-enabled host=node flows
Low
GHSA-cjq8-m7wj-xmq9
was published
for
openclaw
(npm)
Mar 21, 2026
•
withdrawn
OpenClaw reuses the gateway auth token in the owner ID prompt hashing fallback
Low
CVE-2026-32897
was published
for
openclaw
(npm)
Mar 3, 2026
Duplicate Advisory: OpenClaw reuses the gateway auth token in the owner ID prompt hashing fallback
Low
GHSA-8mr2-f9wf-hcfq
was published
for
openclaw
(npm)
Mar 21, 2026
•
withdrawn
Potential leakage of Sentry auth tokens by React Native SDK with Expo plugin
Low
GHSA-68c2-4mpx-qh95
was published
for
@sentry/react-native
(npm)
Mar 1, 2024
OpenClaw has Signal group allowlist authorization bypass via DM pairing-store leakage
Low
CVE-2026-31991
was published
for
openclaw
(npm)
Mar 2, 2026
Withdrawn Advisory: Shescape has possible misidentification of shell due to link chains
Low
CVE-2026-30916
was published
for
shescape
(npm)
Mar 7, 2026
•
withdrawn
Duplicate Advisory: Signal group allowlist authorization bypass via DM pairing-store leakage
Low
GHSA-r849-826x-wgqm
was published
for
openclaw
(npm)
Mar 19, 2026
•
withdrawn
OpenClaw's Control UI Static File Handler Follows Symlinks and Allows Out-of-Root File Read
Low
CVE-2026-32020
was published
for
openclaw
(npm)
Mar 2, 2026
OpenClaw safeBins stdin-only bypass via sort output and recursive grep flags
Low
CVE-2026-31996
was published
for
openclaw
(npm)
Feb 19, 2026
OpenClaw macOS companion app (beta): allowlist parsing mismatch for system.run shell chains
Low
CVE-2026-31993
was published
for
openclaw
(npm)
Mar 2, 2026
Parse Server has a password reset token single-use bypass via concurrent requests
Low
CVE-2026-32943
was published
for
parse-server
(npm)
Mar 17, 2026
Duplicate Advisory: safeBins stdin-only bypass via sort output and recursive grep flags
Low
GHSA-ggm6-h3mx-cmmp
was published
for
openclaw
(npm)
Mar 19, 2026
•
withdrawn
OpenClaw's runtime /debug override path accepted prototype-reserved keys
Low
CVE-2026-27524
was published
for
openclaw
(npm)
Mar 3, 2026
ProTip!
Advisories are also available from the
GraphQL API