Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

5,215 advisories

Loading
fetch(url) leads to a memory leak in undici Moderate
CVE-2024-24750 was published for undici (npm) Feb 16, 2024
mcollina Credited to mcollina
MeshCentral cross-site websocket hijacking (CSWSH) vulnerability High
CVE-2024-26135 was published for meshcentral (npm) Feb 21, 2024
Cross-site Scripting in electron-pdf High
CVE-2024-1648 was published for electron-pdf (npm) Feb 20, 2024
Protocol-Relative URL Injection via Single Backslash Bypass in Angular SSR Moderate
CVE-2026-33397 was published for @angular/ssr (npm) Mar 19, 2026
VenkatKwest Credited to VenkatKwest, alan-agius4, securityMB, josephperrott, and AndrewKushnir alan-agius4 alan-agius4
securityMB securityMB josephperrott josephperrott AndrewKushnir AndrewKushnir
EthanKim88 Credited to EthanKim88 and igalklebanov igalklebanov igalklebanov
OpenClaw: Browser control startup could continue unauthenticated after auth bootstrap failure Moderate
CVE-2026-32041 was published for openclaw (npm) Mar 2, 2026
OpenClaw Vulnerable to HTML injection via unvalidated image MIME type in data-URL interpolation Moderate
CVE-2026-32040 was published for openclaw (npm) Mar 3, 2026
allsmog Credited to allsmog
OpenClaw's typed sender-key matching for toolsBySender prevents identity-collision policy bypass Moderate
CVE-2026-32039 was published for openclaw (npm) Mar 3, 2026
jiseoung Credited to jiseoung
OpenClaw has a sandbox network isolation bypass via docker.network=container:<id> Moderate
CVE-2026-32038 was published for openclaw (npm) Mar 2, 2026
tdjackey Credited to tdjackey
OpenClaw's MSTeams attachment redirect handling could bypass configured media host allowlists High
CVE-2026-32037 was published for openclaw (npm) Mar 3, 2026
tdjackey Credited to tdjackey
zpbrent Credited to zpbrent
tdjackey Credited to tdjackey
OpenClaw has an opt-in insecure Control UI auth over plaintext HTTP could allow privileged access Moderate
CVE-2026-32034 was published for openclaw (npm) Mar 3, 2026
Vasco0x4 Credited to Vasco0x4
OpenClaw has a workspace-only sandbox guard mismatch for @-prefixed absolute paths Moderate
CVE-2026-32033 was published for openclaw (npm) Mar 3, 2026
tdjackey Credited to tdjackey
OpenClaw's shell env fallback trusts unvalidated SHELL path from host environment Moderate
CVE-2026-32032 was published for openclaw (npm) Mar 3, 2026
athuljayaram Credited to athuljayaram
OpenClaw: /api/channels gateway-auth boundary bypass via path canonicalization mismatch Moderate
CVE-2026-32031 was published for openclaw (npm) Mar 12, 2026
tdjackey Credited to tdjackey
OpenClaw vulnerable to sensitive file disclosure via stageSandboxMedia High
CVE-2026-32030 was published for openclaw (npm) Mar 3, 2026
zpbrent Credited to zpbrent
AnthonyDiSanti Credited to AnthonyDiSanti and vincentkoc vincentkoc vincentkoc
OpenClaw: Discord DM reaction ingress missed dmPolicy/allowFrom checks in restricted setups Moderate
CVE-2026-32028 was published for openclaw (npm) Mar 3, 2026
tdjackey Credited to tdjackey
OpenClaw DM pairing-store identities could satisfy group allowlist authorization Moderate
CVE-2026-32027 was published for openclaw (npm) Mar 3, 2026
tdjackey Credited to tdjackey
Temporary path handling could write outside OpenClaw temp boundary Moderate
CVE-2026-32026 was published for openclaw (npm) Mar 3, 2026
tdjackey Credited to tdjackey
luz-oasis Credited to luz-oasis
OpenClaw's avatar symlink traversal can expose out-of-workspace local files Moderate
CVE-2026-32024 was published for openclaw (npm) Mar 3, 2026
tdjackey Credited to tdjackey
tdjackey Credited to tdjackey
OpenClaw safeBins grep -e File Read Bypass (stdin-only policy bypass) Moderate
CVE-2026-32022 was published for openclaw (npm) Mar 3, 2026
athuljayaram Credited to athuljayaram
ProTip! Advisories are also available from the GraphQL API