Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

9,909 advisories

Loading
xmldom: XML injection via unsafe CDATA serialization allows attacker-controlled markup insertion High
CVE-2026-34601 was published for @xmldom/xmldom (npm) Apr 1, 2026
thesmartshadow Credited to thesmartshadow
fg0x0 Credited to fg0x0 and zachdaniel zachdaniel zachdaniel
YesWiki has Persistant Blind XSS at "/?BazaR&vue=consulter" High
CVE-2026-34598 was published for yeswiki/yeswiki (Composer) Apr 1, 2026
kh0kamoni Credited to kh0kamoni
`OpenClaw: session_status` let sandboxed subagents access parent or sibling session state High
CVE-2026-32918 was published for openclaw (npm) Mar 13, 2026
tdjackey Credited to tdjackey
space08 Credited to space08
SiYuan Desktop: Stored XSS in imported .sy.zip content leads to arbitrary command execution High
CVE-2026-34585 was published for github.com/siyuan-note/siyuan/kernel (Go) Apr 1, 2026
ngocnn97 Credited to ngocnn97
TorchGeo Remote Code Execution Vulnerability High
CVE-2024-49048 was published for torchgeo (pip) Apr 1, 2026
zpbrent Credited to zpbrent, calebrob6, and adamjstewart calebrob6 calebrob6
adamjstewart adamjstewart
Duplicate Advisory: TorchGeo Remote Code Execution Vulnerability High
GHSA-g5vp-j278-8pjh was published for torchgeo (pip) Nov 12, 2024 withdrawn
OpenClaw gateway exec allow-always over-trusts positional carrier executables High
GHSA-p4x4-2r7f-wjxg was published for openclaw (npm) Apr 1, 2026
OpenClaw Gateway `operator.write` can reach admin-only session reset via `chat.send` `/reset` High
GHSA-5r8f-96gm-5j6g was published for openclaw (npm) Apr 1, 2026
zpbrent Credited to zpbrent
OpenClaw has a gateway exec allowlist allow-always bypass via unregistered /usr/bin/script wrapper High
GHSA-6pfc-6m7w-m8fx was published for openclaw (npm) Mar 31, 2026
LonggTeng Credited to LonggTeng
OpenClaw: Gateway chat.send ACP-only provenance guard could be bypassed by client identity spoofing High
GHSA-6xg4-82hv-cp6f was published for openclaw (npm) Mar 31, 2026
zpbrent Credited to zpbrent
zpbrent Credited to zpbrent
OpenClaw safeBins jq `$ENV` filter bypass allows environment variable disclosure High
GHSA-jccr-rrw2-vc8h was published for openclaw (npm) Mar 31, 2026
nicky-cc Credited to nicky-cc
OpenClaw's message tool media parameter bypasses tool policy filesystem isolation High
CVE-2026-33581 was published for openclaw (npm) Mar 31, 2026
AntAISecurityLab Credited to AntAISecurityLab
Duplicate Advisory: OpenClaw's message tool media parameter bypasses tool policy filesystem isolation High
GHSA-3gr8-2752-h46q was published for openclaw (npm) Mar 31, 2026 withdrawn
OpenClaw's device removal and token revocation do not terminate active WebSocket sessions High
CVE-2026-34503 was published for openclaw (npm) Mar 31, 2026
AntAISecurityLab Credited to AntAISecurityLab
Duplicate Advisory: OpenClaw's device removal and token revocation do not terminate active WebSocket sessions High
GHSA-89hr-6x2p-8xjv was published for openclaw (npm) Mar 31, 2026 withdrawn
nexrin Credited to nexrin
AntAISecurityLab Credited to AntAISecurityLab
zsxsoft Credited to zsxsoft
parse-server has GraphQL complexity validator exponential fragment traversal DoS High
CVE-2026-34573 was published for parse-server (npm) Mar 31, 2026
bugbunny-research Credited to bugbunny-research and mtrezza mtrezza mtrezza
File Browser's Signup Grants Execution Permissions When Default Permissions Includes Execution High
CVE-2026-34528 was published for github.com/filebrowser/filebrowser/v2 (Go) Mar 31, 2026
offset Credited to offset
ProTip! Advisories are also available from the GraphQL API