GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
47
GitHub Actions
48
Go
3,377
Maven
5,000+
npm
5,000+
NuGet
881
pip
4,573
Pub
13
RubyGems
1,013
Rust
1,205
Swift
51
Unreviewed advisories
All unreviewed
5,000+
9,909 advisories
Filter by severity
xmldom: XML injection via unsafe CDATA serialization allows attacker-controlled markup insertion
High
CVE-2026-34601
was published
for
@xmldom/xmldom
(npm)
Apr 1, 2026
Ash.Type.Module.cast_input/2 atom exhaustion via unchecked Module.concat allows BEAM VM crash
High
CVE-2026-34593
was published
for
ash
(Erlang)
Apr 1, 2026
YesWiki has Persistant Blind XSS at "/?BazaR&vue=consulter"
High
CVE-2026-34598
was published
for
yeswiki/yeswiki
(Composer)
Apr 1, 2026
`OpenClaw: session_status` let sandboxed subagents access parent or sibling session state
High
CVE-2026-32918
was published
for
openclaw
(npm)
Mar 13, 2026
OpenClaw Telegram webhook request bodies were read before secret validation, enabling unauthenticated resource exhaustion
High
CVE-2026-32980
was published
for
openclaw
(npm)
Mar 16, 2026
Duplicate Advisory: OpenClaw Telegram webhook request bodies were read before secret validation, enabling unauthenticated resource exhaustion
High
GHSA-c447-w54g-f55j
was published
for
openclaw
(npm)
Mar 29, 2026
•
withdrawn
SiYuan Desktop: Stored XSS in imported .sy.zip content leads to arbitrary command execution
High
CVE-2026-34585
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Apr 1, 2026
TorchGeo Remote Code Execution Vulnerability
High
CVE-2024-49048
was published
for
torchgeo
(pip)
Apr 1, 2026
Duplicate Advisory: TorchGeo Remote Code Execution Vulnerability
High
GHSA-g5vp-j278-8pjh
was published
for
torchgeo
(pip)
Nov 12, 2024
•
withdrawn
OpenClaw gateway exec allow-always over-trusts positional carrier executables
High
GHSA-p4x4-2r7f-wjxg
was published
for
openclaw
(npm)
Apr 1, 2026
OpenClaw Gateway `operator.write` can reach admin-only session reset via `chat.send` `/reset`
High
GHSA-5r8f-96gm-5j6g
was published
for
openclaw
(npm)
Apr 1, 2026
OpenClaw has a gateway exec allowlist allow-always bypass via unregistered /usr/bin/script wrapper
High
GHSA-6pfc-6m7w-m8fx
was published
for
openclaw
(npm)
Mar 31, 2026
OpenClaw: Gateway chat.send ACP-only provenance guard could be bypassed by client identity spoofing
High
GHSA-6xg4-82hv-cp6f
was published
for
openclaw
(npm)
Mar 31, 2026
OpenClaw: Gateway `operator.write` can reach admin-only persisted `verboseLevel` via `chat.send` `/verbose`
High
GHSA-5h2w-qmfp-ggp6
was published
for
openclaw
(npm)
Mar 31, 2026
OpenClaw safeBins jq `$ENV` filter bypass allows environment variable disclosure
High
GHSA-jccr-rrw2-vc8h
was published
for
openclaw
(npm)
Mar 31, 2026
OpenClaw's message tool media parameter bypasses tool policy filesystem isolation
High
CVE-2026-33581
was published
for
openclaw
(npm)
Mar 31, 2026
Duplicate Advisory: OpenClaw's message tool media parameter bypasses tool policy filesystem isolation
High
GHSA-3gr8-2752-h46q
was published
for
openclaw
(npm)
Mar 31, 2026
•
withdrawn
OpenClaw: Discord text `/approve` bypasses `channels.discord.execApprovals.approvers` and allows non-approvers to resolve pending exec approvals
High
GHSA-98hh-7ghg-x6rq
was published
for
openclaw
(npm)
Mar 31, 2026
OpenClaw's device removal and token revocation do not terminate active WebSocket sessions
High
CVE-2026-34503
was published
for
openclaw
(npm)
Mar 31, 2026
Duplicate Advisory: OpenClaw's device removal and token revocation do not terminate active WebSocket sessions
High
GHSA-89hr-6x2p-8xjv
was published
for
openclaw
(npm)
Mar 31, 2026
•
withdrawn
OpenClaw: CLI Remote Onboarding Persists Unauthenticated Discovery Endpoint and Exfiltrates Gateway Credentials
High
GHSA-3cw3-5vxw-g2h3
was published
for
openclaw
(npm)
Mar 31, 2026
OpenClaw: /pair approve command path omitted caller scope subsetting and reopened device pairing escalation
High
GHSA-hc5h-pmr3-3497
was published
for
openclaw
(npm)
Mar 31, 2026
OpenClaw: Voice-call Plivo V3 webhook replay key uses unsorted URL, allowing replay via query-parameter reordering
High
GHSA-8689-gm9g-jgr6
was published
for
openclaw
(npm)
Mar 31, 2026
parse-server has GraphQL complexity validator exponential fragment traversal DoS
High
CVE-2026-34573
was published
for
parse-server
(npm)
Mar 31, 2026
File Browser's Signup Grants Execution Permissions When Default Permissions Includes Execution
High
CVE-2026-34528
was published
for
github.com/filebrowser/filebrowser/v2
(Go)
Mar 31, 2026
ProTip!
Advisories are also available from the
GraphQL API