Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

5 advisories

Loading
OpenClaw: Forwarding header spoofing bypasses gateway.trustedProxies origin detection Moderate
CVE-2026-35656 was published for openclaw (npm) Mar 26, 2026
lintsinghua Credited to lintsinghua
OpneClaw accepts unsanitized iMessage attachment paths which allowed SCP remote-path command injection High
GHSA-g2f6-pwvx-r275 was published for openclaw (npm) Mar 16, 2026
lintsinghua Credited to lintsinghua
OpenClaw: Feishu webhook mode accepted forged events when only `verificationToken` was configured High
CVE-2026-32974 was published for openclaw (npm) Mar 13, 2026
lintsinghua Credited to lintsinghua
OpenClaw: Workspace plugin auto-discovery allowed code execution from cloned repositories High
CVE-2026-32920 was published for openclaw (npm) Mar 13, 2026
lintsinghua Credited to lintsinghua
lintsinghua Credited to lintsinghua and woreksami woreksami woreksami
ProTip! Advisories are also available from the GraphQL API