Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

50 advisories

Loading
NLTK: Uncontrolled search path when invoking the Graphviz 'dot' binary High
CVE-2026-78680 was published for nltk (pip) Sep 1, 2026
PraisonAI workflow include bypasses tools.py autoload opt-in and executes included recipe code High
CVE-2026-55522 was published for PraisonAI (pip) Aug 25, 2026
rexpository Credited to rexpository
Duplicate Advisory: Uncontrolled search path when invoking the Graphviz 'dot' binary (CWE-426/CWE-427) High
GHSA-54xp-3ww7-6wjg was published for nltk (pip) Aug 25, 2026 withdrawn
AWS-JDBC Wrapper: Privilege Escalation in Aurora PostgreSQL instance High
CVE-2026-11400 was published for software.amazon.jdbc:aws-advanced-jdbc-wrapper (Maven) Jul 17, 2026
ph0smet Credited to ph0smet
OpenClaw: Workspace .env could override Homebrew executable selection for skill install flows High
CVE-2026-53819 was published for openclaw (npm) Jul 2, 2026
feynman-hou Credited to feynman-hou
OpenClaw: Workspace-derived service PATH could influence trash command selection High
CVE-2026-53865 was published for openclaw (npm) Jun 18, 2026
OpenClaw: Workspace .env STATE_DIRECTORY could influence bundled runtime dependency roots High
CVE-2026-53858 was published for openclaw (npm) Jun 18, 2026
feynman-hou Credited to feynman-hou
OpenClaw: Workspace .env npm_execpath could influence bundled runtime dependency install High
CVE-2026-53846 was published for openclaw (npm) Jun 18, 2026
feynman-hou Credited to feynman-hou
OpenClaw: Workspace .env CLOUDSDK_PYTHON could influence Gmail setup gcloud execution High
CVE-2026-53842 was published for openclaw (npm) Jun 18, 2026
feynman-hou Credited to feynman-hou
Duplicate Advisory: Workspace-derived service PATH could influence trash command selection High
GHSA-2w22-3f6x-3hf4 was published for openclaw (npm) Jun 16, 2026 withdrawn
Duplicate Advisory: Workspace .env STATE_DIRECTORY could influence bundled runtime dependency roots High
GHSA-4qgr-57jq-93vh was published for openclaw (npm) Jun 16, 2026 withdrawn
Duplicate Advisory: Workspace .env npm_execpath could influence bundled runtime dependency install High
GHSA-qp5j-jr73-m2pw was published for openclaw (npm) Jun 16, 2026 withdrawn
Duplicate Advisory: Workspace .env CLOUDSDK_PYTHON could influence Gmail setup gcloud execution High
GHSA-9fr2-p65v-gqxq was published for openclaw (pip) Jun 16, 2026 withdrawn
sondt99 Credited to sondt99 and dungNHVhust dungNHVhust dungNHVhust
AWS Advanced Go Wrapper has Privilege Escalation in Aurora PostgreSQL instance High
CVE-2026-11401 was published for github.com/aws/aws-advanced-go-wrapper/auth-helpers (Go) Jun 11, 2026
ph0smet Credited to ph0smet
ouroboros-ai Vulnerable to Remote Code Execution via Untrusted Project-Directory .env High
CVE-2026-47211 was published for ouroboros-ai (pip) May 29, 2026
qerogram Credited to qerogram
uutils coreutils has an Untrusted Search Path High
CVE-2026-35368 was published for coreutils (Rust) Apr 22, 2026
PraisonAI Vulnerable to RCE via Automatic tools.py Import High
CVE-2026-40287 was published for PraisonAI (pip) Apr 10, 2026
l3tchupkt Credited to l3tchupkt
PraisonAI Vulnerable to Implicit Execution of Arbitrary Code via Automatic `tools.py` Loading High
CVE-2026-40156 was published for praisonai (pip) Apr 10, 2026
l3tchupkt Credited to l3tchupkt
opentelemetry-go: BSD kenv command not using absolute path enables PATH hijacking High
CVE-2026-39883 was published for go.opentelemetry.io/otel/sdk (Go) Apr 8, 2026
kodareef5 Credited to kodareef5 and dmathieu dmathieu dmathieu
YLChen-007 Credited to YLChen-007
OpenClaw has an Arbitrary Malicious Code Execution Vulnerability High
CVE-2026-35641 was published for openclaw (npm) Mar 30, 2026
ChangeYourWay Credited to ChangeYourWay
OpenClaw's `tools.exec.safeBins` PATH-hijack allowed trojan binaries to bypass allowlist checks High
CVE-2026-32015 was published for openclaw (npm) Mar 3, 2026
jackhax Credited to jackhax
OpenClaw: safeBins static default trusted dirs allow writable-dir binary hijack (`jq`) High
CVE-2026-32009 was published for openclaw (npm) Mar 3, 2026
tdjackey Credited to tdjackey
OpenClaw's shell env fallback trusts unvalidated SHELL path from host environment High
CVE-2026-32032 was published for openclaw (npm) Mar 3, 2026
athuljayaram Credited to athuljayaram
ProTip! Advisories are also available from the GraphQL API