GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
50
Go
3,623
Maven
5,000+
npm
5,000+
NuGet
927
pip
4,843
Pub
13
RubyGems
1,045
Rust
1,271
Swift
53
Unreviewed advisories
All unreviewed
5,000+
375 advisories
Filter by severity
Keycloak vulnerable to authorization bypass via the Admin API
Low
CVE-2026-2366
was published
for
@keycloak/keycloak-admin-client
(Maven)
Mar 12, 2026
@whyour/qinglong: manipulation of the argument command leads to protection mechanism failure
Low
CVE-2026-3965
was published
for
@whyour/qinglong
(npm)
Mar 12, 2026
OpenClaw: system.run wrapper-depth boundary could skip shell approval gating
Low
CVE-2026-27183
was published
for
openclaw
(npm)
Mar 9, 2026
Withdrawn Advisory: Shescape has possible misidentification of shell due to link chains
Low
CVE-2026-30916
was published
for
shescape
(npm)
Mar 7, 2026
•
withdrawn
Mercurius's queryDepth limit bypassed for WebSocket subscriptions
Low
CVE-2026-30241
was published
for
mercurius
(npm)
Mar 6, 2026
defuddle vulnerable to XSS via unescaped string interpolation in _findContentBySchemaText image tag
Low
CVE-2026-30830
was published
for
defuddle
(npm)
Mar 6, 2026
@backstage/plugin-scaffolder-backend Vulnerable to Potential Session Token Exfiltration via Log Redaction Bypass
Low
CVE-2026-29184
was published
for
@backstage/plugin-scaffolder-backend
(npm)
Mar 5, 2026
Backstage vulnerable to potential reading of SCM URLs using built in token
Low
CVE-2026-29185
was published
for
@backstage/integration
(npm)
Mar 5, 2026
OpenClaw has cross-account DM pairing authorization bypass via unscoped pairing store access
Low
CVE-2026-32067
was published
for
openclaw
(npm)
Mar 4, 2026
Dark Reader gives users the ability to request style sheets from local web servers
Low
CVE-2025-68467
was published
for
darkreader
(npm)
Mar 4, 2026
OpenClaw's tools.exec.safeBins generic fallback allowed interpreter-style inline payload execution in allowlist mode
Low
GHSA-8mf7-vv8w-hjr2
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw reuses the gateway auth token in the owner ID prompt hashing fallback
Low
CVE-2026-32897
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw's voice-call Twilio replay dedupe now bound to authenticated webhook identity
Low
GHSA-gcj7-r3hg-m7w6
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw: Microsoft Teams media fetch paths bypass shared SSRF guard model
Low
GHSA-7qf6-h84j-8fq4
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw's runtime /debug override path accepted prototype-reserved keys
Low
CVE-2026-27524
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw Vulnerable to HTML injection via unvalidated image MIME type in data-URL interpolation
Low
CVE-2026-32040
was published
for
openclaw
(npm)
Mar 3, 2026
@tootallnate/once vulnerable to Incorrect Control Flow Scoping
Low
CVE-2026-3449
was published
for
@tootallnate/once
(npm)
Mar 3, 2026
mailparser vulnerable to Cross-site Scripting
Low
CVE-2026-3455
was published
for
mailparser
(npm)
Mar 3, 2026
OpenClaw Node system.run approval context-binding weakness in approval-enabled host=node flows
Low
CVE-2026-32058
was published
for
openclaw
(npm)
Mar 2, 2026
OpenClaw's Control UI Static File Handler Follows Symlinks and Allows Out-of-Root File Read
Low
CVE-2026-32020
was published
for
openclaw
(npm)
Mar 2, 2026
OpenClaw macOS companion app (beta): allowlist parsing mismatch for system.run shell chains
Low
CVE-2026-31993
was published
for
openclaw
(npm)
Mar 2, 2026
OpenClaw has Signal group allowlist authorization bypass via DM pairing-store leakage
Low
CVE-2026-31991
was published
for
openclaw
(npm)
Mar 2, 2026
NocoDB has Plaintext Storage of Shared View Passwords
Low
CVE-2026-28360
was published
for
nocodb
(npm)
Mar 2, 2026
NocoDB Vulnerable to User Enumeration via Password Reset Endpoint
Low
CVE-2026-28358
was published
for
nocodb
(npm)
Mar 2, 2026
SvelteKit has deserialization expansion in unvalidated `form` remote function leading to Denial of Service (experimental only)
Low
GHSA-fpg4-jhqr-589c
was published
for
@sveltejs/kit
(npm)
Feb 28, 2026
ProTip!
Advisories are also available from the
GraphQL API