GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,407
Maven
5,000+
npm
5,000+
NuGet
1,048
pip
5,000+
Pub
13
RubyGems
1,127
Rust
1,498
Swift
61
Unreviewed advisories
All unreviewed
5,000+
13 advisories
Filter by severity
OpenClaw: Feishu dynamic-agent bindings could miss configWrites enforcement
Low
GHSA-3wqp-prf6-2m72
was published
for
openclaw
(npm)
Jul 2, 2026
OpenClaw: Empty-scope device re-pairing could confuse caller scope containment
Low
CVE-2026-53852
was published
for
openclaw
(npm)
Jun 18, 2026
OpenClaw: Skill-command dispatch could skip before-tool-call hooks
Low
CVE-2026-53845
was published
for
openclaw
(npm)
Jun 18, 2026
OpenClaw: Gateway plugin HTTP `auth: gateway` widens identity-bearing `operator.read` requests into runtime `operator.write`
Low
CVE-2026-42429
was published
for
openclaw
(npm)
Apr 9, 2026
OpenClaw: Isolated cron awareness events were recorded as trusted system events
Low
CVE-2026-44999
was published
for
openclaw
(npm)
Apr 25, 2026
OpenClaw: Delivery queue recovery could lose group tool-policy context for media replay
Low
CVE-2026-43583
was published
for
openclaw
(npm)
Apr 17, 2026
OpenClaw: Gateway `device.token.rotate` does not terminate active WebSocket sessions after credential rotation
Low
CVE-2026-41356
was published
for
openclaw
(npm)
Apr 3, 2026
OpenClaw: Discord Slash Commands Bypass Group DM Channel Allowlist
Low
CVE-2026-41348
was published
for
openclaw
(npm)
Apr 3, 2026
OpenClaw: Discord Component Interaction Misclassifies Group DM as Direct Message
Low
CVE-2026-41341
was published
for
openclaw
(npm)
Apr 3, 2026
OpenClaw: Zalo webhook replay cache cross-target messageId scope bypass
Low
CVE-2026-41402
was published
for
openclaw
(npm)
Apr 2, 2026
OpenClaw: Microsoft Teams SSO invoke handler missed sender authorization checks
Low
CVE-2026-43572
was published
for
openclaw
(npm)
Apr 17, 2026
OpenClaw: Tlon Startup Migration Rehydrates Empty-Array Revocations From File Config
Low
CVE-2026-41388
was published
for
openclaw
(npm)
Apr 3, 2026
OpenClaw: Zalo replay dedupe cache could suppress events across authenticated webhook targets
Low
GHSA-fqrj-m88p-qf3v
was published
for
openclaw
(npm)
Apr 7, 2026
ProTip!
Advisories are also available from the
GraphQL API