GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,407
Maven
5,000+
npm
5,000+
NuGet
1,048
pip
5,000+
Pub
13
RubyGems
1,127
Rust
1,498
Swift
61
Unreviewed advisories
All unreviewed
5,000+
20 advisories
Filter by severity
OpenClaw: Native command authorization could skip owner-command enforcement
High
GHSA-p73f-w79w-jqr5
was published
for
openclaw
(npm)
Jul 2, 2026
OpenClaw: Telegram interactive callbacks could skip commands.allowFrom
High
GHSA-w5ww-7chg-mxcq
was published
for
openclaw
(npm)
Jul 2, 2026
OpenClaw: Node Pairing Reconnect Command Escalation Bypasses operator.admin Scope Requirement
High
CVE-2026-42432
was published
for
openclaw
(npm)
Apr 9, 2026
OpenClaw's gateway config mutation guard allowed unsafe model-driven config writes
High
GHSA-cwj3-vqpp-pmxr
was published
for
openclaw
(npm)
May 5, 2026
OpenClaw: Matrix room control-command authorization no longer trusts DM pairing-store entries
High
CVE-2026-44110
was published
for
openclaw
(npm)
Apr 17, 2026
OpenClaw: CLI Remote Onboarding Persists Unauthenticated Discovery Endpoint and Exfiltrates Gateway Credentials
High
CVE-2026-41342
was published
for
openclaw
(npm)
Mar 31, 2026
OpenClaw: Channel setup catalog lookups could include untrusted workspace plugin shadows
High
CVE-2026-43571
was published
for
openclaw
(npm)
Apr 17, 2026
OpenClaw: Sandboxed agents could escape exec routing via host=node override
High
CVE-2026-42434
was published
for
openclaw
(npm)
Apr 17, 2026
OpenClaw: Workspace `.env` can override the bundled hooks root and load attacker hook code
High
CVE-2026-41336
was published
for
openclaw
(npm)
Apr 2, 2026
OpenClaw: Workspace `.env` can override the bundled plugin trust root
High
CVE-2026-41396
was published
for
openclaw
(npm)
Apr 3, 2026
OpenClaw: PIP_INDEX_URL and UV_INDEX_URL bypass host exec env sanitization and redirect Python package-index traffic
High
CVE-2026-41391
was published
for
openclaw
(npm)
Apr 2, 2026
OpenClaw: config.get redaction bypass through sourceConfig and runtimeConfig aliases
High
CVE-2026-43528
was published
for
openclaw
(npm)
Apr 17, 2026
OpenClaw: Voice-call Plivo V3 webhook replay key uses unsorted URL, allowing replay via query-parameter reordering
High
CVE-2026-41395
was published
for
openclaw
(npm)
Mar 31, 2026
OpenClaw: macOS Tailnet DNS Spoofing & Credential Exfiltration
High
CVE-2026-41393
was published
for
openclaw
(npm)
Apr 3, 2026
OpenClaw gateway exec allow-always over-trusts positional carrier executables
High
CVE-2026-41380
was published
for
openclaw
(npm)
Apr 1, 2026
OpenClaw's Trusted-proxy Control UI sessions retain privileged scopes without device identity on device-less allow paths
High
GHSA-48vw-m3qc-wr99
was published
for
openclaw
(npm)
Mar 26, 2026
OpenClaw: Plivo V2 verified replay identity drifts on query-only variants
High
CVE-2026-35618
was published
for
openclaw
(npm)
Mar 26, 2026
OpenClaw: Gateway agent /reset exposes admin session reset to operator.write callers
High
CVE-2026-35660
was published
for
openclaw
(npm)
Mar 26, 2026
OpenClaw: Node browser proxy `allowProfiles` bypass through persistent profile mutation and runtime profile selection
High
GHSA-h5hg-h7rr-gpf3
was published
for
openclaw
(npm)
Apr 3, 2026
OpenClaw: `session_status` sessionId resolution bypasses sandboxed session-tree visibility
High
GHSA-q2qc-744p-66r2
was published
for
openclaw
(npm)
Mar 29, 2026
ProTip!
Advisories are also available from the
GraphQL API