GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
49
Go
3,549
Maven
5,000+
npm
5,000+
NuGet
917
pip
4,798
Pub
13
RubyGems
1,038
Rust
1,237
Swift
53
Unreviewed advisories
All unreviewed
5,000+
19 advisories
Filter by severity
OpenClaw: GIT_DIR and related git plumbing env vars missing from exec env denylist (GHSA-m866-6qv5-p2fg variant)
Low
GHSA-cm8v-2vh9-cxf3
was published
for
openclaw
(npm)
Apr 9, 2026
Vulnerable endpoints accept user-controlled input through a URL in JSON format which enables...
Low
Unreviewed
CVE-2025-11571
was published
Mar 24, 2026
Duplicate Advisory: safeBins stdin-only bypass via sort output and recursive grep flags
Low
GHSA-ggm6-h3mx-cmmp
was published
for
openclaw
(npm)
Mar 19, 2026
•
withdrawn
A command injection vulnerability has been reported to affect several QNAP operating system...
Low
Unreviewed
CVE-2024-14026
was published
Mar 11, 2026
OpenClaw's tools.exec.safeBins generic fallback allowed interpreter-style inline payload execution in allowlist mode
Low
GHSA-8mf7-vv8w-hjr2
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw safeBins stdin-only bypass via sort output and recursive grep flags
Low
CVE-2026-31996
was published
for
openclaw
(npm)
Feb 19, 2026
A command injection vulnerability has been reported to affect Media Streaming add-on. If an...
Low
Unreviewed
CVE-2024-56808
was published
Feb 11, 2026
wong2 mcp-cli Command Injection Vulnerability
Low
CVE-2025-9262
was published
for
@wong2/mcp-cli
(npm)
Aug 21, 2025
A command injection vulnerability has been reported to affect QHora. If an attacker gains local...
Low
Unreviewed
CVE-2024-13087
was published
Jun 6, 2025
Ackites KillWxapkg vulnerable to OS Command Injection
Low
CVE-2025-5030
was published
for
github.com/Ackites/KillWxapkg
(Go)
May 21, 2025
AWorld OS Command Injection vulnerability
Low
CVE-2025-4032
was published
for
aworld
(pip)
Apr 28, 2025
A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V4.0...
Low
Unreviewed
CVE-2025-27398
was published
Mar 11, 2025
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')...
Low
Unreviewed
CVE-2024-12970
was published
Jan 6, 2025
Harden-Runner has a command injection weaknesses in `setup.ts` and `arc-runner.ts`
Low
CVE-2024-52587
was published
for
step-security/harden-runner
(GitHub Actions)
Nov 18, 2024
A vulnerability classified as critical has been found in TOTOLINK A720R 4.1.5. Affected is the...
Low
Unreviewed
CVE-2024-8869
was published
Sep 16, 2024
IPython vulnerable to command injection via set_term_title
Low
CVE-2023-24816
was published
for
ipython
(pip)
Feb 10, 2023
It was discovered that the get_modified_conffiles() function in backends/packaging-apt-dpkg.py...
Low
Unreviewed
CVE-2021-32556
was published
May 24, 2022
Command injection in @diez/generation
Low
CVE-2021-32830
was published
for
@diez/generation
(npm)
Sep 2, 2021
ProTip!
Advisories are also available from the
GraphQL API