GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
49
Go
3,417
Maven
5,000+
npm
5,000+
NuGet
882
pip
4,658
Pub
13
RubyGems
1,027
Rust
1,211
Swift
53
Unreviewed advisories
All unreviewed
5,000+
3,276 advisories
Filter by severity
When the early_acl_drop (earlyACLDrop in Lua) option is disabled (default is enabled) on a DNS...
Moderate
Unreviewed
CVE-2026-24029
was published
Mar 31, 2026
OpenClaw: `browser.request` still allows `POST /reset-profile` through the `operator.write` surface
High
GHSA-xp9r-prpg-373r
was published
for
openclaw
(npm)
Mar 30, 2026
OpenClaw has a Gateway HTTP /v1/models Route Bypasses Operator Read Scope
Moderate
GHSA-68f8-9mhj-h2mp
was published
for
openclaw
(npm)
Mar 30, 2026
AVideo has User Group-Based Category Access Control Bypass via Missing and Broken Group Filtering in categories.json.php
Moderate
CVE-2026-34364
was published
for
wwbn/avideo
(Composer)
Mar 30, 2026
A critical security vulnerability in parisneo/lollms versions up to 2.2.0 allows any...
High
Unreviewed
CVE-2026-0562
was published
Mar 29, 2026
OpenClaw: Telegram DM-Scoped Inline Button Callbacks Bypass DM Pairing and Mutate Session State
Moderate
GHSA-j4c9-w69r-cw33
was published
for
openclaw
(npm)
Mar 29, 2026
OpenClaw: MS Teams Feedback Invocation Bypasses Sender Allowlists and Records Unauthorized Session Feedback
Moderate
GHSA-rf6h-5gpw-qrgq
was published
for
openclaw
(npm)
Mar 29, 2026
OpenClaw: Gateway Plugin Subagent Fallback `deleteSession` Uses Synthetic `operator.admin`
High
GHSA-h4jx-hjr3-fhgc
was published
for
openclaw
(npm)
Mar 29, 2026
OpenClaw: Feishu Raw Card Send Surface Can Mint Legacy Card Callbacks That Bypass DM Pairing
Moderate
GHSA-77w2-crqv-cmv3
was published
for
openclaw
(npm)
Mar 29, 2026
OpenClaw: Google Chat Authz Bypass via Group Policy Rebinding with Mutable Space displayName
Moderate
GHSA-52q4-3xjc-6778
was published
for
openclaw
(npm)
Mar 29, 2026
OpenClaw: `session_status` sessionId resolution bypasses sandboxed session-tree visibility
High
GHSA-q2qc-744p-66r2
was published
for
openclaw
(npm)
Mar 29, 2026
OpenClaw: Gateway HTTP Session History Route Bypasses Operator Read Scope
Moderate
GHSA-5jvj-hxmh-6h6j
was published
for
openclaw
(npm)
Mar 29, 2026
Duplicate Advisory: `OpenClaw: session_status` let sandboxed subagents access parent or sibling session state
Critical
GHSA-hh43-q692-2xmq
was published
for
openclaw
(npm)
Mar 29, 2026
•
withdrawn
OpenClaw before 2026.3.11 contains an authorization bypass vulnerability allowing write-scoped...
Moderate
Unreviewed
CVE-2026-32919
was published
Mar 29, 2026
OpenClaw before 2026.3.11 contains a sandbox boundary bypass vulnerability allowing leaf...
Critical
Unreviewed
CVE-2026-32915
was published
Mar 29, 2026
OpenClaw before 2026.3.12 contains an insufficient access control vulnerability in the /config...
High
Unreviewed
CVE-2026-32914
was published
Mar 29, 2026
OpenClaw before 2026.3.12 contains an authorization bypass vulnerability where Feishu reaction...
Moderate
Unreviewed
CVE-2026-32924
was published
Mar 29, 2026
OpenClaw before 2026.3.11 contains an authorization bypass vulnerability allowing authenticated...
High
Unreviewed
CVE-2026-32972
was published
Mar 29, 2026
Duplicate Advisory: OpenClaw: Unrecognized script runners could bypass `system.run` approval integrity
Critical
GHSA-rwwx-25m7-ww73
was published
for
openclaw
(npm)
Mar 29, 2026
•
withdrawn
OpenClaw before 2026.3.11 contains an authorization bypass vulnerability in Discord guild...
Moderate
Unreviewed
CVE-2026-32923
was published
Mar 29, 2026
OpenClaw: BlueBubbles Group Reactions Bypass requireMention and Still Enqueue Agent-Visible System Events
Moderate
GHSA-mw7w-g3mg-xqm7
was published
for
openclaw
(npm)
Mar 27, 2026
OpenClaw: Matrix Verification Notices Bypass Matrix DM Policy and Reply to Unpaired DM Peers
Moderate
GHSA-9wqx-g2cw-vc7r
was published
for
openclaw
(npm)
Mar 27, 2026
OpenClaw: Gateway Plugin HTTP Auth Grants Unrestricted operator.admin Runtime Scope to All Callers
High
GHSA-qm2m-28pf-hgjw
was published
for
openclaw
(npm)
Mar 27, 2026
OpenClaw: Silent privilege escalation via gateway shared-auth reconnect
Critical
GHSA-fqw4-mph7-2vr8
was published
for
openclaw
(npm)
Mar 27, 2026
OpenClaw: Gateway Backend Reconnect lets Non-Admin Operator Scopes Self-Claim operator.admin
Critical
GHSA-9hjh-fr4f-gxc4
was published
for
openclaw
(npm)
Mar 27, 2026
ProTip!
Advisories are also available from the
GraphQL API