GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
49
Go
3,414
Maven
5,000+
npm
5,000+
NuGet
882
pip
4,657
Pub
13
RubyGems
1,027
Rust
1,209
Swift
53
Unreviewed advisories
All unreviewed
5,000+
133 advisories
Filter by severity
OpenClaw: OpenShell `mirror` mode can convert untrusted sandbox files into explicitly enabled workspace hooks and execute them on the host during gateway startup
Moderate
GHSA-42mx-vp8m-j7qh
was published
for
openclaw
(npm)
Apr 7, 2026
OpenClaw: `session_status` still bypasses configured `tools.sessions.visibility` for unsandboxed invocations
Moderate
GHSA-fwjq-xwfj-gv75
was published
for
openclaw
(npm)
Apr 7, 2026
OpenClaw: Unbound bootstrap setup codes allow privilege escalation during pairing
High
GHSA-gg9v-mgcp-v6m7
was published
for
openclaw
(npm)
Apr 3, 2026
OpenClaw: Host exec environment sanitization misses package, registry, Docker, compiler, and TLS override variables
Moderate
GHSA-cg7q-fg22-4g98
was published
for
openclaw
(npm)
Apr 3, 2026
OpenClaw: Incomplete host-env-security-policy allows untrusted model to substitute compiler binaries via env overrides
High
GHSA-g8xp-qx39-9jq9
was published
for
openclaw
(npm)
Apr 3, 2026
OpenClaw: Self-Whitelisting in appendLocalMediaParentRoots Allows Arbitrary File Read & Credential Exfiltration
High
GHSA-57gh-m6rq-54cf
was published
for
openclaw
(npm)
Apr 3, 2026
OpenClaw: SSRF via Unguarded `fetch()` in Marketplace Plugin Download and Ollama Model Discovery
Moderate
GHSA-9q7v-8mr7-g23p
was published
for
openclaw
(npm)
Apr 2, 2026
OpenClaw has a CWD `.env` environment variable injection which bypasses host-env policy and allows config takeover
Critical
GHSA-8rh7-6779-cjqq
was published
for
openclaw
(npm)
Apr 1, 2026
OpenClaw's incomplete host env sanitization blocklist allows supply-chain redirection via package-manager env overrides
Critical
GHSA-j7p2-qcwm-94v4
was published
for
openclaw
(npm)
Mar 31, 2026
OpenClaw: Discord text `/approve` bypasses `channels.discord.execApprovals.approvers` and allows non-approvers to resolve pending exec approvals
High
GHSA-98hh-7ghg-x6rq
was published
for
openclaw
(npm)
Mar 31, 2026
OpenClaw: Non-owner command-authorized sender can change the owner-only `/send` session delivery policy
Moderate
GHSA-39mp-545q-w789
was published
for
openclaw
(npm)
Mar 30, 2026
OpenClaw: `browser.request` still allows `POST /reset-profile` through the `operator.write` surface
High
GHSA-xp9r-prpg-373r
was published
for
openclaw
(npm)
Mar 30, 2026
OpenClaw: Mutating internal `/allowlist` chat commands missed `operator.admin` scope enforcement
Moderate
GHSA-vqvg-86cc-cg83
was published
for
openclaw
(npm)
Mar 30, 2026
OpenClaw: Feishu webhook reads and parses unauthenticated request bodies before signature validation
Moderate
GHSA-3h52-cx59-c456
was published
for
openclaw
(npm)
Mar 29, 2026
OpenClaw Bypasses DM Policy Separation via Synology Chat Webhook Path Collision
Moderate
GHSA-rqp8-q22p-5j9q
was published
for
openclaw
(npm)
Mar 26, 2026
OpenClaw's mutating internal ACP chat commands missed operator.admin scope enforcement
High
GHSA-3w6x-gv34-mqpf
was published
for
openclaw
(npm)
Mar 26, 2026
OpenClaw bootstrap setup codes could be replayed to escalate pending pairing scopes before approval
High
GHSA-63f5-hhc7-cx6p
was published
for
openclaw
(npm)
Mar 16, 2026
OpenClaw: Gateway `agent` calls could override the workspace boundary
High
GHSA-2rqg-gjgv-84jm
was published
for
openclaw
(npm)
Mar 13, 2026
`OpenClaw: session_status` let sandboxed subagents access parent or sibling session state
High
CVE-2026-32918
was published
for
openclaw
(npm)
Mar 13, 2026
OpenClaw: Command-authorized non-owners could reach owner-only `/config` and `/debug` surfaces
High
GHSA-r7vr-gr74-94p8
was published
for
openclaw
(npm)
Mar 13, 2026
OpenClaw: `browser.request` let `operator.write` persist admin-only browser profile changes
High
GHSA-vmhq-cqm9-6p7q
was published
for
openclaw
(npm)
Mar 13, 2026
OpenClaw: Unavailable local auth SecretRefs could fall through to remote credentials in local mode
Low
CVE-2026-32970
was published
for
openclaw
(npm)
Mar 13, 2026
OpenClaw: Sandbox staged writes could escape the verified parent directory before commit
High
GHSA-mj4p-rc52-m843
was published
for
openclaw
(npm)
Mar 13, 2026
OpenClaw: Write-scoped callers could reach admin-only session reset logic through `agent`
Moderate
GHSA-jf6w-m8jw-jfxc
was published
for
openclaw
(npm)
Mar 13, 2026
OpenClaw: Unrecognized script runners could bypass `system.run` approval integrity
High
CVE-2026-32978
was published
for
openclaw
(npm)
Mar 13, 2026
ProTip!
Advisories are also available from the
GraphQL API