GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
49
Go
3,426
Maven
5,000+
npm
5,000+
NuGet
882
pip
4,670
Pub
13
RubyGems
1,029
Rust
1,212
Swift
53
Unreviewed advisories
All unreviewed
5,000+
62 advisories
Filter by severity
OpenClaw: OpenShell `mirror` mode can convert untrusted sandbox files into explicitly enabled workspace hooks and execute them on the host during gateway startup
Moderate
GHSA-42mx-vp8m-j7qh
was published
for
openclaw
(npm)
Apr 7, 2026
OpenClaw: `session_status` still bypasses configured `tools.sessions.visibility` for unsandboxed invocations
Moderate
GHSA-fwjq-xwfj-gv75
was published
for
openclaw
(npm)
Apr 7, 2026
OpenClaw's skills-install-download can be redirected outside the tools root by rebinding the validated base path
Moderate
CVE-2026-33574
was published
for
openclaw
(npm)
Mar 12, 2026
OpenClaw's system.run approvals did not bind mutable script operands across approval and execution
Moderate
CVE-2026-32921
was published
for
openclaw
(npm)
Mar 12, 2026
OpenClaw: Host exec environment sanitization misses package, registry, Docker, compiler, and TLS override variables
Moderate
GHSA-cg7q-fg22-4g98
was published
for
openclaw
(npm)
Apr 3, 2026
OpenClaw: SSRF via Unguarded `fetch()` in Marketplace Plugin Download and Ollama Model Discovery
Moderate
GHSA-9q7v-8mr7-g23p
was published
for
openclaw
(npm)
Apr 2, 2026
OpenClaw: Non-owner command-authorized sender can change the owner-only `/send` session delivery policy
Moderate
GHSA-39mp-545q-w789
was published
for
openclaw
(npm)
Mar 30, 2026
OpenClaw: Mutating internal `/allowlist` chat commands missed `operator.admin` scope enforcement
Moderate
GHSA-vqvg-86cc-cg83
was published
for
openclaw
(npm)
Mar 30, 2026
OpenClaw has a BlueBubbles group allowlist mismatch via DM pairing-store fallback
Moderate
CVE-2026-32006
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw's dispatch-wrapper depth-cap mismatch can bypass shell-wrapper approval gating in system.run allowlist mode
Moderate
CVE-2026-32023
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw: macOS optional allowlist basename matching could bypass path-based policy
Moderate
CVE-2026-32016
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw's Slack reaction/pin sender-policy consistency issue in non-message ingress
Moderate
CVE-2026-32899
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw: system.run approval identity mismatch could execute a different binary than displayed
Moderate
CVE-2026-32065
was published
for
openclaw
(npm)
Mar 2, 2026
OpenClaw: Slack system events bypass sender authorization in member and message subtype handlers
Moderate
CVE-2026-32895
was published
for
openclaw
(npm)
Mar 12, 2026
OpenClaw has a Trusted-proxy Control UI pairing bypass which allows unpaired node sessions
Moderate
CVE-2026-32057
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw's system.run shell-wrapper positional argv carriers could execute hidden commands under misleading approval text
Moderate
CVE-2026-32052
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw's Signal reaction-only status events could, in limited cases, be enqueued before access checks
Moderate
CVE-2026-32050
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw's system.run approval TOCTOU via mutable symlink cwd target on node host
Moderate
CVE-2026-32043
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw: Sandboxed /acp spawn requests could initialize host ACP sessions
Moderate
CVE-2026-27646
was published
for
openclaw
(npm)
Mar 9, 2026
OpenClaw's image tool bypasses tools.fs.workspaceOnly on sandbox mount paths and exfiltrates out-of-workspace images
Moderate
CVE-2026-32002
was published
for
openclaw
(npm)
Mar 4, 2026
In OpenClaw, manually adding sort to tools.exec.safeBins could bypass allowlist approval via --compress-program
Moderate
CVE-2026-32010
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw: Feishu webhook reads and parses unauthenticated request bodies before signature validation
Moderate
GHSA-3h52-cx59-c456
was published
for
openclaw
(npm)
Mar 29, 2026
OpenClaw has browser trace/download path symlink escape in temp output handling
Moderate
CVE-2026-32054
was published
for
openclaw
(npm)
Mar 2, 2026
OpenClaw's sandboxed sessions_spawn now enforces sandbox inheritance for cross-agent spawns
Moderate
CVE-2026-32048
was published
for
openclaw
(npm)
Mar 2, 2026
OpenClaw Bypasses DM Policy Separation via Synology Chat Webhook Path Collision
Moderate
GHSA-rqp8-q22p-5j9q
was published
for
openclaw
(npm)
Mar 26, 2026
ProTip!
Advisories are also available from the
GraphQL API