GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
49
Go
3,413
Maven
5,000+
npm
5,000+
NuGet
882
pip
4,656
Pub
13
RubyGems
1,027
Rust
1,209
Swift
53
Unreviewed advisories
All unreviewed
5,000+
1,177 advisories
Filter by severity
pyLoad: Unprotected storage_folder enables arbitrary file write to Flask session store and code execution (Incomplete fix for CVE-2026-33509)
High
CVE-2026-35464
was published
for
pyload-ng
(pip)
Apr 4, 2026
Directus: Authenticated Users Can Extract Concealed Fields via Aggregate Queries
High
CVE-2026-35442
was published
for
directus
(npm)
Apr 4, 2026
Directus: TUS Upload Authorization Bypass Allows Arbitrary File Overwrite
High
CVE-2026-35412
was published
for
directus
(npm)
Apr 4, 2026
LiteLLM: Privilege escalation via unrestricted proxy configuration endpoint
High
CVE-2026-35029
was published
for
litellm
(pip)
Apr 3, 2026
Juju has a resource poisoning vulnerability
High
CVE-2025-68153
was published
for
github.com/juju/juju
(Go)
Apr 3, 2026
OpenClaw: Node browser proxy `allowProfiles` bypass through persistent profile mutation and runtime profile selection
High
GHSA-h5hg-h7rr-gpf3
was published
for
openclaw
(npm)
Apr 3, 2026
OpenClaw: Paired node escalates to gateway RCE via unrestricted node.event agent dispatch
High
GHSA-gjm7-hw8f-73rq
was published
for
openclaw
(npm)
Apr 3, 2026
OpenClaw: Incomplete scope-clearing fix allows operator.admin escalation via trusted-proxy auth mode
High
GHSA-g374-mggx-p6xc
was published
for
openclaw
(npm)
Apr 3, 2026
OpenClaw: Device-Paired Node Skips Node Scope Gate → Host RCE.md
High
GHSA-xj9w-5r6q-x6v4
was published
for
openclaw
(npm)
Apr 3, 2026
Improper authentication in Azure SRE Agent allows an unauthorized attacker to disclose...
High
Unreviewed
CVE-2026-32173
was published
Apr 3, 2026
XenForo before 2.3.5 allows OAuth2 client applications to request unauthorized scopes. This...
High
Unreviewed
CVE-2025-71278
was published
Apr 1, 2026
OpenClaw gateway exec allow-always over-trusts positional carrier executables
High
GHSA-p4x4-2r7f-wjxg
was published
for
openclaw
(npm)
Apr 1, 2026
OpenClaw Gateway `operator.write` can reach admin-only session reset via `chat.send` `/reset`
High
GHSA-5r8f-96gm-5j6g
was published
for
openclaw
(npm)
Apr 1, 2026
OpenClaw: Gateway `operator.write` can reach admin-only persisted `verboseLevel` via `chat.send` `/verbose`
High
GHSA-5h2w-qmfp-ggp6
was published
for
openclaw
(npm)
Mar 31, 2026
OpenClaw: Discord text `/approve` bypasses `channels.discord.execApprovals.approvers` and allows non-approvers to resolve pending exec approvals
High
GHSA-98hh-7ghg-x6rq
was published
for
openclaw
(npm)
Mar 31, 2026
SiYuan: Unauthenticated Access to Password-Protected Bookmarks via /api/bookmark/getBookmark
High
CVE-2026-34453
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Mar 31, 2026
Duplicate Advisory: OpenClaw: /pair approve command path omitted caller scope subsetting and reopened device pairing escalation
High
GHSA-f275-5h5c-5wg5
was published
for
openclaw
(npm)
Mar 31, 2026
•
withdrawn
OpenClaw: `browser.request` still allows `POST /reset-profile` through the `operator.write` surface
High
GHSA-xp9r-prpg-373r
was published
for
openclaw
(npm)
Mar 30, 2026
A critical security vulnerability in parisneo/lollms versions up to 2.2.0 allows any...
High
Unreviewed
CVE-2026-0562
was published
Mar 29, 2026
OpenClaw: Gateway Plugin Subagent Fallback `deleteSession` Uses Synthetic `operator.admin`
High
GHSA-h4jx-hjr3-fhgc
was published
for
openclaw
(npm)
Mar 29, 2026
OpenClaw: `session_status` sessionId resolution bypasses sandboxed session-tree visibility
High
GHSA-q2qc-744p-66r2
was published
for
openclaw
(npm)
Mar 29, 2026
OpenClaw before 2026.3.12 contains an insufficient access control vulnerability in the /config...
High
Unreviewed
CVE-2026-32914
was published
Mar 29, 2026
OpenClaw before 2026.3.11 contains an authorization bypass vulnerability allowing authenticated...
High
Unreviewed
CVE-2026-32972
was published
Mar 29, 2026
OpenClaw: Gateway Plugin HTTP Auth Grants Unrestricted operator.admin Runtime Scope to All Callers
High
GHSA-qm2m-28pf-hgjw
was published
for
openclaw
(npm)
Mar 27, 2026
OpenClaw: Gateway HTTP /sessions/:sessionKey/kill Reaches Admin Kill Path Without Caller Scope Binding
High
GHSA-9p93-7j67-5pc2
was published
for
openclaw
(npm)
Mar 27, 2026
ProTip!
Advisories are also available from the
GraphQL API