Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

5,544 advisories

Loading
fasrm Credited to fasrm and SociableSteve SociableSteve SociableSteve
Signal K Server: Arbitrary Prototype Read via `from` Field Bypass Low
CVE-2026-35038 was published for signalk-server (npm) Apr 3, 2026
VashuVats Credited to VashuVats
DOMPurify ADD_ATTR predicate skips URI validation Moderate
GHSA-cjmm-f4jc-qw8r was published for dompurify (npm) Apr 3, 2026
christos-eth Credited to christos-eth
DOMPurify USE_PROFILES prototype pollution allows event handlers Moderate
GHSA-cj63-jhhr-wcxv was published for dompurify (npm) Apr 3, 2026
christos-eth Credited to christos-eth
Better Auth Has Two-Factor Authentication Bypass via Premature Session Caching (session.cookieCache) Critical
GHSA-xg6x-h9c9-2m83 was published for better-auth (npm) Apr 3, 2026
TriDecent Credited to TriDecent
cyjhhh Credited to cyjhhh
OpenClaw: Discord Component Interaction Misclassifies Group DM as Direct Message Moderate
GHSA-6336-qqw9-v6x6 was published for openclaw (npm) Apr 3, 2026
nexrin Credited to nexrin
OpenClaw: Endpoint persists after trust decline, leaking gateway credentials Moderate
GHSA-9f4w-67g7-mqwv was published for openclaw (npm) Apr 3, 2026
zsxsoft Credited to zsxsoft
OpenClaw: diffs viewer misclassifies proxied remote requests as loopback when `allowRemoteViewer` is disabled Moderate
GHSA-3xv9-89fm-7h4r was published for openclaw (npm) Apr 3, 2026
smaeljaish771 Credited to smaeljaish771
OpenClaw: Discord Slash Commands Bypass Group DM Channel Allowlist Moderate
GHSA-rvvf-6vh3-9j43 was published for openclaw (npm) Apr 3, 2026
nexrin Credited to nexrin
OpenClaw: macOS Tailnet DNS Spoofing & Credential Exfiltration High
GHSA-q9w8-cf67-r238 was published for openclaw (npm) Apr 3, 2026
nexrin Credited to nexrin
OpenClaw: Telegram legacy allowFrom migration fans default-account trust into all named accounts Moderate
GHSA-f693-58pc-2gfr was published for openclaw (npm) Apr 3, 2026
smaeljaish771 Credited to smaeljaish771
OpenClaw: Tlon Startup Migration Rehydrates Empty-Array Revocations From File Config Low
GHSA-3pm9-5j7m-59vc was published for openclaw (npm) Apr 3, 2026
smaeljaish771 Credited to smaeljaish771
OpenClaw: Unbound bootstrap setup codes allow privilege escalation during pairing High
GHSA-gg9v-mgcp-v6m7 was published for openclaw (npm) Apr 3, 2026
tdjackey Credited to tdjackey
smaeljaish771 Credited to smaeljaish771
OpenClaw: Discord voice manager bypasses channel-level member access allowlist Moderate
GHSA-cqgw-44wg-44rf was published for openclaw (npm) Apr 3, 2026
zsxsoft Credited to zsxsoft
OpenClaw: Telegram audio preflight transcription enables resource consumption by unauthorized senders Moderate
GHSA-m6fx-m8hc-572m was published for openclaw (npm) Apr 3, 2026
AntAISecurityLab Credited to AntAISecurityLab
OpenClaw: Paired node escalates to gateway RCE via unrestricted node.event agent dispatch High
GHSA-gjm7-hw8f-73rq was published for openclaw (npm) Apr 3, 2026
AntAISecurityLab Credited to AntAISecurityLab
OpenClaw: Sandbox escape via TOCTOU race in remote FS bridge readFile Critical
GHSA-9p3r-hh9g-5cmg was published for openclaw (npm) Apr 3, 2026
AntAISecurityLab Credited to AntAISecurityLab
Kazamayc Credited to Kazamayc
zsxsoft Credited to zsxsoft
OpenClaw: Fake DeviceToken Bypasses Shared Auth Rate Limiting Moderate
GHSA-6p8r-6m93-557f was published for openclaw (npm) Apr 3, 2026
kexinoh Credited to kexinoh
tdjackey Credited to tdjackey
OpenClaw: Path traversal via inbound channel attachment path in ACP dispatch allows arbitrary file read Moderate
GHSA-58q2-7r52-jq62 was published for openclaw (npm) Apr 3, 2026
north-echo Credited to north-echo
OpenClaw: Incomplete scope-clearing fix allows operator.admin escalation via trusted-proxy auth mode High
GHSA-g374-mggx-p6xc was published for openclaw (npm) Apr 3, 2026
north-echo Credited to north-echo
ProTip! Advisories are also available from the GraphQL API