GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
50
Go
3,606
Maven
5,000+
npm
5,000+
NuGet
924
pip
4,831
Pub
13
RubyGems
1,045
Rust
1,256
Swift
53
Unreviewed advisories
All unreviewed
5,000+
5,911 advisories
Filter by severity
OpenLearnX has Critical Remote Code Execution Through Python Sandbox Escape via Code Execution Environment
High
CVE-2026-41900
was published
for
openlearnx
(npm)
Apr 23, 2026
OpenClaw: Agent gateway config mutations could change protected operator settings
Moderate
GHSA-7jm2-g593-4qrc
was published
for
openclaw
(npm)
Apr 25, 2026
OpenClaw: Bundled MCP/LSP tools could bypass configured tool policy
Moderate
GHSA-qrp5-gfw2-gxv4
was published
for
openclaw
(npm)
Apr 25, 2026
OpenClaw: Workspace dotenv MiniMax host override could redirect credentialed requests
Moderate
GHSA-h2vw-ph2c-jvwf
was published
for
openclaw
(npm)
Apr 25, 2026
OpenClaw: Browser CDP profile creation skipped strict-mode SSRF checks
Low
GHSA-j4c5-89f5-f3pm
was published
for
openclaw
(npm)
Apr 25, 2026
OpenClaw: Paired-device pairing actions were not limited to the caller device
Low
GHSA-xrq9-jm7v-g9h7
was published
for
openclaw
(npm)
Apr 25, 2026
OpenClaw: QQBot direct media upload skipped URL SSRF validation
Low
GHSA-c4qg-j8jg-42q5
was published
for
openclaw
(npm)
Apr 25, 2026
OpenClaw: MCP stdio server env could load dangerous startup variables from workspace config
Moderate
GHSA-mj59-h3q9-ghfh
was published
for
openclaw
(npm)
Apr 25, 2026
OpenClaw: Isolated cron awareness events were recorded as trusted system events
Low
GHSA-57r2-h2wj-g887
was published
for
openclaw
(npm)
Apr 25, 2026
OpenClaw: Workspace dotenv could override runtime-control environment variables
Moderate
GHSA-hxvm-xjvf-93f3
was published
for
openclaw
(npm)
Apr 25, 2026
OpenClaw: Feishu card actions could misclassify DMs and skip dmPolicy
Moderate
GHSA-72q8-jcmc-97wx
was published
for
openclaw
(npm)
Apr 25, 2026
OpenClaw: Assistant media route missed scope enforcement for trusted-proxy authorization
Low
GHSA-v8qf-fr4g-28p2
was published
for
openclaw
(npm)
Apr 25, 2026
OpenClaw: Hook mapping templates could bypass hook session-key opt-in
Moderate
GHSA-2xcp-x87w-q377
was published
for
openclaw
(npm)
Apr 25, 2026
n8n-MCP: Sensitive MCP tool-call arguments logged on authenticated requests in HTTP mode
Moderate
GHSA-wg4g-395p-mqv3
was published
for
n8n-mcp
(npm)
Apr 25, 2026
Gemini CLI: Remote Code Execution via workspace trust and tool allowlisting bypasses
Critical
GHSA-wpqr-6v78-jr5g
was published
for
@google/gemini-cli
(GitHub Actions)
Apr 24, 2026
seroval affected by Denial of Service via RegExp serialization
High
CVE-2026-23956
was published
for
seroval
(npm)
Jan 21, 2026
xmldom: XML injection via unsafe CDATA serialization allows attacker-controlled markup insertion
High
CVE-2026-34601
was published
for
@xmldom/xmldom
(npm)
Apr 1, 2026
Complete Bypass of CVE-2026-24884 Patch via Git-Delivered Symlink Poisoning in compressing
High
CVE-2026-40931
was published
for
compressing
(npm)
Apr 17, 2026
@vendure/core has a SQL Injection vulnerability
Critical
CVE-2026-40887
was published
for
@vendure/core
(npm)
Apr 14, 2026
Hono has incorrect IP matching in ipRestriction() for IPv4-mapped IPv6 addresses
Moderate
CVE-2026-39409
was published
for
hono
(npm)
Apr 8, 2026
OpenClaw: Host exec environment overrides miss proxy, TLS, Docker, and Git TLS controls
Moderate
CVE-2026-41330
was published
for
openclaw
(npm)
Apr 3, 2026
OpenClaw: Telegram audio preflight transcription enables resource consumption by unauthorized senders
Moderate
CVE-2026-41331
was published
for
openclaw
(npm)
Apr 3, 2026
OpenClaw: Forged Nostr DMs could create pairing state before signature verification
Moderate
CVE-2026-41301
was published
for
openclaw
(npm)
Apr 7, 2026
OpenClaw: Read-scoped identity-bearing HTTP clients could kill sessions via /sessions/:sessionKey/kill
Moderate
CVE-2026-41298
was published
for
openclaw
(npm)
Apr 7, 2026
OpenClaw: Android accepted cleartext remote gateway endpoints and sent stored credentials over ws://
Moderate
CVE-2026-40045
was published
for
openclaw
(npm)
Apr 7, 2026
ProTip!
Advisories are also available from the
GraphQL API