GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
46
GitHub Actions
48
Go
3,343
Maven
5,000+
npm
5,000+
NuGet
881
pip
4,550
Pub
12
RubyGems
1,013
Rust
1,203
Swift
51
Unreviewed advisories
All unreviewed
5,000+
120 advisories
Filter by severity
OpenClaw: Feishu webhook reads and parses unauthenticated request bodies before signature validation
Moderate
GHSA-3h52-cx59-c456
was published
for
openclaw
(npm)
Mar 29, 2026
OpenClaw Bypasses DM Policy Separation via Synology Chat Webhook Path Collision
Moderate
GHSA-rqp8-q22p-5j9q
was published
for
openclaw
(npm)
Mar 26, 2026
OpenClaw's mutating internal ACP chat commands missed operator.admin scope enforcement
High
GHSA-3w6x-gv34-mqpf
was published
for
openclaw
(npm)
Mar 26, 2026
OpenClaw bootstrap setup codes could be replayed to escalate pending pairing scopes before approval
High
GHSA-63f5-hhc7-cx6p
was published
for
openclaw
(npm)
Mar 16, 2026
OpenClaw: Gateway `agent` calls could override the workspace boundary
High
GHSA-2rqg-gjgv-84jm
was published
for
openclaw
(npm)
Mar 13, 2026
`OpenClaw: session_status` let sandboxed subagents access parent or sibling session state
High
GHSA-wcxr-59v9-rxr8
was published
for
openclaw
(npm)
Mar 13, 2026
OpenClaw: Command-authorized non-owners could reach owner-only `/config` and `/debug` surfaces
High
GHSA-r7vr-gr74-94p8
was published
for
openclaw
(npm)
Mar 13, 2026
OpenClaw: `browser.request` let `operator.write` persist admin-only browser profile changes
High
GHSA-vmhq-cqm9-6p7q
was published
for
openclaw
(npm)
Mar 13, 2026
OpenClaw: Unavailable local auth SecretRefs could fall through to remote credentials in local mode
Low
GHSA-qvr7-g57c-mrc7
was published
for
openclaw
(npm)
Mar 13, 2026
OpenClaw: Sandbox staged writes could escape the verified parent directory before commit
High
GHSA-mj4p-rc52-m843
was published
for
openclaw
(npm)
Mar 13, 2026
OpenClaw: Write-scoped callers could reach admin-only session reset logic through `agent`
Moderate
GHSA-jf6w-m8jw-jfxc
was published
for
openclaw
(npm)
Mar 13, 2026
OpenClaw: Unrecognized script runners could bypass `system.run` approval integrity
High
GHSA-qc36-x95h-7j53
was published
for
openclaw
(npm)
Mar 13, 2026
OpenClaw: Channel commands could bypass account-scoped `configWrites` restrictions
Moderate
GHSA-8jhh-jcqg-mj5p
was published
for
openclaw
(npm)
Mar 13, 2026
OpenClaw: Node-host approvals could show misleading shell payloads instead of the executed argv
High
GHSA-rw39-5899-8mxp
was published
for
openclaw
(npm)
Mar 13, 2026
OpenClaw: Unbound interpreter and runtime commands could bypass node-host approval integrity
High
GHSA-xf99-j42q-5w5p
was published
for
openclaw
(npm)
Mar 13, 2026
OpenClaw: Leaf subagents could steer sibling sessions across sandbox boundaries
High
GHSA-4w7m-58cg-cmff
was published
for
openclaw
(npm)
Mar 13, 2026
OpenClaw: Pairing-scoped device tokens could mint `operator.admin` and reach node RCE
Critical
GHSA-4jpw-hj22-2xmc
was published
for
openclaw
(npm)
Mar 13, 2026
OpenClaw: Plugin subagent routes could bypass gateway authorization with synthetic admin scopes
Critical
GHSA-xw77-45gv-p728
was published
for
openclaw
(npm)
Mar 13, 2026
OpenClaw: /api/channels gateway-auth boundary bypass via path canonicalization mismatch
Moderate
CVE-2026-32031
was published
for
openclaw
(npm)
Mar 12, 2026
OpenClaw: Slack system events bypass sender authorization in member and message subtype handlers
Moderate
GHSA-v8cg-4474-49v8
was published
for
openclaw
(npm)
Mar 12, 2026
OpenClaw: Sandbox dangling-symlink alias handling could bypass workspace-only write boundary
High
GHSA-qcc4-p59m-p54m
was published
for
openclaw
(npm)
Mar 12, 2026
OpenClaw: workspace path guard bypass on non-existent out-of-root symlink leaf
High
GHSA-mgrq-9f93-wpp5
was published
for
openclaw
(npm)
Mar 12, 2026
OpenClaw: LINE group allowlist scope mismatch with DM pairing-store entries
High
GHSA-gp3q-wpq4-5c5h
was published
for
openclaw
(npm)
Mar 12, 2026
OpenClaw's skills-install-download can be redirected outside the tools root by rebinding the validated base path
Moderate
GHSA-vhwf-4x96-vqx2
was published
for
openclaw
(npm)
Mar 12, 2026
OpenClaw's system.run approvals did not bind mutable script operands across approval and execution
Moderate
GHSA-8g75-q649-6pv6
was published
for
openclaw
(npm)
Mar 12, 2026
ProTip!
Advisories are also available from the
GraphQL API