GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,741
Maven
5,000+
npm
5,000+
NuGet
1,116
pip
5,000+
Pub
13
RubyGems
1,152
Rust
1,570
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
25 advisories
Filter by severity
Electron: Parent process code-sign check is spoofable
Moderate
CVE-2026-70597
was published
for
electron
(npm)
Aug 5, 2026
Ghost: Server-side request forgery via DNS rebinding in external request handling
Moderate
CVE-2026-53945
was published
for
ghost
(npm)
Aug 4, 2026
OpenClaw: Node pairing reconnection could confuse approval scope state
Moderate
CVE-2026-53838
was published
for
openclaw
(npm)
Jul 2, 2026
Duplicate Advisory: OpenClaw: Node pairing reconnection could confuse approval scope state
Moderate
GHSA-c85p-9pvr-f7f5
was published
for
openclaw
(npm)
Jun 13, 2026
•
withdrawn
Duplicate Advisory: OpenClaw: OpenShell FS bridge writes stay pinned to the sandbox mount root
Moderate
GHSA-6f72-9gxx-98mj
was published
for
openclaw
(npm)
May 6, 2026
•
withdrawn
Duplicate Advisory: OpenClaw: OpenShell FS bridge reads pin and verify the opened file before returning bytes
Moderate
GHSA-frr5-j3mh-h9ch
was published
for
openclaw
(npm)
May 6, 2026
•
withdrawn
Duplicate Advisory: OpenClaw: Browser SSRF hostname validation could be bypassed by DNS rebinding
Moderate
GHSA-w7rc-vvgx-pj45
was published
for
openclaw
(npm)
May 6, 2026
•
withdrawn
OpenClaw: OpenShell FS bridge reads pin and verify the opened file before returning bytes
Moderate
CVE-2026-44113
was published
for
openclaw
(npm)
May 4, 2026
OpenClaw: OpenShell FS bridge writes stay pinned to the sandbox mount root
Moderate
CVE-2026-44112
was published
for
openclaw
(npm)
May 4, 2026
Duplicate Advisory: OpenClaw: Voice-call Plivo replay mutates in-process callback origin before replay rejection
Moderate
GHSA-cw28-63x4-37c3
was published
for
openclaw
(npm)
Apr 24, 2026
•
withdrawn
OpenClaw: Sandbox file operations use check-then-act, bypassing fd-based TOCTOU defenses
Moderate
GHSA-rm5c-4rmf-vvhw
was published
for
openclaw
(npm)
Apr 3, 2026
Duplicate Advisory: OpenClaw: Sandbox `writeFile` commit could race outside the validated path
Moderate
GHSA-xxj4-96ph-g6j6
was published
for
openclaw
(npm)
Mar 31, 2026
•
withdrawn
Duplicate Advisory: OpenClaw's system.run approvals did not bind mutable script operands across approval and execution
Moderate
GHSA-wwrj-437c-ppq4
was published
for
openclaw
(npm)
Mar 31, 2026
•
withdrawn
Duplicate Advisory: OpenClaw's skills-install-download can be redirected outside the tools root by rebinding the validated base path
Moderate
GHSA-6q2v-vfwp-pvwh
was published
for
openclaw
(npm)
Mar 29, 2026
•
withdrawn
Duplicate Advisory: OpenClaw's system.run approval TOCTOU via mutable symlink cwd target on node host
Moderate
GHSA-3p2x-hjxj-c7rv
was published
for
openclaw
(npm)
Mar 21, 2026
•
withdrawn
Duplicate Advisory: OpenClaw: system.run approvals did not bind PATH-token executable identity, enabling post-approval executable rebind
Moderate
GHSA-q86m-697p-h7fh
was published
for
openclaw
(npm)
Mar 19, 2026
•
withdrawn
OpenClaw: Sandbox `writeFile` commit could race outside the validated path
Moderate
CVE-2026-32977
was published
for
openclaw
(npm)
Mar 13, 2026
OpenClaw's skills-install-download can be redirected outside the tools root by rebinding the validated base path
Moderate
CVE-2026-33574
was published
for
openclaw
(npm)
Mar 12, 2026
OpenClaw's system.run approvals did not bind mutable script operands across approval and execution
Moderate
CVE-2026-32921
was published
for
openclaw
(npm)
Mar 12, 2026
OpenClaw: Unified root-bound write hardening for browser output and related path-boundary flows
Moderate
CVE-2026-22180
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw's web tools strict URL guard could lose DNS pinning when env proxy is configured
Moderate
CVE-2026-22181
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw's system.run approval TOCTOU via mutable symlink cwd target on node host
Moderate
CVE-2026-32043
was published
for
openclaw
(npm)
Mar 3, 2026
Outray cli is vulnerable to race conditions in tunnels creation
Moderate
CVE-2026-22820
was published
for
outray
(npm)
Jan 13, 2026
Nest has a Fastify URL Encoding Middleware Bypass (TOCTOU)
Moderate
CVE-2025-69211
was published
for
@nestjs/platform-fastify
(npm)
Dec 30, 2025
ProTip!
Advisories are also available from the
GraphQL API