Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

4,733 advisories

Loading
OpenClaw affected by potential code execution via unsafe hook module path handling in Gateway High
GHSA-v6c6-vqqg-w888 was published for openclaw (npm) Feb 18, 2026
222n5
Credited to 222n5
Axios is Vulnerable to Denial of Service via __proto__ Key in mergeConfig High
CVE-2026-25639 was published for axios (npm) Feb 9, 2026
hackerman70000 FeBe95
Credited to hackerman70000 and FeBe95
OpenClaw has a path traversal in browser trace/download output paths may allow arbitrary file writes High
GHSA-gq9c-wg68-gwj2 was published for openclaw (npm) Feb 18, 2026
jackhax
Credited to jackhax
OpenClaw Chutes manual OAuth state validation bypass can cause credential substitution Moderate
GHSA-7rcp-mxpq-72pj was published for openclaw (npm) Feb 18, 2026
OpenClaw has a LFI in BlueBubbles media path handling High
GHSA-rwj8-p9vq-25gv was published for openclaw (npm) Feb 18, 2026
zpbrent
Credited to zpbrent
OpenClaw has two SSRF via sendMediaFeishu and markdown image fetching in Feishu extension High
GHSA-x22m-j5qq-j49m was published for openclaw (npm) Feb 18, 2026
zpbrent
Credited to zpbrent
OpenClaw has an authentication bypass in sandbox browser bridge server High
GHSA-h9g4-589h-68xv was published for openclaw (npm) Feb 18, 2026
jackhax
Credited to jackhax
RediSearch Query Injection in @langchain/langgraph-checkpoint-redis Moderate
CVE-2026-27022 was published for @langchain/langgraph-checkpoint-redis (npm) Feb 18, 2026
yardenporat353 hntrl
Credited to yardenporat353 and hntrl
SandboxJS Vulnerable to Prototype Pollution -> Sandbox Escape -> RCE Critical
CVE-2026-25142 was published for @nyariv/sandboxjs (npm) Feb 2, 2026
c0rydoras
Credited to c0rydoras
Jvr2022
Credited to Jvr2022
BSV Blockchain SDK has an Authentication Signature Data Preparation Vulnerability Moderate
CVE-2025-69287 was published for @bsv/sdk (npm) Feb 17, 2026
F1r3Hydr4nt
Credited to F1r3Hydr4nt
Unauthorized npm publish of cline@2.3.0 with modified postinstall script Low
GHSA-9ppg-jx86-fqw7 was published for cline (npm) Feb 19, 2026
AdnaneKhan
Credited to AdnaneKhan
Cache poisoning in @sveltejs/adapter-vercel Moderate
CVE-2026-27118 was published for @sveltejs/adapter-vercel (npm) Feb 19, 2026
elliott-with-the-longest-name-on-github
Credited to elliott-with-the-longest-name-on-github
Svelte affected by XSS in SSR `<option>` element Moderate
CVE-2026-27119 was published for svelte (npm) Feb 19, 2026
elliott-with-the-longest-name-on-github
Credited to elliott-with-the-longest-name-on-github
Svelte affected by cross-site scripting via spread attributes in Svelte SSR Moderate
CVE-2026-27121 was published for svelte (npm) Feb 19, 2026
elliott-with-the-longest-name-on-github
Credited to elliott-with-the-longest-name-on-github
Svelte SSR does not validate dynamic element tag names in `<svelte:element>` Moderate
CVE-2026-27122 was published for svelte (npm) Feb 19, 2026
elliott-with-the-longest-name-on-github
Credited to elliott-with-the-longest-name-on-github
jsPDF has a PDF Object Injection via Unsanitized Input in addJS Method High
CVE-2026-25755 was published for jspdf (npm) Feb 19, 2026
ZeroXJacks
Credited to ZeroXJacks
OpenClaw has a Web Fetch DoS via unbounded response parsing Moderate
GHSA-p536-vvpp-9mc8 was published for openclaw (npm) Feb 19, 2026
xuemian168 ShangzhiXu
Credited to xuemian168 and ShangzhiXu
OpenClaw replaced a deprecated sandbox hash algorithm Moderate
GHSA-fh3f-q9qw-93j9 was published for openclaw (npm) Feb 19, 2026
kexinoh
Credited to kexinoh
Hono added timing comparison hardening in basicAuth and bearerAuth Low
GHSA-gq3j-xvxp-8hrf was published for hono (npm) Feb 19, 2026
Exagone313
Credited to Exagone313
eBay API MCP Server Affected by Environment Variable Injection High
CVE-2026-27203 was published for ebay-mcp (npm) Feb 19, 2026
nedlir
Credited to nedlir
Prototype pollution in swiper Critical
CVE-2026-27212 was published for swiper (npm) Feb 19, 2026
kevgeoleo vdata1
reallyTG
Credited to kevgeoleo, vdata1, and reallyTG
Svelte SSR attribute spreading includes inherited properties from prototype chain Moderate
CVE-2026-27125 was published for svelte (npm) Feb 19, 2026
elliott-with-the-longest-name-on-github
Credited to elliott-with-the-longest-name-on-github
devalue `uneval`ed code can create objects with polluted prototypes when `eval`ed Low
GHSA-8qm3-746x-r74r was published for devalue (npm) Feb 19, 2026
elliott-with-the-longest-name-on-github
Credited to elliott-with-the-longest-name-on-github
ProTip! Advisories are also available from the GraphQL API