Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

6 advisories

Loading
n8n has Potential Remote Code Execution via Merge Node Critical
CVE-2026-27497 was published for n8n (npm) Feb 25, 2026
allsmog Credited to allsmog and nil340 nil340 nil340
OpenClaw has command injection via Windows shell fallback in Lobster tool execution High
GHSA-7fcc-cw49-xm78 was published for openclaw (npm) Mar 3, 2026
allsmog Credited to allsmog
OpenClaw Vulnerable to HTML injection via unvalidated image MIME type in data-URL interpolation Moderate
GHSA-2ww6-868g-2c56 was published for openclaw (npm) Mar 3, 2026
allsmog Credited to allsmog
OpenClaw vulnerable to path traversal in Feishu media temp-file naming allows writes outside os.tmpdir() Moderate
GHSA-vj3g-5px3-gr46 was published for openclaw (npm) Mar 3, 2026
allsmog Credited to allsmog
allsmog Credited to allsmog
OpenClaw has stored XSS in exported session HTML viewer via markdown/raw-HTML rendering Moderate
GHSA-r294-2894-92j3 was published for openclaw (npm) Mar 3, 2026
allsmog Credited to allsmog
ProTip! Advisories are also available from the GraphQL API