GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
41
Go
3,003
Maven
5,000+
npm
4,732
NuGet
788
pip
4,341
Pub
12
RubyGems
987
Rust
1,137
Swift
50
Unreviewed advisories
All unreviewed
5,000+
1,513 advisories
Filter by severity
OpenClaw: ACP prompt-size checks missing in local stdio bridge could reduce responsiveness with very large inputs
Moderate
CVE-2026-27576
was published
for
openclaw
(npm)
Feb 20, 2026
bn.js affected by an infinite loop
Moderate
CVE-2026-2739
was published
for
bn.js
(npm)
Feb 20, 2026
Sync-in Server has a stored cross-site scripting (XSS) vulnerability
Moderate
CVE-2025-67438
was published
for
@sync-in/server
(npm)
Feb 20, 2026
Lettermint Node.js SDK leaks email properties to unintended recipients when client instance is reused
Moderate
CVE-2026-27492
was published
for
lettermint
(npm)
Feb 20, 2026
OpenClaw hardened cron webhook delivery against SSRF
Moderate
CVE-2026-27488
was published
for
openclaw
(npm)
Feb 20, 2026
OpenClaw: Reject symlinks in local skill packaging script
Moderate
CVE-2026-27485
was published
for
openclaw
(npm)
Feb 20, 2026
ajv has ReDoS when using `$data` option
Moderate
CVE-2025-69873
was published
for
ajv
(npm)
Feb 11, 2026
url-parse Incorrectly parses URLs that include an '@'
Moderate
CVE-2022-0639
was published
for
url-parse
(npm)
Feb 18, 2022
Authorization bypass in url-parse
Moderate
CVE-2022-0512
was published
for
url-parse
(npm)
Feb 15, 2022
OpenClaw: Process Safety - Unvalidated PID Kill via SIGKILL in Process Cleanup
Moderate
CVE-2026-27486
was published
for
openclaw
(npm)
Feb 18, 2026
OpenClaw affected by Stored XSS in Control UI via unsanitized assistant name/avatar in inline script injection
Moderate
CVE-2026-27009
was published
for
openclaw
(npm)
Feb 18, 2026
OpenClaw hardened the skill download target directory validation
Moderate
CVE-2026-27008
was published
for
openclaw
(npm)
Feb 18, 2026
OpenClaw's sandbox config hash sorted primitive arrays and suppressed needed container recreation
Moderate
CVE-2026-27007
was published
for
openclaw
(npm)
Feb 18, 2026
OpenClaw session tool visibility hardening and Telegram webhook secret fallback
Moderate
CVE-2026-27004
was published
for
openclaw
(npm)
Feb 18, 2026
OpenClaw: Telegram bot token exposure via logs
Moderate
CVE-2026-27003
was published
for
openclaw
(npm)
Feb 18, 2026
OpenClaw has a Path Traversal in Browser Download Functionality
Moderate
CVE-2026-26972
was published
for
openclaw
(npm)
Feb 18, 2026
OpenClaw iMessage group allowlist authorization inherited DM pairing-store identities
Moderate
CVE-2026-26328
was published
for
clawdbot
(npm)
Feb 18, 2026
OpenClaw skills.status could leak secrets to operator.read clients
Moderate
CVE-2026-26326
was published
for
openclaw
(npm)
Feb 17, 2026
Pannellum has a XSS vulnerability in hot spot attributes
Moderate
CVE-2026-27210
was published
for
pannellum
(npm)
Feb 19, 2026
OpenClaw safeBins file-existence oracle information disclosure
Moderate
GHSA-6c9j-x93c-rw6j
was published
for
openclaw
(npm)
Feb 19, 2026
n8n's domain allowlist bypass enables credential exfiltration
Moderate
CVE-2026-25631
was published
for
n8n
(npm)
Feb 4, 2026
CPU exhaustion in SvelteKit remote form deserialization (experimental only)
Moderate
GHSA-88qp-p4qg-rqm6
was published
for
@sveltejs/kit
(npm)
Feb 19, 2026
Memory exhaustion in SvelteKit remote form deserialization (experimental only)
Moderate
GHSA-vrhm-gvg7-fpcf
was published
for
@sveltejs/kit
(npm)
Feb 19, 2026
Svelte SSR attribute spreading includes inherited properties from prototype chain
Moderate
CVE-2026-27125
was published
for
svelte
(npm)
Feb 19, 2026
OpenClaw replaced a deprecated sandbox hash algorithm
Moderate
GHSA-fh3f-q9qw-93j9
was published
for
openclaw
(npm)
Feb 19, 2026
ProTip!
Advisories are also available from the
GraphQL API