GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
41
Go
3,003
Maven
5,000+
npm
4,732
NuGet
788
pip
4,341
Pub
12
RubyGems
987
Rust
1,137
Swift
50
Unreviewed advisories
All unreviewed
5,000+
1,845 advisories
Filter by severity
OpenClaw has a path traversal in apply_patch could write/delete files outside the workspace
High
GHSA-r5fq-947m-xm57
was published
for
openclaw
(npm)
Feb 19, 2026
Feathers exposes internal headers via unencrypted session cookie
High
CVE-2026-27193
was published
for
@feathersjs/authentication-oauth
(npm)
Feb 19, 2026
Feathers has an origin validation bypass via prefix matching
High
CVE-2026-27192
was published
for
@feathersjs/authentication-oauth
(npm)
Feb 19, 2026
Feathers has an open redirect in OAuth callback enables account takeover
High
CVE-2026-27191
was published
for
@feathersjs/authentication-oauth
(npm)
Feb 19, 2026
eBay API MCP Server Affected by Environment Variable Injection
High
CVE-2026-27203
was published
for
ebay-mcp
(npm)
Feb 19, 2026
jsPDF has a PDF Injection in AcroForm module allows Arbitrary JavaScript Execution (RadioButton.createOption and "AS" property)
High
CVE-2026-25940
was published
for
jspdf
(npm)
Feb 19, 2026
jsPDF has a PDF Object Injection via Unsanitized Input in addJS Method
High
CVE-2026-25755
was published
for
jspdf
(npm)
Feb 19, 2026
jsPDF Affected by Client-Side/Server-Side Denial of Service via Malicious GIF Dimensions
High
CVE-2026-25535
was published
for
jspdf
(npm)
Feb 19, 2026
Fabric.js Affected by Stored XSS via SVG Export
High
CVE-2026-27013
was published
for
fabric
(npm)
Feb 18, 2026
OpenClaw: Docker container escape via unvalidated bind mount config injection
High
CVE-2026-27002
was published
for
openclaw
(npm)
Feb 18, 2026
OpenClaw: Unsanitized CWD path injection into LLM prompts
High
CVE-2026-27001
was published
for
openclaw
(npm)
Feb 18, 2026
minimatch has a ReDoS via repeated wildcards with non-matching literal in pattern
High
CVE-2026-26996
was published
for
minimatch
(npm)
Feb 18, 2026
Command Injection via Unsanitized `locate` Output in `versions()` — systeminformation
High
CVE-2026-26318
was published
for
systeminformation
(npm)
Feb 18, 2026
Systeminformation has a Command Injection via unsanitized interface parameter in wifi.js retry path
High
CVE-2026-26280
was published
for
systeminformation
(npm)
Feb 18, 2026
Improper Control of Generation of Code ('Code Injection') in @tygo-van-den-hurk/slyde
High
CVE-2026-26974
was published
for
@tygo-van-den-hurk/slyde
(npm)
Feb 18, 2026
OpenClaw has an authentication bypass in sandbox browser bridge server
High
GHSA-h9g4-589h-68xv
was published
for
openclaw
(npm)
Feb 18, 2026
OpenClaw has two SSRF via sendMediaFeishu and markdown image fetching in Feishu extension
High
GHSA-x22m-j5qq-j49m
was published
for
openclaw
(npm)
Feb 18, 2026
OpenClaw has a LFI in BlueBubbles media path handling
High
GHSA-rwj8-p9vq-25gv
was published
for
openclaw
(npm)
Feb 18, 2026
OpenClaw: Prevent shell injection in macOS keychain credential write
High
CVE-2026-27487
was published
for
openclaw
(npm)
Feb 18, 2026
OpenClaw has a path traversal in browser trace/download output paths may allow arbitrary file writes
High
GHSA-gq9c-wg68-gwj2
was published
for
openclaw
(npm)
Feb 18, 2026
OpenClaw affected by potential code execution via unsafe hook module path handling in Gateway
High
GHSA-v6c6-vqqg-w888
was published
for
openclaw
(npm)
Feb 18, 2026
Arbitrary File Read/Write via Hardlink Target Escape Through Symlink Chain in node-tar Extraction
High
CVE-2026-26960
was published
for
tar
(npm)
Feb 18, 2026
OpenClaw inter-session prompts could be treated as direct user instructions
High
GHSA-w5c7-9qqw-6645
was published
for
openclaw
(npm)
Feb 18, 2026
OpenClaw: Command hijacking via unsafe PATH handling (bootstrapping + node-host PATH overrides)
High
GHSA-jqpq-mgvm-f9r6
was published
for
openclaw
(npm)
Feb 18, 2026
OpenClaw Google Chat shared-path webhook target ambiguity allowed cross-account policy-context misrouting
High
GHSA-rq6g-px6m-c248
was published
for
clawdbot
(npm)
Feb 18, 2026
ProTip!
Advisories are also available from the
GraphQL API