Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

1,845 advisories

Loading
OpenClaw has a path traversal in apply_patch could write/delete files outside the workspace High
GHSA-r5fq-947m-xm57 was published for openclaw (npm) Feb 19, 2026
p80n-sec
Credited to p80n-sec
Feathers exposes internal headers via unencrypted session cookie High
CVE-2026-27193 was published for @feathersjs/authentication-oauth (npm) Feb 19, 2026
vvxhid b0-n0-b0
Credited to vvxhid and b0-n0-b0
Feathers has an origin validation bypass via prefix matching High
CVE-2026-27192 was published for @feathersjs/authentication-oauth (npm) Feb 19, 2026
vvxhid b0-n0-b0
Credited to vvxhid and b0-n0-b0
Feathers has an open redirect in OAuth callback enables account takeover High
CVE-2026-27191 was published for @feathersjs/authentication-oauth (npm) Feb 19, 2026
vvxhid b0-n0-b0
Credited to vvxhid and b0-n0-b0
eBay API MCP Server Affected by Environment Variable Injection High
CVE-2026-27203 was published for ebay-mcp (npm) Feb 19, 2026
nedlir
Credited to nedlir
jsPDF has a PDF Object Injection via Unsanitized Input in addJS Method High
CVE-2026-25755 was published for jspdf (npm) Feb 19, 2026
ZeroXJacks
Credited to ZeroXJacks
jsPDF Affected by Client-Side/Server-Side Denial of Service via Malicious GIF Dimensions High
CVE-2026-25535 was published for jspdf (npm) Feb 19, 2026
ZeroXJacks
Credited to ZeroXJacks
Fabric.js Affected by Stored XSS via SVG Export High
CVE-2026-27013 was published for fabric (npm) Feb 18, 2026
nedlir
Credited to nedlir
OpenClaw: Docker container escape via unvalidated bind mount config injection High
CVE-2026-27002 was published for openclaw (npm) Feb 18, 2026
aether-ai-agent
Credited to aether-ai-agent
OpenClaw: Unsanitized CWD path injection into LLM prompts High
CVE-2026-27001 was published for openclaw (npm) Feb 18, 2026
aether-ai-agent
Credited to aether-ai-agent
minimatch has a ReDoS via repeated wildcards with non-matching literal in pattern High
CVE-2026-26996 was published for minimatch (npm) Feb 18, 2026
AkshayJainG
Credited to AkshayJainG
Command Injection via Unsanitized `locate` Output in `versions()` — systeminformation High
CVE-2026-26318 was published for systeminformation (npm) Feb 18, 2026
Sanu1999
Credited to Sanu1999
Systeminformation has a Command Injection via unsanitized interface parameter in wifi.js retry path High
CVE-2026-26280 was published for systeminformation (npm) Feb 18, 2026
mom3gool
Credited to mom3gool
Improper Control of Generation of Code ('Code Injection') in @tygo-van-den-hurk/slyde High
CVE-2026-26974 was published for @tygo-van-den-hurk/slyde (npm) Feb 18, 2026
Tygo-van-den-Hurk
Credited to Tygo-van-den-Hurk
OpenClaw has an authentication bypass in sandbox browser bridge server High
GHSA-h9g4-589h-68xv was published for openclaw (npm) Feb 18, 2026
jackhax
Credited to jackhax
OpenClaw has two SSRF via sendMediaFeishu and markdown image fetching in Feishu extension High
GHSA-x22m-j5qq-j49m was published for openclaw (npm) Feb 18, 2026
zpbrent
Credited to zpbrent
OpenClaw has a LFI in BlueBubbles media path handling High
GHSA-rwj8-p9vq-25gv was published for openclaw (npm) Feb 18, 2026
zpbrent
Credited to zpbrent
OpenClaw: Prevent shell injection in macOS keychain credential write High
CVE-2026-27487 was published for openclaw (npm) Feb 18, 2026
aether-ai-agent
Credited to aether-ai-agent
OpenClaw has a path traversal in browser trace/download output paths may allow arbitrary file writes High
GHSA-gq9c-wg68-gwj2 was published for openclaw (npm) Feb 18, 2026
jackhax
Credited to jackhax
OpenClaw affected by potential code execution via unsafe hook module path handling in Gateway High
GHSA-v6c6-vqqg-w888 was published for openclaw (npm) Feb 18, 2026
222n5
Credited to 222n5
scumfrog
Credited to scumfrog
OpenClaw inter-session prompts could be treated as direct user instructions High
GHSA-w5c7-9qqw-6645 was published for openclaw (npm) Feb 18, 2026
anbecker
Credited to anbecker
OpenClaw: Command hijacking via unsafe PATH handling (bootstrapping + node-host PATH overrides) High
GHSA-jqpq-mgvm-f9r6 was published for openclaw (npm) Feb 18, 2026
akhmittra
Credited to akhmittra
vincentkoc
Credited to vincentkoc
ProTip! Advisories are also available from the GraphQL API