GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
41
Go
2,989
Maven
5,000+
npm
4,699
NuGet
788
pip
4,328
Pub
12
RubyGems
987
Rust
1,133
Swift
49
Unreviewed advisories
All unreviewed
5,000+
4,699 advisories
Filter by severity
Fabric.js Affected by Stored XSS via SVG Export
High
CVE-2026-27013
was published
for
fabric
(npm)
Feb 18, 2026
OpenClaw affected by Stored XSS in Control UI via unsanitized assistant name/avatar in inline script injection
Moderate
CVE-2026-27009
was published
for
openclaw
(npm)
Feb 18, 2026
OpenClaw hardened the skill download target directory validation
Moderate
CVE-2026-27008
was published
for
openclaw
(npm)
Feb 18, 2026
OpenClaw's sandbox config hash sorted primitive arrays and suppressed needed container recreation
Moderate
CVE-2026-27007
was published
for
openclaw
(npm)
Feb 18, 2026
OpenClaw session tool visibility hardening and Telegram webhook secret fallback
Moderate
CVE-2026-27004
was published
for
openclaw
(npm)
Feb 18, 2026
OpenClaw: Telegram bot token exposure via logs
Moderate
CVE-2026-27003
was published
for
openclaw
(npm)
Feb 18, 2026
OpenClaw: Docker container escape via unvalidated bind mount config injection
High
CVE-2026-27002
was published
for
openclaw
(npm)
Feb 18, 2026
OpenClaw: Unsanitized CWD path injection into LLM prompts
High
CVE-2026-27001
was published
for
openclaw
(npm)
Feb 18, 2026
RediSearch Query Injection in @langchain/langgraph-checkpoint-redis
Moderate
CVE-2026-27022
was published
for
@langchain/langgraph-checkpoint-redis
(npm)
Feb 18, 2026
minimatch has a ReDoS via repeated wildcards with non-matching literal in pattern
High
CVE-2026-26996
was published
for
minimatch
(npm)
Feb 18, 2026
Command Injection via Unsanitized `locate` Output in `versions()` — systeminformation
High
CVE-2026-26318
was published
for
systeminformation
(npm)
Feb 18, 2026
Systeminformation has a Command Injection via unsanitized interface parameter in wifi.js retry path
High
CVE-2026-26280
was published
for
systeminformation
(npm)
Feb 18, 2026
Ghost has a SQL injection in Content API
Critical
CVE-2026-26980
was published
for
ghost
(npm)
Feb 18, 2026
Improper Control of Generation of Code ('Code Injection') in @tygo-van-den-hurk/slyde
High
CVE-2026-26974
was published
for
@tygo-van-den-hurk/slyde
(npm)
Feb 18, 2026
OpenClaw has an authentication bypass in sandbox browser bridge server
High
GHSA-h9g4-589h-68xv
was published
for
openclaw
(npm)
Feb 18, 2026
OpenClaw has two SSRF via sendMediaFeishu and markdown image fetching in Feishu extension
High
GHSA-x22m-j5qq-j49m
was published
for
openclaw
(npm)
Feb 18, 2026
OpenClaw has a LFI in BlueBubbles media path handling
High
GHSA-rwj8-p9vq-25gv
was published
for
openclaw
(npm)
Feb 18, 2026
OpenClaw: Process Safety - Unvalidated PID Kill via SIGKILL in Process Cleanup
Moderate
GHSA-jfv4-h8mc-jcp8
was published
for
openclaw
(npm)
Feb 18, 2026
OpenClaw Chutes manual OAuth state validation bypass can cause credential substitution
Moderate
GHSA-7rcp-mxpq-72pj
was published
for
openclaw
(npm)
Feb 18, 2026
OpenClaw: Prevent shell injection in macOS keychain credential write
High
GHSA-4564-pvr2-qq4h
was published
for
openclaw
(npm)
Feb 18, 2026
OpenClaw has a path traversal in browser trace/download output paths may allow arbitrary file writes
High
GHSA-gq9c-wg68-gwj2
was published
for
openclaw
(npm)
Feb 18, 2026
OpenClaw has a Path Traversal in Browser Download Functionality
Moderate
CVE-2026-26972
was published
for
openclaw
(npm)
Feb 18, 2026
OpenClaw affected by potential code execution via unsafe hook module path handling in Gateway
High
GHSA-v6c6-vqqg-w888
was published
for
openclaw
(npm)
Feb 18, 2026
OpenClaw's unsanitized session ID enables path traversal in transcript file operations
Moderate
GHSA-5xfq-5mr7-426q
was published
for
openclaw
(npm)
Feb 18, 2026
Arbitrary File Read/Write via Hardlink Target Escape Through Symlink Chain in node-tar Extraction
High
CVE-2026-26960
was published
for
tar
(npm)
Feb 18, 2026
ProTip!
Advisories are also available from the
GraphQL API