Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

4,699 advisories

Loading
Fabric.js Affected by Stored XSS via SVG Export High
CVE-2026-27013 was published for fabric (npm) Feb 18, 2026
nedlir
Credited to nedlir
Adam55A-code
Credited to Adam55A-code
OpenClaw hardened the skill download target directory validation Moderate
CVE-2026-27008 was published for openclaw (npm) Feb 18, 2026
Adam55A-code
Credited to Adam55A-code
OpenClaw's sandbox config hash sorted primitive arrays and suppressed needed container recreation Moderate
CVE-2026-27007 was published for openclaw (npm) Feb 18, 2026
kexinoh
Credited to kexinoh
OpenClaw session tool visibility hardening and Telegram webhook secret fallback Moderate
CVE-2026-27004 was published for openclaw (npm) Feb 18, 2026
aether-ai-agent
Credited to aether-ai-agent
OpenClaw: Telegram bot token exposure via logs Moderate
CVE-2026-27003 was published for openclaw (npm) Feb 18, 2026
aether-ai-agent
Credited to aether-ai-agent
OpenClaw: Docker container escape via unvalidated bind mount config injection High
CVE-2026-27002 was published for openclaw (npm) Feb 18, 2026
aether-ai-agent
Credited to aether-ai-agent
OpenClaw: Unsanitized CWD path injection into LLM prompts High
CVE-2026-27001 was published for openclaw (npm) Feb 18, 2026
aether-ai-agent
Credited to aether-ai-agent
RediSearch Query Injection in @langchain/langgraph-checkpoint-redis Moderate
CVE-2026-27022 was published for @langchain/langgraph-checkpoint-redis (npm) Feb 18, 2026
yardenporat353 hntrl
Credited to yardenporat353 and hntrl
minimatch has a ReDoS via repeated wildcards with non-matching literal in pattern High
CVE-2026-26996 was published for minimatch (npm) Feb 18, 2026
AkshayJainG
Credited to AkshayJainG
Command Injection via Unsanitized `locate` Output in `versions()` — systeminformation High
CVE-2026-26318 was published for systeminformation (npm) Feb 18, 2026
Sanu1999
Credited to Sanu1999
Systeminformation has a Command Injection via unsanitized interface parameter in wifi.js retry path High
CVE-2026-26280 was published for systeminformation (npm) Feb 18, 2026
mom3gool
Credited to mom3gool
Ghost has a SQL injection in Content API Critical
CVE-2026-26980 was published for ghost (npm) Feb 18, 2026
Improper Control of Generation of Code ('Code Injection') in @tygo-van-den-hurk/slyde High
CVE-2026-26974 was published for @tygo-van-den-hurk/slyde (npm) Feb 18, 2026
Tygo-van-den-Hurk
Credited to Tygo-van-den-Hurk
OpenClaw has an authentication bypass in sandbox browser bridge server High
GHSA-h9g4-589h-68xv was published for openclaw (npm) Feb 18, 2026
jackhax
Credited to jackhax
OpenClaw has two SSRF via sendMediaFeishu and markdown image fetching in Feishu extension High
GHSA-x22m-j5qq-j49m was published for openclaw (npm) Feb 18, 2026
zpbrent
Credited to zpbrent
OpenClaw has a LFI in BlueBubbles media path handling High
GHSA-rwj8-p9vq-25gv was published for openclaw (npm) Feb 18, 2026
zpbrent
Credited to zpbrent
OpenClaw: Process Safety - Unvalidated PID Kill via SIGKILL in Process Cleanup Moderate
GHSA-jfv4-h8mc-jcp8 was published for openclaw (npm) Feb 18, 2026
aether-ai-agent
Credited to aether-ai-agent
OpenClaw Chutes manual OAuth state validation bypass can cause credential substitution Moderate
GHSA-7rcp-mxpq-72pj was published for openclaw (npm) Feb 18, 2026
OpenClaw: Prevent shell injection in macOS keychain credential write High
GHSA-4564-pvr2-qq4h was published for openclaw (npm) Feb 18, 2026
aether-ai-agent
Credited to aether-ai-agent
OpenClaw has a path traversal in browser trace/download output paths may allow arbitrary file writes High
GHSA-gq9c-wg68-gwj2 was published for openclaw (npm) Feb 18, 2026
jackhax
Credited to jackhax
OpenClaw has a Path Traversal in Browser Download Functionality Moderate
CVE-2026-26972 was published for openclaw (npm) Feb 18, 2026
locus-x64
Credited to locus-x64
OpenClaw affected by potential code execution via unsafe hook module path handling in Gateway High
GHSA-v6c6-vqqg-w888 was published for openclaw (npm) Feb 18, 2026
222n5
Credited to 222n5
OpenClaw's unsanitized session ID enables path traversal in transcript file operations Moderate
GHSA-5xfq-5mr7-426q was published for openclaw (npm) Feb 18, 2026
akhmittra
Credited to akhmittra
scumfrog
Credited to scumfrog
ProTip! Advisories are also available from the GraphQL API