GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
49
Go
3,549
Maven
5,000+
npm
5,000+
NuGet
917
pip
4,798
Pub
13
RubyGems
1,038
Rust
1,237
Swift
53
Unreviewed advisories
All unreviewed
5,000+
15 advisories
Filter by severity
OpenClaw: QMD memory_get restricts reads to canonical or indexed memory paths
Moderate
GHSA-f934-5rqf-xx47
was published
for
openclaw
(npm)
Apr 17, 2026
OpenClaw: Gateway HTTP endpoints re-resolve bearer auth after SecretRef rotation
High
GHSA-xmxx-7p24-h892
was published
for
openclaw
(npm)
Apr 17, 2026
OpenClaw: Sandboxed agents could escape exec routing via host=node override
High
GHSA-736r-jwj6-4w23
was published
for
openclaw
(npm)
Apr 17, 2026
OpenClaw: Browser press/type interaction routes missed complete navigation guard coverage
Moderate
GHSA-536q-mj95-h29h
was published
for
openclaw
(npm)
Apr 17, 2026
OpenClaw: Existing-session browser interaction routes bypassed SSRF policy enforcement
Moderate
GHSA-527m-976r-jf79
was published
for
openclaw
(npm)
Apr 17, 2026
OpenClaw: Channel setup catalog lookups could include untrusted workspace plugin shadows
High
GHSA-82qx-6vj7-p8m2
was published
for
openclaw
(npm)
Apr 17, 2026
OpenClaw: Agent hook events could enqueue trusted system events from unsanitized external input
Moderate
GHSA-7g8c-cfr3-vqqr
was published
for
openclaw
(npm)
Apr 17, 2026
OpenClaw: Microsoft Teams SSO invoke handler missed sender authorization checks
Low
GHSA-gc9r-867r-j85f
was published
for
openclaw
(npm)
Apr 17, 2026
OpenClaw: Heartbeat owner downgrade missed local async exec completion events
Moderate
GHSA-g375-h3v6-4873
was published
for
openclaw
(npm)
Apr 17, 2026
OpenClaw: Heartbeat owner downgrade missed untrusted webhook wake events
Moderate
GHSA-g2hm-779g-vm32
was published
for
openclaw
(npm)
Apr 17, 2026
OpenClaw: Browser snapshot and screenshot routes could expose internal page content after navigation
Moderate
GHSA-c4qm-58hj-j6pj
was published
for
openclaw
(npm)
Apr 17, 2026
OpenClaw: config.get redaction bypass through sourceConfig and runtimeConfig aliases
High
GHSA-8372-7vhw-cm6q
was published
for
openclaw
(npm)
Apr 17, 2026
OpenClaw: Collect-mode queue batches could reuse the last sender authorization context
Moderate
GHSA-jwrq-8g5x-5fhm
was published
for
openclaw
(npm)
Apr 17, 2026
OpenClaw has Browser SSRF Policy Bypass via Interaction-Triggered Navigation
Moderate
GHSA-vr5g-mmx7-h897
was published
for
openclaw
(npm)
Apr 9, 2026
OpenClaw Nostr privateKey config redaction bypass leaks plaintext signing key via config.get
Moderate
GHSA-jjw7-3vjf-fg5j
was published
for
openclaw
(npm)
Apr 2, 2026
ProTip!
Advisories are also available from the
GraphQL API