File tree Expand file tree Collapse file tree 8 files changed +72
-16
lines changed
advisories/github-reviewed/2026/03 Expand file tree Collapse file tree 8 files changed +72
-16
lines changed Original file line number Diff line number Diff line change 11{
22 "schema_version" : " 1.4.0" ,
33 "id" : " GHSA-57hq-95w6-v4fc" ,
4- "modified" : " 2026-03-18T19:37:07Z " ,
4+ "modified" : " 2026-03-18T21:51:29Z " ,
55 "published" : " 2026-03-17T17:24:17Z" ,
66 "aliases" : [
77 " CVE-2026-32700"
4343 "type" : " WEB" ,
4444 "url" : " https://github.com/heartcombo/devise/security/advisories/GHSA-57hq-95w6-v4fc"
4545 },
46+ {
47+ "type" : " ADVISORY" ,
48+ "url" : " https://nvd.nist.gov/vuln/detail/CVE-2026-32700"
49+ },
4650 {
4751 "type" : " WEB" ,
4852 "url" : " https://github.com/heartcombo/devise/issues/5783"
6771 "severity" : " MODERATE" ,
6872 "github_reviewed" : true ,
6973 "github_reviewed_at" : " 2026-03-17T17:24:17Z" ,
70- "nvd_published_at" : null
74+ "nvd_published_at" : " 2026-03-18T21:16:26Z "
7175 }
7276}
Original file line number Diff line number Diff line change 11{
22 "schema_version" : " 1.4.0" ,
33 "id" : " GHSA-62f6-mrcj-v8h5" ,
4- "modified" : " 2026-03-18T01:33:52Z " ,
4+ "modified" : " 2026-03-18T21:51:56Z " ,
55 "published" : " 2026-03-03T22:12:20Z" ,
66 "aliases" : [
77 " CVE-2026-27524"
4040 "type" : " WEB" ,
4141 "url" : " https://github.com/openclaw/openclaw/security/advisories/GHSA-62f6-mrcj-v8h5"
4242 },
43+ {
44+ "type" : " ADVISORY" ,
45+ "url" : " https://nvd.nist.gov/vuln/detail/CVE-2026-27524"
46+ },
4347 {
4448 "type" : " WEB" ,
4549 "url" : " https://github.com/openclaw/openclaw/commit/fbb79d4013000552d6a2c23b9613d8b3cb92f6b6"
4650 },
4751 {
4852 "type" : " PACKAGE" ,
4953 "url" : " https://github.com/openclaw/openclaw"
54+ },
55+ {
56+ "type" : " WEB" ,
57+ "url" : " https://www.vulncheck.com/advisories/openclaw-prototype-pollution-via-debug-override-path"
5058 }
5159 ],
5260 "database_specific" : {
5664 "severity" : " LOW" ,
5765 "github_reviewed" : true ,
5866 "github_reviewed_at" : " 2026-03-03T22:12:20Z" ,
59- "nvd_published_at" : null
67+ "nvd_published_at" : " 2026-03-18T02:16:23Z "
6068 }
6169}
Original file line number Diff line number Diff line change 11{
22 "schema_version" : " 1.4.0" ,
33 "id" : " GHSA-gc62-2v5p-qpmp" ,
4- "modified" : " 2026-03-17T17:12:35Z " ,
4+ "modified" : " 2026-03-18T21:51:12Z " ,
55 "published" : " 2026-03-17T17:12:34Z" ,
66 "aliases" : [
77 " CVE-2026-32636"
382382 "type" : " WEB" ,
383383 "url" : " https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-gc62-2v5p-qpmp"
384384 },
385+ {
386+ "type" : " ADVISORY" ,
387+ "url" : " https://nvd.nist.gov/vuln/detail/CVE-2026-32636"
388+ },
385389 {
386390 "type" : " PACKAGE" ,
387391 "url" : " https://github.com/ImageMagick/ImageMagick"
402406 "severity" : " MODERATE" ,
403407 "github_reviewed" : true ,
404408 "github_reviewed_at" : " 2026-03-17T17:12:34Z" ,
405- "nvd_published_at" : null
409+ "nvd_published_at" : " 2026-03-18T21:16:26Z "
406410 }
407411}
Original file line number Diff line number Diff line change 11{
22 "schema_version" : " 1.4.0" ,
33 "id" : " GHSA-jwf4-8wf4-jf2m" ,
4- "modified" : " 2026-03-18T01:25:21Z " ,
4+ "modified" : " 2026-03-18T21:52:51Z " ,
55 "published" : " 2026-03-04T19:44:50Z" ,
66 "aliases" : [
77 " CVE-2026-22170"
4040 "type" : " WEB" ,
4141 "url" : " https://github.com/openclaw/openclaw/security/advisories/GHSA-jwf4-8wf4-jf2m"
4242 },
43+ {
44+ "type" : " ADVISORY" ,
45+ "url" : " https://nvd.nist.gov/vuln/detail/CVE-2026-22170"
46+ },
4347 {
4448 "type" : " WEB" ,
4549 "url" : " https://github.com/openclaw/openclaw/commit/2ba6de7eaad812e5e8603018e14e54e96bdd57dd"
5963 {
6064 "type" : " PACKAGE" ,
6165 "url" : " https://github.com/openclaw/openclaw"
66+ },
67+ {
68+ "type" : " WEB" ,
69+ "url" : " https://www.vulncheck.com/advisories/openclaw-bluebubbles-access-control-bypass-via-empty-allowfrom-configuration"
6270 }
6371 ],
6472 "database_specific" : {
6876 "severity" : " MODERATE" ,
6977 "github_reviewed" : true ,
7078 "github_reviewed_at" : " 2026-03-04T19:44:50Z" ,
71- "nvd_published_at" : null
79+ "nvd_published_at" : " 2026-03-18T02:16:21Z "
7280 }
7381}
Original file line number Diff line number Diff line change 11{
22 "schema_version" : " 1.4.0" ,
33 "id" : " GHSA-m8v2-6wwh-r4gc" ,
4- "modified" : " 2026-03-18T01:33:29Z " ,
4+ "modified" : " 2026-03-18T21:52:35Z " ,
55 "published" : " 2026-03-03T23:10:01Z" ,
66 "aliases" : [
77 " CVE-2026-27523"
4343 "type" : " WEB" ,
4444 "url" : " https://github.com/openclaw/openclaw/security/advisories/GHSA-m8v2-6wwh-r4gc"
4545 },
46+ {
47+ "type" : " ADVISORY" ,
48+ "url" : " https://nvd.nist.gov/vuln/detail/CVE-2026-27523"
49+ },
4650 {
4751 "type" : " WEB" ,
4852 "url" : " https://github.com/openclaw/openclaw/commit/b5787e4abba0dcc6baf09051099f6773c1679ec1"
4953 },
5054 {
5155 "type" : " PACKAGE" ,
5256 "url" : " https://github.com/openclaw/openclaw"
57+ },
58+ {
59+ "type" : " WEB" ,
60+ "url" : " https://www.vulncheck.com/advisories/openclaw-sandbox-bind-validation-bypass-via-symlink-parent-missing-leaf-paths"
5361 }
5462 ],
5563 "database_specific" : {
6068 "severity" : " HIGH" ,
6169 "github_reviewed" : true ,
6270 "github_reviewed_at" : " 2026-03-03T23:10:01Z" ,
63- "nvd_published_at" : null
71+ "nvd_published_at" : " 2026-03-18T02:16:23Z "
6472 }
6573}
Original file line number Diff line number Diff line change 11{
22 "schema_version" : " 1.4.0" ,
33 "id" : " GHSA-p4wh-cr8m-gm6c" ,
4- "modified" : " 2026-03-18T01:32:40Z " ,
4+ "modified" : " 2026-03-18T21:50:28Z " ,
55 "published" : " 2026-03-03T21:36:16Z" ,
66 "aliases" : [
77 " CVE-2026-22217"
4040 "type" : " WEB" ,
4141 "url" : " https://github.com/openclaw/openclaw/security/advisories/GHSA-p4wh-cr8m-gm6c"
4242 },
43+ {
44+ "type" : " ADVISORY" ,
45+ "url" : " https://nvd.nist.gov/vuln/detail/CVE-2026-22217"
46+ },
47+ {
48+ "type" : " WEB" ,
49+ "url" : " https://github.com/openclaw/openclaw/commit/ff10fe8b91670044a6bb0cd85deb736a0ec8fb55"
50+ },
4351 {
4452 "type" : " PACKAGE" ,
4553 "url" : " https://github.com/openclaw/openclaw"
54+ },
55+ {
56+ "type" : " WEB" ,
57+ "url" : " https://www.vulncheck.com/advisories/openclaw-arbitrary-binary-execution-via-shell-environment-variable-trusted-prefix-fallback"
4658 }
4759 ],
4860 "database_specific" : {
5365 "severity" : " HIGH" ,
5466 "github_reviewed" : true ,
5567 "github_reviewed_at" : " 2026-03-03T21:36:16Z" ,
56- "nvd_published_at" : null
68+ "nvd_published_at" : " 2026-03-18T02:16:23Z "
5769 }
5870}
Original file line number Diff line number Diff line change 11{
22 "schema_version" : " 1.4.0" ,
33 "id" : " GHSA-v3j7-34xh-6g3w" ,
4- "modified" : " 2026-03-18T01:29:44Z " ,
4+ "modified" : " 2026-03-18T21:52:16Z " ,
55 "published" : " 2026-03-03T21:50:34Z" ,
66 "aliases" : [
77 " CVE-2026-22174"
4343 "type" : " WEB" ,
4444 "url" : " https://github.com/openclaw/openclaw/security/advisories/GHSA-v3j7-34xh-6g3w"
4545 },
46+ {
47+ "type" : " ADVISORY" ,
48+ "url" : " https://nvd.nist.gov/vuln/detail/CVE-2026-22174"
49+ },
4650 {
4751 "type" : " WEB" ,
4852 "url" : " https://github.com/openclaw/openclaw/commit/afa22acc4a09fdf32be8a167ae216bee85c30dad"
4953 },
5054 {
5155 "type" : " PACKAGE" ,
5256 "url" : " https://github.com/openclaw/openclaw"
57+ },
58+ {
59+ "type" : " WEB" ,
60+ "url" : " https://www.vulncheck.com/advisories/openclaw-gateway-token-disclosure-via-chrome-cdp-probe"
5361 }
5462 ],
5563 "database_specific" : {
6068 "severity" : " MODERATE" ,
6169 "github_reviewed" : true ,
6270 "github_reviewed_at" : " 2026-03-03T21:50:34Z" ,
63- "nvd_published_at" : null
71+ "nvd_published_at" : " 2026-03-18T02:16:21Z "
6472 }
6573}
Original file line number Diff line number Diff line change 11{
22 "schema_version" : " 1.4.0" ,
33 "id" : " GHSA-xvf4-ch4q-2m24" ,
4- "modified" : " 2026-03-16T16:37:42Z " ,
4+ "modified" : " 2026-03-18T21:51:20Z " ,
55 "published" : " 2026-03-16T16:37:42Z" ,
66 "aliases" : [
77 " CVE-2026-32638"
4343 "type" : " WEB" ,
4444 "url" : " https://github.com/withstudiocms/studiocms/security/advisories/GHSA-xvf4-ch4q-2m24"
4545 },
46+ {
47+ "type" : " ADVISORY" ,
48+ "url" : " https://nvd.nist.gov/vuln/detail/CVE-2026-32638"
49+ },
4650 {
4751 "type" : " WEB" ,
4852 "url" : " https://github.com/withstudiocms/studiocms/commit/aebe8bcb3618bb07c6753e3f5c982c1fe6adea64"
6367 "severity" : " LOW" ,
6468 "github_reviewed" : true ,
6569 "github_reviewed_at" : " 2026-03-16T16:37:42Z" ,
66- "nvd_published_at" : null
70+ "nvd_published_at" : " 2026-03-18T21:16:26Z "
6771 }
6872}
You can’t perform that action at this time.
0 commit comments