GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,508
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
70 advisories
Filter by severity
Budibase: Privilege escalation via public role assignment API missing app-level authorization
High
GHSA-j9fc-w3mr-x6mv
was published
for
@budibase/server
(npm)
Jul 24, 2026
n8n: Privilege Escalation and Code Execution via Full Public API Key Scope Assignment to Token Exchange JWTs
High
CVE-2026-65595
was published
for
n8n
(npm)
Jul 22, 2026
Duplicate Advisory: n8n: Privilege Escalation and Code Execution via Full Public API Key Scope Assignment to Token Exchange JWTs
High
GHSA-wq64-hcrf-8m56
was published
for
n8n
(npm)
Jul 22, 2026
•
withdrawn
@better-auth/sso: SSO provider may allow registration for any org member without a checking their role
High
CVE-2026-53515
was published
for
@better-auth/sso
(npm)
Jul 20, 2026
OpenClaw: Same-host trusted-proxy deployments could accept local forged identity headers
High
GHSA-rggc-m335-3wvj
was published
for
openclaw
(npm)
Jul 2, 2026
OpenClaw: Bootstrap token replay could widen pending pairing scopes
Low
CVE-2026-53862
was published
for
openclaw
(npm)
Jun 18, 2026
OpenClaw: Shell positional parameters could weaken strict inline-eval checks
High
CVE-2026-53855
was published
for
openclaw
(npm)
Jun 18, 2026
@hulumi/policies: CIS 1.16 admin policy bypass for inline and attached IAM policies
High
GHSA-4xrh-5m3m-328w
was published
for
@hulumi/policies
(npm)
May 21, 2026
Budibase: Missing Cache Invalidation on Public API Role Unassignment Allows Revoked Users to Retain Privileges for Up to 1 Hour
Moderate
CVE-2026-46424
was published
for
@budibase/backend-core
(npm)
May 19, 2026
Budibase: Builder-to-Admin Privilege Escalation via onboardUsers Endpoint Without SMTP Configuration
High
CVE-2026-45716
was published
for
@budibase/worker
(npm)
May 18, 2026
Open WebUI: Missing `workspace.tools` Authorization Check on Tool Update Endpoint Allows Privilege Escalation to Code Execution
High
CVE-2026-45395
was published
for
open-webui
(npm)
May 14, 2026
Duplicate Advisory: OpenClaw: Gateway operator.write Can Reach Admin-Class Telegram Config and Cron Persistence via send
High
GHSA-394x-274p-mqc6
was published
for
openclaw
(npm)
Apr 24, 2026
•
withdrawn
OpenClaw: Agent hook events could enqueue trusted system events from unsanitized external input
Moderate
CVE-2026-43534
was published
for
openclaw
(npm)
Apr 17, 2026
OpenClaw: Heartbeat owner downgrade missed local async exec completion events
Moderate
GHSA-g375-h3v6-4873
was published
for
openclaw
(npm)
Apr 17, 2026
OpenClaw: Gateway plugin HTTP `auth: gateway` widens identity-bearing `operator.read` requests into runtime `operator.write`
Low
CVE-2026-42429
was published
for
openclaw
(npm)
Apr 9, 2026
OpenClaw `node.pair.approve` placed in `operator.write` scope instead of `operator.pairing` allows unprivileged pairing approval
Moderate
CVE-2026-42426
was published
for
openclaw
(npm)
Apr 9, 2026
OpenClaw: Read-scoped identity-bearing HTTP clients could kill sessions via /sessions/:sessionKey/kill
Moderate
CVE-2026-41298
was published
for
openclaw
(npm)
Apr 7, 2026
OpenClaw: Gateway operator.write Can Reach Admin-Class Telegram Config and Cron Persistence via send
High
CVE-2026-41359
was published
for
openclaw
(npm)
Apr 7, 2026
OpenClaw: Gateway operator.write Can Reach Admin-Class Talk Voice Config Persistence via chat.send
Moderate
CVE-2026-41379
was published
for
openclaw
(npm)
Apr 7, 2026
OpenClaw: Unbound bootstrap setup codes allow privilege escalation during pairing
High
CVE-2026-41386
was published
for
openclaw
(npm)
Apr 3, 2026
OpenClaw: Host exec environment overrides miss proxy, TLS, Docker, and Git TLS controls
Moderate
CVE-2026-41330
was published
for
openclaw
(npm)
Apr 3, 2026
OpenClaw: Unauthenticated plugin-auth HTTP routes receive operator runtime scopes
Moderate
CVE-2026-41394
was published
for
openclaw
(npm)
Apr 2, 2026
OpenClaw: Gateway operator.write Can Reach Admin-Class Channel Allowlist Persistence via chat.send
High
CVE-2026-35621
was published
for
openclaw
(npm)
Mar 30, 2026
OpenClaw: Gateway Backend Reconnect lets Non-Admin Operator Scopes Self-Claim operator.admin
Critical
CVE-2026-35663
was published
for
openclaw
(npm)
Mar 27, 2026
OpenClaw Gateway: RCE and Privilege Escalation from operator.pairing to operator.admin via device.pair.approve
Critical
CVE-2026-35639
was published
for
openclaw
(npm)
Mar 26, 2026
ProTip!
Advisories are also available from the
GraphQL API