GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
42
GitHub Actions
43
Go
3,164
Maven
5,000+
npm
5,000+
NuGet
863
pip
4,458
Pub
12
RubyGems
991
Rust
1,184
Swift
50
Unreviewed advisories
All unreviewed
5,000+
27,184 advisories
Filter by severity
SFTPGo improperly sanitizes placeholders in group home directories/key prefixes
Moderate
CVE-2026-30915
was published
for
github.com/drakkan/sftpgo/v2
(Go)
Mar 13, 2026
SFTPGo Vulnerable to Path Traversal and Permission Bypass via Path Normalization Discrepancy
Moderate
CVE-2026-30914
was published
for
github.com/drakkan/sftpgo
(Go)
Mar 13, 2026
Locutus vulnerable to RCE via unsanitized input in create_function()
Critical
CVE-2026-32304
was published
for
locutus
(npm)
Mar 13, 2026
SM9 Infinity-Point Ciphertext Forgery Vulnerability
Critical
CVE-2026-32614
was published
for
github.com/emmansun/gmsm
(Go)
Mar 13, 2026
OpenClaw: Unavailable local auth SecretRefs could fall through to remote credentials in local mode
Low
GHSA-qvr7-g57c-mrc7
was published
for
openclaw
(npm)
Mar 13, 2026
OpenClaw: Sandbox staged writes could escape the verified parent directory before commit
High
GHSA-mj4p-rc52-m843
was published
for
openclaw
(npm)
Mar 13, 2026
OpenClaw: Write-scoped callers could reach admin-only session reset logic through `agent`
Moderate
GHSA-jf6w-m8jw-jfxc
was published
for
openclaw
(npm)
Mar 13, 2026
OpenClaw: Unrecognized script runners could bypass `system.run` approval integrity
High
GHSA-qc36-x95h-7j53
was published
for
openclaw
(npm)
Mar 13, 2026
OpenClaw: Channel commands could bypass account-scoped `configWrites` restrictions
Moderate
GHSA-8jhh-jcqg-mj5p
was published
for
openclaw
(npm)
Mar 13, 2026
OpenClaw: Node-host approvals could show misleading shell payloads instead of the executed argv
High
GHSA-rw39-5899-8mxp
was published
for
openclaw
(npm)
Mar 13, 2026
OpenClaw: Unbound interpreter and runtime commands could bypass node-host approval integrity
High
GHSA-xf99-j42q-5w5p
was published
for
openclaw
(npm)
Mar 13, 2026
OpenClaw: Leaf subagents could steer sibling sessions across sandbox boundaries
High
GHSA-4w7m-58cg-cmff
was published
for
openclaw
(npm)
Mar 13, 2026
OpenClaw: Pairing-scoped device tokens could mint `operator.admin` and reach node RCE
Critical
GHSA-4jpw-hj22-2xmc
was published
for
openclaw
(npm)
Mar 13, 2026
OpenClaw: Plugin subagent routes could bypass gateway authorization with synthetic admin scopes
Critical
GHSA-xw77-45gv-p728
was published
for
openclaw
(npm)
Mar 13, 2026
OpenClaw: Sandbox `writeFile` commit could race outside the validated path
Moderate
GHSA-xvx8-77m6-gwg6
was published
for
openclaw
(npm)
Mar 13, 2026
flatted vulnerable to unbounded recursion DoS in parse() revive phase
High
CVE-2026-32141
was published
for
flatted
(npm)
Mar 13, 2026
Poseidon V1 variable-length input collision via implicit zero-padding
High
CVE-2026-32129
was published
for
soroban-poseidon
(Rust)
Mar 13, 2026
Magic Wormhole: "wormhole receive" allows arbitrary local file overwrite
High
CVE-2026-32116
was published
for
magic-wormhole
(pip)
Mar 13, 2026
Dagu: Path Traversal via `dagRunId` in Inline DAG Execution
Critical
CVE-2026-31886
was published
for
github.com/dagu-org/dagu
(Go)
Mar 13, 2026
Dagu: SSE Authentication Bypass in Basic Auth Mode
High
CVE-2026-31882
was published
for
dagu
(npm)
Mar 13, 2026
SandboxJS affected by a Sandbox Escape
Critical
CVE-2026-26954
was published
for
@nyariv/sandboxjs
(npm)
Mar 13, 2026
Ella Core: AMF DoS via malformed PathSwitchRequest with empty NR security capability bitstrings
Moderate
CVE-2026-32320
was published
for
github.com/ellanetworks/core
(Go)
Mar 12, 2026
Ella Core vulnerable to Unauthenticated AMF DoS via malformed InitialUEMessage with undersized integrity-protected NAS payload
High
CVE-2026-32319
was published
for
github.com/ellanetworks/core
(Go)
Mar 12, 2026
OpenClaw: Untrusted web origins can obtain authenticated operator.admin access in trusted-proxy mode
High
CVE-2026-32302
was published
for
openclaw
(npm)
Mar 12, 2026
TinaCMS CLI has Arbitrary File Read via Disabled Vite Filesystem Restriction
Moderate
CVE-2026-29066
was published
for
@tinacms/cli
(npm)
Mar 12, 2026
ProTip!
Advisories are also available from the
GraphQL API