Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

33 advisories

Loading
swagger-typescript-api vulnerable to authorization-token exfiltration via spec `$ref` High
CVE-2026-54660 was published for swagger-typescript-api (npm) Jul 29, 2026
thegr1ffyn Credited to thegr1ffyn
Credential confusion in @sigstore/oci can leak registry credentials to an attacker-controlled registry Critical
CVE-2026-59891 was published for @sigstore/oci (npm) Jul 21, 2026
gyubin02 Credited to gyubin02
OpenClaw: message.action forwarding could send Gateway credentials to model-supplied loopback URLs Moderate
GHSA-grc3-2j34-p6gm was published for openclaw (npm) Jul 2, 2026
anshumanbh Credited to anshumanbh
OpenClaw MCP SSE redirects could forward Authorization headers Moderate
GHSA-9c3v-684m-579c was published for openclaw (npm) Jul 1, 2026
dingliweixlm-byte Credited to dingliweixlm-byte
mldangelo-oai Credited to mldangelo-oai
pnpm binds unscoped user-level npm auth credentials to a repository-selected registry Moderate
CVE-2026-50017 was published for pnpm (npm) Jun 26, 2026
mosskappa Credited to mosskappa
launch-editor: NTLMv2 hash disclosure via UNC path handling on Windows Moderate
CVE-2026-53632 was published for launch-editor (npm) Jun 15, 2026
RubenHoms Credited to RubenHoms, toxyl, and bluwy toxyl toxyl
bluwy bluwy
@hapi/wreck: Sensitive credential headers leak across cross-port and cross-scheme redirects Moderate
CVE-2026-48022 was published for @hapi/wreck (npm) Jun 11, 2026
SnailSploit Credited to SnailSploit
FlowiseAI Exposes Basic Auth Credentials via API High
CVE-2026-46440 was published for flowise (npm) May 14, 2026
kolega-ai-dev Credited to kolega-ai-dev
HAXcms: Mass Token Exfiltration and Cross-Tenant Hijack High
CVE-2026-46511 was published for @haxtheweb/haxcms-nodejs (npm) May 19, 2026
trigerman Credited to trigerman
@hapi/wreck leaks sensitive `Proxy-Authorization` header across cross-hostname redirects Moderate
CVE-2026-44979 was published for @hapi/wreck (npm) May 27, 2026
gasbugs Credited to gasbugs
OpenClaw: Workspace dotenv MiniMax host override could redirect credentialed requests Moderate
CVE-2026-44992 was published for openclaw (npm) Apr 25, 2026
nexrin Credited to nexrin
sealed-env: TOTP secret embedded in unseal token payload (enterprise mode) Critical
CVE-2026-45091 was published for io.github.davidalmeidac:sealed-env-core (Maven) May 12, 2026
davidalmeidac Credited to davidalmeidac
@cyclonedx/cdxgen: Docker registry auth substring match forwards credentials to a different registry Moderate
GHSA-qhh4-458h-xwh2 was published for @cyclonedx/cdxgen (npm) May 8, 2026
Flowise: Sensitive Data Leak in public-chatbotConfig High
CVE-2026-41266 was published for flowise (npm) Apr 16, 2026
DenizParlak Credited to DenizParlak
OpenClaw: Media download follows cross-origin redirects with Authorization headers intact Moderate
GHSA-68v4-hmwv-f43h was published for openclaw (npm) Apr 3, 2026
AntAISecurityLab Credited to AntAISecurityLab
OpenClaw: fetch-guard forwards custom authorization headers across cross-origin redirects High
CVE-2026-32913 was published for openclaw (npm) Mar 9, 2026
Rickidevs Credited to Rickidevs
OpenClaw Exposes Credentials Embedded in baseUrl Fields via config.get and channels.status Moderate
GHSA-ppwq-6v66-5m6j was published for openclaw (npm) Mar 26, 2026
zpbrent Credited to zpbrent
OpenClaw reuses the gateway auth token in the owner ID prompt hashing fallback Low
CVE-2026-32897 was published for openclaw (npm) Mar 3, 2026
Duplicate Advisory: OpenClaw reuses the gateway auth token in the owner ID prompt hashing fallback Low
GHSA-8mr2-f9wf-hcfq was published for openclaw (npm) Mar 21, 2026 withdrawn
OpenClaw: Telegram bot token exposure via logs Moderate
CVE-2026-27003 was published for openclaw (npm) Feb 18, 2026
aether-ai-agent Credited to aether-ai-agent
n8n's domain allowlist bypass enables credential exfiltration Moderate
CVE-2026-25631 was published for n8n (npm) Feb 4, 2026
weblover12 Credited to weblover12
Claude Code Leaks Data via Malicious Environment Configuration Before Trust Confirmation Moderate
CVE-2026-21852 was published for @anthropic-ai/claude-code (npm) Jan 21, 2026
Expo SDK has an OAuth vulnerability Critical
CVE-2023-28131 was published for expo (npm) Apr 24, 2023
hbabathe Credited to hbabathe
ChALkeR Credited to ChALkeR
ProTip! Advisories are also available from the GraphQL API