GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
49
Go
3,585
Maven
5,000+
npm
5,000+
NuGet
923
pip
4,817
Pub
13
RubyGems
1,043
Rust
1,251
Swift
53
Unreviewed advisories
All unreviewed
5,000+
40 advisories
Filter by severity
Time-of-check Time-of-use (TOCTOU) Race Condition in chownr
Low
CVE-2017-18869
was published
for
chownr
(npm)
Feb 10, 2022
NodeJS Driver for Snowflake has race condition when checking access to Easy Logging configuration file
Low
CVE-2025-46328
was published
for
snowflake-sdk
(npm)
Apr 28, 2025
Nest has a Fastify URL Encoding Middleware Bypass (TOCTOU)
Moderate
CVE-2025-69211
was published
for
@nestjs/platform-fastify
(npm)
Dec 30, 2025
Outray cli is vulnerable to race conditions in tunnels creation
Moderate
CVE-2026-22820
was published
for
outray
(npm)
Jan 13, 2026
Turbo Frame responses can restore stale session cookies
Low
CVE-2025-66803
was published
for
@hotwired/turbo
(npm)
Jan 20, 2026
n8n's Improper File Access Controls Allow Arbitrary File Read by Authenticated Users
Critical
CVE-2026-25052
was published
for
n8n
(npm)
Feb 4, 2026
@nyariv/sandboxjs vulnerable to sandbox escape via TOCTOU bug on keys in property accesses
Critical
CVE-2026-25641
was published
for
@nyariv/sandboxjs
(npm)
Feb 5, 2026
OpenClaw's TOCTOU symlink race in writeFileWithinRoot could create or truncate files outside root boundaries
High
GHSA-x82f-27x3-q89c
was published
for
openclaw
(npm)
Mar 2, 2026
OpenClaw: Sandbox media TOCTOU could read files outside sandbox root
High
GHSA-7xmq-g46g-f8pv
was published
for
openclaw
(npm)
Mar 2, 2026
OpenClaw: Microsoft Teams media fetch paths bypass shared SSRF guard model
Low
GHSA-7qf6-h84j-8fq4
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw: Sandbox dangling-symlink alias handling could bypass workspace-only write boundary
High
GHSA-qcc4-p59m-p54m
was published
for
openclaw
(npm)
Mar 12, 2026
OpenClaw: Sandbox staged writes could escape the verified parent directory before commit
High
GHSA-mj4p-rc52-m843
was published
for
openclaw
(npm)
Mar 13, 2026
Race Condition in node-tar Path Reservations via Unicode Ligature Collisions on macOS APFS
High
CVE-2026-23950
was published
for
tar
(npm)
Jan 21, 2026
OpenClaw: Unified root-bound write hardening for browser output and related path-boundary flows
Moderate
CVE-2026-22180
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw: Node system.run approval bypass via parent-symlink cwd rebind
High
CVE-2026-27545
was published
for
openclaw
(npm)
Mar 2, 2026
Duplicate Advisory: OpenClaw: system.run approvals did not bind PATH-token executable identity, enabling post-approval executable rebind
Moderate
GHSA-q86m-697p-h7fh
was published
for
openclaw
(npm)
Mar 19, 2026
•
withdrawn
OpenClaw's web tools strict URL guard could lose DNS pinning when env proxy is configured
Moderate
CVE-2026-22181
was published
for
openclaw
(npm)
Mar 3, 2026
Parse Server has a password reset token single-use bypass via concurrent requests
Low
CVE-2026-32943
was published
for
parse-server
(npm)
Mar 17, 2026
OpenClaw: system.run approvals did not bind PATH-token executable identity, enabling post-approval executable rebind
High
CVE-2026-31997
was published
for
openclaw
(npm)
Mar 2, 2026
OpenClaw: ZIP extraction race could write outside destination via parent symlink rebind
High
CVE-2026-28483
was published
for
openclaw
(npm)
Mar 3, 2026
Duplicate Advisory: OpenClaw's system.run approval TOCTOU via mutable symlink cwd target on node host
Moderate
GHSA-3p2x-hjxj-c7rv
was published
for
openclaw
(npm)
Mar 21, 2026
•
withdrawn
Parse Server: MFA recovery code single-use bypass via concurrent requests
Low
CVE-2026-33624
was published
for
parse-server
(npm)
Mar 24, 2026
Handlebars.js has a Property Access Validation Bypass in container.lookup
Low
GHSA-442j-39wm-28r2
was published
for
handlebars
(npm)
Mar 29, 2026
ProTip!
Advisories are also available from the
GraphQL API