豆豆友情提示:这是一个非官方 GitHub 代理镜像,主要用于网络测试或访问加速。请勿在此进行登录、注册或处理任何敏感信息。进行这些操作请务必访问官方网站 github.com。 Raw 内容也通过此代理提供。
Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

5 advisories

Loading
Flowise: APIChain Prompt Injection SSRF in GET/POST API Chains High
GHSA-6r77-hqx7-7vw8 was published for flowise (npm) Apr 16, 2026
wsparks-vc Credited to wsparks-vc
OpenClaw Host-Exec Environment Variable Injection Moderate
GHSA-w9j9-w4cp-6wgr was published for openclaw (npm) Apr 9, 2026
wsparks-vc Credited to wsparks-vc
OpenClaw: Windows-compatible env override keys could bypass system.run approval binding Moderate
GHSA-98ch-45wp-ch47 was published for openclaw (npm) Apr 7, 2026
wsparks-vc Credited to wsparks-vc and iskindar iskindar iskindar
OpenClaw's complex interpreter pipelines could skip exec script preflight validation Moderate
CVE-2026-34425 was published for openclaw (npm) Apr 6, 2026
wsparks-vc Credited to wsparks-vc and iskindar iskindar iskindar
OpenClaw: Media Parsing Path Traversal Leads to Arbitrary File Read High
GHSA-f6pf-4gjx-c94r was published for openclaw (npm) Apr 3, 2026
wsparks-vc Credited to wsparks-vc and iskindar iskindar iskindar
ProTip! Advisories are also available from the GraphQL API