Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
light_mode
dark_mode
Vulnerabilities
search
All ecosystems
2242520
AlmaLinux
5975
Alpaquita
16176
Alpine
4655
Android
3708
Azure Linux
17971
BellSoft Hardened Containers
770
Bitnami
9501
Chainguard
1048512
CleanStart
5432
CRAN
14
crates.io
2768
Debian
68992
Echo
7853
GHC
3
GIT
109121
GitHub Actions
55
Go
9332
Hackage
33
Hex
365
Julia
1713
Linux
29975
Mageia
6237
Maven
7055
MinimOS
148659
npm
229266
NuGet
1869
opam
29
openEuler
8900
openSUSE
14647
OSS-Fuzz
4019
Packagist
7103
Pub
11
PyPI
25495
Red Hat
23535
Rocky Linux
4344
Root
19650
RubyGems
5369
SUSE
23455
SwiftURL
61
TuxCare
9974
Ubuntu
66090
VSCode
21
Wolfi
293807
ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-g7fw-3gjp-g5hf
npm/@openclaw/feishu
npm/@openclaw/googlechat
npm/@openclaw/matrix
npm/@openclaw/msteams
OpenClaw: Channel read actions could skip target allowlists
5 hours ago
Fix available
Severity - 6.5 (Medium)
MAL-2026-16476
npm/@memtensor/memos-cloud-openclaw-plugin
Malicious code in @memtensor/memos-cloud-openclaw-plugin (npm)
23 Sep
No fix available
GHSA-w8wf-3qvj-6xqf
npm/@openclaw/feishu
OpenClaw Feishu permission tools could ignore per-account disablement
03 Sep
Fix available
Severity - 8.1 (High)
GHSA-2q7j-2vhx-56g8
npm/@openclaw/feishu
OpenClaw Feishu tools could ignore per-account disablement
03 Sep
Fix available
Severity - 8.1 (High)
MAL-2026-11528
npm/@ks-openclaw/kim
Malicious code in @ks-openclaw/kim (npm)
04 Aug
No fix available
GHSA-p73f-w79w-jqr5
npm/openclaw
OpenClaw: Native command authorization could skip owner-command enforcement
02 Jul
Fix available
Severity - 7.2 (High)
GHSA-j472-gf56-x589
npm/openclaw
OpenClaw: PowerShell encoded-command aliases could miss exec allowlist checks
02 Jul
Fix available
Severity - 8.7 (High)
GHSA-77q5-rr5v-x43q
npm/openclaw
OpenClaw: Trusted retry endpoint checks could match hostname prefixes
02 Jul
Fix available
Severity - 7.1 (High)
GHSA-w5ww-7chg-mxcq
npm/openclaw
OpenClaw: Telegram interactive callbacks could skip commands.allowFrom
02 Jul
Fix available
Severity - 8.8 (High)
GHSA-7hxm-f538-3xp6
npm/openclaw
OpenClaw: Matrix allowFrom could bind to mutable display names
02 Jul
Fix available
Severity - 7.7 (High)
GHSA-4m3v-q747-pc6h
npm/openclaw
OpenClaw: Mattermost slash token revocation could lag until monitor refresh
02 Jul
Fix available
Severity - 6.3 (Medium)
GHSA-3c6j-hq33-3jv4
npm/openclaw
OpenClaw: Paired nodes could forge exec lifecycle events without system.run provenance
02 Jul
Fix available
Severity - 8.6 (High)
GHSA-vxx3-6hc9-7cc3
npm/openclaw
OpenClaw: Combined POSIX shell options could confuse exec revalidation
02 Jul
Fix available
Severity - 7.7 (High)
GHSA-rj6p-xmxr-qj4h
npm/openclaw
OpenClaw: MCP loopback could skip owner-only tool policy for non-owner callers
02 Jul
Fix available
Severity - 6.9 (Medium)
GHSA-275c-xpvc-jgfw
npm/openclaw
OpenClaw: Slack and Zalo webhook secrets could remain active after secrets.reload
02 Jul
Fix available
Severity - 6.0 (Medium)
GHSA-3wqp-prf6-2m72
npm/openclaw
OpenClaw: Feishu dynamic-agent bindings could miss configWrites enforcement
02 Jul
Fix available
Severity - 3.1 (Low)
Load more...
npm - OSV