OsVault/npm/agents
npm

agents

19 known vulnerabilities · 0 critical · 0 high

CVE-2026-1664

Cloudflare Agents SDK has Insecure Direct Object Reference (IDOR) via Header-Based Email Routing

Published Feb 3, 2026
GHSA-w5cr-2qhr-jqc5

Cloudflare Agents has a Reflected Cross-Site Scripting (XSS) vulnerability in AI Playground site

Published Feb 13, 2026
CVE-2026-1721

Cloudflare Agents is Vulnerable to Reflected Cross-Site Scripting in the AI Playground's OAuth callback handler

Published Feb 13, 2026
GHSA-3xx2-mqjm-hg9x

Paperclip: Cross-tenant agent API key IDOR in `/agents/:id/keys` routes allows full victim-company compromise

Published Apr 16, 2026
GHSA-47wq-cj9q-wpmp

Paperclip: Cross-tenant agent API token minting via missing assertCompanyAccess on /api/agents/:id/keys

Published Apr 16, 2026
MAL-2026-3322

Malicious code in microsoft-agents-auth-service (npm)

Published May 4, 2026
GHSA-52vj-fvrv-7q82

OpenClaw vulnerable to SSRF in src/agents/tools/web-fetch.ts

Published Apr 10, 2026
GHSA-7xr2-q9vf-x4r5

OpenClaw: Symlink Traversal via IDENTITY.md appendFile in agents.create/update (Incomplete Fix for CVE-2026-32013)

Published Mar 26, 2026
GHSA-736r-jwj6-4w23

OpenClaw: Sandboxed agents could escape exec routing via host=node override

Published Apr 17, 2026
GHSA-4w7m-58cg-cmff

OpenClaw: Leaf subagents could steer sibling sessions across sandbox boundaries

Published Mar 13, 2026
CVE-2026-32013

OpenClaw gateway agents.files symlink escape allowed out-of-workspace file read/write

Published Mar 2, 2026
GHSA-pmf3-2q63-jmp6

Duplicate Advisory: OpenClaw: Symlink Traversal via IDENTITY.md appendFile in agents.create/update (Incomplete Fix for CVE-2026-32013)

Published Apr 10, 2026
GHSA-x2cm-hg9c-mf5w

OpenClaw leaf subagents can bypass controlScope restrictions to send messages to child sessions

Published Mar 26, 2026
MAL-2025-4880

Malicious code in scrapy-user-agents (npm)

Published Jun 10, 2025
CVE-2026-32918

`OpenClaw: session_status` let sandboxed subagents access parent or sibling session state

Published Mar 13, 2026
GHSA-hh43-q692-2xmq

Duplicate Advisory: `OpenClaw: session_status` let sandboxed subagents access parent or sibling session state

Published Mar 29, 2026
MAL-2026-3149

Malicious code in agents-a365-runtime (npm)

Published Apr 29, 2026
MAL-2025-4322

Malicious code in com.unity.ml-agents (npm)

Published May 23, 2025
MAL-2025-47415

Malicious code in top-crawl-agents (npm)

Published Sep 16, 2025
Check your entire dependency tree at onceRun dependency scan →