OsVault/npm/ses
npm8 critical

ses

254 known vulnerabilities · 8 critical · 16 high

CVE-2023-39532CRITICAL

SES's dynamic import and spread operator provides possible path to arbitrary exfiltration and execution

Published Aug 9, 2023
CVE-2026-25722

Claude Code Vulnerable to Command Injection via Directory Change Bypasses Write Protection

Published Feb 6, 2026
CVE-2022-39225MEDIUM

parse-server's session object properties can be updated by foreign user if object ID is known

Published Sep 21, 2022
CVE-2025-4644

Payload's SQLite adapter Session Fixation vulnerability

Published Aug 29, 2025
CVE-2023-29019HIGH

Session fixation in fastify-passport

Published Apr 21, 2023
GHSA-4x48-cgf9-q33f

Novu has SSRF via conditions filter webhook bypasses validateUrlSsrf() protection

Published Apr 14, 2026
CVE-2026-25641

@nyariv/sandboxjs vulnerable to sandbox escape via TOCTOU bug on keys in property accesses

Published Feb 5, 2026
GHSA-2qqc-p94c-hxwh

Flowise: Weak Default Express Session Secret

Published Apr 16, 2026
GHSA-2w79-r9g8-wmcr

OpenClaw: Voice-call still parses large WebSocket frames before start validation (Incomplete fix for CVE-2026-32062)

Published Apr 3, 2026
CVE-2021-23348MEDIUM

Arbitrary Command Injection in portprocesses

Published Apr 6, 2021
CVE-2022-2064HIGH

Insufficient Session Expiration in NocoDB

Published Jun 14, 2022
MAL-2026-2419

Malicious code in express-session-js (npm)

Published Apr 2, 2026
GHSA-hv93-r4j3-q65f

OpenClaw Hook Session Key Override Enables Targeted Cross-Session Routing

Published Feb 17, 2026
CVE-2025-53364

Parse Server exposes the data schema via GraphQL API

Published Jul 10, 2025
CVE-2022-0639MEDIUM

url-parse Incorrectly parses URLs that include an '@'

Published Feb 18, 2022
MAL-2026-889

Malicious code in responses-starter-app (npm)

Published Feb 13, 2026
CVE-2026-28482

OpenClaw's unsanitized session ID enables path traversal in transcript file operations

Published Feb 18, 2026
CVE-2023-42282CRITICAL

NPM IP package incorrectly identifies some private IP addresses as public

Published Feb 8, 2024
CVE-2022-31367HIGH

Strapi mishandles hidden attributes within admin API responses

Published Sep 28, 2022
GHSA-39q2-94rc-95cp

DOMPurify's ADD_TAGS function form bypasses FORBID_TAGS due to short-circuit evaluation

Published Apr 16, 2026
CVE-2023-2850MEDIUM

Unintentional leakage of private information via cross-origin websocket session hijacking

Published Jul 25, 2023
GHSA-3f6h-2hrp-w5wx

@sveltejs/kit: Unvalidated redirect in handle hook causes Denial-of-Service

Published Apr 10, 2026
CVE-2025-61686

React Router has Path Traversal in File Session Storage

Published Jan 8, 2026
GHSA-3j8v-cgw4-2g6q

fast-jwt: Stateful RegExp (/g or /y) causes non-deterministic allowed-claim validation (logical DoS)

Published Apr 9, 2026
CVE-2021-25979CRITICAL

Apostrophe CMS Insufficient Session Expiration vulnerability

Published Nov 10, 2021
GHSA-9p93-7j67-5pc2

OpenClaw: Gateway HTTP /sessions/:sessionKey/kill Reaches Admin Kill Path Without Caller Scope Binding

Published Mar 27, 2026
MAL-2022-1136

Malicious code in assessment-zmarta (npm)

Published Jun 20, 2022
CVE-2022-29247LOW

Compromised child renderer processes could obtain IPC access without nodeIntegrationInSubFrames being enabled

Published Jun 16, 2022
CVE-2026-33672

Picomatch: Method Injection in POSIX Character Classes causes incorrect Glob Matching

Published Mar 25, 2026
CVE-2013-7454MEDIUM

Multiple XSS Filter Bypasses in validator

Published Oct 24, 2017
GHSA-48vw-m3qc-wr99

OpenClaw's Trusted-proxy Control UI sessions retain privileged scopes without device identity on device-less allow paths

Published Mar 26, 2026
CVE-2026-33724

n8n's Source Control SSH Configuration Uses StrictHostKeyChecking=no

Published Mar 25, 2026
CVE-2018-7307HIGH

Auth0-js bypasses CSRF checks

Published Mar 7, 2018
GHSA-w7j5-j98m-w679

OpenClaw has multiple E2E/test Dockerfiles that run all processes as root

Published Mar 3, 2026
GHSA-96qw-h329-v5rg

Shakapacker has environment variable leak via EnvironmentPlugin that exposes secrets to client-side bundles

Published Jan 8, 2026
GHSA-wr92-6w3g-2hwc

Duplicate Advisory: OpenClaw's sandboxed sessions_spawn now enforces sandbox inheritance for cross-agent spawns

Published Mar 21, 2026
CVE-2026-33421

Parse Server's LiveQuery bypasses CLP pointer permission enforcement

Published Mar 20, 2026
GHSA-xh9j-mpc9-2m9p

Duplicate Advisory: OpenClaw has a Trusted-proxy Control UI pairing bypass which allows unpaired node sessions

Published Mar 21, 2026
GHSA-8689-gm9g-jgr6

OpenClaw: Voice-call Plivo V3 webhook replay key uses unsorted URL, allowing replay via query-parameter reordering

Published Mar 31, 2026
GHSA-xpcf-pg52-r92g

Hono has incorrect IP matching in ipRestriction() for IPv4-mapped IPv6 addresses

Published Apr 8, 2026
GHSA-chfm-xgc4-47rj

OpenClaw: MSTeams thread history bypasses sender allowlist via Graph API

Published Apr 2, 2026
CVE-2026-32638

StudioCMS REST getUsers Exposes Owner Account Records to Admin Tokens

Published Mar 16, 2026
CVE-2023-22578CRITICAL

Sequelize - Default support for “raw attributes” when using parentheses

Published Feb 24, 2023
CVE-2025-62378

CommandKit has incorrect command name exposure in context object for message command aliases

Published Oct 13, 2025
GHSA-cqgw-44wg-44rf

OpenClaw: Discord voice manager bypasses channel-level member access allowlist

Published Apr 3, 2026
CVE-2026-27004

OpenClaw session tool visibility hardening and Telegram webhook secret fallback

Published Feb 18, 2026
GHSA-j4c9-w69r-cw33

OpenClaw: Telegram DM-Scoped Inline Button Callbacks Bypass DM Pairing and Mutate Session State

Published Mar 29, 2026
GHSA-5r8f-96gm-5j6g

OpenClaw Gateway `operator.write` can reach admin-only session reset via `chat.send` `/reset`

Published Apr 1, 2026
CVE-2026-32742

Parse Server session creation endpoint allows overwriting server-generated session fields

Published Mar 17, 2026
MAL-2026-3053

Malicious code in @apple-pay-trust/merchant-session (npm)

Published Apr 25, 2026
GHSA-5hff-46vh-rxmw

OpenClaw: Read-scoped identity-bearing HTTP clients could kill sessions via /sessions/:sessionKey/kill

Published Apr 7, 2026
GHSA-5j35-xr4g-vwf4

@grackle-ai/server has a Missing Secure Flag on Session Cookie

Published Mar 25, 2026
CVE-2026-28459

OpenClaw has an arbitrary transcript path file write via gateway sessionFile

Published Feb 17, 2026
CVE-2022-3224MEDIUM

parse-url parses http URLs incorrectly, making it vulnerable to host name spoofing

Published Sep 16, 2022
CVE-2026-32594

Parse Server's GraphQL WebSocket endpoint bypasses security middleware

Published Mar 13, 2026
GHSA-8wc6-vgrq-x6cf

Child processes spawned by Renovate incorrectly have full access to environment variables

Published Feb 13, 2026
CVE-2026-30850

Parse Server: File metadata endpoint bypasses `beforeFind` / `afterFind` trigger authorization

Published Mar 9, 2026
GHSA-qf48-qfv4-jjm9

OpenClaw: Feishu extension resolveUploadInput bypasses file-system sandbox and allows arbitrary file reads via upload_image

Published Mar 31, 2026
CVE-2026-27610

Parse Dashboard Has a Cache Key Collision that Leaks Master Key to Read-Only Sessions

Published Feb 25, 2026
MAL-2025-2703

Malicious code in requestz-promises (npm)

Published Mar 25, 2025
CVE-2020-28462HIGH

ion-parser Prototype Pollution when malicious INI file submitted to application that parses with `parse`

Published Jul 26, 2022
GHSA-5wj5-87vq-39xm

OpenClaw: Node Pairing Reconnect Command Escalation Bypasses operator.admin Scope Requirement

Published Apr 9, 2026
CVE-2020-28498MEDIUM

Elliptic Uses a Broken or Risky Cryptographic Algorithm

Published Mar 8, 2021
GHSA-72gr-qfp7-vwhw

h3: Double Decoding in `serveStatic` Bypasses `resolveDotSegments` Path Traversal Protection via `%252e%252e`

Published Mar 20, 2026
GHSA-q2qc-744p-66r2

OpenClaw: `session_status` sessionId resolution bypasses sandboxed session-tree visibility

Published Mar 29, 2026
GHSA-8372-7vhw-cm6q

OpenClaw: config.get redaction bypass through sourceConfig and runtimeConfig aliases

Published Apr 17, 2026
GHSA-75hx-xj24-mqrw

n8n-mcp has unauthenticated session termination and information disclosure in HTTP transport

Published Apr 10, 2026
GHSA-844j-xrrq-wgh4

OpenClaw: Forwarding header spoofing bypasses gateway.trustedProxies origin detection

Published Mar 26, 2026
GHSA-6p8r-6m93-557f

OpenClaw: Fake DeviceToken Bypasses Shared Auth Rate Limiting

Published Apr 3, 2026
GHSA-rqp8-q22p-5j9q

OpenClaw Bypasses DM Policy Separation via Synology Chat Webhook Path Collision

Published Mar 26, 2026
CVE-2026-30965

Parse Server vulnerable to session token exfiltration via `redirectClassNameForKey` query parameter

Published Mar 11, 2026
MAL-2022-2663

Malicious code in edit_session (npm)

Published Nov 7, 2022
CVE-2026-32897

OpenClaw reuses the gateway auth token in the owner ID prompt hashing fallback

Published Mar 3, 2026
MAL-2022-2297

Malicious code in cxd-npm-releases (npm)

Published Jun 20, 2022
CVE-2017-18355HIGH

Rendertron discloses absolute paths of files

Published Feb 12, 2019
CVE-2026-32050

OpenClaw's Signal reaction-only status events could, in limited cases, be enqueued before access checks

Published Mar 3, 2026
CVE-2025-30208

Vite bypasses server.fs.deny when using ?raw??

Published Mar 25, 2025
CVE-2024-45835

Mattermost Desktop App fails to sufficiently configure Electron Fuses

Published Sep 16, 2024
GHSA-w2fm-25vw-vh7f

mcp-handler has a tool response leak across concurrent client sessions ('Race Condition')

Published Apr 1, 2026
CVE-2026-23744

REC in MCPJam inspector due to HTTP Endpoint exposes

Published Jan 16, 2026
CVE-2026-32029

OpenClaw improperly parses X-Forwarded-For behind trusted proxies allows client IP spoofing in security decisions

Published Mar 3, 2026
CVE-2020-15270MEDIUM

receiving subscription objects with deleted session

Published Oct 27, 2020
MAL-2022-132

Malicious code in @bmw-chris/onlinesession-default-frontend (npm)

Published Jun 20, 2022
GHSA-86jj-29wc-7q2w

Duplicate Advisory: OpenClaw's Signal reaction-only status events could, in limited cases, be enqueued before access checks

Published Mar 21, 2026
MAL-2022-2932

Malicious code in exsess (npm)

Published Aug 19, 2022
MAL-2022-1942

Malicious code in cloudshell-session (npm)

Published Jun 20, 2022
GHSA-8f9r-gr6r-x63q

Duplicate Advisory: OpenClaw: Feishu webhook reads and parses unauthenticated request bodies before signature validation

Published Apr 10, 2026
CVE-2026-29184

@backstage/plugin-scaffolder-backend Vulnerable to Potential Session Token Exfiltration via Log Redaction Bypass

Published Mar 5, 2026
GHSA-8rh7-6779-cjqq

OpenClaw has a CWD `.env` environment variable injection which bypasses host-env policy and allows config takeover

Published Apr 1, 2026
GHSA-39mp-545q-w789

OpenClaw: Non-owner command-authorized sender can change the owner-only `/send` session delivery policy

Published Mar 30, 2026
CVE-2020-36732MEDIUM

crypto-js uses insecure random numbers

Published Jun 12, 2023
MAL-2022-3837

Malicious code in ing-util-scr-session (npm)

Published Jun 20, 2022
GHSA-98hh-7ghg-x6rq

OpenClaw: Discord text `/approve` bypasses `channels.discord.execApprovals.approvers` and allows non-approvers to resolve pending exec approvals

Published Mar 31, 2026
GHSA-4w7m-58cg-cmff

OpenClaw: Leaf subagents could steer sibling sessions across sandbox boundaries

Published Mar 13, 2026
GHSA-fwjq-xwfj-gv75

OpenClaw: `session_status` still bypasses configured `tools.sessions.visibility` for unsandboxed invocations

Published Apr 7, 2026
GHSA-527m-976r-jf79

OpenClaw: Existing-session browser interaction routes bypassed SSRF policy enforcement

Published Apr 17, 2026
CVE-2026-27193

Feathers exposes internal headers via unencrypted session cookie

Published Feb 19, 2026
CVE-2026-30827

express-rate-limit: IPv4-mapped IPv6 addresses bypass per-client rate limiting on servers with dual-stack network

Published Mar 6, 2026
GHSA-9mph-4f7v-fmvh

OpenClaw has agent avatar symlink traversal in gateway session metadata

Published Mar 4, 2026
CVE-2021-41246MEDIUM

Session fixation in express-openid-connect

Published Dec 9, 2021
GHSA-9q8j-chc7-wpgp

Duplicate Advisory: OpenClaw session transcript files were created without forced user-only permissions

Published Mar 29, 2026
CVE-2024-34709MEDIUM

Directus Lacks Session Tokens Invalidation

Published May 13, 2024
CVE-2025-13321

Mattermost Desktop App exposes sensitive information in its application logs

Published Dec 17, 2025
GHSA-g8mc-c5f2-mqg7

Duplicate Advisory: OpenClaw Bypasses DM Policy Separation via Synology Chat Webhook Path Collision

Published Apr 10, 2026
GHSA-5fc7-f62m-8983

OpenClaw: Feishu docx upload_file/upload_image Bypasses Workspace-Only Filesystem Policy (GHSA-qf48-qfv4-jjm9 Incomplete Fix)

Published Apr 9, 2026
CVE-2022-24723MEDIUM

Leading white space bypasses protocol validation

Published Mar 3, 2022
MAL-2022-5421

Malicious code in poseshield (npm)

Published Jun 20, 2022
CVE-2022-0691CRITICAL

url-parse incorrectly parses hostname / protocol due to unstripped leading control characters.

Published Feb 22, 2022
CVE-2025-60794

@perfood/couch-auth may expose session tokens, passwords

Published Nov 20, 2025
GHSA-m5jp-p3r5-mfqp

Duplicate Advisory: OpenClaw: Gateway Plugin Subagent Fallback `deleteSession` Uses Synthetic `operator.admin`

Published Apr 10, 2026
GHSA-g4v2-qx3q-4p64

Parse Server's Endpoint `/sessions/me` bypasses `_Session` `protectedFields`

Published Apr 8, 2026
GHSA-g86v-f9qv-rh6m

OpenClaw SSRF guard misses four IPv6 special-use ranges

Published Mar 31, 2026
GHSA-p464-m8x6-vhv8

OpenClaw: MS Teams webhook parses body before JWT validation, enabling unauthenticated resource exhaustion

Published Apr 3, 2026
CVE-2026-32048

OpenClaw's sandboxed sessions_spawn now enforces sandbox inheritance for cross-agent spawns

Published Mar 2, 2026
MAL-2025-191422

Malicious code in selenium-session-client (npm)

Published Nov 25, 2025
MAL-2025-191423

Malicious code in shelf-jwt-sessions (npm)

Published Nov 25, 2025
GHSA-cg7q-fg22-4g98

OpenClaw: Host exec environment sanitization misses package, registry, Docker, compiler, and TLS override variables

Published Apr 3, 2026
CVE-2026-33750

brace-expansion: Zero-step sequence causes process hang and memory exhaustion

Published Mar 26, 2026
CVE-2026-27522

OpenClaw: Message action attachment hydration bypasses local media root checks when sandboxRoot is unset

Published Mar 2, 2026
CVE-2025-53886

Directus tokens are not redacted in flow logs, exposing session credentials to all admin

Published Jul 15, 2025
MAL-2022-849

Malicious code in adc-session-id (npm)

Published Jun 20, 2022
CVE-2026-31800

Parse Server: Classes `_GraphQLConfig` and `_Audience` master key bypass via generic class routes

Published Mar 11, 2026
GHSA-g5cg-8x5w-7jpm

OpenClaw: Heartbeat context inheritance bypasses sandbox via senderIsOwner escalation

Published Apr 2, 2026
MAL-2025-47023

Malicious code in x-session-parser (npm)

Published Sep 10, 2025
CVE-2023-51839CRITICAL

DeviceFarmer stf uses DES-ECB

Published Jan 29, 2024
GHSA-x2cm-hg9c-mf5w

OpenClaw leaf subagents can bypass controlScope restrictions to send messages to child sessions

Published Mar 26, 2026
CVE-2025-14505

Elliptic Uses a Cryptographic Primitive with a Risky Implementation

Published Jan 8, 2026
CVE-2016-10615HIGH

Downloads Resources over HTTP in curses

Published Feb 18, 2019
GHSA-4qwc-c7g9-4xcw

OpenClaw: Remote media error responses could trigger unbounded memory allocation before failure

Published Mar 26, 2026
GHSA-92jp-89mq-4374

OpenClaw: Sandbox noVNC helper route exposed interactive browser session credentials

Published Apr 17, 2026
GHSA-gfmx-pph7-g46x

OpenClaw: Lower-trust background runtime output is injected into trusted `System:` events, and local async exec completion misses the intended `exec-event` downgrade

Published Apr 9, 2026
MAL-2026-1997

Malicious code in ty-web-session (npm)

Published Mar 20, 2026
CVE-2026-27646

OpenClaw: Sandboxed /acp spawn requests could initialize host ACP sessions

Published Mar 9, 2026
MAL-2025-190630

Malicious code in parse-session (npm)

Published Nov 24, 2025
GHSA-h4jx-hjr3-fhgc

OpenClaw: Gateway Plugin Subagent Fallback `deleteSession` Uses Synthetic `operator.admin`

Published Mar 29, 2026
MAL-2025-48830

Malicious code in cross-sessions (npm)

Published Oct 23, 2025
CVE-2026-22036

Undici has an unbounded decompression chain in HTTP responses on Node.js Fetch API via Content-Encoding leads to resource exhaustion

Published Jan 14, 2026
MAL-2025-192861

Malicious code in session-keeper (npm)

Published Dec 23, 2025
GHSA-hrwm-hgmj-7p9c

@fastify/express's middleware path doubling causes authentication bypass in child plugin scopes

Published Apr 16, 2026
CVE-2026-24887

Claude Code has a Command Injection in find Command Bypasses User Approval Prompt

Published Feb 3, 2026
GHSA-j9pv-rrcj-6pfx

OpenClaw: SSH-based sandbox backends pass unsanitized process.env to child processes

Published Apr 2, 2026
CVE-2026-33527

Parse Server's Session Update endpoint allows overwriting server-generated session fields

Published Mar 24, 2026
GHSA-jf6w-m8jw-jfxc

OpenClaw: Write-scoped callers could reach admin-only session reset logic through `agent`

Published Mar 13, 2026
MAL-2025-3907

Malicious code in mongooses-db (npm)

Published May 16, 2025
MAL-2025-589

Malicious code in dummy-loosesight-gc (npm)

Published Jan 27, 2025
GHSA-q5pr-72pq-83v3

H3: Unbounded Chunked Cookie Count in Session Cleanup Loop may Lead to Denial of Service

Published Mar 23, 2026
CVE-2026-32002

OpenClaw's image tool bypasses tools.fs.workspaceOnly on sandbox mount paths and exfiltrates out-of-workspace images

Published Mar 4, 2026
CVE-2026-33581MEDIUM
Risk: 32.51/100

OpenClaw's message tool media parameter bypasses tool policy filesystem isolation

Published Mar 31, 2026
CVE-2022-25896MEDIUM

Passport vulnerable to session regeneration when a users logs in or out

Published Jul 2, 2022
GHSA-qj83-cq47-w5f8

Axios HTTP/2 Session Cleanup State Corruption Vulnerability

Published Apr 8, 2026
CVE-2025-66803

Turbo Frame responses can restore stale session cookies

Published Jan 20, 2026
CVE-2026-32057

OpenClaw has a Trusted-proxy Control UI pairing bypass which allows unpaired node sessions

Published Mar 3, 2026
GHSA-rm5c-4rmf-vvhw

OpenClaw: Sandbox file operations use check-then-act, bypassing fd-based TOCTOU defenses

Published Apr 3, 2026
CVE-2020-28461HIGH

js-ini Prorotype Pollution when malicious INI files submitted to an application that parses it with `parse`

Published Jul 26, 2022
CVE-2023-48309MEDIUM

Possible user mocking that bypasses basic authentication

Published Nov 20, 2023
MAL-2024-8921

Malicious code in shopify-app-session-storage-test-utils (npm)

Published Sep 19, 2024
MAL-2022-718

Malicious code in @web-utilities/session-id (npm)

Published Jun 20, 2022
CVE-2026-25723

Claude Code Vulnerable to Command Injection via Piped sed Command Bypasses File Write Restrictions

Published Feb 6, 2026
CVE-2026-34226

Happy DOM's fetch credentials include uses page-origin cookies instead of target-origin cookies

Published Mar 29, 2026
GHSA-wmjr-v86c-m9jj

Better Auth's multi-session sign-out hook allows forged cookies to revoke arbitrary sessions

Published Nov 26, 2025
CVE-2026-32918

`OpenClaw: session_status` let sandboxed subagents access parent or sibling session state

Published Mar 13, 2026
CVE-2025-13437

zx Uses Incorrectly-Resolved Name or Reference

Published Nov 20, 2025
CVE-2026-35409HIGH
Risk: 49.29/100

Directus: SSRF Protection Bypass via IPv4-Mapped IPv6 Addresses in File Import

Published Apr 4, 2026
CVE-2026-34215MEDIUM
Risk: 32.51/100

Parse Server exposes auth data via verify password endpoint

Published Mar 29, 2026
CVE-2026-33627

Parse Server exposes auth data via /users/me endpoint

Published Mar 24, 2026
GHSA-5h3f-885m-v22w

OpenClaw: Existing WS sessions survive shared gateway token rotation

Published Apr 9, 2026
MAL-2024-1269

Malicious code in hosted-lenses-ui (npm)

Published Apr 16, 2024
CVE-2020-7784CRITICAL

Command injection in ts-process-promises

Published Jan 13, 2021
GHSA-3h52-cx59-c456

OpenClaw: Feishu webhook reads and parses unauthenticated request bodies before signature validation

Published Mar 29, 2026
MAL-2025-192862

Malicious code in session-parse (npm)

Published Dec 23, 2025
GHSA-cmfr-9m2r-xwhq

OpenClaw `node.invoke(browser.proxy)` bypasses `browser.request` persistent profile-mutation guard

Published Apr 9, 2026
CVE-2024-29901MEDIUM

@workos-inc/authkit-nextjs session replay vulnerability

Published Mar 29, 2024
GHSA-wq58-2pvg-5h4f

OpenClaw: Gateway agent /reset exposes admin session reset to operator.write callers

Published Mar 26, 2026
MAL-2022-135

Malicious code in @bmw-chris/vehiclesession-default-frontend (npm)

Published Jun 20, 2022
GHSA-5jvj-hxmh-6h6j

OpenClaw: Gateway HTTP Session History Route Bypasses Operator Read Scope

Published Mar 29, 2026
GHSA-89hr-6x2p-8xjv

Duplicate Advisory: OpenClaw's device removal and token revocation do not terminate active WebSocket sessions

Published Mar 31, 2026
MAL-2025-190649

Malicious code in posthog-react-native-session-replay (npm)

Published Nov 24, 2025
MAL-2025-3568

Malicious code in expi-session (npm)

Published May 1, 2025
CVE-2025-47269

code-server's session cookie can be extracted by having user visit specially crafted proxy URL

Published May 9, 2025
GHSA-hh43-q692-2xmq

Duplicate Advisory: `OpenClaw: session_status` let sandboxed subagents access parent or sibling session state

Published Mar 29, 2026
GHSA-hm63-vwj4-mj2q

Duplicate Advisory: OpenClaw: Remote media error responses could trigger unbounded memory allocation before failure

Published Apr 10, 2026
MAL-2022-6177

Malicious code in smc-extendsession (npm)

Published Jun 20, 2022
CVE-2022-35513HIGH

Blink1Control2 uses weak password encryption

Published Sep 8, 2022
MAL-2022-2480

Malicious code in discord-canvases (npm)

Published Sep 21, 2022
CVE-2025-53624

docusaurus-plugin-content-gists vulnerability exposes GitHub Personal Access Token

Published Jul 9, 2025
CVE-2026-34209HIGH
Risk: 37.51/100

mppx: Tempo has a session close voucher bypass vulnerability due to settled amount equality

Published Mar 29, 2026
MAL-2023-439

Malicious code in fierce-obsessions-the-phoenix-pack-6-by-suzanne-wright-online-new-pages- (npm)

Published May 10, 2023
CVE-2026-30228

parse-server's file creation and deletion bypasses `readOnlyMasterKey` write restriction

Published Mar 6, 2026
GHSA-8mr2-f9wf-hcfq

Duplicate Advisory: OpenClaw reuses the gateway auth token in the owner ID prompt hashing fallback

Published Mar 21, 2026
GHSA-w5c7-9qqw-6645

OpenClaw inter-session prompts could be treated as direct user instructions

Published Feb 18, 2026
CVE-2024-31206HIGH

dectalk-tts Uses Unencrypted HTTP Request

Published Apr 4, 2024
CVE-2021-41109HIGH

LiveQuery publishes user session tokens in parse-server

Published Sep 30, 2021
MAL-2022-7285

Malicious code in xms-error-responses (npm)

Published Jun 20, 2022
CVE-2025-7783

form-data uses unsafe random function in form-data for choosing boundary

Published Jul 21, 2025
CVE-2023-44400MEDIUM

Uptime Kuma has Persistentent User Sessions

Published Oct 10, 2023
GHSA-rf6h-5gpw-qrgq

OpenClaw: MS Teams Feedback Invocation Bypasses Sender Allowlists and Records Unauthorized Session Feedback

Published Mar 29, 2026
CVE-2026-34784HIGH
Risk: 37.51/100

Parser Server's streaming file download bypasses afterFind file trigger authorization

Published Apr 1, 2026
GHSA-rj39-33v7-9xrq

Duplicate Advisory: OpenClaw's shell startup env injection bypasses system.run allowlist intent (RCE class)

Published Mar 21, 2026
MAL-2022-453

Malicious code in @ncr-swt-retail/scox-npm-releases (npm)

Published Jun 20, 2022
CVE-2024-34706CRITICAL

@valtimo/components exposes access token to form.io

Published May 13, 2024
GHSA-r294-2894-92j3

OpenClaw has stored XSS in exported session HTML viewer via markdown/raw-HTML rendering

Published Mar 3, 2026
CVE-2026-32056

OpenClaw's shell startup env injection bypasses system.run allowlist intent (RCE class)

Published Mar 3, 2026
GHSA-vrqm-gvq7-rrwh

PDFME Affected by Decompression Bomb in FlateDecode Stream Parsing Causes Memory Exhaustion DoS

Published Mar 20, 2026
MAL-2026-3122

Malicious code in @w3m-frame/session_update (npm)

Published Apr 27, 2026
GHSA-xg6x-h9c9-2m83

Better Auth Has Two-Factor Authentication Bypass via Premature Session Caching (session.cookieCache)

Published Apr 3, 2026
CVE-2026-34775MEDIUM
Risk: 34.01/100

Electron: nodeIntegrationInWorker not correctly scoped in shared renderer processes

Published Apr 3, 2026
MAL-2026-2128

Malicious code in express-session-vailidator (npm)

Published Mar 24, 2026
MAL-2026-612

Malicious code in sharedclasses (npm)

Published Jan 30, 2026
MAL-2022-4872

Malicious code in noblox.js-promises (npm)

Published Jun 20, 2022
MAL-2022-2756

Malicious code in envoy-curses (npm)

Published Jun 20, 2022
MAL-2022-451

Malicious code in @ncr-design-system/cxd-npm-releases (npm)

Published Jun 20, 2022
MAL-2026-1486

Malicious code in trello-enterprises (npm)

Published Mar 16, 2026
MAL-2023-675

Malicious code in pdf-gods-generals-the-military-lives-of-moses-the-buddha-and-muhammad-by-richard-a-gabriel-on-textbo (npm)

Published May 10, 2023
MAL-2025-190842

Malicious code in expo-audio-session (npm)

Published Nov 24, 2025
MAL-2026-2129

Malicious code in express-session-validator (npm)

Published Mar 24, 2026
MAL-2025-4514

Malicious code in telegraf-mysql2-session (npm)

Published May 27, 2025
CVE-2023-37478HIGH

pnpm incorrectly parses tar archives relative to specification

Published Aug 1, 2023
MAL-2022-5197

Malicious code in pagseguro-user-session (npm)

Published Jun 20, 2022
MAL-2022-7203

Malicious code in wm-publish-statuses (npm)

Published Jul 20, 2022
MAL-2022-3670

Malicious code in hope-session-manager (npm)

Published Jun 20, 2022
CVE-2021-39138MEDIUM

parse-server new anonymous user session acts as if it's created with password

Published Aug 23, 2021
MAL-2026-218

Malicious code in express-sessions-id (npm)

Published Jan 12, 2026
MAL-2024-1118

Malicious code in eng-intern-assessment-react-native (npm)

Published Mar 18, 2024
MAL-2024-1196

Malicious code in shopify-app-session-storage-prisma (npm)

Published Apr 3, 2024
MAL-2024-1195

Malicious code in shopify-app-session-storage-drizzle (npm)

Published Apr 3, 2024
MAL-2025-191586

Malicious code in session-validate (npm)

Published Dec 1, 2025
GHSA-ppwq-6v66-5m6j

OpenClaw Exposes Credentials Embedded in baseUrl Fields via config.get and channels.status

Published Mar 26, 2026
MAL-2025-3569

Malicious code in expo-sessoion (npm)

Published May 1, 2025
MAL-2025-2638

Malicious code in @sensort/session (npm)

Published Mar 25, 2025
MAL-2023-366

Malicious code in fc-session-state (npm)

Published Jun 6, 2023
MAL-2025-4719

Malicious code in sess-mgmt (npm)

Published Jun 7, 2025
MAL-2024-9344

Malicious code in availab-le-alb-um-zip-25931-the-life-aquatic-studio-sessions-mocn6-tnmvnd (npm)

Published Oct 16, 2024
CVE-2026-33490

h3: Missing Path Segment Boundary Check in `mount()` Causes Middleware Execution on Unrelated Prefix-Matching Routes

Published Mar 20, 2026
CVE-2026-34503HIGH
Risk: 40.51/100

OpenClaw's device removal and token revocation do not terminate active WebSocket sessions

Published Mar 31, 2026
GHSA-3gr8-2752-h46q

Duplicate Advisory: OpenClaw's message tool media parameter bypasses tool policy filesystem isolation

Published Mar 31, 2026
CVE-2026-25918

unity-cli Exposes Plaintext Credentials in Debug Logs (sign-package command)

Published Feb 10, 2026
GHSA-474h-prjg-mmw3

OpenClaw: Sandboxed sessions_spawn(runtime="acp") bypassed sandbox inheritance and allowed host ACP initialization

Published Mar 3, 2026
MAL-2025-2702

Malicious code in requests-promises (npm)

Published Mar 25, 2025
MAL-2023-674

Malicious code in pdf-a-court-of-wings-and-ruin-a-court-of-thorns-and-roses-3-by-sarah-j-maas-on-iphone-full-chapters- (npm)

Published May 10, 2023
GHSA-68f8-9mhj-h2mp

OpenClaw has a Gateway HTTP /v1/models Route Bypasses Operator Read Scope

Published Mar 30, 2026
CVE-2026-34574MEDIUM
Risk: 27.01/100

Parse Server has a session field immutability bypass via falsy-value guard

Published Apr 1, 2026
GHSA-h2v7-xc88-xx8c

OpenClaw: `/phone arm`/`/phone disarm` Bypasses `operator.admin` Scope Check for External Channels

Published Apr 7, 2026
MAL-2024-1314

Malicious code in viseshthemed (npm)

Published May 1, 2024
GHSA-rfqg-qgf8-xr9x

OpenClaw: Gateway `device.token.rotate` does not terminate active WebSocket sessions after credential rotation

Published Apr 3, 2026
MAL-2022-1835

Malicious code in casesensitijepathswebpackplugin (npm)

Published Aug 19, 2022
CVE-2026-33572

OpenClaw session transcript files were created without forced user-only permissions

Published Mar 16, 2026
MAL-2025-4599

Malicious code in nexpi-session (npm)

Published May 30, 2025
MAL-2025-4720

Malicious code in sess-store (npm)

Published Jun 7, 2025
MAL-2025-191421

Malicious code in selenium-session (npm)

Published Nov 25, 2025
MAL-2025-48865

Malicious code in sessionfiy (npm)

Published Oct 23, 2025
MAL-2025-48015

Malicious code in cross-session (npm)

Published Oct 8, 2025
MAL-2025-48754

Malicious code in purchases-roku (npm)

Published Oct 23, 2025
MAL-2025-3560

Malicious code in rei-session (npm)

Published May 1, 2025
MAL-2025-719

Malicious code in dummy-loosesight-gd (npm)

Published Jan 31, 2025
Check your entire dependency tree at onceRun dependency scan →