OsVault/npm/st
npm33 critical

st

1000 known vulnerabilities · 33 critical · 89 high

CVE-2017-16224MEDIUM

Open Redirect in st

Published Aug 6, 2018
CVE-2014-3744HIGH

Directory Traversal in st

Published Aug 31, 2020
CVE-2021-23398MEDIUM

Cross-site scripting in react-bootstrap-table

Published Dec 10, 2021
CVE-2024-36361MEDIUM

Pug allows JavaScript code execution if an application accepts untrusted input

Published May 24, 2024
MAL-2025-129

Malicious code in jssdk-infrastructure (npm)

Published Jan 16, 2025
MAL-2022-1850

Malicious code in cd-system (npm)

Published Jul 5, 2022
MAL-2022-7443

Malicious code in @getstep/sdk (npm)

Published Jun 20, 2022
CVE-2026-33896CRITICAL
Risk: 88/100

Forge has a basicConstraints bypass in its certificate chain verification (RFC 5280 violation)

Published Mar 26, 2026
CVE-2020-7704CRITICAL

linux-cmdline is vulnerable to Prototype Pollution via the constructor

Published May 24, 2022
CVE-2023-26135HIGH

flatnest Prototype Pollution vulnerability

Published Jun 30, 2023
MAL-2025-1532

Malicious code in int_pinterest_sfra (npm)

Published Feb 23, 2025
GHSA-2qrv-rc5x-2g2h

OpenClaw: Untrusted workspace channel shadows could execute during built-in channel setup

Published Apr 7, 2026
MAL-2025-1625

Malicious code in sddst-ui (npm)

Published Feb 28, 2025
CVE-2023-38507HIGH

Strapi Improper Rate Limiting vulnerability

Published Sep 13, 2023
MAL-2025-1689

Malicious code in @f2p-mml-frontends/mml-styles (npm)

Published Mar 3, 2025
MAL-2025-182

Malicious code in dotgov-list (npm)

Published Jan 20, 2025
MAL-2025-1906

Malicious code in npm-manifest (npm)

Published Mar 3, 2025
MAL-2025-190674

Malicious code in @posthog/rrweb-snapshot (npm)

Published Nov 24, 2025
CVE-2018-3730HIGH

Path Traversal in mcstatic

Published Jul 27, 2018
CVE-2022-36083MEDIUM

JOSE vulnerable to resource exhaustion via specifically crafted JWE

Published Sep 16, 2022
CVE-2022-39382CRITICAL

@keystone-6/core's NODE_ENV defaults to development with esbuild

Published Nov 3, 2022
MAL-2025-190958

Malicious code in email-deliverability-tester (npm)

Published Nov 24, 2025
CVE-2025-12758

Validator is Vulnerable to Incomplete Filtering of One or More Instances of Special Elements

Published Nov 27, 2025
CVE-2026-3635

fastify: request.protocol and request.host Spoofable via X-Forwarded-Proto/Host from Untrusted Connections

Published Mar 25, 2026
CVE-2026-5323MEDIUM
Risk: 26.5/100

a11y-mcp: Server-Side Request Forgery (SSRF) vulnerability in A11yServer function

Published Apr 2, 2026
CVE-2022-41654MEDIUM

ghost vulnerable to unauthorized newsletter modification via improper access controls

Published Nov 28, 2022
MAL-2024-8040

Malicious code in system-library-gameanalytics-common (npm)

Published Aug 26, 2024
CVE-2014-8883

Directory Traversal in nhouston

Published Aug 31, 2020
GHSA-4948-f92q-f432

@nocobase/database has SQL Injection via String Concatenation through Recursive Eager Loading

Published Apr 22, 2026
CVE-2023-29019HIGH

Session fixation in fastify-passport

Published Apr 21, 2023
MAL-2022-6498

Malicious code in test494 (npm)

Published Jun 20, 2022
CVE-2024-47529

OpenC3 stores passwords in clear text (`GHSL-2024-129`)

Published Oct 2, 2024
MAL-2024-81

Malicious code in schibsted-style (npm)

Published Jan 11, 2024
MAL-2025-191191

Malicious code in @antstackio/shelbysam (npm)

Published Nov 25, 2025
CVE-2025-45143

string-math's string-math.js vulnerability can cause Regex Denial of Service (ReDoS)

Published Jun 30, 2025
CVE-2022-37262HIGH

steal vulnerable to Regular Expression Denial of Service via source and sourceWithComments

Published Sep 16, 2022
MAL-2024-12119

Malicious code in stablecoin-aptos (npm)

Published Dec 24, 2024
MAL-2025-191294

Malicious code in @posthog/laudspeaker-plugin (npm)

Published Nov 25, 2025
CVE-2024-27088

es5-ext vulnerable to Regular Expression Denial of Service in `function#copy` and `function#toStringTokens`

Published Feb 26, 2024
MAL-2024-8041

Malicious code in system-library-gameanalytics-slotanalytics (npm)

Published Aug 26, 2024
CVE-2023-29020MEDIUM

CSRF token fixation in fastify-passport

Published Apr 21, 2023
CVE-2022-27263CRITICAL

Unrestricted Upload of File with Dangerous Type in Strapi

Published Apr 13, 2022
CVE-2018-11537MEDIUM

Auth0 angular-jwt misinterprets allowlist as regex

Published May 14, 2022
MAL-2025-191495

Malicious code in @bingads-webui-clientcenter/instrumentation (npm)

Published Dec 1, 2025
MAL-2025-191497

Malicious code in handtalk-test-app (npm)

Published Dec 1, 2025
MAL-2025-191199

Malicious code in @browserbasehq/stagehand-docs (npm)

Published Nov 25, 2025
CVE-2023-7078HIGH

Miniflare vulnerable to Server-Side Request Forgery (SSRF)

Published Dec 29, 2023
MAL-2025-191359

Malicious code in @voiceflow/nestjs-rate-limit (npm)

Published Nov 25, 2025
CVE-2026-32003

OpenClaw has system.run shell-wrapper env injection via SHELLOPTS/PS4 can bypass allowlist intent (RCE)

Published Mar 3, 2026
MAL-2025-191519

Malicious code in mongodb-stitch-server-testutils (npm)

Published Dec 1, 2025
MAL-2025-191543

Malicious code in stream-xor-chain (npm)

Published Dec 2, 2025
MAL-2025-191546

Malicious code in chai-status (npm)

Published Dec 2, 2025
MAL-2025-191491

Malicious code in babel-plugin-standalone (npm)

Published Nov 30, 2025
CVE-2021-31597CRITICAL

Improper Certificate Validation in xmlhttprequest-ssl

Published May 24, 2021
MAL-2025-191502

Malicious code in pluxee-design-system (npm)

Published Dec 1, 2025
CVE-2023-45884MEDIUM

NASA Open MCT Cross Site Request Forgery (CSRF) vulnerability

Published Nov 9, 2023
CVE-2023-23636MEDIUM

Jellyfin Web Cross-Site Scripting (XSS) via Playlist Name

Published Feb 3, 2023
CVE-2023-39655CRITICAL

CouchAuth host header injection vulnerability leaks the password reset token

Published Jan 3, 2024
CVE-2023-27490HIGH

Missing proper state, nonce and PKCE checks for OAuth authentication

Published Mar 13, 2023
GHSA-5fw2-mwhh-9947

Flowise: Unauthenticated TTS endpoint accepts arbitrary credential IDs — enables API credit abuse via stored credentials

Published Apr 17, 2026
MAL-2025-7074

Malicious code in @amber-team/storybook-utils (npm)

Published Aug 14, 2025
CVE-2026-2265MEDIUM
Risk: 32.52/100

Replicator deserializes untrusted user input

Published Apr 1, 2026
MAL-2022-1031

Malicious code in aoe_playstyle (npm)

Published Jun 20, 2022
MAL-2025-191973

Malicious code in elf-stats-fuzzy-fir-973 (npm)

Published Dec 3, 2025
MAL-2025-191977

Malicious code in elf-stats-rooftop-stockpile-626 (npm)

Published Dec 3, 2025
MAL-2025-191988

Malicious code in elf-stats-aurora-candy-291 (npm)

Published Dec 3, 2025
MAL-2025-191989

Malicious code in elf-stats-aurora-garland-513 (npm)

Published Dec 3, 2025
MAL-2025-191990

Malicious code in elf-stats-aurora-workbench-513 (npm)

Published Dec 3, 2025
MAL-2025-191993

Malicious code in elf-stats-bright-cushion-246 (npm)

Published Dec 3, 2025
MAL-2025-191996

Malicious code in elf-stats-candlelit-toy-571 (npm)

Published Dec 3, 2025
MAL-2025-192020

Malicious code in elf-stats-evergreen-chimney-857 (npm)

Published Dec 3, 2025
MAL-2025-192025

Malicious code in elf-stats-evergreen-sled-681 (npm)

Published Dec 3, 2025
CVE-2023-32235HIGH

Path Traversal in Ghost

Published May 5, 2023
MAL-2025-192033

Malicious code in elf-stats-flickering-candy-280 (npm)

Published Dec 3, 2025
MAL-2025-192034

Malicious code in elf-stats-flickering-fir-572 (npm)

Published Dec 3, 2025
MAL-2026-3260

Malicious code in google-storage-cloud (npm)

Published Apr 29, 2026
MAL-2025-192078

Malicious code in elf-stats-lanternlit-sled-571 (npm)

Published Dec 3, 2025
MAL-2025-192085

Malicious code in elf-stats-merry-chimney-765 (npm)

Published Dec 3, 2025
MAL-2022-1042

Malicious code in api-routes-rest (npm)

Published Jul 21, 2022
MAL-2025-192086

Malicious code in elf-stats-merry-cookiejar-754 (npm)

Published Dec 3, 2025
MAL-2025-192087

Malicious code in elf-stats-merry-cookiejar-915 (npm)

Published Dec 3, 2025
CVE-2026-30920

OneUptime has broken access control in GitHub App installation flow that allows unauthorized project binding

Published Mar 9, 2026
MAL-2025-192132

Malicious code in elf-stats-shimmering-workshop-590 (npm)

Published Dec 3, 2025
CVE-2020-7629CRITICAL

OS Command Injection in install-package

Published Feb 10, 2022
MAL-2024-8262

Malicious code in @diotoborg/dolorum-iste-excepturi (npm)

Published Sep 2, 2024
MAL-2025-192134

Malicious code in elf-stats-silvered-mitten-503 (npm)

Published Dec 3, 2025
MAL-2025-192139

Malicious code in elf-stats-snowdusted-bauble-104 (npm)

Published Dec 3, 2025
MAL-2024-8272

Malicious code in @diotoborg/eaque-iste (npm)

Published Sep 2, 2024
CVE-2025-69262

pnpm vulnerable to Command Injection via environment variable substitution

Published Jan 7, 2026
MAL-2025-192140

Malicious code in elf-stats-snowdusted-fireplace-396 (npm)

Published Dec 3, 2025
MAL-2025-192141

Malicious code in elf-stats-snowdusted-saddlebag-790 (npm)

Published Dec 3, 2025
GHSA-6pfc-6m7w-m8fx

OpenClaw has a gateway exec allowlist allow-always bypass via unregistered /usr/bin/script wrapper

Published Mar 31, 2026
GHSA-534w-2vm4-89xr

OpenClaw's Zalo group sender allowlist bypass permits unauthorized GROUP dispatch

Published Mar 3, 2026
MAL-2025-192154

Malicious code in elf-stats-sparkly-cocoa-863 (npm)

Published Dec 3, 2025
MAL-2025-192159

Malicious code in elf-stats-sprucey-snowman-250 (npm)

Published Dec 3, 2025
MAL-2025-192160

Malicious code in elf-stats-sprucey-train-471 (npm)

Published Dec 3, 2025
CVE-2020-26768MEDIUM

Formstone Vulnerable to Reflected XSS

Published May 24, 2022
MAL-2025-192181

Malicious code in elf-stats-twinkling-marshmallow-913 (npm)

Published Dec 3, 2025
CVE-2025-5276

Markdownify MCP Server allows Server-Side Request Forgery (SSRF) via the Markdownify.get() function

Published May 29, 2025
MAL-2025-192197

Malicious code in elf-stats-wintry-icicle-283 (npm)

Published Dec 3, 2025
MAL-2022-109

Malicious code in @azure-tests/perf-service-bus (npm)

Published Jun 20, 2022
MAL-2025-192204

Malicious code in elf-stats-caroling-mailbag-397 (npm)

Published Dec 3, 2025
MAL-2024-8291

Malicious code in @diotoborg/esse-distinctio-repellat (npm)

Published Sep 2, 2024
MAL-2025-192210

Malicious code in elf-stats-frostbitten-reindeer-875 (npm)

Published Dec 3, 2025
MAL-2025-192212

Malicious code in elf-stats-ginger-reindeer-411 (npm)

Published Dec 3, 2025
MAL-2025-192213

Malicious code in elf-stats-gingersnap-ornament-469 (npm)

Published Dec 3, 2025
MAL-2025-192214

Malicious code in elf-stats-glittering-fir-252 (npm)

Published Dec 3, 2025
CVE-2020-7639MEDIUM

eivindfjeldstad-dot contains prototype pollution vulnerability

Published May 25, 2021
MAL-2025-192215

Malicious code in elf-stats-glittering-nutcracker-709 (npm)

Published Dec 3, 2025
CVE-2022-29257MEDIUM

AutoUpdater module fails to validate certain nested components of the bundle

Published Jun 16, 2022
GHSA-3298-56p6-rpw2

OpenClaw has incomplete Fix for CVE-2026-27486: Unvalidated SIGKILL in `!stop` Chat Command via `shell-utils.ts`

Published Mar 30, 2026
GHSA-g87j-gm7p-6vw2

Duplicate Advisory: OpenClaw's Node system.run approval hardening wrapper semantic drift can execute unintended local scripts

Published Mar 19, 2026
GHSA-2w79-r9g8-wmcr

OpenClaw: Voice-call still parses large WebSocket frames before start validation (Incomplete fix for CVE-2026-32062)

Published Apr 3, 2026
CVE-2023-31999HIGH

@fastify/oauth2 vulnerable to Cross Site Request Forgery due to reused Oauth2 state

Published Jul 5, 2023
GHSA-7853-gqqm-vcwx

openclaw-claude-bridge: sandbox is not effective - `--allowed-tools ""` does not restrict available tools

Published Apr 8, 2026
MAL-2025-192218

Malicious code in elf-stats-merry-cookiejar-442 (npm)

Published Dec 3, 2025
MAL-2025-192229

Malicious code in elf-stats-sleighing-nutcracker-806 (npm)

Published Dec 3, 2025
MAL-2025-192266

Malicious code in elf-stats-silvered-star-676 (npm)

Published Dec 3, 2025
MAL-2025-192267

Malicious code in elf-stats-snowdusted-lantern-234 (npm)

Published Dec 3, 2025
GHSA-7jp6-r74r-995q

OpenClaw: Matrix profile config persistence was reachable from operator.write message tools

Published Apr 17, 2026
MAL-2026-3337

Malicious code in @t-in-one/save_application_hid_to_storage (npm)

Published May 4, 2026
MAL-2025-192370

Malicious code in elf-stats-snowdusted-cookiejar-250 (npm)

Published Dec 4, 2025
CVE-2026-33468

Kysely has a MySQL SQL Injection via Insufficient Backslash Escaping in `sql.lit(string)` usage or similar methods that append string literal values into the compiled SQL strings

Published Mar 20, 2026
MAL-2025-192473

Malicious code in elf-stats-candlelit-train-228 (npm)

Published Dec 11, 2025
MAL-2025-192480

Malicious code in elf-stats-caroling-hammer-382 (npm)

Published Dec 11, 2025
GHSA-855c-r2vq-c292

Stored XSS in SEO Fields Leads to Authenticated API Data Exposure in ApostropheCMS

Published Apr 16, 2026
CVE-2023-6460MEDIUM

Logging of the firestore key within nodejs-firestore

Published Dec 4, 2023
MAL-2025-192539

Malicious code in elf-stats-twinkling-bell-867 (npm)

Published Dec 11, 2025
CVE-2025-64765

Astro's middleware authentication checks based on url.pathname can be bypassed via url encoded values

Published Nov 19, 2025
MAL-2024-8380

Malicious code in @diotoborg/iste-laborum (npm)

Published Sep 2, 2024
MAL-2025-192626

Malicious code in elf-stats-cocoa-workshop-459 (npm)

Published Dec 19, 2025
CVE-2019-15479MEDIUM

Status Board vulnerable to Cross-Site Scripting before v1.1.82

Published Sep 23, 2019
MAL-2022-1098

Malicious code in arm-attestation (npm)

Published Jun 20, 2022
MAL-2022-1099

Malicious code in arm-azurestack (npm)

Published Jun 20, 2022
CVE-2020-28436HIGH

google-cloudstorage-commands Command Injection vulnerability

Published Jul 26, 2022
GHSA-63f5-hhc7-cx6p

OpenClaw bootstrap setup codes could be replayed to escalate pending pairing scopes before approval

Published Mar 16, 2026
GHSA-h97f-6pqj-q452

OpenClaw has a IPv6 multicast SSRF classifier bypass

Published Mar 3, 2026
CVE-2026-22177

OpenClaw's config env vars allowed startup env injection into service runtime

Published Mar 3, 2026
MAL-2025-192709

Malicious code in amazon-testpackage (npm)

Published Dec 23, 2025
MAL-2024-8428

Malicious code in @diotoborg/molestiae-doloribus (npm)

Published Sep 2, 2024
MAL-2025-192740

Malicious code in elf-stats-caroling-wreath-635 (npm)

Published Dec 23, 2025
MAL-2024-8429

Malicious code in @diotoborg/molestiae-maxime (npm)

Published Sep 2, 2024
MAL-2025-192771

Malicious code in elf-stats-glittering-cookie-844 (npm)

Published Dec 23, 2025
GHSA-939r-rj45-g2rj

OpenClaw: Workspace provider auth choices could auto-enable untrusted provider plugins

Published Apr 17, 2026
CVE-2026-29185

Backstage vulnerable to potential reading of SCM URLs using built in token

Published Mar 5, 2026
CVE-2026-25047

deepHas vulnerable to Prototype Pollution via constructor.prototype

Published Jan 29, 2026
GHSA-jjw7-3vjf-fg5j

OpenClaw Nostr privateKey config redaction bypass leaks plaintext signing key via config.get

Published Apr 2, 2026
MAL-2025-2109

Malicious code in lappsec-testpackage (npm)

Published Mar 4, 2025
MAL-2025-2716

Malicious code in vistar-ad-clienttestadv3 (npm)

Published Mar 25, 2025
CVE-2025-30359

webpack-dev-server users' source code may be stolen when they access a malicious web site

Published Jun 4, 2025
CVE-2024-29194HIGH

OneUptime Vulnerable to a Privilege Escalation via Local Storage Key Manipulation

Published Mar 25, 2024
CVE-2022-23080MEDIUM

Server-Side Request Forgery in Directus

Published Jun 23, 2022
MAL-2025-4134

Malicious code in string-multiutils (npm)

Published May 21, 2025
MAL-2025-4135

Malicious code in system-v11 (npm)

Published May 21, 2025
GHSA-5jg4-p4qw-cgfr

@stablelib/cbor: Stack exhaustion Denial of Service via deeply nested CBOR arrays, maps, or tags

Published Apr 4, 2026
MAL-2025-47892

Malicious code in pycodestyle (npm)

Published Oct 2, 2025
CVE-2016-10695HIGH

Downloads Resources over HTTP in npm-test-sqlite3-trunk

Published Sep 1, 2020
MAL-2025-6334

Malicious code in style-postprocessor (npm)

Published Jul 28, 2025
CVE-2026-29607

OpenClaw's allow-always wrapper persistence could bypass future approvals and enable command execution

Published Mar 2, 2026
MAL-2026-2696

Malicious code in bfx-hf-strategy-perf (npm)

Published Apr 15, 2026
CVE-2026-26316

OpenClaw BlueBubbles webhook auth bypass via loopback proxy trust

Published Feb 17, 2026
MAL-2026-2915

Malicious code in bitu-staking (npm)

Published Apr 12, 2026
GHSA-6pcv-j4jx-m4vx

Flowise: Unauthenticated Information Disclosure of OAuth Secrets (Cleartext) via GET Request

Published Apr 16, 2026
GHSA-6r77-hqx7-7vw8

Flowise: APIChain Prompt Injection SSRF in GET/POST API Chains

Published Apr 16, 2026
CVE-2025-26042

Uptime Kuma's Regular Expression in pushdeeer and whapi file Leads to ReDoS Vulnerability Due to Catastrophic Backtracking

Published Mar 31, 2025
CVE-2026-32731

ApostropheCMS has Arbitrary File Write (Zip Slip / Path Traversal) in Import-Export Gzip Extraction

Published Mar 18, 2026
CVE-2025-12735

expr-eval does not restrict functions passed to the evaluate function

Published Nov 5, 2025
MAL-2026-3006

Malicious code in changelog-utils-structured-logger (npm)

Published Apr 23, 2026
MAL-2026-889

Malicious code in responses-starter-app (npm)

Published Feb 13, 2026
CVE-2016-10703HIGH

Denial of Service in ecstatic

Published Dec 28, 2017
MAL-2025-192249

Malicious code in elf-stats-shimmering-muffin-598 (npm)

Published Dec 3, 2025
GHSA-c276-fj82-f2pq

ApostropheCMS: Information Disclosure via choices/counts Query Parameters Bypassing publicApiProjection Field Restrictions

Published Apr 16, 2026
CVE-2024-56159

Astro's server source code is exposed to the public if sourcemaps are enabled

Published Dec 19, 2024
CVE-2018-16474MEDIUM

Stored Cross-Site Scripting in tianma-static

Published Nov 6, 2018
GHSA-gwhp-pf74-vj37

Fastify's connection header abuse enables stripping of proxy-added headers

Published Apr 16, 2026
CVE-2025-70948

@perfood/couch-auth has a host header injection vulnerability

Published Mar 5, 2026
CVE-2026-27013

Fabric.js Affected by Stored XSS via SVG Export

Published Feb 18, 2026
GHSA-2858-xg23-26fp

OpenClaw: Node camera URL payload host-binding bypass allowed gateway fetch pivots

Published Mar 3, 2026
CVE-2026-25128

fast-xml-parser has RangeError DoS Numeric Entities Bug

Published Jan 30, 2026
CVE-2023-23936MEDIUM

CRLF Injection in Nodejs ‘undici’ via host

Published Feb 16, 2023
CVE-2022-31069MEDIUM

Potential Authorization Header Exposure in NPM Packages @finastra/nestjs-proxy, @ffdc/nestjs-proxy

Published Jun 17, 2022
GHSA-m866-6qv5-p2fg

OpenClaw host-env blocklist missing `GIT_TEMPLATE_DIR` and `AWS_CONFIG_FILE` allows code execution via env override

Published Mar 31, 2026
MAL-2022-106

Malicious code in @azure-tests/perf-keyvault-secrets (npm)

Published Jun 20, 2022
CVE-2025-59142

color-string@2.1.1 contains malware after npm account takeover

Published Sep 15, 2025
CVE-2016-10626HIGH

Downloads Resources over HTTP in mystem3

Published Feb 18, 2019
GHSA-r849-826x-wgqm

Duplicate Advisory: Signal group allowlist authorization bypass via DM pairing-store leakage

Published Mar 19, 2026
CVE-2026-32055

OpenClaw: workspace path guard bypass on non-existent out-of-root symlink leaf

Published Mar 12, 2026
CVE-2026-21852

Claude Code Leaks Data via Malicious Environment Configuration Before Trust Confirmation

Published Jan 21, 2026
GHSA-mhr7-2xmv-4c4q

OpenClaw: HTTP operator endpoints lack browser-origin validation in trusted-proxy mode

Published Apr 3, 2026
GHSA-767m-xrhc-fxm7

OpenClaw: Gateway operator.write Can Reach Admin-Class Telegram Config and Cron Persistence via send

Published Apr 7, 2026
CVE-2025-68157

webpack buildHttp HttpUriPlugin allowedUris bypass via HTTP redirects → SSRF + cache persistence

Published Feb 5, 2026
CVE-2026-34767MEDIUM
Risk: 29.51/100

Electron: HTTP Response Header Injection in custom protocol handlers and webRequest

Published Apr 3, 2026
CVE-2015-9545HIGH

Improper Input Validation in xdLocalStorage

Published Dec 9, 2021
CVE-2022-21144HIGH

Denial of service vulnerability exists in libxmljs

Published May 3, 2022
CVE-2023-31133HIGH

Ghost vulnerable to information disclosure of private API fields

Published May 3, 2023
CVE-2024-41818HIGH

fast-xml-parser vulnerable to ReDOS at currency parsing

Published Jul 29, 2024
CVE-2022-31367HIGH

Strapi mishandles hidden attributes within admin API responses

Published Sep 28, 2022
CVE-2026-33768

Astro: Unauthenticated Path Override via `x-astro-path` / `x_astro_path`

Published Mar 26, 2026
MAL-2024-8819

Malicious code in 0g-storage-contracts (npm)

Published Sep 5, 2024
GHSA-39pp-xp36-q6mg

OpenClaw has Inconsistent Host Exec Environment Override Sanitization

Published Mar 26, 2026
GHSA-mvv8-v4jj-g47j

Directus: Sensitive fields exposed in revision history

Published Apr 4, 2026
CVE-2018-1999024MEDIUM

Macro in MathJax running untrusted Javascript within a web browser

Published Jul 27, 2018
CVE-2026-28363

OpenClaw's tools.exec.safeBins sort long-option abbreviation bypass can skip exec approval in allowlist mode

Published Mar 3, 2026
CVE-2026-28446

OpenClaw has an inbound allowlist policy bypass in voice-call extension (empty caller ID + suffix matching)

Published Feb 17, 2026
MAL-2024-8867

Malicious code in node-integration-test (npm)

Published Sep 11, 2024
MAL-2024-8895

Malicious code in bamoe-standalone-dmn-editor (npm)

Published Sep 18, 2024
GHSA-72c6-fx6q-fr5w

@fastify/middie vulnerable to middleware authentication bypass in child plugin scopes

Published Apr 16, 2026
CVE-2026-22818

Hono JWK Auth Middleware has JWT algorithm confusion when JWK lacks "alg" (untrusted header.alg fallback)

Published Jan 13, 2026
CVE-2022-24717MEDIUM

Cross Site Scripting (XSS) in @finastra/ssr-pages

Published Mar 1, 2022
CVE-2022-37257CRITICAL

steal vulnerable to Prototype Pollution via requestedVersion variable

Published Sep 16, 2022
CVE-2025-61686

React Router has Path Traversal in File Session Storage

Published Jan 8, 2026
CVE-2026-34773MEDIUM
Risk: 23.51/100

Electron: Registry key path injection in app.setAsDefaultProtocolClient on Windows

Published Apr 3, 2026
CVE-2022-31150MEDIUM

undici before v5.8.0 vulnerable to CRLF injection in request headers

Published Jul 21, 2022
CVE-2025-68272

Signal K Server Vulnerable to Denial of Service via Unrestricted Access Request Flooding

Published Jan 2, 2026
MAL-2022-107

Malicious code in @azure-tests/perf-monitor-query (npm)

Published Jun 20, 2022
CVE-2025-59536

Claude Code can execute commands prior to the startup trust dialog

Published Oct 3, 2025
CVE-2026-28486

OpenClaw vulnerable to path traversal (Zip Slip) in archive extraction during explicit installation commands

Published Mar 2, 2026
CVE-2022-2216CRITICAL

Server-Side Request Forgery in parse-url

Published Jun 28, 2022
CVE-2026-32000

OpenClaw has command injection via Windows shell fallback in Lobster tool execution

Published Mar 3, 2026
CVE-2022-25848HIGH

static-dev-server vulnerable to path traversal

Published Nov 29, 2022
CVE-2024-53983

Backstage Scaffolder plugin vulnerable to Server-Side Request Forgery

Published Dec 2, 2024
CVE-2025-69211

Nest has a Fastify URL Encoding Middleware Bypass (TOCTOU)

Published Dec 30, 2025
CVE-2026-26319

OpenClaw is Missing Webhook Authentication in Telnyx Provider Allows Unauthenticated Requests

Published Feb 17, 2026
CVE-2025-59343

tar-fs has a symlink validation bypass if destination directory is predictable with a specific tarball

Published Sep 24, 2025
GHSA-3h2q-j2v4-6w5r

OpenClaw's system.run allowlist approval parsing missed PowerShell encoded-command wrappers

Published Mar 9, 2026
CVE-2025-62410

happy-dom's `--disallow-code-generation-from-strings` is not sufficient for isolating untrusted JavaScript

Published Oct 15, 2025
MAL-2026-3158

Malicious code in apple-internal-pki-trust (npm)

Published Apr 29, 2026
MAL-2026-3215

Malicious code in archetype-style (npm)

Published May 1, 2026
CVE-2024-37890HIGH

ws affected by a DoS when handling a request with many HTTP headers

Published Jun 17, 2024
MAL-2025-4355

Malicious code in gop_status_frontend (npm)

Published May 23, 2025
CVE-2026-33287

LiquidJS has Exponential Memory Amplification through its replace_first Filter $& Pattern

Published Mar 25, 2026
CVE-2017-16155HIGH

Directory Traversal in fast-http-cli

Published Jul 23, 2018
CVE-2024-43035MEDIUM

Fonoster is vulnerable to directory traversal

Published Mar 5, 2026
CVE-2026-28470

OpenClaw has an exec allowlist bypass via command substitution/backticks inside double quotes

Published Feb 17, 2026
GHSA-9gp8-hjxr-6f34

OpenClaw: Host exec environment overrides miss proxy, TLS, Docker, and Git TLS controls

Published Apr 3, 2026
MAL-2024-9277

Malicious code in opti-distube (npm)

Published Oct 11, 2024
MAL-2024-9278

Malicious code in ts-jest-starter-kit (npm)

Published Oct 11, 2024
GHSA-vrhm-gvg7-fpcf

Memory exhaustion in SvelteKit remote form deserialization (experimental only)

Published Feb 19, 2026
MAL-2022-1107

Malicious code in arm-storsimple8000series (npm)

Published Jun 20, 2022
CVE-2026-24006

Seroval affected by Denial of Service via Deeply Nested Objects

Published Jan 22, 2026
CVE-2025-30360

webpack-dev-server users' source code may be stolen when they access a malicious web site with non-Chromium based browser

Published Jun 4, 2025
GHSA-3j8v-cgw4-2g6q

fast-jwt: Stateful RegExp (/g or /y) causes non-deterministic allowed-claim validation (logical DoS)

Published Apr 9, 2026
CVE-2021-25979CRITICAL

Apostrophe CMS Insufficient Session Expiration vulnerability

Published Nov 10, 2021
MAL-2026-476

Malicious code in @transaction-list/transaction-list-xs (npm)

Published Jan 23, 2026
CVE-2026-32052

OpenClaw's system.run shell-wrapper positional argv carriers could execute hidden commands under misleading approval text

Published Mar 3, 2026
MAL-2025-7075

Malicious code in @amber-team/stylelint-config (npm)

Published Aug 14, 2025
MAL-2022-112

Malicious code in @azure-tests/perf-storage-blob-track-1 (npm)

Published Jun 20, 2022
CVE-2026-29784

Ghost has incomplete CSRF protections around OTC use

Published Mar 5, 2026
GHSA-392f-ggf5-fp3c

OpenClaw: Unicode canonicalization drift in node metadata policy classification could broaden node allowlists

Published Mar 2, 2026
MAL-2024-9382

Malicious code in mp3-file-zip-d-ownload-33971-the-imagination-stage-ar0bb-cvzjxl (npm)

Published Oct 16, 2024
CVE-2018-3771MEDIUM

statics-server Cross-site Scripting vulnerability

Published May 13, 2022
CVE-2018-15494CRITICAL

dojox vulnerable to unescaped string injection

Published Oct 15, 2018
MAL-2026-3232

Malicious code in codewhisperer-streaming (npm)

Published May 2, 2026
CVE-2018-20676MEDIUM

XSS vulnerability that affects bootstrap

Published Jan 17, 2019
GHSA-mj7r-x3h3-7rmr

ApostropheCMS: User Enumeration via Timing Side Channel in Password Reset Endpoint

Published Apr 16, 2026
CVE-2026-25474

OpenClaw has a Telegram webhook request forgery (missing `channels.telegram.webhookSecret`) → auth bypass

Published Feb 17, 2026
MAL-2024-9445

Malicious code in reqstus (npm)

Published Oct 22, 2024
GHSA-3pm9-5j7m-59vc

OpenClaw: Tlon Startup Migration Rehydrates Empty-Array Revocations From File Config

Published Apr 3, 2026
CVE-2026-28450

OpenClaw's unauthenticated Nostr profile HTTP endpoints allow remote profile/config tampering

Published Feb 17, 2026
CVE-2025-64745

Astro development server error page is vulnerable to reflected Cross-site Scripting

Published Nov 13, 2025
CVE-2024-37145MEDIUM

Flowise Cross-site Scripting in /api/v1/chatflows-streaming/id

Published Aug 5, 2024
CVE-2023-5572CRITICAL

Server-Side Request Forgery (SSRF) in vriteio/vrite

Published Oct 13, 2023
CVE-2020-26245HIGH

Prototype Pollution in systeminformation

Published Nov 27, 2020
GHSA-8883-9w57-vwv6

OpenClaw: Mattermost callback dispatch allowed non-allowlisted sender actions

Published Mar 26, 2026
CVE-2016-10664HIGH

mystem downloads Resources over HTTP

Published Feb 18, 2019
CVE-2026-27488

OpenClaw hardened cron webhook delivery against SSRF

Published Feb 20, 2026
MAL-2024-987

Malicious code in @globalsearch/productstub (npm)

Published Feb 10, 2024
GHSA-3q42-xmxv-9vfr

OpenClaw: Gateway operator.write Can Reach Admin-Class Talk Voice Config Persistence via chat.send

Published Apr 7, 2026
CVE-2024-39008CRITICAL

robinweser fast-loops vulnerable to prototype pollution

Published Jul 1, 2024
GHSA-w48f-fwg7-ww6p

@stablelib/cbor: Prototype poisoning via `__proto__` map keys in CBOR decoding

Published Apr 4, 2026
CVE-2026-32944

Parse Server crash via deeply nested query condition operators

Published Mar 17, 2026
CVE-2018-6835CRITICAL

Etherpad Lite Access Restriction Bypass

Published May 13, 2022
CVE-2020-28283CRITICAL

Prototype pollution vulnerability in 'libnested'

Published Oct 12, 2021
CVE-2024-39338HIGH

Server-Side Request Forgery in axios

Published Aug 12, 2024
CVE-2026-24046

Backstage has a Possible Symlink Path Traversal in Scaffolder Actions

Published Jan 21, 2026
CVE-2023-38698MEDIUM

.eth registrar controller can shorten the duration of registered names

Published Aug 1, 2023
CVE-2026-32895

OpenClaw: Slack system events bypass sender authorization in member and message subtype handlers

Published Mar 12, 2026
GHSA-48m6-ch88-55mj

Flowise: Improper Mass Assignment in Account Registration Enables Unauthorized Organization Association

Published Apr 16, 2026
CVE-2025-24010

Websites were able to send any requests to the development server and read the response in vite

Published Jan 21, 2025
CVE-2026-26280

Systeminformation has a Command Injection via unsanitized interface parameter in wifi.js retry path

Published Feb 18, 2026
GHSA-2cwr-f5hx-gg3w

Duplicate Advisory: OpenClaw: stageSandboxMedia destination symlink traversal can overwrite files outside sandbox workspace

Published Mar 19, 2026
CVE-2021-23497HIGH

Prototype Pollution in @strikeentco/set

Published Feb 5, 2022
GHSA-9f79-7pw8-3fj8

Duplicate Advisory: OpenClaw: workspace path guard bypass on non-existent out-of-root symlink leaf

Published Mar 21, 2026
MAL-2026-2110

Malicious code in react-tailwindcss-style (npm)

Published Mar 23, 2026
CVE-2026-30229

parse-server's endpoint `/loginAs` allows `readOnlyMasterKey` to gain full read and write access as any user

Published Mar 6, 2026
GHSA-9gvx-vj57-vqqx

Duplicate Advisory: OpenClaw: Gateway Canvas local-direct requests bypass Canvas HTTP and WebSocket authentication

Published Apr 10, 2026
CVE-2022-25931HIGH

easy-static-server vulnerable to Directory Traversal

Published Dec 20, 2022
CVE-2026-29772

Astro: Memory exhaustion DoS due to missing request body size limit in Server Islands

Published Mar 24, 2026
CVE-2022-27260CRITICAL

Unrestricted Upload of File with Dangerous Type in ButterCMS

Published Apr 13, 2022
CVE-2022-32213MEDIUM

llhttp allows HTTP Request Smuggling via Flawed Parsing of Transfer-Encoding

Published Jul 15, 2022
CVE-2020-8134HIGH

Server-side request forgery in Ghost CMS

Published May 6, 2021
CVE-2023-45857MEDIUM

Axios Cross-Site Request Forgery Vulnerability

Published Nov 8, 2023
CVE-2022-24718HIGH

Path Traversal in @finastra/ssr-pages

Published Mar 1, 2022
CVE-2024-56198

path-sanitizer allows bypassing the existing filters to achieve path-traversal vulnerability

Published Jan 2, 2025
GHSA-qcj9-wwgw-6gm8

OpenClaw: Workspace `.env` can override the bundled plugin trust root

Published Apr 3, 2026
GHSA-5cwg-9f6j-9jvx

Claude Code: Insecure System-Wide Configuration Loading Enables Local Privilege Escalation on Windows

Published Apr 17, 2026
GHSA-5f7h-p83x-5vc2

Duplicate Advisory: OpenClaw: Nextcloud Talk room allowlist matched colliding room names instead of stable room tokens

Published Apr 10, 2026
GHSA-wh77-3x4m-4q9g

Moderate severity vulnerability that affects bootstrap and bootstrap-sass

Published Feb 22, 2019
CVE-2026-32234

Parse Server has a SQL injection via query field name when using PostgreSQL

Published Mar 12, 2026
GHSA-qj22-xqjr-v83v

OpenClaw's Telegram message_reaction authorization bypass allows unauthorized system-event injection

Published Mar 3, 2026
CVE-2026-31991

OpenClaw has Signal group allowlist authorization bypass via DM pairing-store leakage

Published Mar 2, 2026
CVE-2021-42228HIGH

Cross Site Request Forgery in kindeditor

Published Oct 18, 2021
MAL-2025-1350

Malicious code in deepcoin-test (npm)

Published Feb 13, 2025
CVE-2016-10679HIGH

Downloads Resources over HTTP in selenium-standalone-painful

Published Feb 18, 2019
GHSA-wmgj-hrx3-23gj

Duplicate Advisory: OpenClaw: Unbound interpreter and runtime commands could bypass node-host approval integrity

Published Mar 29, 2026
MAL-2025-1359

Malicious code in assisted-chat (npm)

Published Feb 13, 2025
CVE-2026-28471

OpenClaw has a Matrix allowlist bypass via displayName and cross-homeserver localpart matching

Published Feb 17, 2026
GHSA-48vw-m3qc-wr99

OpenClaw's Trusted-proxy Control UI sessions retain privileged scopes without device identity on device-less allow paths

Published Mar 26, 2026
CVE-2023-27474HIGH

directus vulnerable to HTML Injection in Password Reset email to custom Reset URL

Published Mar 7, 2023
CVE-2026-27492

Lettermint Node.js SDK leaks email properties to unintended recipients when client instance is reused

Published Feb 20, 2026
CVE-2026-32237

@backstage/plugin-scaffolder-backend: Possible exposure of defaultEnvironment secrets using dry-run endpoint

Published Mar 12, 2026
CVE-2021-29369CRITICAL

Code injection in @rkesters/gnuplot

Published Feb 10, 2022
CVE-2025-65959

Open WebUI Vulnerable to Stored DOM XSS via Note 'Download PDF'

Published Dec 4, 2025
CVE-2020-28360CRITICAL

Server-Side Request Forgery in private-ip

Published Apr 13, 2021
CVE-2026-33724

n8n's Source Control SSH Configuration Uses StrictHostKeyChecking=no

Published Mar 25, 2026
CVE-2021-37504MEDIUM

jQuery-Upload-File XSS in fileNameStr

Published Feb 26, 2022
CVE-2024-47183

Parse Server's custom object ID allows to acquire role privileges

Published Oct 4, 2024
CVE-2021-26272MEDIUM

Inclusion of Functionality from Untrusted Control Sphere in CKEditor 4

Published Oct 13, 2021
CVE-2016-10566HIGH

install-nw downloads Resources over HTTP

Published Feb 18, 2019
CVE-2025-47935

Multer vulnerable to Denial of Service via memory leaks from unclosed streams

Published May 19, 2025
CVE-2026-28475

OpenClaw: Config writes could persist resolved ${VAR} secrets to disk

Published Mar 2, 2026
GHSA-w7j5-j98m-w679

OpenClaw has multiple E2E/test Dockerfiles that run all processes as root

Published Mar 3, 2026
GHSA-wr4h-v87w-p3r7

h3 has a Path Traversal via Percent-Encoded Dot Segments in serveStatic Allows Arbitrary File Read

Published Mar 18, 2026
CVE-2026-28461

OpenClaw has unbounded memory growth in Zalo webhook via query-string key churn (unauthenticated DoS)

Published Mar 2, 2026
CVE-2025-1692

MongoDB Shell may be susceptible to control character injection via pasting

Published Feb 27, 2025
CVE-2020-28482MEDIUM

Cross-site Request Forgery in fastify-csrf

Published Jan 20, 2021
CVE-2026-21884

React Router SSR XSS in ScrollRestoration

Published Jan 8, 2026
CVE-2020-36376CRITICAL

Vulnerability in list function leads to arbitrary code execution via filePath parameters

Published Nov 2, 2021
CVE-2025-68467

Dark Reader gives users the ability to request style sheets from local web servers

Published Mar 4, 2026
CVE-2023-26920MEDIUM

fast-xml-parser vulnerable to Prototype Pollution through tag or attribute name

Published Jun 13, 2023
GHSA-4ggg-h7ph-26qr

n8n-mcp has authenticated SSRF via instance-URL header in multi-tenant HTTP mode

Published Apr 8, 2026
CVE-2023-41646MEDIUM

Buttercup allows attackers to obtain the hash of the master password

Published Sep 8, 2023
CVE-2024-48913

Hono allows bypass of CSRF Middleware by a request without Content-Type header.

Published Oct 15, 2024
CVE-2026-30820

Flowise has Authorization Bypass via Spoofed x-request-from Header

Published Mar 6, 2026
CVE-2022-23458MEDIUM

Toast UI Grid vulnerable to Cross-site Scripting

Published Sep 23, 2022
CVE-2025-25285

@octokit/endpoint has a Regular Expression in parse that Leads to ReDoS Vulnerability Due to Catastrophic Backtracking

Published Feb 14, 2025
CVE-2025-55284

Claude Code's Permissive Default Allowlist Enables Unauthorized File Read and Network Exfiltration in Claude Code

Published Aug 18, 2025
CVE-2016-10528MEDIUM

Directory Traversal in restafary

Published Feb 18, 2019
CVE-2018-14042MEDIUM

Bootstrap Cross-site Scripting vulnerability

Published Sep 13, 2018
CVE-2020-7610CRITICAL

Deserialization of Untrusted Data in bson

Published May 7, 2021
CVE-2022-25352HIGH

Prototype Pollution in libnested

Published Mar 18, 2022
CVE-2018-3729HIGH

Path Traversal in localhost-now

Published Jul 25, 2018
CVE-2022-30618HIGH

Improper Removal of Sensitive Information Before Storage or Transfer in Strapi

Published May 20, 2022
GHSA-g2hm-779g-vm32

OpenClaw: Heartbeat owner downgrade missed untrusted webhook wake events

Published Apr 17, 2026
CVE-2022-29256MEDIUM

sharp vulnerable to Command Injection in post-installation over build environment

Published Jun 1, 2022
CVE-2026-33574

OpenClaw's skills-install-download can be redirected outside the tools root by rebinding the validated base path

Published Mar 12, 2026
GHSA-g374-mggx-p6xc

OpenClaw: Incomplete scope-clearing fix allows operator.admin escalation via trusted-proxy auth mode

Published Apr 3, 2026
CVE-2022-26183HIGH

Untrusted Search Path in PNPM

Published Mar 23, 2022
CVE-2025-59155

HackMD MCP Server has Server-Side Request Forgery (SSRF) vulnerability

Published Sep 15, 2025
CVE-2025-31475

tarteaucitron.js allows prototype pollution via custom text injection

Published Apr 7, 2025
GHSA-4hxc-9384-m385

h3: SSE Event Injection via Unsanitized Carriage Return (`\r`) in EventStream Data and Comment Fields (Bypass of CVE Fix)

Published Mar 20, 2026
CVE-2025-55303

Astro allows unauthorized third-party images in _image endpoint

Published Aug 19, 2025
MAL-2022-134

Malicious code in @bmw-chris/testmodule-default-frontend (npm)

Published Jun 20, 2022
CVE-2026-33769

Astro: Remote allowlist bypass via unanchored matchPathname wildcard

Published Mar 26, 2026
CVE-2020-36049HIGH

Resource exhaustion in socket.io-parser

Published Jun 30, 2021
CVE-2026-32015

OpenClaw's `tools.exec.safeBins` PATH-hijack allowed trojan binaries to bypass allowlist checks

Published Mar 3, 2026
GHSA-9r7h-6639-v5mw

Cross-Site Scripting in bootstrap-select

Published Sep 3, 2020
CVE-2020-11021MEDIUM

Http request which redirect to another hostname do not strip authorization header in @actions/http-client

Published Apr 29, 2020
CVE-2023-2307MEDIUM

@builder.io/qwik-city Cross-Site Request Forgery vulnerability

Published Apr 26, 2023
GHSA-xh9j-mpc9-2m9p

Duplicate Advisory: OpenClaw has a Trusted-proxy Control UI pairing bypass which allows unpaired node sessions

Published Mar 21, 2026
CVE-2021-4264MEDIUM

dustjs-linkedin vulnerable to Prototype Pollution

Published Dec 21, 2022
MAL-2022-1723

Malicious code in buildstamp-monorepo (npm)

Published Jun 20, 2022
CVE-2022-39386HIGH

fastify/websocket vulnerable to uncaught exception via crash on malformed packet

Published Nov 7, 2022
CVE-2016-10521HIGH

Regular Expression Denial of Service in jshamcrest

Published Feb 18, 2019
MAL-2022-1905

Malicious code in circonus-statsd-backend (npm)

Published Jun 20, 2022
CVE-2026-24473

Hono has an Arbitrary Key Read in Serve static Middleware (Cloudflare Workers Adapter)

Published Jan 27, 2026
CVE-2018-3726MEDIUM

Cross-site Scripting (XSS) - Stored in crud-file-server

Published Jul 18, 2018
CVE-2017-18353HIGH

rendertron can remotely shut down Chrome instance

Published Jan 4, 2019
MAL-2022-116

Malicious code in @azure-tests/perf-template (npm)

Published Jun 20, 2022
MAL-2025-190982

Malicious code in orchestrix (npm)

Published Nov 24, 2025
CVE-2026-24778

Ghost vulnerable to XSS via malicious Portal preview links

Published Jan 28, 2026
CVE-2018-3734HIGH

Path Traversal in stattic

Published Jul 18, 2018
MAL-2022-266

Malicious code in @fbsystem/figma-graphql (npm)

Published Jun 20, 2022
CVE-2025-25288

@octokit/plugin-paginate-rest has a Regular Expression in iterator Leads to ReDoS Vulnerability Due to Catastrophic Backtracking

Published Feb 14, 2025
GHSA-xpcf-pg52-r92g

Hono has incorrect IP matching in ipRestriction() for IPv4-mapped IPv6 addresses

Published Apr 8, 2026
MAL-2022-2735

Malicious code in encryptte-test (npm)

Published Jun 20, 2022
GHSA-chfm-xgc4-47rj

OpenClaw: MSTeams thread history bypasses sender allowlist via Graph API

Published Apr 2, 2026
MAL-2022-1378

Malicious code in azure-storage-blob-changefeed (npm)

Published Jun 20, 2022
MAL-2022-1379

Malicious code in azure-storage-common-cpp (npm)

Published Jun 20, 2022
MAL-2022-2879

Malicious code in etn_validator_list (npm)

Published Jun 20, 2022
MAL-2022-141

Malicious code in @boosted-bounty/cassandra-helpers (npm)

Published Jun 20, 2022
GHSA-xv56-3wq5-9997

Renovate vulnerable to arbitrary command injection via kustomize manager and malicious helm repository

Published Jan 13, 2026
GHSA-jqpf-vj28-9v7r

Duplicate Advisory: Synology Chat dmPolicy=allowlist failed open on empty allowedUserIds, allowing unauthorized agent dispatch

Published Mar 19, 2026
CVE-2026-26980

Ghost has a SQL injection in Content API

Published Feb 18, 2026
GHSA-w6v6-49gh-mc9w

Flowise: Path Traversal in Vector Store basePath

Published Apr 16, 2026
CVE-2022-31198HIGH

OpenZeppelin Contracts's GovernorVotesQuorumFraction updates to quorum may affect past defeated proposals

Published Aug 18, 2022
CVE-2019-18954MEDIUM

Pomelo allows external control of critical state data

Published Dec 2, 2019
CVE-2025-68470

React Router has unexpected external redirect via untrusted paths

Published Jan 8, 2026
MAL-2022-319

Malicious code in @harrysforge/number-stepper (npm)

Published Jun 20, 2022
CVE-2021-44906CRITICAL

Prototype Pollution in minimist

Published Mar 18, 2022
CVE-2026-32638

StudioCMS REST getUsers Exposes Owner Account Records to Admin Tokens

Published Mar 16, 2026
MAL-2022-4507

Malicious code in mattermost-webapp-profiling (npm)

Published Jun 20, 2022
MAL-2022-2167

Malicious code in construct-burst (npm)

Published Jun 20, 2022
CVE-2025-55346

Flowise vulnerable to RCE via Dynamic function constructor injection

Published Oct 6, 2025
MAL-2022-2283

Malicious code in custom-pages-react-boilerplate (npm)

Published Jun 20, 2022
MAL-2022-2284

Malicious code in custom-script-vanilla-js (npm)

Published Jun 20, 2022
CVE-2020-8128CRITICAL

Server-Side Request Forgery and Inclusion of Functionality from Untrusted Control Sphere in jsreport

Published Apr 13, 2021
CVE-2024-46976

@backstage/plugin-techdocs-backend vulnerable to circumvention of cross site scripting protection

Published Sep 17, 2024
CVE-2021-23430HIGH

Directory Traversal in startserver

Published Sep 2, 2021
MAL-2022-5544

Malicious code in qiwi-substrate-monorepo (npm)

Published Jun 20, 2022
MAL-2022-6495

Malicious code in test1_l3yx (npm)

Published Jun 20, 2022
CVE-2026-32065

OpenClaw: system.run approval identity mismatch could execute a different binary than displayed

Published Mar 2, 2026
MAL-2022-6499

Malicious code in test4948 (npm)

Published Jun 20, 2022
MAL-2022-2447

Malicious code in design-system-base (npm)

Published Jun 20, 2022
MAL-2022-4823

Malicious code in newtestforme1008 (npm)

Published Jun 9, 2022
CVE-2021-23346MEDIUM

html-parse-stringify and html-parse-stringify2 vulnerable to Regular expression denial of service (ReDoS)

Published Mar 18, 2021
CVE-2017-16143HIGH

Directory Traversal in commentapp.stetsonwood

Published Jul 23, 2018
MAL-2025-191456

Malicious code in @medusajs/analytics-posthog (npm)

Published Nov 24, 2025
CVE-2026-25762

AdonisJS vulnerable to Denial of Service (DoS) via Unrestricted Memory Buffering in PartHandler during File Type Detection

Published Feb 6, 2026
CVE-2025-47828

@lumieducation/h5p-server Fails to Sanitize Plain Text Strings

Published May 11, 2025
MAL-2022-1000

Malicious code in angieslist-styles (npm)

Published Jun 20, 2022
MAL-2023-1438

Malicious code in exp-core-style (npm)

Published Aug 10, 2023
CVE-2025-15104

Nu Html Checker (vnu) contains a Server-Side Request Forgery (SSRF) vulnerability

Published Jan 16, 2026
MAL-2022-1006

Malicious code in angular-dev-test (npm)

Published Jun 20, 2022
GHSA-w8hx-hqjv-vjcq

Paperclip: Malicious skills able to exfiltrate and destroy all user data

Published Apr 16, 2026
CVE-2025-7338

Multer vulnerable to Denial of Service via unhandled exception from malformed request

Published Jul 17, 2025
MAL-2023-690

Malicious code in postcss-file-match (npm)

Published Jan 30, 2023
MAL-2024-36

Malicious code in @monokera/react-components-storybook (npm)

Published Jan 5, 2024
CVE-2026-33349

Entity Expansion Limits Bypassed When Set to Zero Due to JavaScript Falsy Evaluation in fast-xml-parser

Published Mar 19, 2026
CVE-2021-23382MEDIUM

Regular Expression Denial of Service in postcss

Published Jan 7, 2022
MAL-2022-104

Malicious code in @azure-tests/perf-keyvault-certificates (npm)

Published Jun 20, 2022
CVE-2020-24807HIGH

File restriction bypass in socket.io-file

Published Oct 2, 2020
MAL-2022-1040

Malicious code in api-extractor-test-01 (npm)

Published May 16, 2022
GHSA-569q-mpph-wgww

Better Auth affected by external request basePath modification DoS

Published Dec 1, 2025
GHSA-56p5-8mhr-2fph

LiquidJS: Root restriction bypass for partial and layout loading through symlinked templates

Published Apr 8, 2026
CVE-2016-10671HIGH

Downloads Resources over HTTP in mystem-wrapper

Published Feb 18, 2019
GHSA-wxw2-rwmh-vr8f

electerm: electerm_install_script_CommandInjection Vulnerability Report

Published Apr 16, 2026
MAL-2022-1106

Malicious code in arm-storsimple1200series (npm)

Published Jun 20, 2022
MAL-2022-1108

Malicious code in arm-streamanalytics (npm)

Published Jun 20, 2022
CVE-2026-3419

Fastify's Missing End Anchor in "subtypeNameReg" Allows Malformed Content-Types to Pass Validation

Published Mar 5, 2026
GHSA-57gh-m6rq-54cf

OpenClaw: Self-Whitelisting in appendLocalMediaParentRoots Allows Arbitrary File Read & Credential Exfiltration

Published Apr 3, 2026
CVE-2016-10620HIGH

Downloads Resources over HTTP in atom-node-module-installer

Published Feb 18, 2019
MAL-2022-115

Malicious code in @azure-tests/perf-storage-file-share-track-1 (npm)

Published Jun 20, 2022
CVE-2026-27942

fast-xml-parser has stack overflow in XMLBuilder with preserveOrder

Published Feb 26, 2026
GHSA-cqgw-44wg-44rf

OpenClaw: Discord voice manager bypasses channel-level member access allowlist

Published Apr 3, 2026
GHSA-x428-ghpx-8j92

@fastify/static vulnerable to route guard bypass via encoded path separators

Published Apr 16, 2026
MAL-2022-1157

Malicious code in atlas-custom-behaviour (npm)

Published Jun 20, 2022
CVE-2026-27612

repostat: Reflected Cross-Site Scripting (XSS) via repo prop in RepoCard

Published Feb 25, 2026
MAL-2025-192143

Malicious code in elf-stats-snowy-candy-850 (npm)

Published Dec 3, 2025
MAL-2024-7251

Malicious code in @zitterorg/iusto-iusto-quasi (npm)

Published Jul 4, 2024
CVE-2026-25153

@backstage/plugin-techdocs-node vulnerable to arbitrary code execution via MkDocs hooks

Published Feb 2, 2026
MAL-2024-1040

Malicious code in emilkylandertestnpmpackge (npm)

Published Feb 27, 2024
GHSA-j4c9-w69r-cw33

OpenClaw: Telegram DM-Scoped Inline Button Callbacks Bypass DM Pairing and Mutate Session State

Published Mar 29, 2026
CVE-2021-41249HIGH

XSS vulnerability in GraphQL Playground from untrusted schemas

Published Nov 8, 2021
CVE-2022-27139CRITICAL

Arbitrary file upload in Ghost

Published Apr 13, 2022
CVE-2019-13173HIGH

Arbitrary File Overwrite in fstream

Published May 30, 2019
GHSA-5c6j-r48x-rmvq

Serialize JavaScript is Vulnerable to RCE via RegExp.flags and Date.prototype.toISOString()

Published Feb 28, 2026
MAL-2025-190924

Malicious code in posthog-docusaurus (npm)

Published Nov 24, 2025
MAL-2024-10477

Malicious code in chat-history-log-viewer (npm)

Published Nov 6, 2024
MAL-2025-192088

Malicious code in elf-stats-merry-sparkler-742 (npm)

Published Dec 3, 2025
MAL-2024-8572

Malicious code in @diotoborg/quis-tempore-distinctio (npm)

Published Sep 2, 2024
MAL-2025-192100

Malicious code in elf-stats-mulled-drum-529 (npm)

Published Dec 3, 2025
MAL-2025-3726

Malicious code in com.unity.cluster-display (npm)

Published May 10, 2025
GHSA-xgwg-m42c-8q62

Duplicate Advisory: OpenClaw: Slack system events bypass sender authorization in member and message subtype handlers

Published Mar 21, 2026
CVE-2025-57283

BrowserStack Local vulnerable to Command Injection through logfile variable

Published Jan 28, 2026
MAL-2025-192279

Malicious code in elf-stats-candystriped-chimney-879 (npm)

Published Dec 3, 2025
MAL-2025-192297

Malicious code in elf-stats-bright-cocoa-293 (npm)

Published Dec 4, 2025
MAL-2022-1269

Malicious code in azure-arm-postgresql-flexible-samples-js (npm)

Published Jun 20, 2022
MAL-2025-40

Malicious code in solana-stable-web-huks (npm)

Published Jan 10, 2025
GHSA-j8j5-7r4h-vj2g

DbGate has cross site scripting via the SVG Icon String Handler component

Published Apr 13, 2026
CVE-2023-48218MEDIUM

Bypass of field access control in strapi-plugin-protected-populate

Published Nov 20, 2023
MAL-2025-192326

Malicious code in elf-stats-candlelit-hollyberry-248 (npm)

Published Dec 5, 2025
GHSA-mj4p-rc52-m843

OpenClaw: Sandbox staged writes could escape the verified parent directory before commit

Published Mar 13, 2026
MAL-2024-11104

Malicious code in ssc-ui-static (npm)

Published Nov 27, 2024
GHSA-6hw5-45gm-fj88

@fastify/express has a middleware authentication bypass via URL normalization gaps (duplicate slashes and semicolons)

Published Apr 16, 2026
CVE-2026-21894

n8n's Missing Stripe-Signature Verification Allows Unauthenticated Forged Webhooks

Published Jan 7, 2026
CVE-2026-32302

OpenClaw: Untrusted web origins can obtain authenticated operator.admin access in trusted-proxy mode

Published Mar 12, 2026
GHSA-xhmj-rg95-44hv

Flowise: SSRF Protection Bypass via Unprotected Built-in HTTP Modules in Custom Function Sandbox

Published Apr 16, 2026
MAL-2025-191957

Malicious code in elf-stats-sparkly-hammer-880 (npm)

Published Dec 3, 2025
MAL-2025-192242

Malicious code in elf-stats-whimsical-chimney-949 (npm)

Published Dec 3, 2025
CVE-2026-33940

Handlebars.js has JavaScript Injection via AST Type Confusion when passing an object as dynamic partial

Published Mar 27, 2026
CVE-2026-22594

Ghost has Staff 2FA bypass

Published Jan 8, 2026
MAL-2024-8250

Malicious code in @diotoborg/dolores-iusto (npm)

Published Sep 2, 2024
CVE-2026-26862

CleverTap Web SDK is vulnerable to DOM-based Cross-Site Scripting (XSS) via window.postMessage

Published Feb 27, 2026
GHSA-5gjc-grvm-m88j

OpenClaw: Memory dreaming config persistence was reachable from operator.write commands

Published Apr 17, 2026
MAL-2026-2730

Malicious code in browserstack-utils (npm)

Published Apr 16, 2026
MAL-2022-1312

Malicious code in azure-container-registry-samples-ts (npm)

Published Jun 20, 2022
MAL-2025-2760

Malicious code in f0-state-holder-duke (npm)

Published Mar 28, 2025
MAL-2025-3085

Malicious code in @harvest-finance/harvest-strategy-polygon (npm)

Published Apr 3, 2025
MAL-2025-3224

Malicious code in @bane-mlb/less-styles (npm)

Published Apr 17, 2025
GHSA-736r-jwj6-4w23

OpenClaw: Sandboxed agents could escape exec routing via host=node override

Published Apr 17, 2026
CVE-2018-3787HIGH

simplehttpserver allows directory traversal and file listing

Published Sep 6, 2018
MAL-2025-192540

Malicious code in elf-stats-twinkling-wishlist-283 (npm)

Published Dec 11, 2025
MAL-2026-3037

Malicious code in standalone-apps (npm)

Published Apr 25, 2026
MAL-2022-1360

Malicious code in azure-output-customization-samples-ts (npm)

Published Jun 20, 2022
CVE-2020-7603CRITICAL

OS Command Injection in closure-compiler-stream

Published May 7, 2021
GHSA-xr8f-h2gw-9xh6

OAuth 2.1 Provider: Unprivileged users can register OAuth clients

Published Apr 16, 2026
MAL-2026-2731

Malicious code in buildkite-test-collector-cypress-example (npm)

Published Apr 16, 2026
MAL-2025-1608

Malicious code in material-start (npm)

Published Feb 28, 2025
CVE-2022-37260HIGH

steal vulnerable to Regular Expression Denial of Service via input variable

Published Sep 16, 2022
CVE-2025-69981

FUXA contains an Unrestricted File Upload vulnerability

Published Feb 3, 2026
CVE-2025-29192

Flowise Stored XSS vulnerability through logs in chatbot

Published Oct 3, 2025
MAL-2026-3054

Malicious code in @apple-pay-trust/start (npm)

Published Apr 25, 2026
MAL-2025-190673

Malicious code in @posthog/rrweb (npm)

Published Nov 24, 2025
GHSA-7g8c-cfr3-vqqr

OpenClaw: Agent hook events could enqueue trusted system events from unsanitized external input

Published Apr 17, 2026
CVE-2025-31119

generator-jhipster-entity-audit vulnerable to Unsafe Reflection when having Javers selected as Entity Audit Framework

Published Apr 4, 2025
MAL-2022-110

Malicious code in @azure-tests/perf-service-bus-track-1 (npm)

Published Jun 20, 2022
GHSA-h43v-27wg-5mf9

OpenClaw: Forged Nostr DMs could create pairing state before signature verification

Published Apr 7, 2026
MAL-2026-3055

Malicious code in @apple-pay-trust/validate-merchant (npm)

Published Apr 25, 2026
CVE-2021-27516HIGH

URIjs Hostname spoofing via backslashes in URL

Published Mar 1, 2021
MAL-2025-190715

Malicious code in @asyncapi/java-spring-cloud-stream-template (npm)

Published Nov 24, 2025
MAL-2022-1178

Malicious code in automate-loadtest-action (npm)

Published Jun 20, 2022
MAL-2026-3053

Malicious code in @apple-pay-trust/merchant-session (npm)

Published Apr 25, 2026
MAL-2026-3057

Malicious code in @clearpool/streaming (npm)

Published Apr 26, 2026
CVE-2018-3711HIGH

Denial of Service vulnerability with large JSON payloads in fastify

Published Jul 18, 2018
MAL-2022-1459

Malicious code in bankin_thechnical_test (npm)

Published Jun 20, 2022
CVE-2020-15092HIGH

Stored XSS in TimelineJS3

Published Jul 9, 2020
MAL-2026-3061

Malicious code in @google-pay-trust/authorize-payment (npm)

Published Apr 25, 2026
MAL-2022-146

Malicious code in @bootstrap-base-design/bootstrap-base (npm)

Published Jun 20, 2022
MAL-2026-3062

Malicious code in @google-pay-trust/cancelled (npm)

Published Apr 25, 2026
MAL-2026-3063

Malicious code in @google-pay-trust/finish (npm)

Published Apr 25, 2026
MAL-2026-3064

Malicious code in @google-pay-trust/init-google-pay (npm)

Published Apr 25, 2026
CVE-2021-4299MEDIUM

string-kit Inefficient Regular Expression Complexity vulnerability

Published Jan 2, 2023
MAL-2022-1203

Malicious code in aws-solutions-constructs (npm)

Published Jun 20, 2022
MAL-2026-3125

Malicious code in transform-regexp-constructors (npm)

Published Mar 16, 2026
CVE-2026-32020

OpenClaw's Control UI Static File Handler Follows Symlinks and Allows Out-of-Root File Read

Published Mar 2, 2026
MAL-2026-3073

Malicious code in @tw-utils/static (npm)

Published Apr 25, 2026
MAL-2025-191277

Malicious code in @oku-ui/toast (npm)

Published Nov 25, 2025
CVE-2016-10643HIGH

Downloads Resources over HTTP in jstestdriver

Published Aug 15, 2018
GHSA-5h2w-qmfp-ggp6

OpenClaw: Gateway `operator.write` can reach admin-only persisted `verboseLevel` via `chat.send` `/verbose`

Published Mar 31, 2026
MAL-2025-192864

Malicious code in stream-chain-xor (npm)

Published Dec 23, 2025
MAL-2025-191956

Malicious code in elf-stats-snowdusted-wishlist-166 (npm)

Published Dec 3, 2025
MAL-2025-192111

Malicious code in elf-stats-nutmeg-stocking-515 (npm)

Published Dec 3, 2025
MAL-2025-192149

Malicious code in elf-stats-snuggly-cookie-673 (npm)

Published Dec 3, 2025
MAL-2025-192173

Malicious code in elf-stats-sugarplum-star-404 (npm)

Published Dec 3, 2025
MAL-2025-192174

Malicious code in elf-stats-sugarplum-stockpile-238 (npm)

Published Dec 3, 2025
MAL-2025-192178

Malicious code in elf-stats-tinsel-pantry-856 (npm)

Published Dec 3, 2025
GHSA-pqhr-mp3f-hrpp

Nuxt OG Image vulnerable to Server-Side Request Forgery via user-controlled parameters

Published Mar 31, 2026
CVE-2022-3224MEDIUM

parse-url parses http URLs incorrectly, making it vulnerable to host name spoofing

Published Sep 16, 2022
MAL-2025-192208

Malicious code in elf-stats-cranberry-hollyberry-804 (npm)

Published Dec 3, 2025
MAL-2026-626

Malicious code in react-toast-cold (npm)

Published Jan 28, 2026
MAL-2025-192225

Malicious code in elf-stats-nutmeg-stockpile-999 (npm)

Published Dec 3, 2025
MAL-2025-192228

Malicious code in elf-stats-piney-nightcap-782 (npm)

Published Dec 3, 2025
MAL-2025-192262

Malicious code in elf-stats-joyous-hollyberry-121 (npm)

Published Dec 3, 2025
MAL-2022-1313

Malicious code in azure-core-rest-pipeline (npm)

Published Jun 20, 2022
MAL-2022-1314

Malicious code in azure-core-rest-pipeline-js (npm)

Published Jun 20, 2022
GHSA-pw7h-9g6p-c378

OpenClaw: Tlon settings empty-allowlist reconciliation bypassed intended revocation

Published Mar 26, 2026
MAL-2025-192284

Malicious code in elf-stats-sprucey-fireplace-355 (npm)

Published Dec 3, 2025
MAL-2022-1315

Malicious code in azure-core-rest-pipeline-ts (npm)

Published Jun 20, 2022
CVE-2026-30945

StudioCMS: IDOR — Arbitrary API Token Revocation Leading to Denial of Service

Published Mar 11, 2026
CVE-2021-33420CRITICAL

replicator vulnerable to Deserialization of Untrusted Data

Published Dec 15, 2022
MAL-2022-1328

Malicious code in azure-eventhubs-checkpointstore (npm)

Published Jun 20, 2022
MAL-2025-192300

Malicious code in elf-stats-marzipan-cocoa-562 (npm)

Published Dec 4, 2025
MAL-2025-192335

Malicious code in elf-stats-mulled-snowglobe-636 (npm)

Published Dec 5, 2025
MAL-2025-192336

Malicious code in elf-stats-northbound-drum-422 (npm)

Published Dec 5, 2025
CVE-2026-32978

OpenClaw: Unrecognized script runners could bypass `system.run` approval integrity

Published Mar 13, 2026
MAL-2025-192337

Malicious code in elf-stats-shimmering-garland-476 (npm)

Published Dec 5, 2025
CVE-2026-28398

NocoDB Vulnerable to Stored Cross-Site Scripting via Comments and Rich Text Cells

Published Mar 3, 2026
MAL-2025-192344

Malicious code in elf-stats-whimsical-pantry-974 (npm)

Published Dec 5, 2025
MAL-2022-1597

Malicious code in bitski-quickstart (npm)

Published Jun 20, 2022
GHSA-qf48-qfv4-jjm9

OpenClaw: Feishu extension resolveUploadInput bypasses file-system sandbox and allows arbitrary file reads via upload_image

Published Mar 31, 2026
MAL-2022-1361

Malicious code in azure-package-name-test (npm)

Published Jun 20, 2022
MAL-2025-192345

Malicious code in native-component-list (npm)

Published Dec 5, 2025
GHSA-pg8g-f2hf-x82m

Duplicate Advisory: OpenClaw: `fetchWithSsrFGuard` replays unsafe request bodies across cross-origin redirects

Published Apr 9, 2026
MAL-2025-192481

Malicious code in elf-stats-caroling-sled-530 (npm)

Published Dec 11, 2025
CVE-2026-31856

Parse Server vulnerable to SQL injection via `Increment` operation on nested object field in PostgreSQL

Published Mar 11, 2026
MAL-2022-1370

Malicious code in azure-schema-registry-avro (npm)

Published Jun 20, 2022
CVE-2019-16303CRITICAL

JHipster Kotlin using insecure source of randomness `RandomStringUtils` before v1.2.0

Published Jun 26, 2020
MAL-2022-1371

Malicious code in azure-schema-registry-avro-js (npm)

Published Jun 20, 2022
CVE-2023-26492MEDIUM

Directus vulnerable to Server-Side Request Forgery On File Import

Published Mar 3, 2023
MAL-2022-1372

Malicious code in azure-schema-registry-avro-ts (npm)

Published Jun 20, 2022
MAL-2022-1373

Malicious code in azure-schema-registry-js (npm)

Published Jun 20, 2022
MAL-2022-1383

Malicious code in azure-storage-queue (npm)

Published Jun 20, 2022
MAL-2022-1624

Malicious code in blockstream-adapter (npm)

Published Jun 20, 2022
CVE-2024-47762

Unexpected visibility of environment variable configurations in @backstage/plugin-app-backend

Published Oct 3, 2024
MAL-2022-1639

Malicious code in body-string-rest (npm)

Published Jun 20, 2022
MAL-2025-2335

Malicious code in ward-steward (npm)

Published Mar 12, 2025
CVE-2022-2900CRITICAL

Server-Side Request Forgery (SSRF) in GitHub repository ionicabizau/parse-url

Published Sep 15, 2022
CVE-2016-10677HIGH

Downloads Resources over HTTP in google-closure-tools-latest

Published Feb 18, 2019
CVE-2024-29181LOW

@strapi/plugin-content-manager leaks data via relations via the Admin Panel

Published Jun 12, 2024
MAL-2022-1645

Malicious code in bolt-styles (npm)

Published May 16, 2022
CVE-2022-31170HIGH

OpenZeppelin Contracts's ERC165Checker may revert instead of returning false

Published Jul 21, 2022
MAL-2022-1649

Malicious code in bootstrap-base-design (npm)

Published Jun 20, 2022
GHSA-94pw-c6m8-p9p9

OpenClaw: Gateway operator.write Can Reach Admin-Class Channel Allowlist Persistence via chat.send

Published Mar 30, 2026
CVE-2026-27610

Parse Dashboard Has a Cache Key Collision that Leaks Master Key to Read-Only Sessions

Published Feb 25, 2026
MAL-2022-1650

Malicious code in bootstrap-base-managed-designs (npm)

Published Jun 20, 2022
MAL-2022-1651

Malicious code in bootstrap-base-nabtrade-design (npm)

Published Jun 20, 2022
MAL-2022-1394

Malicious code in azurearctest (npm)

Published Jun 20, 2022
MAL-2025-192964

Malicious code in @peter_wilson12091/internal-json-test-parser (npm)

Published Dec 30, 2025
MAL-2025-2703

Malicious code in requestz-promises (npm)

Published Mar 25, 2025
MAL-2025-2711

Malicious code in standard-demo (npm)

Published Mar 25, 2025
CVE-2020-27543HIGH

Denial of Service (DoS) in restify-paginate

Published Apr 12, 2021
CVE-2026-4040

OpenClaw safeBins file-existence oracle information disclosure

Published Feb 19, 2026
MAL-2022-160

Malicious code in @bynder-private/persistgraphql-webpack-plugin (npm)

Published Jun 20, 2022
CVE-2026-22686

enclave-vm Vulnerable to Sandbox Escape via Host Error Prototype Chain

Published Jan 14, 2026
MAL-2022-1550

Malicious code in bfx-stuff-ui (npm)

Published Jun 20, 2022
MAL-2022-1564

Malicious code in bifrostmigrationmonitor (npm)

Published Jul 21, 2022
CVE-2026-27578

n8n Vulnerable to Stored XSS via Various Nodes

Published Feb 25, 2026
CVE-2025-67419

evershop allows unauthenticated attackers to exhaust application server's resources via "GET /images" API

Published Jan 5, 2026
MAL-2022-1648

Malicious code in bootlstap (npm)

Published Aug 19, 2022
CVE-2026-27670

OpenClaw: ZIP extraction race could write outside destination via parent symlink rebind

Published Mar 3, 2026
MAL-2025-3906

Malicious code in mobile-test-px (npm)

Published May 16, 2025
CVE-2020-27666MEDIUM

Cross-site Scripting in Strapi

Published Oct 29, 2020
CVE-2020-36851

cors-anywhere vulnerable to server-side request forgery

Published Sep 25, 2025
MAL-2022-166

Malicious code in @ch-post-common/common-web-frontend (npm)

Published Jun 20, 2022
MAL-2025-3947

Malicious code in cp-area-nao-correntista-fgts-ui (npm)

Published May 15, 2025
CVE-2016-10657HIGH

Downloads Resources over HTTP in co-cli-installer

Published Feb 18, 2019
CVE-2026-26318

Command Injection via Unsanitized `locate` Output in `versions()` — systeminformation

Published Feb 18, 2026
GHSA-82qx-6vj7-p8m2

OpenClaw: Channel setup catalog lookups could include untrusted workspace plugin shadows

Published Apr 17, 2026
CVE-2026-22168

OpenClaw has Windows system.run approval mismatch on cmd.exe /c trailing arguments

Published Mar 2, 2026
CVE-2025-66415

fastify-reply-from affected by bypass of reply forwarding

Published Dec 2, 2025
CVE-2021-43783HIGH

Path Traversal in @backstage/plugin-scaffolder-backend

Published Dec 1, 2021
CVE-2024-31207MEDIUM

Vite's `server.fs.deny` did not deny requests for patterns with directories.

Published Apr 3, 2024
MAL-2022-177

Malicious code in @codahosted/fetlife-assets (npm)

Published Jun 20, 2022
CVE-2026-34210HIGH
Risk: 40.51/100

mppx has Stripe charge credential replay via missing idempotency check

Published Mar 29, 2026
CVE-2024-28181HIGH

TurboBoost Commands vulnerable to arbitrary method invocation

Published Mar 15, 2024
GHSA-72gr-qfp7-vwhw

h3: Double Decoding in `serveStatic` Bypasses `resolveDotSegments` Path Traversal Protection via `%252e%252e`

Published Mar 20, 2026
CVE-2020-11610HIGH

xdlocalstorage does not verify request origin

Published May 24, 2022
CVE-2017-15879HIGH

Keystone is vulnerable to CSV injection

Published Nov 16, 2017
MAL-2025-3166

Malicious code in stormapp765 (npm)

Published Apr 7, 2025
GHSA-q2qc-744p-66r2

OpenClaw: `session_status` sessionId resolution bypasses sandboxed session-tree visibility

Published Mar 29, 2026
MAL-2022-181

Malicious code in @contrast-security-inc/design-system-foundations (npm)

Published Jun 20, 2022
CVE-2020-13961MEDIUM

Improper Input Validation in strapi

Published May 24, 2022
CVE-2018-14040MEDIUM

Bootstrap vulnerable to Cross-Site Scripting (XSS)

Published May 13, 2022
CVE-2026-25957

Cube Core is vulnerable to Denial of Service (DoS) via crafted request

Published Feb 10, 2026
CVE-2026-32017

OpenClaw exec allowlist safeBins short-option bypass could permit arbitrary file write

Published Mar 3, 2026
CVE-2023-28155MEDIUM

Server-Side Request Forgery in Request

Published Mar 16, 2023
CVE-2026-27980

Next.js: Unbounded next/image disk cache growth can exhaust storage

Published Mar 17, 2026
GHSA-67mf-f936-ppxf

OpenClaw `node.pair.approve` placed in `operator.write` scope instead of `operator.pairing` allows unprivileged pairing approval

Published Apr 9, 2026
CVE-2018-20677MEDIUM

bootstrap Cross-site Scripting vulnerability

Published Jan 17, 2019
MAL-2022-1856

Malicious code in cdk-fargate-fastautlscaler (npm)

Published Jun 20, 2022
CVE-2018-16489CRITICAL

Prototype Pollution in just-extend

Published Feb 7, 2019
CVE-2026-32023

OpenClaw's dispatch-wrapper depth-cap mismatch can bypass shell-wrapper approval gating in system.run allowlist mode

Published Mar 3, 2026
MAL-2022-207

Malicious code in @dqwdqwas/testconf (npm)

Published Jun 20, 2022
GHSA-844j-xrrq-wgh4

OpenClaw: Forwarding header spoofing bypasses gateway.trustedProxies origin detection

Published Mar 26, 2026
MAL-2022-1926

Malicious code in client-sdk-contract-tests (npm)

Published Jun 20, 2022
MAL-2022-1929

Malicious code in clinstestpackage (npm)

Published May 16, 2022
GHSA-ch86-pxr9-j9h9

Duplicate Advisory: OpenClaw: Gemini OAuth exposed the PKCE verifier through the OAuth state parameter

Published Apr 3, 2026
CVE-2026-33937

Handlebars.js has JavaScript Injection via AST Type Confusion

Published Mar 27, 2026
GHSA-rp42-5vxx-qpwr

basic-ftp vulnerable to denial of service via unbounded memory consumption in Client.list()

Published Apr 16, 2026
CVE-2026-32774

Vulnogram contains a stored cross-site scripting vulnerability in comment hypertext handling

Published Mar 16, 2026
CVE-2019-5416HIGH

Path Traversal in localhost-now

Published Mar 25, 2019
MAL-2022-1991

Malicious code in coldstone-sls (npm)

Published May 16, 2022
CVE-2025-59471

Next.js self-hosted applications vulnerable to DoS via Image Optimizer remotePatterns configuration

Published Jan 27, 2026
CVE-2021-25952CRITICAL

Prototype polluation in just-safe-set

Published Dec 10, 2021
CVE-2026-25528

LangSmith Client SDK Affected by Server-Side Request Forgery via Tracing Header Injection

Published Feb 9, 2026
CVE-2026-27183

OpenClaw: system.run wrapper-depth boundary could skip shell approval gating

Published Mar 9, 2026
CVE-2019-15478MEDIUM

Cross-Site Scripting in status-board

Published Sep 23, 2019
MAL-2022-2113

Malicious code in comcast.business.web.ui.trident (npm)

Published Jun 20, 2022
CVE-2026-32913

OpenClaw: fetch-guard forwards custom authorization headers across cross-origin redirects

Published Mar 9, 2026
CVE-2023-36472MEDIUM

Strapi may leak sensitive user information, user reset password, tokens via content-manager views

Published Sep 13, 2023
MAL-2022-2432

Malicious code in dependency-confusion-art-test2 (npm)

Published Jun 20, 2022
GHSA-6q2v-vfwp-pvwh

Duplicate Advisory: OpenClaw's skills-install-download can be redirected outside the tools root by rebinding the validated base path

Published Mar 29, 2026
CVE-2026-32730

ApostropheCMS MFA/TOTP Bypass via Incorrect MongoDB Query in Bearer Token Middleware

Published Mar 18, 2026
GHSA-9ppg-jx86-fqw7

Unauthorized npm publish of cline@2.3.0 with modified postinstall script

Published Feb 19, 2026
MAL-2022-2637

Malicious code in dynamic-virtualized-list (npm)

Published Jun 20, 2022
CVE-2022-22138HIGH

Uncontrolled Resource Consumption in fast-string-search

Published Jun 18, 2022
CVE-2025-27097

Cache variables with the operations when transforms exist on the root level even if variables change in the further requests with the same operation

Published Oct 10, 2023
CVE-2021-36383MEDIUM

Xen Orchestra Mishandles Authorization

Published May 24, 2022
CVE-2026-23634

Pepr Has Overly Permissive RBAC ClusterRole in Admin Mode

Published Jan 15, 2026
GHSA-6rmx-gvvg-vh6j

OpenClaw's hooks count non-POST requests toward auth lockout

Published Mar 9, 2026
CVE-2025-15284

qs's arrayLimit bypass in its bracket notation allows DoS via memory exhaustion

Published Dec 30, 2025
CVE-2024-57556

Cross Site Scripting vulnerability in store2

Published Jan 24, 2025
CVE-2023-34104HIGH

fast-xml-parser vulnerable to Regex Injection via Doctype Entities

Published Jun 6, 2023
MAL-2022-3619

Malicious code in hft-frontend-test (npm)

Published Jul 25, 2022
CVE-2025-6514

mcp-remote exposed to OS command injection via untrusted MCP server connections

Published Jul 9, 2025
CVE-2020-7730CRITICAL

Command injection in bestzip

Published May 6, 2021
MAL-2022-2193

Malicious code in core-guest-spa (npm)

Published Jun 20, 2022
CVE-2025-1520

PostHog Plugin Server SQL Injection Vulnerability

Published Apr 23, 2025
CVE-2022-31175MEDIUM

CKEditor5 cross-site scripting vulnerability caused by the editor instance destroying process

Published Aug 6, 2022
MAL-2022-4945

Malicious code in npm_test_nothing (npm)

Published May 16, 2022
CVE-2025-1398

Mattermost Desktop App allows the bypass of Transparency, Consent, and Control (TCC) via code injection

Published Mar 17, 2025
MAL-2022-2240

Malicious code in cro-staking (npm)

Published Jun 20, 2022
MAL-2022-3678

Malicious code in hosted-checkout-tutorial (npm)

Published Jun 20, 2022
CVE-2020-7696MEDIUM

Credential leak in react-native-fast-image

Published May 18, 2021
CVE-2026-25041

@budibase/server: Command Injection in PostgreSQL Dump Command

Published Mar 9, 2026
MAL-2022-3680

Malicious code in hpathexists (npm)

Published Aug 19, 2022
CVE-2022-37265CRITICAL

steal vulnerable to Prototype Pollution via alias variable

Published Sep 21, 2022
MAL-2022-1364

Malicious code in azure-purview-administration (npm)

Published Jun 20, 2022
GHSA-7437-7hg8-frrw

OpenClaw: HGRCPATH, CARGO_BUILD_RUSTC_WRAPPER, RUSTC_WRAPPER, and MAKEFLAGS missing from exec env denylist — RCE via build tool env injection (GHSA-cm8v-2vh9-cxf3 class)

Published Apr 9, 2026
CVE-2023-35926HIGH

Backstage Scaffolder plugin has insecure sandbox

Published Jun 21, 2023
CVE-2017-16165HIGH

Directory Traversal in calmquist.static-server

Published Jul 23, 2018
CVE-2022-31070MEDIUM

Potential Sensitive Cookie Exposure in NPM Packages @finastra/nestjs-proxy, @ffdc/nestjs-proxy

Published Jun 17, 2022
MAL-2022-613

Malicious code in @status-waku-voting/core (npm)

Published Jun 20, 2022
MAL-2022-4379

Malicious code in logi-bootstrap (npm)

Published Jun 20, 2022
CVE-2021-32809MEDIUM

Clipboard feature vulnerability allowing to inject arbitrary HTML into the editor using paste functionality

Published Aug 23, 2021
MAL-2022-4382

Malicious code in loglongakamairequest (npm)

Published Jun 20, 2022
MAL-2022-238

Malicious code in @epc-infra/clinstestpackage (npm)

Published May 16, 2022
MAL-2022-4492

Malicious code in material-ui-plugin-styles-provider-cache (npm)

Published Jun 30, 2022
CVE-2026-32050

OpenClaw's Signal reaction-only status events could, in limited cases, be enqueued before access checks

Published Mar 3, 2026
GHSA-wxf3-4fvj-vqqx

Unsafe plugins can be installed via pack import by tenant admins

Published Jul 27, 2023
CVE-2021-33360CRITICAL

stoqey/gnuplot is vulnerable to command injection

Published Mar 10, 2023
MAL-2022-4503

Malicious code in mattermost-plugin-docs (npm)

Published Jun 20, 2022
MAL-2022-4504

Malicious code in mattermost-push-proxy (npm)

Published Jun 20, 2022
CVE-2026-32037

OpenClaw's MSTeams attachment redirect handling could bypass configured media host allowlists

Published Mar 3, 2026
MAL-2022-2591

Malicious code in dreactbvotstrap (npm)

Published Aug 19, 2022
MAL-2022-2646

Malicious code in ea-test-helpers (npm)

Published Jun 20, 2022
MAL-2022-268

Malicious code in @fbsystem/figma-messenger (npm)

Published Jun 20, 2022
CVE-2026-33331

oRPC has Stored XSS in OpenAPI Reference Plugin via unescaped JSON.stringify

Published Mar 20, 2026
MAL-2022-6295

Malicious code in starlink2 (npm)

Published Jul 25, 2022
MAL-2022-6296

Malicious code in starter-theme (npm)

Published May 18, 2022
MAL-2022-6297

Malicious code in stasis-adapter (npm)

Published Jun 20, 2022
CVE-2026-27959

Koa has Host Header Injection via ctx.hostname

Published Feb 26, 2026
GHSA-7ggg-pvrf-458v

OpenClaw: PIP_INDEX_URL and UV_INDEX_URL bypass host exec env sanitization and redirect Python package-index traffic

Published Apr 2, 2026
CVE-2024-45835

Mattermost Desktop App fails to sufficiently configure Electron Fuses

Published Sep 16, 2024
CVE-2024-34448HIGH

Ghost allows CSV Injection during member CSV export

Published May 22, 2024
MAL-2022-2474

Malicious code in dinesh-dev-nagajikkktest11223qa (npm)

Published Jun 20, 2022
MAL-2022-4632

Malicious code in mitui-util-test (npm)

Published Jun 20, 2022
GHSA-x8rx-789c-2pxq

RedwoodSDK has a CSRF vulnerability in server function dispatch via GET requests

Published Apr 8, 2026
MAL-2022-4556

Malicious code in mephisto-task-compiler (npm)

Published Jun 20, 2022
MAL-2022-4557

Malicious code in mephisto-worker-experience (npm)

Published Jun 21, 2022
CVE-2023-25571MEDIUM

Cross site scripting Vulnerability in backstage Software Catalog

Published Feb 14, 2023
CVE-2026-34211HIGH
Risk: 50.42/100

SandboxJS: Stack overflow DoS via deeply nested expressions in recursive descent parser

Published Apr 3, 2026
GHSA-wpc6-37g7-8q4w

OpenClaw: Shell init-file options could satisfy exec allowlist script matching

Published Apr 7, 2026
CVE-2026-34825
Risk: 0.01/100

NocoBase Has SQL Injection via template variable substitution in workflow SQL node

Published Apr 1, 2026
CVE-2026-32898

OpenClaw ACP client has permission auto-approval bypass via untrusted tool metadata

Published Feb 27, 2026
CVE-2025-65964

n8n vulnerable to Remote Code Execution via Git Node Custom Pre-Commit Hook

Published Dec 8, 2025
MAL-2022-1147

Malicious code in astar-portal-test-depconf (npm)

Published Jul 25, 2022
CVE-2026-28357

NocoDB has Stored Cross-site Scripting via Formula Cell

Published Mar 2, 2026
CVE-2026-31828

Parse Server vulnerable to LDAP injection via unsanitized user input in DN and group filter construction

Published Mar 11, 2026
MAL-2022-4722

Malicious code in msal-react-quickstart (npm)

Published Jun 20, 2022
MAL-2022-3234

Malicious code in fstream-package-2 (npm)

Published Jun 20, 2022
CVE-2022-24794HIGH

URL Redirection to Untrusted Site ('Open Redirect') in express-openid-connect

Published Mar 31, 2022
MAL-2022-4767

Malicious code in mynewpkgtest (npm)

Published Jun 20, 2022
MAL-2022-4808

Malicious code in netlify-testing-stuff (npm)

Published Jun 20, 2022
MAL-2022-4816

Malicious code in new-random-test (npm)

Published Jun 20, 2022
GHSA-7q64-3rg2-h9pf

Duplicate Advisory: Nest has a Fastify URL Encoding Middleware Bypass

Published Feb 27, 2026
GHSA-7q9x-8g6p-3x75

@grackle-ai/server: Unescaped Error String in renderPairingPage() HTML Template

Published Mar 25, 2026
CVE-2022-29229MEDIUM

Missing Cryptographic Step in cassproject

Published May 25, 2022
CVE-2024-36287LOW

Mattermost Desktop App allows for bypassing TCC restrictions on macOS

Published Jun 14, 2024
MAL-2022-5559

Malicious code in qs-state-visualizer (npm)

Published Jun 20, 2022
CVE-2026-27903

minimatch has ReDoS: matchOne() combinatorial backtracking via multiple non-adjacent GLOBSTAR segments

Published Feb 26, 2026
MAL-2022-4127

Malicious code in kbrstore (npm)

Published Jun 13, 2022
MAL-2022-1329

Malicious code in azure-eventhubs-checkpointstore-blob (npm)

Published Jun 20, 2022
MAL-2022-4172

Malicious code in kiota-abstractions (npm)

Published Jun 20, 2022
CVE-2026-33624

Parse Server: MFA recovery code single-use bypass via concurrent requests

Published Mar 24, 2026
CVE-2026-32308

OneUptime: Stored XSS via Mermaid Diagram Rendering (securityLevel: "loose")

Published Mar 13, 2026
MAL-2022-4322

Malicious code in list-images (npm)

Published Jul 21, 2022
MAL-2022-1132

Malicious code in ashion-ingest (npm)

Published Jun 20, 2022
GHSA-7rx3-28cr-v5wh

Handlebars.js has a Prototype Method Access Control Gap via Missing __lookupSetter__ Blocklist Entry

Published Mar 29, 2026
CVE-2017-16084HIGH

Directory Traversal in list-n-stream

Published Jul 24, 2018
GHSA-247c-9743-5963

Fastify has a Body Schema Validation Bypass via Leading Space in Content-Type Header

Published Apr 15, 2026
CVE-2026-28481

OpenClaw MS Teams inbound attachment downloader leaks bearer tokens to allowlisted suffix domains

Published Feb 17, 2026
GHSA-2f7j-rp58-mr42

OpenClaw: Gateway hello snapshots exposed host config and state paths to non-admin clients

Published Apr 7, 2026
CVE-2017-16029HIGH

Directory Traversal in hostr

Published Nov 9, 2018
MAL-2022-1374

Malicious code in azure-schema-registry-ts (npm)

Published Jun 20, 2022
GHSA-xrgv-34cc-q765

Duplicate Advisory: OpenClaw's system.run allowlist bypass via shell line-continuation command substitution

Published Mar 19, 2026
MAL-2022-1369

Malicious code in azure-schema-registry (npm)

Published Jun 20, 2022
CVE-2021-39134HIGH

@npmcli/arborist vulnerable to UNIX Symbolic Link (Symlink) Following

Published Aug 31, 2021
CVE-2017-16026MEDIUM

Remote Memory Exposure in request

Published Nov 9, 2018
MAL-2022-6311

Malicious code in storage-file-datalake (npm)

Published Jun 20, 2022
MAL-2022-6057

Malicious code in sfdc-stream (npm)

Published Jun 20, 2022
CVE-2023-22621HIGH

Strapi plugins vulnerable to Server-Side Template Injection and Remote Code Execution in the Users-Permissions Plugin

Published Apr 19, 2023
MAL-2022-6327

Malicious code in strip-json-combmentd (npm)

Published Aug 19, 2022
MAL-2022-1433

Malicious code in babelpreset4stag3 (npm)

Published Aug 19, 2022
MAL-2022-4663

Malicious code in modernizr-custom (npm)

Published Jun 20, 2022
MAL-2022-6215

Malicious code in son-stringiy-safe (npm)

Published Aug 19, 2022
MAL-2022-6192

Malicious code in sncicd-tests-run (npm)

Published Jun 20, 2022
GHSA-2mc2-g238-722j

OpenClaw affected by iMessage remote attachment SCP hardening (strict host-key checks and remoteHost validation)

Published Mar 3, 2026
CVE-2026-24047

@backstage/cli-common has a possible `resolveSafeChildPath` Symlink Chain Bypass

Published Jan 21, 2026
CVE-2025-25289

@octokit/request-error has a Regular Expression in index that Leads to ReDoS Vulnerability Due to Catastrophic Backtracking

Published Feb 14, 2025
MAL-2022-163

Malicious code in @calcalist/fetlife-assets (npm)

Published Jun 20, 2022
CVE-2026-32029

OpenClaw improperly parses X-Forwarded-For behind trusted proxies allows client IP spoofing in security decisions

Published Mar 3, 2026
CVE-2026-33864

Convict has Prototype Pollution via startsWith() function

Published Mar 26, 2026
MAL-2022-1148

Malicious code in astrajs (npm)

Published Jun 20, 2022
MAL-2022-1595

Malicious code in bitpay-rest-client (npm)

Published Jun 20, 2022
MAL-2022-6529

Malicious code in testpkgabc (npm)

Published Jun 20, 2022
MAL-2022-6470

Malicious code in test-code-012111 (npm)

Published Jun 20, 2022
MAL-2022-667

Malicious code in @transaction-history/ui-components (npm)

Published Jun 13, 2022
MAL-2022-4768

Malicious code in mynewpkgtest1 (npm)

Published Jun 20, 2022
MAL-2022-1714

Malicious code in buffer-auth-test (npm)

Published Jun 20, 2022
MAL-2022-6492

Malicious code in test-rule-package (npm)

Published Jun 20, 2022
MAL-2022-6493

Malicious code in test-task-react-client (npm)

Published Jun 20, 2022
MAL-2022-105

Malicious code in @azure-tests/perf-keyvault-keys (npm)

Published Jun 20, 2022
MAL-2022-6524

Malicious code in testingx (npm)

Published May 16, 2022
MAL-2022-1077

Malicious code in apth-exists (npm)

Published Aug 19, 2022
MAL-2022-1085

Malicious code in argo-hosting-api (npm)

Published May 31, 2022
CVE-2026-25631

n8n's domain allowlist bypass enables credential exfiltration

Published Feb 4, 2026
MAL-2022-1200

Malicious code in aws-ms-deploy-assistant (npm)

Published Jun 20, 2022
MAL-2022-1288

Malicious code in azure-arm-storagecache-samples-js (npm)

Published Jun 20, 2022
MAL-2022-1289

Malicious code in azure-arm-storageimportexport-samples-js (npm)

Published Jun 20, 2022
MAL-2022-1290

Malicious code in azure-arm-storageimportexport-samples-ts (npm)

Published Jun 20, 2022
MAL-2022-5075

Malicious code in one-question-survey (npm)

Published Jun 20, 2022
MAL-2022-6996

Malicious code in vue-test-utils-mic (npm)

Published Jul 26, 2022
CVE-2020-26291MEDIUM

Hostname spoofing via backslashes in URL

Published Dec 30, 2020
MAL-2022-1928

Malicious code in clientlib-manifests (npm)

Published Jun 20, 2022
MAL-2022-5212

Malicious code in parcel-plugin-test (npm)

Published Jun 20, 2022
MAL-2022-1733

Malicious code in buy-button-storefront (npm)

Published Jun 20, 2022
MAL-2022-1295

Malicious code in azure-arm-visualstudio-samples-js-beta (npm)

Published Jun 20, 2022
CVE-2021-46440HIGH

Insecure password handling vulnerability in Strapi

Published May 4, 2022
MAL-2022-1990

Malicious code in coldstone-helpers (npm)

Published May 16, 2022
MAL-2022-1377

Malicious code in azure-storage-blob (npm)

Published Jun 20, 2022
MAL-2022-612

Malicious code in @status-waku-voting/contracts (npm)

Published Jun 20, 2022
MAL-2022-1381

Malicious code in azure-storage-file-datalake-samples-ts (npm)

Published Jun 20, 2022
MAL-2022-1382

Malicious code in azure-storage-file-share (npm)

Published Jun 20, 2022
MAL-2022-2213

Malicious code in country-nationality-list (npm)

Published Jun 20, 2022
CVE-2026-25536

@modelcontextprotocol/sdk has cross-client data leak via shared server/transport instance reuse

Published Feb 4, 2026
GHSA-86jj-29wc-7q2w

Duplicate Advisory: OpenClaw's Signal reaction-only status events could, in limited cases, be enqueued before access checks

Published Mar 21, 2026
MAL-2022-6322

Malicious code in strapi-provider-upload-aws-s3-auth (npm)

Published Jun 20, 2022
MAL-2022-2091

Malicious code in com.unity.modules.unitywebrequesttexture (npm)

Published Jun 20, 2022
MAL-2022-1629

Malicious code in bluejeans-api-rest-meetings (npm)

Published Jun 20, 2022
MAL-2022-2933

Malicious code in ext-iconv-test (npm)

Published Jun 20, 2022
MAL-2022-2961

Malicious code in facebook-nodejs-business-sdk-tests (npm)

Published Jun 20, 2022
MAL-2022-6323

Malicious code in streamer-market-dashboard (npm)

Published Jun 20, 2022
MAL-2022-6913

Malicious code in vhustlcfimgkwyzq (npm)

Published Jul 11, 2022
CVE-2023-32325MEDIUM

Potential for cross-site scripting in PostHog-js

Published May 22, 2023
GHSA-877v-w3f5-3pcq

OpenClaw: Feishu thread history and quoted messages bypass sender allowlist

Published Apr 2, 2026
MAL-2022-1899

Malicious code in chnifdwmostgqvyp (npm)

Published Jul 11, 2022
MAL-2022-6496

Malicious code in test2_11931193 (npm)

Published Jun 20, 2022
CVE-2026-33036

fast-xml-parser affected by numeric entity expansion bypassing all entity expansion limits (incomplete fix for CVE-2026-26278)

Published Mar 17, 2026
MAL-2022-6490

Malicious code in test-proj-for-myself (npm)

Published Jun 20, 2022
MAL-2022-2169

Malicious code in container-registry (npm)

Published Jun 20, 2022
MAL-2022-6516

Malicious code in testfromauro (npm)

Published Jun 20, 2022
GHSA-353c-v8x9-v7c3

MCP-Framework: Unbounded memory allocation in readRequestBody allows denial of service via HTTP transport

Published Apr 16, 2026
CVE-2026-32028

OpenClaw: Discord DM reaction ingress missed dmPolicy/allowFrom checks in restricted setups

Published Mar 3, 2026
MAL-2022-6522

Malicious code in testingpp (npm)

Published Jun 20, 2022
MAL-2022-6997

Malicious code in vue2-jest (npm)

Published Jun 20, 2022
CVE-2025-32395

Vite has an `server.fs.deny` bypass with an invalid `request-target`

Published Apr 11, 2025
MAL-2022-2724

Malicious code in ember-tracked-local-storag (npm)

Published Jun 20, 2022
MAL-2022-2800

Malicious code in eslint-config-mattermost (npm)

Published Jun 20, 2022
MAL-2022-2820

Malicious code in eslint-plugin-mattermost (npm)

Published Jun 20, 2022
MAL-2022-3053

Malicious code in firestore-messagebird-send-msg (npm)

Published Jun 20, 2022
MAL-2022-882

Malicious code in af-test (npm)

Published Jun 20, 2022
CVE-2021-29489HIGH

Options structure open to Cross-site Scripting if passed unfiltered

Published May 6, 2021
MAL-2022-2867

Malicious code in ethereumjstox (npm)

Published Aug 19, 2022
MAL-2022-784

Malicious code in @xvideos/test-utils (npm)

Published Jun 20, 2022
CVE-2026-34725HIGH
Risk: 41.01/100

dbgate-web: Stored XSS in applicationIcon leads to potential RCE in Electron due to unsafe renderer configuration

Published Apr 1, 2026
MAL-2022-7128

Malicious code in wfs-admin-test (npm)

Published Jun 20, 2022
MAL-2022-856

Malicious code in adiostcheusia (npm)

Published Jun 20, 2022
MAL-2023-1040

Malicious code in testhacknowz (npm)

Published Aug 1, 2023
GHSA-36cp-mh65-x882

Duplicate Advisory: OpenClaw is vulnerable to unauthenticated resource exhaustion through its voice call webhook handling

Published Apr 10, 2026
CVE-2022-39288HIGH

fastify vulnerable to denial of service via malicious Content-Type

Published Oct 11, 2022
MAL-2022-2056

Malicious code in com.unity.burst (npm)

Published Jun 20, 2022
MAL-2022-3055

Malicious code in firstloadedvideopriorityadjuster (npm)

Published Jun 20, 2022
MAL-2022-3228

Malicious code in frontend-restclient (npm)

Published Jun 20, 2022
MAL-2022-7120

Malicious code in wf-kyt-starter (npm)

Published Jun 20, 2022
MAL-2022-7121

Malicious code in wf-kyt-starter-universal (npm)

Published Jun 20, 2022
CVE-2021-3647MEDIUM

URIjs Vulnerable to Hostname spoofing via backslashes in URL

Published Jul 19, 2021
MAL-2022-3855

Malicious code in instanthangouts (npm)

Published Jun 20, 2022
CVE-2020-26256MEDIUM

Denial of service in fast-csv

Published Dec 8, 2020
MAL-2023-1352

Malicious code in zsbpwebsdktest (npm)

Published Apr 30, 2023
GHSA-8f9r-gr6r-x63q

Duplicate Advisory: OpenClaw: Feishu webhook reads and parses unauthenticated request bodies before signature validation

Published Apr 10, 2026
MAL-2023-662

Malicious code in owa-strings (npm)

Published Mar 6, 2023
CVE-2025-68458

webpack buildHttp: allowedUris allow-list bypass via URL userinfo (@) leading to build-time SSRF behavior

Published Feb 5, 2026
CVE-2026-29184

@backstage/plugin-scaffolder-backend Vulnerable to Potential Session Token Exfiltration via Log Redaction Bypass

Published Mar 5, 2026
GHSA-8rh7-6779-cjqq

OpenClaw has a CWD `.env` environment variable injection which bypasses host-env policy and allows config takeover

Published Apr 1, 2026
CVE-2017-16177HIGH

Directory Traversal in chatbyvista

Published Sep 1, 2020
CVE-2026-35515
Risk: 44.14/100

@nestjs/core Improperly Neutralizes Special Elements in Output Used by a Downstream Component ('Injection')

Published Apr 6, 2026
MAL-2022-2813

Malicious code in eslint-plugin-elastic-charts (npm)

Published Jun 20, 2022
MAL-2022-3056

Malicious code in firstrunwizard (npm)

Published Jun 20, 2022
CVE-2015-9240HIGH

Authentication Weakness in keystone

Published Jun 7, 2018
MAL-2022-4751

Malicious code in my-very-first-own-package (npm)

Published Jul 26, 2022
MAL-2022-4772

Malicious code in mynewpkgtest5 (npm)

Published Jun 20, 2022
GHSA-3c7f-5hgj-h279

n8n has XSS in Chat Trigger Node through Custom CSS

Published Mar 27, 2026
MAL-2023-8244

Malicious code in arcotest1 (npm)

Published Sep 26, 2023
MAL-2022-477

Malicious code in @nothingfu/test (npm)

Published Jun 20, 2022
MAL-2022-5121

Malicious code in origami-registry-ui (npm)

Published Jun 20, 2022
MAL-2023-8410

Malicious code in discordstream (npm)

Published Oct 31, 2023
GHSA-3cw3-5vxw-g2h3

OpenClaw: CLI Remote Onboarding Persists Unauthenticated Discovery Endpoint and Exfiltrates Gateway Credentials

Published Mar 31, 2026
MAL-2022-4034

Malicious code in jive-styling-toolkit (npm)

Published Jun 20, 2022
MAL-2022-4153

Malicious code in keyvault-mock-attestation (npm)

Published Jun 20, 2022
CVE-2025-68150

Parse Server is vulnerable to Server-Side Request Forgery (SSRF) via Instagram OAuth Adapter

Published Dec 16, 2025
MAL-2023-694

Malicious code in presto-webui (npm)

Published Jul 14, 2023
MAL-2022-2088

Malicious code in com.unity.modules.unitywebrequest (npm)

Published Jun 20, 2022
MAL-2022-2089

Malicious code in com.unity.modules.unitywebrequestassetbundle (npm)

Published Jun 20, 2022
CVE-2026-31992

OpenClaw has allowlist exec-guard bypass via env -S

Published Mar 3, 2026
CVE-2022-41919MEDIUM

Fastify: Incorrect Content-Type parsing can lead to CSRF attack

Published Nov 21, 2022
MAL-2022-765

Malicious code in @xvideos/install (npm)

Published Jun 20, 2022
MAL-2023-7992

Malicious code in pingserver-test.01 (npm)

Published Sep 3, 2023
MAL-2024-10401

Malicious code in puppeteerrequestinterceptor (npm)

Published Nov 5, 2024
MAL-2022-213

Malicious code in @dsgn-sys/editor-elements-design-systems (npm)

Published Jun 20, 2022
MAL-2023-800

Malicious code in speedtestsolo (npm)

Published Jan 18, 2023
MAL-2023-8009

Malicious code in ajaxmanager-custom (npm)

Published Apr 17, 2023
MAL-2024-10673

Malicious code in lightweight-store (npm)

Published Nov 13, 2024
CVE-2026-22704

HAXcms Has Stored XSS Vulnerability that May Lead to Account Takeover

Published Jan 13, 2026
MAL-2022-4305

Malicious code in lido-dao-test-dp (npm)

Published Jul 25, 2022
MAL-2022-4941

Malicious code in npm-test-bravol33 (npm)

Published Jun 20, 2022
MAL-2022-2165

Malicious code in constant-unifi (npm)

Published Jun 20, 2022
CVE-2026-26317

OpenClaw affected by cross-site request forgery (CSRF) through loopback browser mutation endpoints

Published Feb 18, 2026
MAL-2022-4356

Malicious code in lodaschisstring (npm)

Published Aug 19, 2022
MAL-2023-8097

Malicious code in purplebricks-administration (npm)

Published Sep 13, 2023
MAL-2024-10924

Malicious code in dl-testes (npm)

Published Nov 25, 2024
MAL-2022-5012

Malicious code in oci-console-navigation-registry (npm)

Published Jun 20, 2022
MAL-2023-813

Malicious code in statfacepy (npm)

Published Jan 30, 2023
MAL-2024-10658

Malicious code in eslint-plugin-foody-custom (npm)

Published Nov 13, 2024
CVE-2026-22178

OpenClaw has ReDoS and regex injection via unescaped Feishu mention metadata in RegExp construction

Published Mar 2, 2026
MAL-2022-5338

Malicious code in pingone-angular-registration (npm)

Published Jun 20, 2022
MAL-2022-6221

Malicious code in sovryn-node-integration-tests (npm)

Published Jun 20, 2022
CVE-2017-16134HIGH

Directory Traversal in http_static_simple

Published Jul 23, 2018
MAL-2023-853

Malicious code in testben (npm)

Published Feb 6, 2023
CVE-2026-26326

OpenClaw skills.status could leak secrets to operator.read clients

Published Feb 17, 2026
MAL-2023-1029

Malicious code in bluehost-wordpress-plugin (npm)

Published Aug 1, 2023
MAL-2023-940

Malicious code in visual_studio_1_37_1_crack_top_activation_key_latest_2019_win_mac__2rl (npm)

Published May 9, 2023
MAL-2024-11222

Malicious code in prettier-v3-for-testing (npm)

Published Dec 6, 2024
GHSA-3p2x-hjxj-c7rv

Duplicate Advisory: OpenClaw's system.run approval TOCTOU via mutable symlink cwd target on node host

Published Mar 21, 2026
CVE-2021-41167HIGH

modern-async's `forEachSeries` and `forEachLimit` functions do not limit the number of requests

Published Oct 21, 2021
MAL-2024-11230

Malicious code in testing-bounty123 (npm)

Published Dec 7, 2024
GHSA-3prp-9gf7-4rxx

Flowise: Mass Assignment in DocumentStore Create Endpoint Leads to Cross-Workspace Object Takeover (IDOR)

Published Apr 17, 2026
GHSA-3pw3-v88x-xj24

Paperclip: Arbitrary File Read via Agent-Controlled adapterConfig.instructionsFilePath

Published Apr 16, 2026
MAL-2022-5084

Malicious code in ood-listener (npm)

Published Aug 19, 2022
MAL-2024-1125

Malicious code in sqltest6 (npm)

Published Mar 18, 2024
MAL-2023-1493

Malicious code in postman-zendesk-support-theme (npm)

Published Aug 19, 2023
MAL-2022-467

Malicious code in @nexthink/investigations-components (npm)

Published Oct 19, 2022
MAL-2024-3831

Malicious code in vrt_hitlijst_generic_voting (npm)

Published Jun 25, 2024
MAL-2024-3834

Malicious code in vscode-ui5-language-assistant (npm)

Published Jun 25, 2024
MAL-2022-5564

Malicious code in quewynstring (npm)

Published Aug 19, 2022
MAL-2022-2364

Malicious code in dbabelpreetstage1 (npm)

Published Aug 19, 2022
MAL-2022-4698

Malicious code in mostly-harmless (npm)

Published Jun 20, 2022
MAL-2022-5296

Malicious code in perf-storage-file-share (npm)

Published Jun 20, 2022
MAL-2024-10755

Malicious code in marketing-jest-cli (npm)

Published Nov 14, 2024
MAL-2022-2679

Malicious code in eg-clickstream-sdk-js (npm)

Published Jun 8, 2022
MAL-2024-1116

Malicious code in custom-banner-react (npm)

Published Mar 18, 2024
MAL-2022-480

Malicious code in @omega-tracker/omg-abstract-strategy-plugin (npm)

Published Jun 20, 2022
MAL-2022-2934

Malicious code in ext-iconv-test-3 (npm)

Published Jun 20, 2022
MAL-2024-10571

Malicious code in testing-logger-bush1do-c0de (npm)

Published Nov 8, 2024
CVE-2024-48460

Eugeny Tabby Sends Password Despite Host Key Verification Failure

Published Jan 17, 2025
MAL-2023-8415

Malicious code in bonded-stablecoin (npm)

Published Nov 1, 2023
MAL-2023-8420

Malicious code in astar-portal (npm)

Published Nov 2, 2023
MAL-2022-4819

Malicious code in newhistory (npm)

Published Jun 20, 2022
MAL-2022-3000

Malicious code in federalist-uswds-jekyll (npm)

Published Jun 20, 2022
MAL-2022-5735

Malicious code in registrydependency1 (npm)

Published Jun 20, 2022
MAL-2022-594

Malicious code in @smartsteuer/solo-vue-heroicons (npm)

Published Jun 20, 2022
MAL-2023-316

Malicious code in eumetcast-gluing (npm)

Published Jan 30, 2023
MAL-2024-7427

Malicious code in brightspot-styleguide (npm)

Published Jul 8, 2024
GHSA-8wj8-cfxr-9374

AWS Advanced NodeJS Wrapper: Privilege Escalation in Aurora PostgreSQL instance

Published Nov 13, 2025
GHSA-92pp-h63x-v22m

@hono/node-server: Middleware bypass via repeated slashes in serveStatic

Published Apr 8, 2026
MAL-2022-2844

Malicious code in eslintpwuginjest (npm)

Published Aug 19, 2022
MAL-2024-11018

Malicious code in web_enhance_sap-stable (npm)

Published Nov 27, 2024
MAL-2022-2897

Malicious code in everest-contracts (npm)

Published Jun 20, 2022
MAL-2022-2901

Malicious code in evil-test-1 (npm)

Published Jun 20, 2022
MAL-2024-75

Malicious code in lwc-jest-serializer (npm)

Published Jan 11, 2024
MAL-2022-6467

Malicious code in test-code-012 (npm)

Published Jun 20, 2022
MAL-2022-6504

Malicious code in test_1_59 (npm)

Published Oct 24, 2022
MAL-2022-4949

Malicious code in npmupload_test-xxxxxxxxxxxxx (npm)

Published May 31, 2022
MAL-2022-6536

Malicious code in tetstetegg (npm)

Published Sep 13, 2022
GHSA-42mx-vp8m-j7qh

OpenClaw: OpenShell `mirror` mode can convert untrusted sandbox files into explicitly enabled workspace hooks and execute them on the host during gateway startup

Published Apr 7, 2026
MAL-2024-1311

Malicious code in vue2-amis-custom-widget-kk (npm)

Published Apr 30, 2024
MAL-2024-7756

Malicious code in moto-test-int (npm)

Published Jul 15, 2024
MAL-2024-7759

Malicious code in zonduutest (npm)

Published Jul 16, 2024
MAL-2022-3441

Malicious code in gradient-stringss (npm)

Published Jun 20, 2022
MAL-2022-6739

Malicious code in ufx-lib-wrk-state (npm)

Published Jun 20, 2022
CVE-2026-32728

Parse Server has a stored XSS filter bypass via Content-Type MIME parameter and missing XML extension blocklist entries

Published Mar 16, 2026
CVE-2021-23362MEDIUM

Regular Expression Denial of Service in hosted-git-info

Published May 6, 2021
CVE-2026-4603

jsrsasign: Division by Zero Allows Invalid JWK Modulus to Cause Deterministic Zero Output in RSA Operations

Published Mar 23, 2026
MAL-2022-3652

Malicious code in hoisting-peer-check-child (npm)

Published Sep 13, 2022
MAL-2023-529

Malicious code in instant_verb_tables_roxanne_burns_pdf___hot___uy4 (npm)

Published May 9, 2023
MAL-2024-1676

Malicious code in world-id-onchain-starter (npm)

Published Jun 27, 2024
CVE-2026-24766

NocoDB has Prototype Pollution in Connection Test Endpoint, Leading to DoS

Published Jan 28, 2026
MAL-2023-549

Malicious code in karma-jasmine-i-request (npm)

Published Jan 30, 2023
MAL-2024-12032

Malicious code in reftest-helper (npm)

Published Dec 19, 2024
MAL-2024-8230

Malicious code in @diotoborg/distinctio-quaerat (npm)

Published Sep 2, 2024
CVE-2026-31996

OpenClaw safeBins stdin-only bypass via sort output and recursive grep flags

Published Feb 19, 2026
CVE-2026-33226

Budibase Unrestricted Server-Side Request Forgery (SSRF) via REST Datasource Query Preview

Published Mar 18, 2026
CVE-2026-33532

yaml is vulnerable to Stack Overflow via deeply nested YAML collections

Published Mar 25, 2026
MAL-2024-8283

Malicious code in @diotoborg/eligendi-est-unde (npm)

Published Sep 2, 2024
MAL-2024-8285

Malicious code in @diotoborg/enim-molestias (npm)

Published Sep 2, 2024
MAL-2022-3817

Malicious code in infrastructure_skypefeedback_tools (npm)

Published Jun 20, 2022
GHSA-98ch-45wp-ch47

OpenClaw: Windows-compatible env override keys could bypass system.run approval binding

Published Apr 7, 2026
GHSA-49cg-279w-m73x

OpenClaw: Empty approver lists could grant explicit approval authorization

Published Apr 17, 2026
CVE-2024-23724CRITICAL

Ghost has possible Cross-site Scripting issue

Published Feb 11, 2024
MAL-2024-8307

Malicious code in @diotoborg/eum-nostrum (npm)

Published Sep 2, 2024
MAL-2022-5297

Malicious code in perf-storage-file-share-track-1 (npm)

Published Jun 20, 2022
MAL-2022-7391

Malicious code in zilliqa-testing-library (npm)

Published Jun 20, 2022
GHSA-f7fh-qg34-x2xh

OpenClaw: CDP /json/version WebSocket URL could pivot to untrusted second-hop targets

Published Apr 17, 2026
GHSA-f934-5rqf-xx47

OpenClaw: QMD memory_get restricts reads to canonical or indexed memory paths

Published Apr 17, 2026
CVE-2025-66400

mdast-util-to-hast has unsanitized class attribute

Published Dec 2, 2025
MAL-2023-211

Malicious code in crack_vialibera_gestione_contabile_free__qls (npm)

Published May 9, 2023
MAL-2023-215

Malicious code in criteo-static-variables-datasource (npm)

Published Jun 24, 2023
MAL-2022-4262

Malicious code in launcher-start-page (npm)

Published Jun 20, 2022
MAL-2024-8466

Malicious code in @diotoborg/nisi-molestiae (npm)

Published Sep 2, 2024
GHSA-4g5x-2jfc-xm98

OpenClaw: Tlon media downloads can bypass core safety limits and exhaust disk

Published Apr 7, 2026
MAL-2022-6223

Malicious code in sp-bootstrap (npm)

Published Jun 13, 2022
MAL-2022-6326

Malicious code in stringjs_lib (npm)

Published Jul 26, 2022
MAL-2024-8875

Malicious code in rust-functions (npm)

Published Sep 16, 2024
MAL-2023-8077

Malicious code in testingsomethingforscanner (npm)

Published Sep 11, 2023
MAL-2024-8877

Malicious code in afe-host-client (npm)

Published Sep 16, 2024
MAL-2024-8878

Malicious code in awsspeedtest (npm)

Published Sep 16, 2024
MAL-2024-8885

Malicious code in stedi-integrations (npm)

Published Sep 17, 2024
MAL-2022-4627

Malicious code in mitui-util-bootstrap (npm)

Published Jun 20, 2022
MAL-2023-1032

Malicious code in eslint-config-scp-custom-rules (npm)

Published Aug 1, 2023
MAL-2023-1033

Malicious code in eslint-plugin-scp-custom-rules (npm)

Published Aug 1, 2023
CVE-2020-28168MEDIUM

Axios vulnerable to Server-Side Request Forgery

Published Jan 4, 2021
CVE-2020-26288HIGH

Parse Server stores password in plain text

Published Dec 28, 2020
GHSA-4w7m-58cg-cmff

OpenClaw: Leaf subagents could steer sibling sessions across sandbox boundaries

Published Mar 13, 2026
MAL-2023-1039

Malicious code in storyblok-bridge (npm)

Published Aug 1, 2023
MAL-2023-1070

Malicious code in @freestarcapital/collector-pipeline (npm)

Published Aug 9, 2023
GHSA-8g75-q649-6pv6

OpenClaw's system.run approvals did not bind mutable script operands across approval and execution

Published Mar 12, 2026
GHSA-fwjq-xwfj-gv75

OpenClaw: `session_status` still bypasses configured `tools.sessions.visibility` for unsandboxed invocations

Published Apr 7, 2026
GHSA-527m-976r-jf79

OpenClaw: Existing-session browser interaction routes bypassed SSRF policy enforcement

Published Apr 17, 2026
CVE-2017-16152HIGH

Directory Traversal in static-html-server

Published Jul 23, 2018
CVE-2020-8205HIGH

Server-Side Request Forgery in @uppy/companion

Published Aug 13, 2020
MAL-2024-7718

Malicious code in stylesheeet (npm)

Published Jul 11, 2024
MAL-2022-4469

Malicious code in malicious-pre-install-package (npm)

Published May 31, 2022
CVE-2026-30827

express-rate-limit: IPv4-mapped IPv6 addresses bypass per-client rate limiting on servers with dual-stack network

Published Mar 6, 2026
MAL-2022-6508

Malicious code in testapp00009 (npm)

Published May 17, 2022
MAL-2022-4769

Malicious code in mynewpkgtest2 (npm)

Published Jun 20, 2022
MAL-2022-6509

Malicious code in testdir12345 (npm)

Published Sep 21, 2022
MAL-2022-4472

Malicious code in manualtestapp (npm)

Published Jun 20, 2022
MAL-2022-4771

Malicious code in mynewpkgtest4 (npm)

Published Jun 20, 2022
MAL-2022-6520

Malicious code in testing-npm-random (npm)

Published Jun 20, 2022
MAL-2024-7916

Malicious code in @incisive/rvtestmodule (npm)

Published Aug 7, 2024
CVE-2026-22814

Mass Assignment in AdonisJS Lucid Allows Overwriting Internal ORM State

Published Jan 13, 2026
MAL-2024-9458

Malicious code in monday-react-quickstart-app (npm)

Published Oct 22, 2024
CVE-2023-40028MEDIUM

Ghost vulnerable to arbitrary file read via symlinks in content import

Published Aug 15, 2023
MAL-2022-684

Malicious code in @uc-maps/test (npm)

Published Jun 20, 2022
MAL-2023-8342

Malicious code in onno-missing-2023-full-movies-at-home-streamnig (npm)

Published Oct 13, 2023
MAL-2024-7962

Malicious code in incisive_testing_stuffasdasdasd (npm)

Published Aug 7, 2024
MAL-2023-8373

Malicious code in @bitsoex/react-design-system (npm)

Published Oct 13, 2023
CVE-2025-13321

Mattermost Desktop App exposes sensitive information in its application logs

Published Dec 17, 2025
MAL-2023-276

Malicious code in dow-load-get-your-sht-together-how-to-stop-worrying-about-what-you-should-do-so-you-can-fi (npm)

Published May 10, 2023
Check your entire dependency tree at onceRun dependency scan →