Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

33 advisories

Loading
consciousness-explorer / sublinear-time-solver MCP export_state has an arbitrary file write High
CVE-2026-55609 was published for consciousness-explorer (npm) Aug 25, 2026
BruceJqs Credited to BruceJqs
NocoBase: Arbitrary File Write chained with Local file Inclusion leads to Remote code execution High
GHSA-ghvf-qf6h-g8x5 was published for @nocobase/server (npm) Aug 20, 2026
lukehebe Credited to lukehebe
claude-faf-mcp has an arbitrary local file read/write via unconfined `path` argument in FAF tools High
GHSA-rr55-jp92-8wp2 was published for claude-faf-mcp (npm) Aug 19, 2026
faf-mcp has an arbitrary local file read/write via unconfined `path` argument in FAF tools High
GHSA-j4r7-8ph4-43g3 was published for faf-mcp (npm) Aug 19, 2026
grok-faf-mcp has an arbitrary local file read via unconfined `path` argument in FAF tools High
GHSA-cc2g-gq8c-r332 was published for grok-faf-mcp (npm) Aug 19, 2026
Mirr2 Credited to Mirr2
n8n: Edit Image Node Format Injection Allows Arbitrary File Write High
GHSA-xmc9-4f2h-jf9c was published for n8n (npm) Jul 22, 2026
simonkoeck Credited to simonkoeck
pnpm: `patch-remove` could delete project-selected files outside the patches directory High
GHSA-72r4-9c5j-mj57 was published for pnpm (npm) Jun 27, 2026
pnpm: Hoisted install imports lockfile alias outside node_modules High
GHSA-fr4h-3cph-29xv was published for pnpm (npm) Jun 27, 2026
pnpm: Reserved bin name deletes PNPM_HOME during global remove Moderate
CVE-2026-55699 was published for pnpm (npm) Jun 26, 2026
Network-AI: Poisoned environment backup manifest allows arbitrary recursive deletion during backup pruning High
GHSA-2fmp-9rvw-hc96 was published for network-ai (npm) Jun 19, 2026
sondt99 Credited to sondt99
launch-editor: NTLMv2 hash disclosure via UNC path handling on Windows Moderate
CVE-2026-53632 was published for launch-editor (npm) Jun 15, 2026
RubenHoms Credited to RubenHoms, toxyl, and bluwy toxyl toxyl
bluwy bluwy
offset Credited to offset
i18next-fs-backend: Path traversal via unsanitised lng/ns allows arbitrary file read/overwrite High
CVE-2026-41693 was published for i18next-fs-backend (npm) Apr 22, 2026
Duplicate Advisory: OpenClaw: Webchat media embedding enforces local-root containment for tool-result files Moderate
GHSA-qc5j-2mqx-x83q was published for openclaw (npm) Apr 20, 2026 withdrawn
OpenClaw: Webchat media embedding enforces local-root containment for tool-result files Moderate
CVE-2026-41389 was published for openclaw (npm) Apr 17, 2026
Kherrisan Credited to Kherrisan
Paperclip: Arbitrary File Read via Agent-Controlled adapterConfig.instructionsFilePath Moderate
GHSA-3pw3-v88x-xj24 was published for @paperclipai/shared (npm) Apr 16, 2026
lilmingwa13 Credited to lilmingwa13
threalwinky Credited to threalwinky
maru1009 Credited to maru1009
@tinacms/graphql has Path Traversal that leads to overwrite of arbitrary files High
CVE-2026-33949 was published for @tinacms/graphql (npm) Mar 30, 2026
aarjubh Credited to aarjubh
@mobilenext/mobile-mcp alllows arbitrary file write via Path Traversal in mobile screen capture tools High
CVE-2026-33989 was published for @mobilenext/mobile-mcp (npm) Mar 27, 2026
AbhiTheModder Credited to AbhiTheModder
OpenClaw hardened the skill download target directory validation Moderate
CVE-2026-27008 was published for openclaw (npm) Feb 18, 2026
Adam55A-code Credited to Adam55A-code
OpenClaw has an arbitrary transcript path file write via gateway sessionFile High
CVE-2026-28459 was published for openclaw (npm) Feb 17, 2026
tubadeligoz Credited to tubadeligoz
ProTip! Advisories are also available from the GraphQL API