Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

4 advisories

Loading
OpenClaw: QQBot reply media URL handling could trigger SSRF and re-upload fetched bytes Moderate
GHSA-2767-2q9v-9326 was published for openclaw (npm) Apr 17, 2026
threalwinky Credited to threalwinky
Ech0: Missing authorization on dashboard log endpoints allows low-privilege users to access sensitive system logs Moderate
GHSA-cp79-9mwr-wr49 was published for github.com/lin-snow/ech0 (Go) Apr 10, 2026
threalwinky Credited to threalwinky
threalwinky Credited to threalwinky
WWBN AVideo has a Live restream log callback flow enabling stored SSRF to internal services Moderate
CVE-2026-39368 was published for WWBN/AVideo (Composer) Apr 8, 2026
threalwinky Credited to threalwinky
ProTip! Advisories are also available from the GraphQL API