检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-J5QH-5234-4RQP | Duplicate Advisory: OpenClaw: Workspace plugin auto-discovery allowed code execution from cloned repositories 已撤回 | 高危 | npmopenclaw | 已审查 | 2026-03-31 20:31 | 2026-04-07 06:49 |
当前筛选结果 998 条 · 时间按北京时间显示
| GHSA-QQRV-2HCH-83Q4 |
Duplicate Advisory: Kyverno is vulnerable to server-side request forgery (SSRF) 已撤回 |
| 中危 |
Gogithub.com/kyverno/kyverno |
| 已审查 |
| 2026-03-31 05:31 |
| 2026-04-15 06:36 |
| GHSA-9Q8J-CHC7-WPGP | Duplicate Advisory: OpenClaw session transcript files were created without forced user-only permissions 已撤回 | 中危 | npmopenclaw | 已审查 | 2026-03-29 23:30 | 2026-04-07 06:46 |
| GHSA-6Q2V-VFWP-PVWH | Duplicate Advisory: OpenClaw's skills-install-download can be redirected outside the tools root by rebinding the validated base path 已撤回 | 中危 | npmopenclaw | 已审查 | 2026-03-29 23:30 | 2026-04-07 06:46 |
| GHSA-WMGJ-HRX3-23GJ | Duplicate Advisory: OpenClaw: Unbound interpreter and runtime commands could bypass node-host approval integrity 已撤回 | 高危 | npmopenclaw | 已审查 | 2026-03-29 23:30 | 2026-04-07 06:36 |
| GHSA-VJQW-W5JR-G9W5 | Duplicate Advisory: OpenClaw: Feishu webhook mode accepted forged events when only `verificationToken` was configured 已撤回 | 高危 | npmopenclaw | 已审查 | 2026-03-29 23:30 | 2026-04-07 06:32 |
| GHSA-RWWX-25M7-WW73 | Duplicate Advisory: OpenClaw: Unrecognized script runners could bypass `system.run` approval integrity 已撤回 | 严重 | npmopenclaw | 已审查 | 2026-03-29 23:30 | 2026-04-07 06:35 |
| GHSA-HH43-Q692-2XMQ | Duplicate Advisory: `OpenClaw: session_status` let sandboxed subagents access parent or sibling session state 已撤回 | 严重 | npmopenclaw | 已审查 | 2026-03-29 23:30 | 2026-04-01 08:06 |
| GHSA-C447-W54G-F55J | Duplicate Advisory: OpenClaw Telegram webhook request bodies were read before secret validation, enabling unauthenticated resource exhaustion 已撤回 | 高危 | npmopenclaw | 已审查 | 2026-03-29 23:30 | 2026-04-01 08:05 |
| GHSA-CW7V-45WM-MCF2 CVE-2026-29905 | Withdrawn Advisory: Kirby CMS has Persistent DoS via Malformed Image Upload 已撤回 | 中危 | Packagistgetkirby/cms | 已审查 | 2026-03-28 06:21 | 2026-05-01 02:33 |
| GHSA-VH4C-J2XV-9PV9 | Duplicate Advisory: OpenClaw: BlueBubbles beta plugin webhook auth hardening (remove passwordless fallback) 已撤回 | 中危 | npmopenclaw | 已审查 | 2026-03-21 11:31 | 2026-03-25 03:07 |
| GHSA-RCX4-77X4-HJX5 | Duplicate Advisory: OpenClaw ACP client has permission auto-approval bypass via untrusted tool metadata 已撤回 | 中危 | npmopenclaw | 已审查 | 2026-03-21 11:31 | 2026-03-25 03:07 |
| GHSA-G839-VP47-WGH8 | Duplicate Advisory: OpenClaw's Slack reaction/pin sender-policy consistency issue in non-message ingress 已撤回 | 中危 | npmopenclaw | 已审查 | 2026-03-21 11:31 | 2026-03-25 03:07 |
| GHSA-8MR2-F9WF-HCFQ | Duplicate Advisory: OpenClaw reuses the gateway auth token in the owner ID prompt hashing fallback 已撤回 | 低危 | npmopenclaw | 已审查 | 2026-03-21 11:31 | 2026-03-25 01:54 |
| GHSA-XH9J-MPC9-2M9P | Duplicate Advisory: OpenClaw has a Trusted-proxy Control UI pairing bypass which allows unpaired node sessions 已撤回 | 中危 | npmopenclaw | 已审查 | 2026-03-21 11:31 | 2026-03-25 03:06 |
| GHSA-XGWG-M42C-8Q62 | Duplicate Advisory: OpenClaw: Slack system events bypass sender authorization in member and message subtype handlers 已撤回 | 中危 | npmopenclaw | 已审查 | 2026-03-21 11:31 | 2026-03-25 03:06 |
| GHSA-VMVW-PWWF-CC2W | Duplicate Advisory: OpenClaw has cross-account DM pairing authorization bypass via unscoped pairing store access 已撤回 | 低危 | NuGetopenclaw | 已审查 | 2026-03-21 11:31 | 2026-03-25 03:06 |
| GHSA-RJ39-33V7-9XRQ | Duplicate Advisory: OpenClaw's shell startup env injection bypasses system.run allowlist intent (RCE class) 已撤回 | 高危 | npmopenclaw | 已审查 | 2026-03-21 11:31 | 2026-03-25 03:06 |
| GHSA-MXMG-3P7M-2GHR | Duplicate Advisory: OpenClaw: system.run approval identity mismatch could execute a different binary than displayed 已撤回 | 中危 | npmopenclaw | 已审查 | 2026-03-21 11:31 | 2026-03-25 03:07 |
| GHSA-FFR4-MRHV-VFR2 | Duplicate Advisory: OpenClaw has browser trace/download path symlink escape in temp output handling 已撤回 | 中危 | npmopenclaw | 已审查 | 2026-03-21 11:31 | 2026-03-28 04:18 |
| GHSA-CXCW-JM67-3WWP | Duplicate Advisory: OpenClaw's andbox browser noVNC observer lacked VNC authentication 已撤回 | 高危 | npmopenclaw | 已审查 | 2026-03-21 11:31 | 2026-03-25 03:06 |
| GHSA-CJQ8-M7WJ-XMQ9 | Duplicate Advisory: OpenClaw Node system.run approval context-binding weakness in approval-enabled host=node flows 已撤回 | 低危 | npmopenclaw | 已审查 | 2026-03-21 11:31 | 2026-03-25 03:06 |
| GHSA-9F79-7PW8-3FJ8 | Duplicate Advisory: OpenClaw: workspace path guard bypass on non-existent out-of-root symlink leaf 已撤回 | 高危 | npmopenclaw | 已审查 | 2026-03-21 11:31 | 2026-03-25 03:05 |
| GHSA-3R78-RQG8-95GG | Duplicate Advisory: OpenClaw's voice-call Twilio webhook replay could bypass manager dedupe because normalized event IDs were randomized per parse 已撤回 | 中危 | npmopenclaw | 已审查 | 2026-03-21 11:31 | 2026-03-25 03:05 |
| GHSA-XQ3G-M3J8-2VMM | Duplicate Advisory: OpenClaw's inbound media downloads could exceed configured byte limits before rejection across multiple channels 已撤回 | 高危 | npmopenclaw | 已审查 | 2026-03-21 11:31 | 2026-03-25 03:04 |