检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-G796-JQMX-WF9Q | Duplicate Advisory: macOS Swift exec allowlist missed combined POSIX inline flags 已撤回 | 中危 | npmopenclaw | 已审查 | 2026-06-17 05:32 | 2026-06-18 22:52 |
当前筛选结果 998 条 · 时间按北京时间显示
Duplicate Advisory: Tool group policy callers could accept unvalidated group IDs 已撤回 |
| 中危 |
npmopenclaw |
| 已审查 |
| 2026-06-17 05:32 |
| 2026-06-18 21:04 |
| GHSA-8HJ2-W4C9-FJFQ | Duplicate Advisory: BlueBubbles sender policy could match mutable conversation identifiers 已撤回 | 低危 | npmopenclaw | 已审查 | 2026-06-17 05:32 | 2026-06-19 04:32 |
| GHSA-2W22-3F6X-3HF4 | Duplicate Advisory: Workspace-derived service PATH could influence trash command selection 已撤回 | 高危 | npmopenclaw | 已审查 | 2026-06-17 05:32 | 2026-06-19 04:40 |
| GHSA-W7M7-3XCF-MP48 | Duplicate Advisory: Zalo allowFrom could bind to mutable display names 已撤回 | 高危 | npmopenclaw | 已审查 | 2026-06-17 05:31 | 2026-06-19 04:17 |
| GHSA-VQX6-6J84-2794 | Duplicate Advisory: Hostname checks could treat trailing-dot hosts inconsistently 已撤回 | 中危 | npmopenclaw | 已审查 | 2026-06-17 05:31 | 2026-06-19 04:11 |
| GHSA-VQJ9-VHG4-27MG | Duplicate Advisory: Config recovery could restore openclaw.json with broad file permissions 已撤回 | 中危 | npmopenclaw | 已审查 | 2026-06-17 05:31 | 2026-06-19 04:18 |
| GHSA-R2FX-HP6P-PGRM | Duplicate Advisory: Internal/webchat command auth could inherit ownerAllowFrom wildcard state 已撤回 | 中危 | npmopenclaw | 已审查 | 2026-06-17 05:31 | 2026-06-19 04:43 |
| GHSA-HC4W-HM59-9W88 | Duplicate Advisory: Empty-scope device re-pairing could confuse caller scope containment 已撤回 | 低危 | npmopenclaw | 已审查 | 2026-06-17 05:31 | 2026-06-19 04:42 |
| GHSA-4QGR-57JQ-93VH | Duplicate Advisory: Workspace .env STATE_DIRECTORY could influence bundled runtime dependency roots 已撤回 | 高危 | npmopenclaw | 已审查 | 2026-06-17 05:31 | 2026-06-19 04:38 |
| GHSA-3V3J-737J-7G74 | Duplicate Advisory: Linux and macOS exec allowlists skipped configured argument patterns 已撤回 | 高危 | npmopenclaw | 已审查 | 2026-06-17 05:31 | 2026-06-19 04:32 |
| GHSA-27PQ-2PH8-8X25 | Duplicate Advisory: Shell positional parameters could weaken strict inline-eval checks 已撤回 | 高危 | npmopenclaw | 已审查 | 2026-06-17 05:31 | 2026-06-19 04:11 |
| GHSA-WRR6-P5R6-474M | Duplicate Advisory: Exec allowlist could miss side effects from transparent command wrappers 已撤回 | 低危 | npmopenclaw | 已审查 | 2026-06-17 05:31 | 2026-06-19 04:10 |
| GHSA-R7VV-6763-M739 | Duplicate Advisory: Skill-command dispatch could skip before-tool-call hooks 已撤回 | 低危 | npmopenclaw | 已审查 | 2026-06-17 05:31 | 2026-06-19 04:15 |
| GHSA-QP5J-JR73-M2PW | Duplicate Advisory: Workspace .env npm_execpath could influence bundled runtime dependency install 已撤回 | 高危 | npmopenclaw | 已审查 | 2026-06-17 05:31 | 2026-06-19 04:33 |
| GHSA-P44V-RX83-VJP4 | Duplicate Advisory: Discord allowFrom could bind to mutable display names 已撤回 | 高危 | npmopenclaw | 已审查 | 2026-06-17 05:31 | 2026-06-19 04:35 |
| GHSA-GW2C-6HCG-5G52 | Duplicate Advisory: Focus command could miss controlScope enforcement 已撤回 | 中危 | npmopenclaw | 已审查 | 2026-06-17 05:31 | 2026-06-19 04:34 |
| GHSA-C8W7-9W9H-X69Q | Duplicate Advisory: Slack reaction events could ignore reaction notification settings 已撤回 | 中危 | npmopenclaw | 已审查 | 2026-06-17 05:31 | 2026-06-19 04:12 |
| GHSA-58WC-8WRV-XP9J | Duplicate Advisory: Active Memory write scope could mutate global config 已撤回 | 中危 | npmopenclaw | 已审查 | 2026-06-17 05:31 | 2026-06-19 04:14 |
| GHSA-X7CF-6GP3-Q5F8 | Duplicate Advisory: MCP Streamable HTTP redirects could forward configured custom headers to another origin 已撤回 | 中危 | PyPIopenclaw | 已审查 | 2026-06-17 05:31 | 2026-06-18 01:54 |
| GHSA-WRMQ-9FC4-GWWJ | Duplicate Advisory: Pairing-scoped device session could restore revoked node token authority 已撤回 | 高危 | npmopenclaw | 已审查 | 2026-06-17 05:31 | 2026-06-18 21:03 |
| GHSA-9FR2-P65V-GQXQ | Duplicate Advisory: Workspace .env CLOUDSDK_PYTHON could influence Gmail setup gcloud execution 已撤回 | 高危 | PyPIopenclaw | 已审查 | 2026-06-17 05:31 | 2026-06-18 21:03 |
| GHSA-6XCG-6Q43-RJ2V | Duplicate Advisory: Exported session HTML could keep unsafe markdown links 已撤回 | 低危 | npmopenclaw | 已审查 | 2026-06-17 05:31 | 2026-06-19 04:13 |
| GHSA-6JM4-83G2-35GV | Duplicate Advisory: memory-wiki shared search could miss session visibility checks 已撤回 | 中危 | npmopenclaw | 已审查 | 2026-06-17 05:31 | 2026-06-19 04:31 |
| GHSA-VG9F-Q4XH-62R4 | Duplicate Advisory: utcp-gql SSRF: CVE-2026-44661 fix not applied to the GraphQL and WebSocket plugins 已撤回 | 低危 | PyPIutcp-gql | 已审查 | 2026-06-15 11:30 | 2026-08-26 02:09 |