AgentGGAgentGG
Security research

Security Advisories

Vulnerabilities discovered by AgentGG agents in open source projects, disclosed responsibly: maintainers are notified privately and details publish once a fix ships. Unpublished accepted findings show as TBD; published entries link to the official GitHub advisory.

The agents find far more than we can triage and report ourselves. Our mission is to put the same tool in every maintainer's hands, so open source projects can secure their own code.

IDProjectAdvisoryTypeSeverityCVEPublished
AGG-001openclawSlack allowFrom could bind to mutable display names
GHSA-c29c-2q9c-pc86
Auth bypass (CWE-290)HighReservedMay 28, 2026
AGG-002openclawDiscord allowFrom could bind to mutable display names
GHSA-cw4q-gqg5-g38h
Auth bypass (CWE-290)HighCVE-2026-53849May 28, 2026
AGG-003openclawMatrix allowFrom could bind to mutable display names
GHSA-7hxm-f538-3xp6
Auth bypass (CWE-290)HighCVE-2026-53811May 28, 2026
AGG-004openclawZalo allowFrom could bind to mutable display names
GHSA-8c59-hr4w-qg69
Auth bypass (CWE-290)HighCVE-2026-53857May 28, 2026
AGG-005openclawMS Teams allowFrom could bind to mutable display names
GHSA-7w4v-g4m6-j88v
Auth bypass (CWE-290)ModerateReservedJun 30, 2026
AGG-006MapServerReflected XSS via unescaped offset/limit params in OGC API HTML output
GHSA-288j-mhpj-gmmr
Reflected XSS (CWE-79)ModerateReservedJul 10, 2026
AGG-007DirectusStored XSS via unsanitized project color in the generated favicon
GHSA-788p-cvgf-q973
Stored XSS (CWE-79)ModerateReservedAug 5, 2026
AGG-008QGISStored XSS in WFS3 getFeatures HTML page via unescaped feature attribute values
GHSA-cr49-pm9v-m788
Stored XSS (CWE-79)ModerateReservedAug 11, 2026
AGG-009QGISTBDTBDCriticalTBDTBD
AGG-010GeoNetworkTBDTBDCriticalTBDTBD
AGG-011GeoNetworkTBDTBDCriticalTBDTBD
AGG-012GeoNetworkTBDTBDCriticalTBDTBD
AGG-013GeoNetworkTBDTBDHighTBDTBD
AGG-014GeoNetworkTBDTBDHighTBDTBD
AGG-015GeoServerTBDTBDHighTBDTBD
AGG-016ZOO-ProjectTBDTBDCriticalTBDTBD
AGG-017ZOO-ProjectTBDTBDCriticalTBDTBD
AGG-018NocoDBTBDTBDHighTBDTBD
AGG-019GeoToolsTBDTBDCriticalTBDTBD

TBD rows are accepted by the maintainers and publish as fixes ship; hundreds more findings are in triage behind them.

The same agents can patrol your codebase.

Everything on this page was found by the open source agent catalog. The platform goes further: your past security issues become custom agents that scan every repo and every PR.