Security research
Security Advisories
Vulnerabilities discovered by AgentGG agents in open source projects, disclosed responsibly: maintainers are notified privately and details publish once a fix ships. Unpublished accepted findings show as TBD; published entries link to the official GitHub advisory.
The agents find far more than we can triage and report ourselves. Our mission is to put the same tool in every maintainer's hands, so open source projects can secure their own code.
| ID | Project | Advisory | Type | Severity | CVE | Published |
|---|---|---|---|---|---|---|
| AGG-001 | openclaw | Slack allowFrom could bind to mutable display names GHSA-c29c-2q9c-pc86 | Auth bypass (CWE-290) | High | Reserved | May 28, 2026 |
| AGG-002 | openclaw | Discord allowFrom could bind to mutable display names GHSA-cw4q-gqg5-g38h | Auth bypass (CWE-290) | High | CVE-2026-53849 | May 28, 2026 |
| AGG-003 | openclaw | Matrix allowFrom could bind to mutable display names GHSA-7hxm-f538-3xp6 | Auth bypass (CWE-290) | High | CVE-2026-53811 | May 28, 2026 |
| AGG-004 | openclaw | Zalo allowFrom could bind to mutable display names GHSA-8c59-hr4w-qg69 | Auth bypass (CWE-290) | High | CVE-2026-53857 | May 28, 2026 |
| AGG-005 | openclaw | MS Teams allowFrom could bind to mutable display names GHSA-7w4v-g4m6-j88v | Auth bypass (CWE-290) | Moderate | Reserved | Jun 30, 2026 |
| AGG-006 | MapServer | Reflected XSS via unescaped offset/limit params in OGC API HTML output GHSA-288j-mhpj-gmmr | Reflected XSS (CWE-79) | Moderate | Reserved | Jul 10, 2026 |
| AGG-007 | Directus | Stored XSS via unsanitized project color in the generated favicon GHSA-788p-cvgf-q973 | Stored XSS (CWE-79) | Moderate | Reserved | Aug 5, 2026 |
| AGG-008 | QGIS | Stored XSS in WFS3 getFeatures HTML page via unescaped feature attribute values GHSA-cr49-pm9v-m788 | Stored XSS (CWE-79) | Moderate | Reserved | Aug 11, 2026 |
| AGG-009 | QGIS | TBD | TBD | Critical | TBD | TBD |
| AGG-010 | GeoNetwork | TBD | TBD | Critical | TBD | TBD |
| AGG-011 | GeoNetwork | TBD | TBD | Critical | TBD | TBD |
| AGG-012 | GeoNetwork | TBD | TBD | Critical | TBD | TBD |
| AGG-013 | GeoNetwork | TBD | TBD | High | TBD | TBD |
| AGG-014 | GeoNetwork | TBD | TBD | High | TBD | TBD |
| AGG-015 | GeoServer | TBD | TBD | High | TBD | TBD |
| AGG-016 | ZOO-Project | TBD | TBD | Critical | TBD | TBD |
| AGG-017 | ZOO-Project | TBD | TBD | Critical | TBD | TBD |
| AGG-018 | NocoDB | TBD | TBD | High | TBD | TBD |
| AGG-019 | GeoTools | TBD | TBD | Critical | TBD | TBD |
TBD rows are accepted by the maintainers and publish as fixes ship; hundreds more findings are in triage behind them.
The same agents can patrol your codebase.
Everything on this page was found by the open source agent catalog. The platform goes further: your past security issues become custom agents that scan every repo and every PR.