Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%
Vulnerability List
Found 341 results
CVE IDTitleVendorProductSeverityCVSS ScorePublished AtAI Analysis
CVE-2026-32060 OpenClaw < 2026.2.14 - Path Traversal in apply_patch via Crafted Paths openclawopenclaw High 8.8 2026-03-11 13:32:34 Deep Dive
CVE-2026-32059 OpenClaw 2026.2.22-2 < 2026.2.23 - Allowlist Bypass via sort Long-Option Abbreviation in tools.exec.safeBins openclawopenclaw High 8.8 2026-03-11 13:32:32 Deep Dive
CVE-2026-29612 OpenClaw < 2026.2.14 - Denial of Service via Large Base64 Media File Decoding OpenClawOpenClaw Medium 5.5 2026-03-05 22:00:11 Deep Dive
CVE-2026-29613 OpenClaw < 2026.2.12 - Webhook Authentication Bypass via Loopback remoteAddress Trust OpenClawOpenClaw Medium 5.9 2026-03-05 22:00:11 Deep Dive
CVE-2026-29611 OpenClaw < 2026.2.14 - Local File Inclusion via mediaPath Parameter in BlueBubbles Media Handling OpenClawOpenClaw High 7.5 2026-03-05 22:00:10 Deep Dive
CVE-2026-29610 OpenClaw < 2026.2.14 - Command Hijacking via Unsafe PATH Handling OpenClawOpenClaw High 8.8 2026-03-05 22:00:08 Deep Dive
CVE-2026-29609 OpenClaw < 2026.2.14 - Denial of Service via Unbounded URL-backed Media Fetch OpenClawOpenClaw High 7.5 2026-03-05 22:00:07 Deep Dive
CVE-2026-29606 OpenClaw < 2026.2.14 - Webhook Signature Verification Bypass via ngrok Loopback Compatibility OpenClawOpenClaw Medium 6.5 2026-03-05 22:00:06 Deep Dive
CVE-2026-28486 OpenClaw 2026.1.16-2 < 2026.2.14 - Path Traversal (Zip Slip) in Archive Extraction via Installation Commands OpenClawOpenClaw Medium 6.1 2026-03-05 22:00:03 Deep Dive
CVE-2026-28485 OpenClaw 2026.1.5 < 2026.2.12 - Missing Authentication in Browser Control HTTP Endpoints OpenClawOpenClaw High 8.4 2026-03-05 22:00:00 Deep Dive
CVE-2026-28482 OpenClaw < 2026.2.12 - Path Traversal via Unsanitized sessionId and sessionFile Parameters OpenClawOpenClaw High 7.1 2026-03-05 21:59:57 Deep Dive
CVE-2026-28480 OpenClaw < 2026.2.14 - Identity Spoofing via Mutable Username in Telegram Allowlist Authorization OpenClawOpenClaw Medium 6.5 2026-03-05 21:59:56 Deep Dive
CVE-2026-28481 OpenClaw < 2026.2.1 - Bearer Token Leakage via MS Teams Attachment Downloader Suffix Matching OpenClawOpenClaw Medium 6.5 2026-03-05 21:59:56 Deep Dive
CVE-2026-28479 OpenClaw < 2026.2.15 - Cache Poisoning via Deprecated SHA-1 Hash in Sandbox Configuration OpenClawOpenClaw High 7.5 2026-03-05 21:59:55 Deep Dive
CVE-2026-28478 OpenClaw < 2026.2.13 - Denial of Service via Unbounded Webhook Request Body Buffering OpenClawOpenClaw High 7.5 2026-03-05 21:59:54 Deep Dive
CVE-2026-28477 OpenClaw < 2026.2.14 - OAuth State Validation Bypass in Manual Chutes Login Flow OpenClawOpenClaw High 7.1 2026-03-05 21:59:53 Deep Dive
CVE-2026-28475 OpenClaw < 2026.2.13 - Timing Attack via Hook Token Comparison OpenClawOpenClaw Medium 4.8 2026-03-05 21:59:51 Deep Dive
CVE-2026-28476 OpenClaw < 2026.2.14 - Server-Side Request Forgery in Tlon Extension Authentication OpenClawOpenClaw High 8.3 2026-03-05 21:59:51 Deep Dive
CVE-2026-28474 OpenClaw Nextcloud Talk < 2026.2.6 - Allowlist Bypass via actor.name Display Name Spoofing OpenClawnextcloud-talk Critical 9.8 2026-03-05 21:59:50 Deep Dive
CVE-2026-28473 OpenClaw < 2026.2.2 - Authorization Bypass via /approve Chat Command OpenClawOpenClaw High 8.1 2026-03-05 21:59:49 Deep Dive