All 5 CVE vulnerabilities found in crabbox, with AI-generated Chinese analysis, references, and POCs.
Vendor: openclaw
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-8634 | Crabbox < v0.12.0 Environment Variable Information Disclosure CWE-94 | 9.1 | Critical | 2026-05-14 |
| CVE-2026-8629 | Crabbox < v0.12.0 Privilege Escalation via Agent Ticket Endpoints CWE-639 | 8.1 | High | 2026-05-14 |
| CVE-2026-8621 | Crabbox < v0.12.0 Authentication Bypass via Header Spoofing CWE-287 | 8.8 | High | 2026-05-14 |
| CVE-2026-45224 | Crabbox < 0.9.0 Path Traversal via Islo Provider Workspace Resolution CWE-22 | 7.1 | High | 2026-05-11 |
| CVE-2026-45223 | Crabbox < 0.9.0 Authentication Bypass via Admin Claim Injection CWE-290 | 8.8 | High | 2026-05-11 |
All 5 known CVE vulnerabilities affecting crabbox with full Chinese analysis, references, and POCs where available.