All 4 CVE vulnerabilities found in openclaude, with AI-generated Chinese analysis, references, and POCs.
Vendor: Gitlawb
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-90712 | Gitlawb openclaude xAI OAuth Callback xaiOAuthCallback.ts waitForCallback denial of service CWE-404 | 4.3 | Medium | 2026-09-14 |
| CVE-2026-42073 | OpenClaude's MCP OAuth Callback: State Check Bypass via error Param Leads to DoS CWE-352 | 6.5 | Medium | 2026-06-02 |
| CVE-2026-42074 | OpenClaude: Sandbox Bypass via Model-Controlled `dangerouslyDisableSandbox` Input CWE-306 | - | - | 2026-06-02 |
| CVE-2026-35570 | OpenClaude has Sandbox Bypass via Early-Exit Logic Flaw that Allows Path Traversal CWE-22 | 8.4 | High | 2026-04-20 |
All 4 known CVE vulnerabilities affecting openclaude with full Chinese analysis, references, and POCs where available.