← All credits
KeenSecurityLab
91 vulnerability records and advisories credit this contributor.
CVE-2026-44997
OpenClaw < 2026.4.22 - Security Envelope Constraint Bypass in ACP Child Sessions
CVE-2026-44996
OpenClaw < 2026.4.15 - Arbitrary Local File Read via Webchat Audio Embedding
CVE-2026-44994
OpenClaw < 2026.4.22 - Authentication Bypass in Gateway Control UI Bootstrap Config Endpoint
CVE-2026-44993
OpenClaw < 2026.4.20 - Direct Message Misclassification in Feishu Card Actions
CVE-2026-44991
OpenClaw < 2026.4.21 - Authorization Bypass in Owner-Enforced Commands via Wildcard Channel Senders
CVE-2026-44111
OpenClaw < 2026.4.15 - Arbitrary Markdown File Read via QMD memory_get
CVE-2026-44110
OpenClaw < 2026.4.15 - Authorization Bypass in Matrix Room Control Commands via DM Pairing Store
CVE-2026-43585
OpenClaw < 2026.4.15 - Bearer Token Validation Bypass via Stale SecretRef Resolution
CVE-2026-43583
OpenClaw 2026.4.10 < 2026.4.14 - Loss of Group Tool-Policy Context in Delivery Queue Recovery
CVE-2026-43580
OpenClaw < 2026.4.10 - Incomplete Navigation Guard Coverage in Browser Interactions