← All credits
KeenSecurityLab
91 vulnerability records and advisories credit this contributor.
CVE-2026-41403
OpenClaw < 2026.3.31 - Access Control Bypass via Proxied Remote Request Misclassification
CVE-2026-41402
OpenClaw < 2026.3.31 - Webhook Replay Cache Cross-Target messageId Scope Bypass
CVE-2026-41398
OpenClaw - Unauthorized Agent Request Dispatch via Untrusted Local-Network Pages in iOS A2UI Bridge
CVE-2026-41396
OpenClaw < 2026.3.31 - Environment Variable Override of Plugin Trust Root
CVE-2026-41395
OpenClaw < 2026.3.28 - Webhook Replay via Query Parameter Reordering in Plivo V3
CVE-2026-41393
OpenClaw < 2026.3.31 - Arbitrary DNS Authority Acceptance and Credential Exfiltration via Wide-Area Discovery
CVE-2026-41391
OpenClaw < 2026.3.31 - Environment Variable Bypass in Package Index URL Handling
CVE-2026-41388
OpenClaw < 2026.3.31 - Configuration Rehydration via Empty-Array Revocation Handling
CVE-2026-41385
OpenClaw < 2026.3.31 - Nostr Private Key Exposure via config.get Redaction Bypass
CVE-2026-41381
OpenClaw < 2026.3.31 - Access Control Bypass in Discord Voice Manager via Channel Allowlist