← All credits
KeenSecurityLab
91 vulnerability records and advisories credit this contributor.
CVE-2026-41380
OpenClaw < 2026.3.28 - Arbitrary Execution Allowlist via Wrapper Carrier Executables
CVE-2026-41356
OpenClaw < 2026.3.31 - Incomplete WebSocket Session Termination in device.token.rotate
CVE-2026-41353
OpenClaw < 2026.3.22 - allowProfiles Bypass via Profile Mutation and Runtime Selection
CVE-2026-41348
OpenClaw < 2026.3.31 - Group DM Channel Allowlist Bypass via Discord Slash Commands
CVE-2026-41346
OpenClaw 2026.2.26 < 2026.3.31 - Denial of Service via Improper Pending Pairing Request Cap Enforcement
CVE-2026-41343
OpenClaw < 2026.3.31 - Denial of Service via LINE Webhook Handler Pre-Auth Concurrency
CVE-2026-41342
OpenClaw < 2026.3.28 - Unauthenticated Discovery Endpoint Credential Exfiltration via Remote Onboarding
CVE-2026-41341
OpenClaw < 2026.3.31 - Component Interaction Misclassification in Discord Extension
CVE-2026-41340
OpenClaw < 2026.3.31 - Authentication Boundary Bypass via Telegram Legacy allowFrom Migration
CVE-2026-41337
OpenClaw < 2026.3.31 - Callback Origin Mutation in Plivo Voice-call Replay