← All credits
KeenSecurityLab
91 vulnerability records and advisories credit this contributor.
CVE-2026-41336
OpenClaw < 2026.3.31 - Arbitrary Hook Code Execution via OPENCLAW_BUNDLED_HOOKS_DIR Environment Variable Override
CVE-2026-41301
OpenClaw 2026.3.22 < 2026.3.31 - Forged Nostr DM Pairing State Creation via Signature Verification Bypass
CVE-2026-41300
OpenClaw < 2026.3.31 - Preservation of Attacker-Discovered Endpoints in Remote Onboarding
CVE-2026-40045
OpenClaw < 2026.4.2 - Cleartext Credential Transmission via Unencrypted WebSocket Gateway Endpoints
CVE-2026-35670
OpenClaw < 2026.3.22 - Webhook Reply Rebinding via Username Resolution in Synology Chat
CVE-2026-35660
OpenClaw < 2026.3.23 - Insufficient Access Control in Gateway Agent Session Reset
CVE-2026-35659
OpenClaw < 2026.3.22 - Unresolved Service Metadata Routing via Bonjour and DNS-SD Discovery
CVE-2026-35651
OpenClaw 2026.2.13 < 2026.3.25 - ANSI Escape Sequence Injection in Approval Prompt
CVE-2026-35638
OpenClaw < 2026.3.22 - Privilege Escalation via Self-Declared Scopes in Trusted-Proxy Control UI
CVE-2026-35636
OpenClaw 2026.3.11 < 2026.3.25 - Session Isolation Bypass via sessionId Resolution