← All credits
Peng Zhou (@zpbrent)
47 vulnerability records and advisories credit this contributor.
CVE-2026-32896
OpenClaw < 2026.2.21 - Unauthenticated Webhook Access via Passwordless Fallback in BlueBubbles Plugin
CVE-2026-34506
OpenClaw < 2026.3.8 - Sender Allowlist Bypass in Microsoft Teams Plugin via Route Allowlist Configuration
CVE-2026-34505
OpenClaw < 2026.3.12 - Webhook Rate Limiting Bypass via Pre-Authentication Secret Validation
CVE-2026-41371
OpenClaw < 2026.3.28 - Privilege Escalation via chat.send Reset Command
CVE-2026-43579
OpenClaw < 2026.4.10 - Insufficient Access Control in Nostr Profile Mutation Routes
CVE-2026-43569
OpenClaw < 2026.4.9 - Untrusted Provider Plugin Auto-enablement via Workspace Provider Auth
CVE-2026-43568
OpenClaw 2026.4.5 through 2026.4.9 - Privilege Escalation via Memory Dreaming Configuration in /dreaming Endpoint
CVE-2026-42433
OpenClaw < 2026.4.10 - Unauthorized Matrix Profile Config Persistence Access via operator.write Message Tools
CVE-2026-41379
OpenClaw < 2026.3.28 - Privilege Escalation via chat.send to Admin-Class Talk Voice Config
CVE-2026-41359
OpenClaw < 2026.3.28 - Privilege Escalation via operator.write to Admin-Class Telegram Config and Cron Persistence