← All credits
tdjackey
102 vulnerability records and advisories credit this contributor.
CVE-2026-35635
OpenClaw < 2026.3.22 - Webhook Path Route Replacement Vulnerability in Synology Chat
CVE-2026-35631
OpenClaw < 2026.3.22 - Missing Authorization Enforcement in Internal ACP Chat Commands
CVE-2026-35620
OpenClaw < 2026.3.24 - Missing Authorization in /send and /allowlist Chat Commands
CVE-2026-33574
OpenClaw < 2026.3.8 - Path Traversal via Tools Root Rebinding in Skills Download
CVE-2026-33573
OpenClaw < 2026.3.11 - Workspace Boundary Bypass via Agent RPC Parameters
CVE-2026-32987
OpenClaw < 2026.3.13 - Bootstrap Setup Code Replay via Device Pairing
CVE-2026-32979
OpenClaw < 2026.3.11 - Unbound Interpreter and Runtime Commands Bypass in node-host Approval
CVE-2026-32978
OpenClaw < 2026.3.11 - Approval Bypass via Unrecognized Script Runners
CVE-2026-32972
OpenClaw < 2026.3.11 - Authorization Bypass in Browser Profile Management via browser.request
CVE-2026-32922
OpenClaw < 2026.3.11 - Privilege Escalation via Unvalidated Scope in device.token.rotate