Search
| CVE | Severity | CVSS | Risk | Flags | OS | Vendor | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-32022 | medium | 6.5 | 6.5 | openclaw | 3mo ago | OpenClaw safeBins grep -e File Read Bypass (stdin-only policy bypass) | ||
| CVE-2026-22217 | medium | 6.1 | 6.1 | openclaw | 3mo ago | OpenClaw: shell-env trusted-prefix fallback allowed attacker-controlled binary execution via $SHELL | ||
| CVE-2026-28474 | critical | 9.8 | 9.8 | openclaw | 3mo ago | Nextcloud Talk allowlist bypass via actor.name display name spoofing | ||
| CVE-2026-28395 | critical | 9.1 | 9.1 | openclaw | 3mo ago | OpenClaw's Chrome extension relay binds publicly due to wildcard treated as loopback |