4.1

CVSS3.1

CVE-2026-35601 - Vikunja has an iCalendar Property Injection via CRLF in CalDAV Task Output

Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the CalDAV output generator builds iCalendar VTODO entries via raw string concatenation without applying RFC 5545 TEXT value escaping. User-controlled task titles containing CRLF characters break the iCalendar property …

📅 Published: April 10, 2026, 4:08 p.m. 🔄 Last Modified: April 10, 2026, 5:17 p.m.

5.4

CVSS3.1

CVE-2026-35600 - Vikunja has HTML Injection via Task Titles in Overdue Email Notifications

Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, task titles are embedded directly into Markdown link syntax in overdue email notifications without escaping Markdown special characters. When rendered by goldmark and sanitized by bluemonday (which allows <a> and <img> …

📅 Published: April 10, 2026, 4:07 p.m. 🔄 Last Modified: April 10, 2026, 5:17 p.m.

6.5

CVSS3.1

CVE-2026-35599 - Vikunja has an Algorithmic Complexity DoS in Repeating Task Handler

Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the addRepeatIntervalToTime function uses an O(n) loop that advances a date by the task's RepeatAfter duration until it exceeds the current time. By creating a repeating task with a 1-second interval and a due date far …

📅 Published: April 10, 2026, 4:05 p.m. 🔄 Last Modified: April 10, 2026, 6:28 p.m.

4.3

CVSS3.1

CVE-2026-35598 - Vikunja has Missing Authorization on CalDAV Task Read

Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the CalDAV GetResource and GetResourcesByList methods fetch tasks by UID from the database without verifying that the authenticated user has access to the task's project. Any authenticated CalDAV user who knows (or gues…

📅 Published: April 10, 2026, 4:04 p.m. 🔄 Last Modified: April 10, 2026, 5:17 p.m.

6

CVSS4.0

CVE-2026-35670 - OpenClaw < 2026.3.22 - Webhook Reply Rebinding via Username Resolution in Synology Chat

OpenClaw before 2026.3.22 contains a webhook reply delivery vulnerability that allows attackers to rebind chat replies to unintended users by exploiting mutable username matching instead of stable numeric user identifiers. Attackers can manipulate username changes to redirect webhook-triggered repl…

📅 Published: April 10, 2026, 4:03 p.m. 🔄 Last Modified: April 10, 2026, 5:17 p.m.

8.7

CVSS4.0

CVE-2026-35669 - OpenClaw < 2026.3.25 - Privilege Escalation via Gateway Plugin HTTP Authentication Scope

OpenClaw before 2026.3.25 contains a privilege escalation vulnerability in gateway-authenticated plugin HTTP routes that incorrectly mint operator.admin runtime scope regardless of caller-granted scopes. Attackers can exploit this scope boundary bypass to gain elevated privileges and perform unauth…

📅 Published: April 10, 2026, 4:03 p.m. 🔄 Last Modified: April 10, 2026, 5:17 p.m.

7.1

CVSS4.0

CVE-2026-35668 - OpenClaw < 2026.3.24 - Sandbox Media Root Bypass via Unnormalized mediaUrl and fileUrl Parameters

OpenClaw before 2026.3.24 contains a path traversal vulnerability in sandbox enforcement allowing sandboxed agents to read arbitrary files from other agents' workspaces via unnormalized mediaUrl or fileUrl parameter keys. Attackers can exploit incomplete parameter validation in normalizeSandboxMedi…

📅 Published: April 10, 2026, 4:03 p.m. 🔄 Last Modified: April 10, 2026, 6:27 p.m.

6.9

CVSS4.0

CVE-2026-35667 - OpenClaw < 2026.3.24 - Improper Process Termination via Unpatched killProcessTree in shell-utils.ts

OpenClaw before 2026.3.24 contains an incomplete fix for CVE-2026-27486 where the !stop chat command uses an unpatched killProcessTree function from shell-utils.ts that sends SIGKILL immediately without graceful SIGTERM shutdown. Attackers can trigger process termination via the !stop command, caus…

📅 Published: April 10, 2026, 4:03 p.m. 🔄 Last Modified: April 10, 2026, 8:17 p.m.

7.7

CVSS4.0

CVE-2026-35666 - OpenClaw < 2026.3.22 - Allowlist Bypass via Unregistered Time Dispatch Wrapper

OpenClaw before 2026.3.22 contains an allowlist bypass vulnerability in system.run approvals that fails to unwrap /usr/bin/time wrappers. Attackers can bypass executable binding restrictions by using an unregistered time wrapper to reuse approval state for inner commands.

📅 Published: April 10, 2026, 4:03 p.m. 🔄 Last Modified: April 10, 2026, 5:17 p.m.

6.9

CVSS4.0

CVE-2026-35665 - OpenClaw < 2026.3.24 - Denial of Service via Feishu Webhook Pre-Auth Body Parsing

OpenClaw before 2026.3.24 contains an incomplete fix for CVE-2026-32011 where the Feishu webhook handler accepts request bodies with permissive limits of 1MB and 30-second timeout before signature verification. An unauthenticated attacker can exhaust server connection resources by sending concurren…

📅 Published: April 10, 2026, 4:03 p.m. 🔄 Last Modified: April 10, 2026, 5:17 p.m.
Total resulsts: 343982
Page 17 of 34,399
« previous page » next page
Filters