4.8

CVSS4.0

CVE-2026-27576 - OpenClaw: ACP prompt-size checks missing in local stdio bridge could reduce responsiveness with ver…

OpenClaw is a personal AI assistant. In versions 2026.2.17 and below, the ACP bridge accepts very large prompt text blocks and can assemble oversized prompt payloads before forwarding them to chat.send. Because ACP runs over local stdio, this mainly affects local ACP clients (for example IDE integr…

πŸ“… Published: Feb. 21, 2026, 10 a.m. πŸ”„ Last Modified: Feb. 21, 2026, 10:16 a.m.

6.9

CVSS4.0

CVE-2026-27488 - OpenClaw hardened cron webhook delivery against SSRF

OpenClaw is a personal AI assistant. In versions 2026.2.17 and below, Cron webhook delivery in src/gateway/server-cron.ts uses fetch() directly, so webhook targets can reach private/metadata/internal endpoints without SSRF policy checks. This issue was fixed in version 2026.2.19.

πŸ“… Published: Feb. 21, 2026, 9:49 a.m. πŸ”„ Last Modified: Feb. 21, 2026, 10:16 a.m.

7.6

CVSS3.1

CVE-2026-27487 - OpenClaw: Prevent shell injection in macOS keychain credential write

OpenClaw is a personal AI assistant. In versions 2026.2.13 and below, when using macOS, the Claude CLI keychain credential refresh path constructed a shell command to write the updated JSON blob into Keychain via security add-generic-password -w .... Because OAuth tokens are user-controlled data, t…

πŸ“… Published: Feb. 21, 2026, 9:35 a.m. πŸ”„ Last Modified: Feb. 21, 2026, 10:16 a.m.

4.3

CVSS4.0

CVE-2026-27486 - OpenClaw: Process Safety - Unvalidated PID Kill via SIGKILL in Process Cleanup

OpenClaw is a personal AI assistant. In versions 2026.2.13 and below of the OpenClaw CLI, the process cleanup uses system-wide process enumeration and pattern matching to terminate processes without verifying if they are owned by the current OpenClaw process. On shared hosts, unrelated processes ca…

πŸ“… Published: Feb. 21, 2026, 9:32 a.m. πŸ”„ Last Modified: Feb. 21, 2026, 10:16 a.m.

6.5

CVSS3.1

CVE-2025-14339 - weMail <= 2.0.7 - Missing Authorization to Unauthenticated Form Deletion

The weMail - Email Marketing, Lead Generation, Optin Forms, Email Newsletters, A/B Testing, and Automation plugin for WordPress is vulnerable to unauthorized form deletion in all versions up to, and including, 2.0.7. This is due to the `Forms::permission()` callback only validating the `X-WP-Nonce`…

πŸ“… Published: Feb. 21, 2026, 9:27 a.m. πŸ”„ Last Modified: Feb. 21, 2026, 10:16 a.m.

4.6

CVSS4.0

CVE-2026-27485 - OpenClaw affected by Stored XSS in Control UI via unsanitized assistant name/avatar in inline scrip…

OpenClaw is a personal AI assistant. In versions 2026.2.17 and below, skills/skill-creator/scripts/package_skill.py (a local helper script used when authors package skills) previously followed symlinks while building .skill archives. If an author runs this script on a crafted local skill directory …

πŸ“… Published: Feb. 21, 2026, 9:27 a.m. πŸ”„ Last Modified: Feb. 21, 2026, 10:16 a.m.

2.3

CVSS4.0

CVE-2026-27484 - OpenClaw Discord moderation authorization used untrusted sender identity in tool-driven flows

OpenClaw is a personal AI assistant. In versions 2026.2.17 and below, the Discord moderation action handling (timeout, kick, ban) uses sender identity from request parameters in tool-driven flows, instead of trusted runtime sender context. In setups where Discord moderation actions are enabled and …

πŸ“… Published: Feb. 21, 2026, 9:21 a.m. πŸ”„ Last Modified: Feb. 21, 2026, 10:16 a.m.

5.9

CVSS3.1

CVE-2026-27482 - Ray: Dashboard DELETE endpoints allow unauthenticated browser-triggered DoS (Serve shutdown / job d…

Ray is an AI compute engine. In versions 2.53.0 and below, thedashboard HTTP server blocks browser-origin POST/PUT but does not cover DELETE, and key DELETE endpoints are unauthenticated by default. If the dashboard/agent is reachable (e.g., --dashboard-host=0.0.0.0), a web page via DNS rebinding o…

πŸ“… Published: Feb. 21, 2026, 9:18 a.m. πŸ”„ Last Modified: Feb. 21, 2026, 10:16 a.m.

5.3

CVSS3.1

CVE-2026-27480 - Static Web Server: Timing-Based Username Enumeration in Basic Authentication

Static Web Server (SWS) is a production-ready web server suitable for static web files or assets. In versions 2.1.0 through 2.40.1, a timing-based username enumeration vulnerability in Basic Authentication allows attackers to identify valid users by exploiting early responses for invalid usernames,…

πŸ“… Published: Feb. 21, 2026, 9:14 a.m. πŸ”„ Last Modified: Feb. 21, 2026, 10:16 a.m.

7.7

CVSS3.1

CVE-2026-27479 - Wallos: SSRF via Redirect Bypass in Logo/Icon URL Fetch

Wallos is an open-source, self-hostable personal subscription tracker. Versions 4.6.0 and below contain a Server-Side Request Forgery (SSRF) vulnerability in the subscription and payment logo/icon upload functionality. The application validates the IP address of the provided URL before making the r…

πŸ“… Published: Feb. 21, 2026, 8:15 a.m. πŸ”„ Last Modified: Feb. 21, 2026, 9:15 a.m.
Total resulsts: 334177
Page 2 of 33,418
Β« previous page Β» next page
Filters