8.7

CVSS4.0

CVE-2026-32982 - OpenClaw < 2026.3.13 - Telegram Bot Token Exposure in Media Fetch Error Logs

OpenClaw before 2026.3.13 contains an information disclosure vulnerability in the fetchRemoteMedia function that exposes Telegram bot tokens in error messages. When media downloads fail, the original Telegram file URLs containing bot tokens are embedded in MediaFetchError strings and leaked to logs…

πŸ“… Published: March 31, 2026, 11:17 a.m. πŸ”„ Last Modified: April 2, 2026, 1:12 p.m.

5.8

CVSS4.0

CVE-2026-32977 - OpenClaw < 2026.3.11 - Sandbox Boundary Bypass via Unanchored writeFile Commit Path

OpenClaw before 2026.3.11 contains a sandbox boundary bypass vulnerability in the fs-bridge writeFile commit step that uses an unanchored container path during the final move operation. An attacker can exploit a time-of-check-time-of-use race condition by modifying parent paths inside the sandbox t…

πŸ“… Published: March 31, 2026, 11:17 a.m. πŸ”„ Last Modified: April 2, 2026, 1:14 p.m.

7.1

CVSS4.0

CVE-2026-32976 - OpenClaw < 2026.3.11 - Account-Scoped configWrites Policy Bypass via Channel Commands

OpenClaw before 2026.3.11 contains an authorization bypass vulnerability allowing channel commands to mutate protected sibling-account configuration despite configWrites restrictions. Attackers with authorized access on one account can execute channel commands like /config set channels.<provider>.a…

πŸ“… Published: March 31, 2026, 11:17 a.m. πŸ”„ Last Modified: March 31, 2026, 11:17 a.m.

7.3

CVSS4.0

CVE-2026-32971 - OpenClaw < 2026.3.11 - Node-Host Approval UI Mismatch Allows Execution of Unintended Commands

OpenClaw before 2026.3.11 contains an approval-integrity vulnerability in node-host system.run approvals that displays extracted shell payloads instead of the executed argv. Attackers can place wrapper binaries and induce wrapper-shaped commands to execute local code after operators approve mislead…

πŸ“… Published: March 31, 2026, 11:17 a.m. πŸ”„ Last Modified: April 1, 2026, 3:55 a.m.

2

CVSS4.0

CVE-2026-32970 - OpenClaw < 2026.3.11 - Credential Fallback Logic Bypass via Unavailable Local Auth SecretRefs

OpenClaw before 2026.3.11 contains a credential fallback vulnerability where unavailable local gateway.auth.token and gateway.auth.password SecretRefs are treated as unset, allowing fallback to remote credentials in local mode. Attackers can exploit misconfigured local auth references to cause CLI …

πŸ“… Published: March 31, 2026, 11:17 a.m. πŸ”„ Last Modified: March 31, 2026, 11:17 a.m.

5.3

CVSS4.0

CVE-2026-32921 - OpenClaw < 2026.3.8 - Script Content Modification via Mutable Operand Binding in system.run

OpenClaw before 2026.3.8 contains an approval bypass vulnerability in system.run where mutable script operands are not bound across approval and execution phases. Attackers can obtain approval for script execution, modify the approved script file before execution, and execute different content whil…

πŸ“… Published: March 31, 2026, 11:17 a.m. πŸ”„ Last Modified: March 31, 2026, 11:17 a.m.

8.6

CVSS4.0

CVE-2026-32920 - OpenClaw < 2026.3.12 - Arbitrary Code Execution via Auto-Discovery of Workspace Plugins

OpenClaw before 2026.3.12 automatically discovers and loads plugins from .OpenClaw/extensions/ without explicit trust verification, allowing arbitrary code execution. Attackers can execute malicious code by including crafted workspace plugins in cloned repositories that execute when users run OpenC…

πŸ“… Published: March 31, 2026, 11:17 a.m. πŸ”„ Last Modified: March 31, 2026, 11:17 a.m.

9.2

CVSS4.0

CVE-2026-32917 - OpenClaw < 2026.3.13 - Remote Command Injection via Unsanitized iMessage Attachment Paths in SCP

OpenClaw before 2026.3.13 contains a remote command injection vulnerability in the iMessage attachment staging flow that allows attackers to execute arbitrary commands on configured remote hosts. The vulnerability exists because unsanitized remote attachment paths containing shell metacharacters ar…

πŸ“… Published: March 31, 2026, 11:17 a.m. πŸ”„ Last Modified: March 31, 2026, 11:17 a.m.

9.2

CVSS4.0

CVE-2026-32916 - OpenClaw 2026.3.7 < 2026.3.11 - Authorization Bypass in Plugin Subagent Routes via Synthetic Admin …

OpenClaw versions 2026.3.7 before 2026.3.11 contain an authorization bypass vulnerability where plugin subagent routes execute gateway methods through a synthetic operator client with broad administrative scopes. Remote unauthenticated requests to plugin-owned routes can invoke runtime.subagent met…

πŸ“… Published: March 31, 2026, 11:17 a.m. πŸ”„ Last Modified: March 31, 2026, 11:17 a.m.

6.9

CVSS4.0

CVE-2026-5198 - code-projects Student Membership System Admin Login index.php sql injection

A vulnerability was determined in code-projects Student Membership System 1.0. The impacted element is an unknown function of the file /admin/index.php of the component Admin Login. This manipulation of the argument username/password causes sql injection. Remote exploitation of the attack is possib…

πŸ“… Published: March 31, 2026, 11 a.m. πŸ”„ Last Modified: March 31, 2026, 11 a.m.
Total resulsts: 341722
Page 41 of 34,173
Β« previous page Β» next page
Filters