Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.4 CRITICAL
CVE-2026-28448 — OpenClaw 2026.1.29 < 2026.2.1 - Authorization Bypass in Twitch Plugin allowFrom Access Co…

OpenClaw versions 2026.1.29 prior to 2026.2.1 contain a vulnerability in the Twitch plugin (must be installed and enabled) in which it fails to enforce the allowFrom allowlist when allowedRoles is un…

openclaw | Remote | Authorization
Mar 05, 2026 Mar 11, 2026
Mar 05, 2026
Mar 11, 2026
8.1 HIGH
CVE-2026-28447 — OpenClaw 2026.1.29-beta.1 < 2026.2.1 - Path Traversal in Plugin Installation via Package …

OpenClaw versions 2026.1.29-beta.1 prior to 2026.2.1 contain a path traversal vulnerability in plugin installation that allows malicious plugin package names to escape the extensions directory. Attac…

openclaw | Remote | Path Traversal
Mar 05, 2026 Mar 10, 2026
Mar 05, 2026
Mar 10, 2026
9.8 CRITICAL
CVE-2026-28446 — OpenClaw < 2026.2.1 - Inbound Allowlist Policy Bypass in voice-call Extension via Empty C…

OpenClaw versions prior to 2026.2.1 with the voice-call extension installed and enabled contain an authentication bypass vulnerability in inbound allowlist policy validation that accepts empty caller…

openclaw | Remote | Authentication
Mar 05, 2026 Mar 11, 2026
Mar 05, 2026
Mar 11, 2026
9.8 CRITICAL
CVE-2026-28395 — OpenClaw 2026.1.14-1 < 2026.2.12 - Unintended Public Binding of Chrome Extension Relay vi…

OpenClaw version 2026.1.14-1 prior to 2026.2.12 contain an improper network binding vulnerability in the Chrome extension (must be installed and enabled) relay server that treats wildcard hosts as lo…

openclaw | Remote | Misconfiguration
Mar 05, 2026 Mar 09, 2026
Mar 05, 2026
Mar 09, 2026
7.5 HIGH
CVE-2026-28394 — OpenClaw < 2026.2.15 - Denial of Service via Unbounded Response Parsing in web_fetch Tool

OpenClaw versions prior to 2026.2.15 contain a denial of service vulnerability in the web_fetch tool that allows attackers to crash the Gateway process through memory exhaustion by parsing oversized …

openclaw | Remote | Denial of Service
Mar 05, 2026 Mar 09, 2026
Mar 05, 2026
Mar 09, 2026
9.8 CRITICAL
CVE-2026-28393 — OpenClaw 2.0.0-beta3 < 2026.2.14 - Arbitrary JavaScript Module Loading via Hook Transform…

OpenClaw versions 2.0.0-beta3 prior to 2026.2.14 contain a path traversal vulnerability in hook transform module loading that allows arbitrary JavaScript execution. The hooks.mappings[].transform.mod…

openclaw | Remote | Path Traversal
Mar 05, 2026 Mar 11, 2026
Mar 05, 2026
Mar 11, 2026
9.8 CRITICAL
CVE-2026-28392 — OpenClaw < 2026.2.14 - Privilege Escalation in Slack Slash Command Handler via Direct Mes…

OpenClaw versions prior to 2026.2.14 contain a privilege escalation vulnerability in the Slack slash-command handler that incorrectly authorizes any direct message sender when dmPolicy is set to open…

openclaw | Remote | Authorization
Mar 05, 2026 Mar 10, 2026
Mar 05, 2026
Mar 10, 2026
9.8 CRITICAL
CVE-2026-28391 — OpenClaw < 2026.2.2 - Command Injection via cmd.exe Parsing Bypass in Allowlist Enforceme…

OpenClaw versions prior to 2026.2.2 fail to properly validate Windows cmd.exe metacharacters in allowlist-gated exec requests (non-default configuration), allowing attackers to bypass command approva…

openclaw | Remote | Injection
Mar 05, 2026 Mar 10, 2026
Mar 05, 2026
Mar 10, 2026
9.8 CRITICAL
CVE-2026-21622 — Password Reset Tokens Do Not Expire

Insufficient Session Expiration vulnerability in hexpm hexpm/hexpm ('Elixir.Hexpm.Accounts.PasswordReset' module) allows Account Takeover. Password reset tokens generated via the "Reset your passwor…

hexpm hexpm hexpm | Remote | Authentication
Mar 05, 2026 Mar 19, 2026
Mar 05, 2026
Mar 19, 2026
Showing 20 of 6029 Results