Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.3 HIGH
CVE-2026-62240 — CrewAI < 1.15.1 SSRF Filter Bypass via HTTP Redirect in Scrape Tools

CrewAI before 1.15.1 contains a server-side request forgery vulnerability in the validate_url function that performs one-shot DNS resolution and blocklist checks before returning the original URL unc…

crewai | Remote | Server-Side Request Forgery
Jul 13, 2026 Jul 14, 2026
Jul 13, 2026
Jul 14, 2026
6.6 MEDIUM
CVE-2026-62239 — FlashAttention Symlink Attack via tarfile.extractall in hopper/setup.py

FlashAttention through 2.8.3.post1, fixed in commit 0816ef1, contains a symlink attack vulnerability in the download_and_copy() function within hopper/setup.py that extracts NVIDIA toolchain archives…

| Misconfiguration
Jul 13, 2026 Jul 15, 2026
Jul 13, 2026
Jul 15, 2026
8.8 HIGH
CVE-2026-62200 — OpenClaw < 2026.6.6 Authentication Bypass via Git ext transport

OpenClaw versions before 2026.6.6 contain a flaw in host exec environment filtering that could allow Git ext transport to be abused. When the affected feature is enabled and reachable, a lower-trust …

openclaw | Remote | Authorization
Jul 13, 2026 Jul 15, 2026
Jul 13, 2026
Jul 15, 2026
8.8 HIGH
CVE-2026-62199 — OpenClaw < 2026.6.6 Authentication Bypass via Environment Filtering

OpenClaw versions before 2026.6.6 contain a flaw in host exec environment filtering that can miss interpreter startup variables. When the affected feature is enabled and reachable, a lower-trust call…

openclaw | Remote | Injection
Jul 13, 2026 Jul 15, 2026
Jul 13, 2026
Jul 15, 2026
5.4 MEDIUM
CVE-2026-62198 — OpenClaw 2026.5.28 < 2026.6.6 Authorization Bypass via Web Search

OpenClaw versions 2026.5.28 before 2026.6.6 contain an authorization bypass vulnerability in native web search that allows lower-trust callers to perform actions requiring stronger policy checks. Att…

openclaw | Remote | Authorization
Jul 13, 2026 Jul 14, 2026
Jul 13, 2026
Jul 14, 2026
8.5 HIGH
CVE-2026-62197 — OpenClaw < 2026.6.6 Policy Bypass via CDP Discovery

OpenClaw before 2026.6.6 contains a policy bypass vulnerability in browser CDP discovery that accepts blocked WebSocket URLs. Attackers with lower-trust access can reach network destinations that sho…

openclaw | Remote | Misconfiguration
Jul 13, 2026 Jul 14, 2026
Jul 13, 2026
Jul 14, 2026
8.7 HIGH
CVE-2026-62196 — OpenClaw 2026.3.22 < 2026.6.6 Authorization Bypass via WhatsApp Group IDs

OpenClaw versions 2026.3.22 before 2026.6.6 contain an authorization bypass vulnerability where WhatsApp group IDs can satisfy elevated sender allowlists. Attackers with lower-trust access can perfor…

openclaw | Remote | Authorization
Jul 13, 2026 Jul 15, 2026
Jul 13, 2026
Jul 15, 2026
8.7 HIGH
CVE-2026-62195 — OpenClaw 2026.5.20 < 2026.6.6 Authorization Bypass via MCP loopback

OpenClaw versions 2026.5.20 before 2026.6.6 contain an authorization bypass vulnerability in the MCP loopback feature that allows lower-trust callers to execute owner-only tools. Attackers can bypass…

openclaw | Remote | Authorization
Jul 13, 2026 Jul 15, 2026
Jul 13, 2026
Jul 15, 2026
8.8 HIGH
CVE-2026-62194 — OpenClaw 2026.5.20 < 2026.6.9 Privilege Escalation via Plugin Install

OpenClaw versions 2026.5.20 before 2026.6.9 contain a privilege escalation vulnerability in plugin install commands that allows lower-trust callers to execute or persist actions beyond their intended…

openclaw | Remote | Authorization
Jul 13, 2026 Jul 15, 2026
Jul 13, 2026
Jul 15, 2026
6.9 MEDIUM
CVE-2026-62193 — OpenClaw 2026.6.5 < 2026.6.9 Authentication Bypass via Plugin Install

OpenClaw versions 2026.6.5 before 2026.6.9 contain a vulnerability in the plugin install wrappers that could skip the install policy (authorization) check. When the affected feature is enabled and re…

openclaw | Remote | Authorization
Jul 13, 2026 Jul 15, 2026
Jul 13, 2026
Jul 15, 2026
8.1 HIGH
CVE-2026-62192 — OpenClaw 2026.6.6 < 2026.6.9 Authorization Bypass

OpenClaw versions 2026.6.6 before 2026.6.9 contain an authorization bypass vulnerability in Discord guild actions that allows lower-trust callers to perform actions requiring stronger authorization c…

openclaw | Remote | Authorization
Jul 13, 2026 Jul 14, 2026
Jul 13, 2026
Jul 14, 2026
7.1 HIGH
CVE-2026-62191 — OpenClaw 2026.6.6 < 2026.6.9 Authorization Bypass via Message Mutations

OpenClaw versions 2026.6.6 before 2026.6.9 contain an authorization bypass vulnerability in message mutation handling that allows lower-trust callers to perform actions requiring stronger authorizati…

openclaw | Remote | Authorization
Jul 13, 2026 Jul 14, 2026
Jul 13, 2026
Jul 14, 2026
8.8 HIGH
CVE-2026-62190 — OpenClaw < 2026.6.9 Authorization Bypass via flock wrapper

OpenClaw versions before 2026.6.9 contain an authorization bypass vulnerability in the flock wrapper that allows lower-trust callers to execute or persist actions beyond their intended authorization.…

openclaw | Remote | Authorization
Jul 13, 2026 Jul 15, 2026
Jul 13, 2026
Jul 15, 2026
7.6 HIGH
CVE-2026-62189 — OpenClaw < 2026.6.9 Symlink Following via Mirror Sync

OpenClaw versions before 2026.6.9 contain a symlink following vulnerability in the mirror sync feature that allows lower-trust callers to perform actions requiring stronger authorization. Attackers c…

openclaw | Remote | Authorization
Jul 13, 2026 Jul 15, 2026
Jul 13, 2026
Jul 15, 2026
8.6 HIGH
CVE-2026-62188 — OpenClaw < 2026.6.9 Feishu Authorization Bypass

OpenClaw @openclaw/feishu versions 2026.6.6 and earlier contain an incorrect authorization vulnerability in which the Feishu permission tools could ignore per-account disablement settings. When the a…

feishu openclaw openclaw\/feishu | Remote | Authorization
Jul 13, 2026 Jul 15, 2026
Jul 13, 2026
Jul 15, 2026
8.6 HIGH
CVE-2026-62187 — OpenClaw < 2026.6.9 Feishu tools Authorization Bypass

OpenClaw Feishu tools (npm package @openclaw/feishu) in versions <= 2026.6.6 could ignore per-account disablement. A lower-trust caller or a configured input path could perform actions that should ha…

feishu openclaw openclaw\/feishu | Remote | Authorization
Jul 13, 2026 Jul 15, 2026
Jul 13, 2026
Jul 15, 2026
7.6 HIGH
CVE-2026-62186 — OpenClaw < 2026.6.8 Authorization Bypass via HTTP Model Override

OpenClaw versions before 2026.6.8 contain an authorization bypass vulnerability in OpenAI-compatible HTTP model overrides that allows lower-trust callers to perform actions requiring stronger authori…

openclaw | Remote | Authorization
Jul 13, 2026 Jul 14, 2026
Jul 13, 2026
Jul 14, 2026
8.6 HIGH
CVE-2026-62185 — Argo CD Helm Chart < 10.0.0 Missing Network Policy RCE

Argo CD Helm Chart before 10.0.0 fails to install network policies by default, allowing any pod on a cluster to access repo-server and other Argo APIs. Attackers can exploit this unrestricted network…

| Misconfiguration
Jul 13, 2026 Jul 15, 2026
Jul 13, 2026
Jul 15, 2026
8.7 HIGH
CVE-2026-62184 — luci-app-banip Log Monitor IP Extraction Bypass

luci-app-banip contains a log parsing vulnerability where the awk-based parser extracts the first IPv4 address from log lines regardless of field position, allowing attackers to inject arbitrary IPs …

luci | Remote | Injection
Jul 13, 2026 Jul 15, 2026
Jul 13, 2026
Jul 15, 2026
8.7 HIGH
CVE-2026-61458 — PasswordPusher < 2.9.2 Passphrase Brute-Force via Unthrottled Endpoint

PasswordPusher before 2.9.2 contains a brute-force vulnerability in the POST /p/:token/access endpoint that lacks route-specific rate limiting and per-push lockout mechanisms. Attackers who know a pu…

password_pusher | Remote | Authentication
Jul 13, 2026 Jul 15, 2026
Jul 13, 2026
Jul 15, 2026
Showing 20 of 10953 Results