Recent Advisories

Severity ID Title Vendor Product Date Type
LOW 2.3 CVE-2026-41358

OpenClaw < 2026.4.2 - Sender Allowlist Bypass via Slack Thread Context_CVE-2026-41358

OpenClaw before 2026.4.2 fails to filter Slack thread context by sender allowlist, allowing non-allowlisted messages to enter agent context. Attack...

OpenClaw OpenClaw CVE
LOW 2 CVE-2026-41357

OpenClaw < 2026.3.31 - Unsanitized Environment Variable Leakage in SSH Sandbox Backends_CVE-2026-41357

OpenClaw before 2026.3.31 contains an environment variable leakage vulnerability in SSH-based sandbox backends that pass unsanitized process.env to...

OpenClaw OpenClaw CVE
LOW 2.3 CVE-2026-41356

OpenClaw < 2026.3.31 - Incomplete WebSocket Session Termination in device.token.rotate_CVE-2026-41356

OpenClaw before 2026.3.31 fails to terminate active WebSocket sessions when rotating device tokens. Attackers with previously compromised credentia...

OpenClaw OpenClaw CVE
LOW 2.3 CVE-2026-41348

OpenClaw < 2026.3.31 - Group DM Channel Allowlist Bypass via Discord Slash Commands_CVE-2026-41348

OpenClaw before 2026.3.31 contains an authorization bypass vulnerability in Discord slash command and autocomplete paths that fail to enforce group...

OpenClaw OpenClaw CVE
LOW 2.3 CVE-2026-41347

OpenClaw < 2026.3.31 - Cross-Site Request Forgery via Missing Browser-Origin Validation in HTTP Operator Endpoints_CVE-2026-41347

OpenClaw before 2026.3.31 lacks browser-origin validation in HTTP operator endpoints when operating in trusted-proxy mode, allowing cross-site requ...

OpenClaw OpenClaw CVE
LOW 2.3 CVE-2026-41341

OpenClaw < 2026.3.31 - Component Interaction Misclassification in Discord Extension_CVE-2026-41341

OpenClaw before 2026.3.31 contains a logic error in Discord component interaction routing that misclassifies group direct messages as direct messag...

OpenClaw OpenClaw CVE
LOW 3.7 CVE-2026-2708

Libsoup: libsoup: http request smuggling via duplicate content-length headers_CVE-2026-2708

A request smuggling vulnerability exists in libsoup's HTTP/1 header parsing logic. The soup_message_headers_append_common() function in libsoup/sou...

Red Hat Red Hat Enterprise Linux 10 CVE
LOW 2.3 CVE-2026-41908

OpenClaw < 2026.4.20 - Scope Enforcement Bypass in Assistant-Media Route_CVE-2026-41908

OpenClaw before 2026.4.20 contains a scope enforcement bypass vulnerability in the assistant-media route that allows trusted-proxy callers without ...

OpenClaw OpenClaw CVE
LOW 3.5 CVE-2026-4512

WP reCaptcha by WebDesignBy < 2.0 – Admin+ Stored XSS_CVE-2026-4512

The reCaptcha by WebDesignBy WordPress plugin before 2.0 does not sanitize or escape the Site Key setting before outputting it in a JavaScript stri...

Unknown reCaptcha by WebDesignBy CVE
LOW 3.2 CVE-2026-41988

CVE-2026-41988_CVE-2026-41988

uuid before 14.0.0 can make unexpected writes when external output buffers are used, and the UUID version is 3, 5, or 6. In particular, UUID versio...

uuidjs uuid CVE