Recent Advisories

Severity ID Title Vendor Product Date Type
LOW 2.3 CVE-2026-7317

Grav CMS Cache Value FileCache.php doGet deserialization_CVE-2026-7317

A vulnerability was found in Grav CMS up to 1.7.49.5/2.0.0-beta.1. Affected by this vulnerability is the function FileCache::doGet of the file syst...

Grav CMS 1.7.49.0 CVE
LOW 2.3 CVE-2026-42421

OpenClaw < 2026.4.8 - WebSocket Session Persistence via Shared Gateway Token Rotation_CVE-2026-42421

OpenClaw before 2026.4.8 contains a session management vulnerability where existing WebSocket sessions survive shared gateway token rotation. Attac...

OpenClaw OpenClaw CVE
LOW 2.3 CVE-2026-41916

OpenClaw < 2026.4.8 - Stale Authentication State via Config Reload_CVE-2026-41916

OpenClaw before 2026.4.8 contains an authentication state management vulnerability where the resolvedAuth closure becomes stale after configuration...

OpenClaw OpenClaw CVE
LOW 2.3 CVE-2026-41910

OpenClaw < 2026.4.8 - Missing Owner-Only Enforcement in /allowlist Cross-Channel Writes_CVE-2026-41910

OpenClaw before 2026.4.8 omits owner-only enforcement for cross-channel allowlist writes in the /allowlist endpoint. An authorized non-owner sender...

OpenClaw OpenClaw CVE
LOW 2.3 CVE-2026-41408

OpenClaw < 2026.3.31 - Disk Exhaustion via Media Download Bypass_CVE-2026-41408

OpenClaw before 2026.3.31 contains a resource exhaustion vulnerability in media downloads that bypasses core safety limits for file size, count, an...

OpenClaw OpenClaw CVE
LOW 2.3 CVE-2026-41406

OpenClaw < 2026.3.31 - Sender Allowlist Bypass via Thread History and Quoted Messages_CVE-2026-41406

OpenClaw before 2026.3.31 contains a sender allowlist bypass vulnerability that allows remote attackers to access restricted messages. Attackers ca...

OpenClaw OpenClaw CVE
LOW 2.3 CVE-2026-41402

OpenClaw < 2026.3.31 - Webhook Replay Cache Cross-Target messageId Scope Bypass_CVE-2026-41402

OpenClaw before 2026.3.31 contains a scope bypass vulnerability in webhook replay cache deduplication that allows authenticated attackers to replay...

OpenClaw OpenClaw CVE
LOW 2.1 CVE-2026-41398

OpenClaw – Unauthorized Agent Request Dispatch via Untrusted Local-Network Pages in iOS A2UI Bridge_CVE-2026-41398

OpenClaw before 2026.4.2 contains an improper access control vulnerability in the iOS A2UI bridge that treats generic local-network pages as truste...

OpenClaw OpenClaw CVE
LOW 2.3 CVE-2026-41382

OpenClaw < 2026.3.31 - Discord Voice Ingress Authorization Bypass via Channel and Role Validation Gaps_CVE-2026-41382

OpenClaw before 2026.3.31 contains an authorization bypass vulnerability in Discord voice ingress that allows attackers to bypass channel and membe...

OpenClaw OpenClaw CVE
LOW 2.3 CVE-2026-41381

OpenClaw < 2026.3.31 - Access Control Bypass in Discord Voice Manager via Channel Allowlist_CVE-2026-41381

OpenClaw before 2026.3.31 contains an access control bypass vulnerability in the Discord voice manager that allows attackers to bypass channel-leve...

OpenClaw OpenClaw CVE