Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:brew/openclaw-cli

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

A path-confinement bypass vulnerability in openclaw-cli versions up to 2026.3.1 allowed writes outside intended root directories during browser output handling. This issue was fixed in version 2026.3.2 by unifying root-bound, file-descriptor-verified write semantics and canonical path-boundary validation across browser output and related install/skills write paths.

Join the discussion

OpenClaw CLI versions from 2026.1.29 up to but not including 2026.2.14 are affected by a cross-site request forgery (CSRF) vulnerability in browser-facing localhost mutation endpoints. These endpoints accept cross-origin requests without proper Origin or Referer validation, allowing malicious websites to trigger unauthorized state changes in the victim's local OpenClaw browser control plane. The vulnerability is mitigated by rejecting mutating HTTP methods when requests indicate a non-loopback Origin or cross-site fetch context. A patch is available that enforces these checks, and enabling authentication on the browser control interface also mitigates risk.

Join the discussion

OpenClaw CLI versions up to 2026.2.13 have a vulnerability in the Telnyx webhook handler of the optional voice-call plugin that allows unauthenticated HTTP POST requests if the Telnyx public key is not configured. This enables attackers to forge Telnyx events. The issue affects deployments where the voice-call plugin is enabled and the webhook endpoint is accessible to attackers. A fix is planned for version 2026.2.14 and later, which enforces signature verification by requiring the Telnyx public key configuration.

Join the discussion

OpenClaw CLI versions before 2026.2.15 embed the current working directory path into LLM prompts without sanitization. This allows an attacker who can control the directory name to inject control or format characters, potentially altering the prompt structure and injecting malicious instructions. The vulnerability was patched in version 2026.2.15 by sanitizing the workspace path to remove such characters.

Join the discussion

OpenClaw CLI versions up to 2026.2.14 are affected by a stored cross-site scripting (XSS) vulnerability in the Control UI. The vulnerability arises from unsanitized assistant identity values (name/avatar) being injected into an inline script tag without proper escaping, allowing script injection. This can lead to execution of attacker-controlled JavaScript in the UI context. The issue is fixed in version 2026.2.15 by removing inline script injection and adding a restrictive Content Security Policy.

Join the discussion

A command injection vulnerability exists in the openclaw CLI on macOS when refreshing keychain credentials. The vulnerability arises because user-controlled OAuth tokens are passed unsafely to a shell command, allowing potential OS command injection. This issue affects openclaw versions up to 2026.2.13 on macOS. The vulnerability is fixed in version 2026.2.14 by avoiding shell invocation and using a safer execFileSync call.

Join the discussion

OpenClaw CLI's tools.exec.safeBins validation for the 'sort' command can be bypassed using GNU long-option abbreviations in allowlist mode, allowing execution without required approval. This affects versions up to 2026.2.22-2 and is fixed in version 2026.2.23. The vulnerability arises because long-option handling only matched denied flags by exact string and accepted unknown long options with inline values instead of failing closed.

Join the discussion

OpenClaw CLI versions up to 2026.2.1 have an authentication bypass vulnerability in the optional voice-call extension when using inbound allowlist or pairing policies. The flaw allows calls with empty or missing caller IDs and calls from numbers ending with an allowlisted number to bypass access controls. This could enable unauthorized callers to reach voice-call agents. The issue is fixed in version 2026.2.2 by rejecting calls with missing caller IDs and enforcing strict caller ID matching.

Join the discussion

A vulnerability in the optional Twitch plugin of the OpenClaw CLI allowed unauthorized Twitch users to trigger the agent pipeline despite being excluded by the configured allowlist. This occurred because the 'allowFrom' user ID list was not properly enforced when 'allowedRoles' was unset or empty, resulting in an authorization bypass. The issue affects OpenClaw versions from 2026.1.29 up to but not including 2026.2.1. A fix is available in version 2026.2.1.

Join the discussion

OpenClaw CLI versions up to 2026.2.1 have a critical vulnerability (CVE-2026-28470) that allows bypassing the exec approvals allowlist via command substitution or backticks inside double quotes. This issue only affects setups that explicitly enable the optional exec approvals allowlist feature; default installations are not impacted. The vulnerability is fixed in version 2026.2.2 and later by rejecting unescaped command substitutions and backticks during allowlist analysis.

Join the discussion

Showing 1 to 10 of 585 results

Filters:Package: pkg:brew/openclaw-cli
Page 1 of 59
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses