Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
0 OpenClaw Windows Node before 2026.7.1 contains an incomplete environment-variable sanitizer in system.run that fails to block GIT_CONFIG_*, DOTNET_STARTUP_HOOKS, and JAVA_TOOL_OPTIONS variables. Attackers with gateway or agent access can supply these variables to allowlisted tools like git, dotnet, or java to load attacker-controlled code and achieve arbitrary code execution. Join the discussion | CVE Database V5 | 09/30/2026, 19:16:04 UTC Added: 09/30/2026, 19:33:33 UTC |
0 CVE-2026-101883 is a server-side request forgery (SSRF) vulnerability in OpenClaw Windows Node versions up to 2026.9.4. The flaw exists in the canvas.present capability, which bypasses URL risk evaluation enforced by canvas.navigate. An attacker with gateway or agent access can exploit this to make the node's WebView send requests to localhost, private networks, or tailnet services from the user's machine. Join the discussion | CVE Database V5 | 09/30/2026, 19:16:03 UTC Added: 09/30/2026, 19:33:33 UTC |
0 OpenClaw Windows Node versions before 2026.7.1 have a vulnerability in the system.execApprovals.set function that allows remote callers to add overly permissive execution rules. This flaw involves incomplete validation of inputs, permitting wildcard-executable rules and the use of abusable system binaries such as mshta, rundll32, and certutil. Exploitation enables arbitrary command execution on the Windows host without operator checks or user prompts. Join the discussion | CVE Database V5 | 09/30/2026, 19:16:03 UTC Added: 09/30/2026, 19:33:33 UTC |
0 OpenClaw Windows Node before 2026.7.1 contains an allocation of resources without limits vulnerability in the gateway WebSocket transport that allows connected gateways to exhaust node memory. Attackers can send an unending sequence of WebSocket continuation frames without EndOfMessage to cause unbounded memory growth until the node process crashes. Join the discussion | CVE Database V5 | 09/30/2026, 19:16:02 UTC Added: 09/30/2026, 19:33:33 UTC |
OpenClaw Windows Node before 2026.7.1 contains an incorrect authorization vulnerability in the system.run exec-approval policy where ExecShellWrapperParser fails to split commands on pipe operators or extract command substitutions. Connected gateways or agents can bypass approval rules by placing denied commands behind allowed prefixes using pipe operators or command substitution syntax, achieving arbitrary command execution on Windows hosts. Join the discussion | CVE Database V5 | 09/30/2026, 19:16:01 UTC Added: 09/30/2026, 19:33:33 UTC |
OpenClaw Windows Node versions before 2026.7.1-3 have a missing authorization vulnerability in NodeService capture handlers. This flaw allows connected gateways or agents to perform screen snapshots, camera snaps, and location captures without user consent. Attackers can silently invoke these functions over the node WebSocket, capturing screenshots, webcam photos, and device geolocation without user interaction. Join the discussion | CVE Database V5 | 09/30/2026, 19:16:01 UTC Added: 09/30/2026, 19:33:33 UTC |
Showing 1 to 6 of 6 results