Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:npm/@openclaw/whatsapp

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

OpenClaw versions prior to 2026.7.1 contain an authorization vulnerability allowing non-owner users to execute MCP configuration changes via /mcp set and /mcp unset commands. This flaw permits attackers to persist arbitrary stdio MCP commands that run with OpenClaw process privileges during configuration loading, impacting host confidentiality, integrity, and availability.

Join the discussion

OpenClaw versions 2026.5.1 through 2026.7.0 contain a vulnerability where the configured exec approval path is not applied to Google Meet node commands. Specifically, the googlemeet.chrome command executes caller-supplied audio command arrays on a paired node without the normal approval flow. This allows a tool-enabled agent with permission to invoke this command to execute arbitrary processes on the paired node, potentially affecting files, credentials, browser profiles, and system availability. The issue is fixed in version 2026.7.1. As a workaround, removing the googlemeet.chrome command from allowed node commands or disabling the Google Meet plugin mitigates the risk.

Join the discussion

OpenClaw (npm package 'openclaw') versions before 2026.7.1 contain a time-of-check time-of-use (TOCTOU) race condition in the OpenShell local mirror filesystem mutation operations. This vulnerability affects the remove, mkdir, and rename operations, which can act on a different filesystem target if the path changes concurrently after the sandbox path-safety check. An attacker who wins the race can perform filesystem operations outside the intended sandbox with the permissions of the OpenClaw process user. The issue is fixed in version 2026.7.1.

Join the discussion

OpenClaw versions before 2026.7.1 have an authorization bypass vulnerability in the diagnostics export command. This flaw allows non-owner channel senders to access diagnostic bundles intended only for owners, exposing sensitive host, configuration, runtime, and connected services information. The vulnerability has a CVSS 3.1 score of 6.5, indicating a high severity impact on confidentiality without affecting integrity or availability.

Join the discussion

OpenClaw npm package versions before 2026.7.1 have a vulnerability where the enforcement of the documented owner-only restriction for persistent /activation policy changes in group channels is missing. This allows authorized non-owner channel senders to modify the agent's activation behavior, potentially causing it to respond more broadly or suppress expected activations until corrected by an owner. The issue is resolved in version 2026.7.1.

Join the discussion

OpenClaw versions before 2026.7.1 have an authorization bypass vulnerability in the /export-trajectory endpoint. This flaw allows non-owner users to request and receive trajectory bundles intended only for owners. Exploiting this vulnerability exposes sensitive session data including prompts, model messages, tool schemas, runtime events, and local path metadata.

Join the discussion

OpenClaw npm package versions before 2026.7.1 have a vulnerability where Signal approval reactions can be incorrectly bound. This causes reactions meant to approve or deny structured requests to mistakenly apply to unrelated outbound messages if both are present in the same conversation. The vulnerability does not affect the authority of legitimate approvers and is fixed in version 2026.7.1.

Join the discussion

OpenClaw versions from 2026.4.10 up to but not including 2026.7.1 have a vulnerability where persistent memory dreaming commands can be issued by authorized users who are not owners, bypassing owner permission checks. This allows such users to enable or disable the Gateway's Memory Core dreaming behavior, potentially affecting the confidentiality, integrity, and availability of stored conversation data. The vulnerability is fixed in version 2026.7.1. Mitigation includes disabling dreaming commands in external channels or restricting command access to owners.

Join the discussion

The Automatic.css WordPress plugin version 4.0.0 contains a stored cross-site scripting (XSS) vulnerability via the REQUEST_URI. This vulnerability arises from insufficient input sanitization and output escaping, allowing unauthenticated attackers to inject malicious scripts. These scripts execute when an administrator visits the Activity Log settings page. The vulnerability has a medium severity score of 6.4 CVSS v3.1.

Join the discussion

OpenClaw (npm package 'openclaw') versions before 2026.7.1 have a security vulnerability where the administrator scope requirement is not enforced on browser control when accessed via the node.invoke method. This allows a write-scoped caller with access to a connected browser-capable node to perform actions such as inspecting pages, navigating tabs, or interacting with browser-visible applications without needing administrator privileges. The vulnerability is fixed in version 2026.7.1.

Join the discussion

Showing 1 to 10 of 139373 results

Filters:Package: pkg:npm/@openclaw/whatsapp
Page 1 of 13938
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses