Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

风间映川

#18963of 53,635
14.2Total CVSS
Vulnerabilities · 2
Medium
1
High
1
PT-2026-34791
6.7
2026-04-23
Pnpm · Pnpm · CVE-2026-41360
**Name of the Vulnerable Software and Affected Versions** OpenClaw versions prior to 2026.4.2 **Description** An approval integrity issue exists in pnpm dlx that fails to bind local script operands consistently with pnpm exec flows. This allows attackers to replace approved local scripts before execution without invalidating the approval plan, leading to the execution of modified script contents. **Recommendations** Update to version 2026.4.2.
PT-2026-35784
7.5
2026-04-03
Openclaw · Openclaw · CVE-2026-41400
**Name of the Vulnerable Software and Affected Versions** OpenClaw versions prior to 2026.3.31 **Description** The voice-call component parses large WebSocket frames before start validation. Remote attackers can send oversized pre-start WebSocket frames to cause resource consumption and denial of service (DoS), which is a state where a system becomes unavailable to its intended users. **Recommendations** Update to version 2026.3.31 or later.