Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Ccreater

#18997of 53,619
14.1Total CVSS
Vulnerabilities · 2
Medium
1
High
1
PT-2026-35794
7.6
2026-04-09
Openclaw · Openclaw · CVE-2026-41912
**Name of the Vulnerable Software and Affected Versions** OpenClaw versions prior to 2026.4.8 **Description** A server-side request forgery (SSRF) policy bypass allows attackers to trigger navigations that circumvent standard SSRF checks. By exploiting browser interactions, attackers can bypass these protections to access restricted resources. SSRF is a flaw where an attacker can force a server-side application to make HTTP requests to an arbitrary domain of the attacker's choosing. **Recommendations** Update to version 2026.4.8.
PT-2026-35770
6.5
2026-04-02
Openclaw · Openclaw · CVE-2026-41385
**Name of the Vulnerable Software and Affected Versions** OpenClaw versions prior to 2026.3.31 **Description** The software stores the Nostr `privateKey` as plaintext within the configuration. This allows the exposure of plaintext signing keys used for Nostr protocol operations through calls to the `config.get()` function, which bypasses redaction mechanisms. **Recommendations** Update to version 2026.3.31 or later.