Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Chinmohan Nayak

#14182of 53,633
18.9Total CVSS
Vulnerabilities · 3
Medium
2
High
1
PT-2026-49765
4.3
2026-06-16
Openclaw · Openclaw · CVE-2026-53848
OpenClaw before 2026.5.26 contains an exec allowlist bypass vulnerability allowing authenticated operators to execute wrapper-level side effects outside allowlisted command intent. Attackers can craft command requests that bypass allowlist validation by leveraging transparent command wrappers to perform unintended operations.
PT-2026-49776
6.5
2026-06-16
Openclaw · Openclaw · CVE-2026-53859
OpenClaw before 2026.5.26 contains a hostname validation vulnerability allowing attackers to bypass blocklist comparisons using trailing-dot notation in model or workspace-derived URLs. Attackers can exploit inconsistent hostname checks to reach destinations that operators intended to block through hostname policies.
PT-2026-49781
8.1
2026-06-16
Openclaw · Openclaw · CVE-2026-53864
OpenClaw before 2026.5.26 contains an insufficient sanitization vulnerability in the host environment sanitizer that allows Node.js control variables to bypass validation. Attackers with access to workspace .env files, tool environment overrides, or skill environment blocks can pass malicious Node.js control variables to influence child processes or coverage output paths.