Agustin Rivera
11 exploits
Active since Apr 2026
OpenClaw < 2026.4.2 - Arbitrary Remote Directory Deletion via Mis-scoped Mirror Mode Paths
CVSS 8.1
OpenClaw - Unauthorized Agent Request Dispatch via Untrusted Local-Network Pages in iOS A2UI Bridge
CVSS 4.6
OpenClaw < 2026.3.31 - Access Control Bypass via Proxied Remote Request Misclassification
CVSS 2.9
OpenClaw < 2026.4.2 - Timing Side Channel in Shared-Secret Comparison
CVSS 3.7
OpenClaw < 2026.4.2 - Information Disclosure via Gateway Connect Snapshot
CVSS 4.3
OpenClaw < 2026.4.2 - Insufficient Scope in Zalo Webhook Replay Dedupe Keys
CVSS 3.7
OpenClaw < 2026.4.20 - Scope Enforcement Bypass in Assistant-Media Route
CVSS 4.3
OpenClaw < 2026.4.20 - Improper Authorization in Paired-Device Pairing Actions
CVSS 5.4
OpenClaw < 2026.4.2 - Cleartext Credential Transmission via Unencrypted WebSocket Gateway Endpoints
CVSS 5.7
OpenClaw < 2026.4.2 - Authorization Bypass in Session Termination Endpoint
CVSS 5.4
OpenClaw < 2026.4.2 - PKCE Verifier Exposure via OAuth State Parameter
CVSS 5.3