Agustin Rivera
28 exploits
Active since Apr 2026
OpenClaw < 2026.4.20 - Gateway Config Mutation Guard Bypass via Agent Tool Access
CVSS 7.1
OpenClaw < 2026.4.10 - Incomplete Navigation Guard Coverage in Browser Interactions
CVSS 7.7
OpenClaw 2026.2.21 < 2026.4.10 - Authentication Bypass in Sandbox noVNC Helper Route
CVSS 9.8
OpenClaw < 2026.4.9 - Arbitrary File Read via Browser Interaction Routes
CVSS 6.5
OpenClaw < 2026.4.10 - Incomplete Navigation Guard Coverage in Browser Interactions
CVSS 7.7
OpenClaw < 2026.4.10 - DNS Rebinding SSRF via Hostname Validation Bypass
CVSS 6.3
OpenClaw 2026.4.10 < 2026.4.14 - Loss of Group Tool-Policy Context in Delivery Queue Recovery
CVSS 5.3
OpenClaw < 2026.4.15 - Authentication Bypass in Feishu Webhook and Card-Action Validation
CVSS 9.8
OpenClaw < 2026.4.15 - Arbitrary Markdown File Read via QMD memory_get
CVSS 4.3
OpenClaw < 2026.4.20 - Environment Variable Namespace Collision via Workspace dotenv
CVSS 7.8
OpenClaw < 2026.4.10 - Unauthorized Matrix Profile Config Persistence Access via operator.write Message Tools
CVSS 6.5
OpenClaw 2026.4.9 < 2026.4.10 - Sender Policy Bypass in Host Media Attachment Reads
CVSS 7.7
OpenClaw < 2026.4.9 - Environment Variable Injection via Workspace .env File
CVSS 7.3
OpenClaw < 2026.4.10 - Unsanitized External Input in Agent Hook Events
CVSS 9.1
OpenClaw < 2026.4.14 - Authorization Context Reuse in Collect-Mode Queue Batches
CVSS 6.8
OpenClaw 2026.3.22 < 2026.4.5 - Symlink Traversal in Remote Marketplace Repository Path Handling
CVSS 6.5
OpenClaw < 2026.4.10 - SSRF Policy Bypass in Existing-Session Browser Interaction Routes
CVSS 7.7
OpenClaw < 2026.4.2 - Arbitrary Remote Directory Deletion via Mis-scoped Mirror Mode Paths
CVSS 8.1
OpenClaw - Unauthorized Agent Request Dispatch via Untrusted Local-Network Pages in iOS A2UI Bridge
CVSS 4.6
OpenClaw < 2026.3.31 - Access Control Bypass via Proxied Remote Request Misclassification
CVSS 2.9
OpenClaw < 2026.4.2 - Timing Side Channel in Shared-Secret Comparison
CVSS 3.7
OpenClaw < 2026.4.2 - Information Disclosure via Gateway Connect Snapshot
CVSS 4.3
OpenClaw < 2026.4.2 - Insufficient Scope in Zalo Webhook Replay Dedupe Keys
CVSS 3.7
OpenClaw < 2026.4.20 - Scope Enforcement Bypass in Assistant-Media Route
CVSS 4.3
OpenClaw < 2026.4.20 - Improper Authorization in Paired-Device Pairing Actions
CVSS 5.4