Coy Geek
5 exploits
Active since Feb 2026
OpenClaw bluebubbles Webhook monitor.ts handleBlueBubblesWebhookRequest improper authentication
CVSS 7.3
OpenClaw < 2026.2.21 - Insecure Control UI Authentication over Plaintext HTTP
CVSS 8.1
OpenClaw < 2026.2.12 - Unauthenticated Profile Tampering via Nostr Plugin HTTP Endpoints
CVSS 6.8
OpenClaw < 2026.2.12 - Unauthenticated Webhook Authentication Bypass via Loopback RemoteAddress Trust
CVSS 5.9
OpenClaw < 2026.2.13 - Incorrect Authorization via BlueBubbles Webhook Loopback Bypass
CVSS 7.5