Devin Robison
14 exploits
Active since Mar 2026
OpenClaw < 2026.3.24 - Environment Variable Injection via Workspace Config in CLI Backend
CVSS 7.8
OpenClaw - Unauthorized Agent Request Dispatch via Untrusted Local-Network Pages in iOS A2UI Bridge
CVSS 4.6
OpenClaw < 2026.4.2 - Information Disclosure via Gateway Connect Snapshot
CVSS 4.3
OpenClaw < 2026.3.31 - Component Interaction Misclassification in Discord Extension
CVSS 5.4
OpenClaw < 2026.3.31 - Group DM Channel Allowlist Bypass via Discord Slash Commands
CVSS 5.4
OpenClaw < 2026.3.28 - Privilege Escalation via operator.write to Admin-Class Telegram Config and Cron Persistence
CVSS 7.1
OpenClaw < 2026.4.20 - Scope Enforcement Bypass in Assistant-Media Route
CVSS 4.3
OpenClaw < 2026.4.20 - Improper Authorization in Paired-Device Pairing Actions
CVSS 5.4
OpenClaw < 2026.4.2 - Cleartext Credential Transmission via Unencrypted WebSocket Gateway Endpoints
CVSS 5.7
OpenClaw 2026.4.7 < 2026.4.15 - Arbitrary File Read via Unvalidated Tool-Result Media Paths
CVSS 5.8
OpenClaw < 2026.3.25 - Privilege Escalation via Silent Local Shared-Auth Reconnect
CVSS 7.8
OpenClaw - Shell-Bleed Protection Preflight Validation Bypass
CVSS 5.4
OpenClaw < 2026.3.24 - Arbitrary File Read via mediaUrl and fileUrl Parameters
CVSS 6.5
OpenClaw Media Parsing Path Traversal to Arbitrary File Read
CVSS 7.5