Devin Robison
48 exploits
Active since Mar 2026
OpenClaw < 2026.4.21 - Authorization Bypass in Owner-Enforced Commands via Wildcard Channel Senders
CVSS 4.2
OpenClaw < 2026.4.21 - Authorization Bypass in Owner-Enforced Commands via Wildcard Channel Senders
CVSS 4.2
OpenClaw < 2026.4.20 - Direct Message Misclassification in Feishu Card Actions
CVSS 5.4
OpenClaw < 2026.4.22 - Authentication Bypass in Gateway Control UI Bootstrap Config Endpoint
CVSS 5.3
OpenClaw < 2026.4.20 - Arbitrary Code Execution via MCP stdio Environment Variables
CVSS 7.3
OpenClaw < 2026.4.20 - Tool Policy Bypass via Bundled MCP/LSP Tools
CVSS 5.4
OpenClaw < 2026.4.20 - Improper Trust Labeling in Isolated Cron Awareness Events
CVSS 5.3
OpenClaw < 2026.4.20 - Gateway Config Mutation Guard Bypass via Agent Tool Access
CVSS 7.1
OpenClaw < 2026.4.22 - Connector Endpoint Host Override via Workspace dotenv Files
CVSS 5.0
OpenClaw < 2026.4.23 - Arbitrary Code Execution via setup-api.js in Current Working Directory
CVSS 7.8
OpenClaw < 2026.4.23 - Webhook Route Secret Cache Not Invalidated After Rotation
CVSS 6.0
OpenClaw < 2026.4.23 - Unsafe Config Mutation via Gateway Tool Denylist Bypass
CVSS 8.8
OpenClaw < 2026.4.10 - Incomplete Navigation Guard Coverage in Browser Interactions
CVSS 7.7
OpenClaw < 2026.4.10 - Incomplete Navigation Guard Coverage in Browser Interactions
CVSS 7.7
OpenClaw < 2026.4.9 - Arbitrary File Read via Browser Interaction Routes
CVSS 6.5
OpenClaw 2026.3.31 < 2026.4.10 - Privilege Escalation via Missed Async Exec Completion Events in Heartbeat Owner Downgrade
CVSS 9.1
OpenClaw < 2026.4.10 - Chrome DevTools Protocol Exposure via Overly Broad CDP Relay Binding
CVSS 9.6
OpenClaw < 2026.4.10 - DNS Rebinding SSRF via Hostname Validation Bypass
CVSS 6.3
OpenClaw 2026.4.10 < 2026.4.14 - Loss of Group Tool-Policy Context in Delivery Queue Recovery
CVSS 5.3
OpenClaw < 2026.4.15 - Bearer Token Validation Bypass via Stale SecretRef Resolution
CVSS 8.1
OpenClaw < 2026.4.15 - Authentication Bypass in Feishu Webhook and Card-Action Validation
CVSS 9.8
OpenClaw < 2026.4.15 - Arbitrary Markdown File Read via QMD memory_get
CVSS 4.3
OpenClaw < 2026.4.22 - Symlink Swap Race Condition in OpenShell FS Bridge Writes
CVSS 9.6
OpenClaw < 2026.4.22 - Time-of-Check/Time-of-Use Race Condition in OpenShell FS Bridge
CVSS 7.7
OpenClaw < 2026.4.22 - Shell Expansion Bypass in Unquoted Heredocs via Exec Allowlist
CVSS 8.8