Dragonmonk111
5 exploits
Active since May 2026
JunoClaw: upload_wasm accepted arbitrary filesystem paths without validation
CVSS 8.5
JunoClaw: plugin-shell shell-metacharacter injection via shell wrapper
CVSS 8.4
JunoClaw: plugin-shell shell-injection bypass via substring blocklist
CVSS 8.4
JunoClaw: MCP write tools exposed raw BIP-39 mnemonic as a tool-call parameter
CVSS 9.8
JunoClaw: SSRF in WAVS computeDataVerify allows cloud-metadata and internal-service access
CVSS 8.2