Jacob Tomlinson
59 exploits
Active since Jan 2026
OpenClaw < 2026.3.31 - Compiler Binary Substitution via Environment Variable Override in Host Execution Policy
CVSS 6.1
OpenClaw < 2026.3.31 - Resource Consumption via Discord Audio Preflight Before Member Authorization
CVSS 5.3
OpenClaw < 2026.3.28 - Authorization Bypass in /phone arm and /phone disarm Endpoints
CVSS 6.5
OpenClaw < 2026.3.31 - Matrix Thread Context Allowlist Bypass via Sender Validation
CVSS 5.4
OpenClaw < 2026.3.31 - Fail-Open Security Scan Bypass in Plugin Installation
CVSS 4.6
OpenClaw < 2026.3.31 - Privilege Escalation to Remote Code Execution via Unrestricted node.event Agent Dispatch
CVSS 8.8
OpenClaw < 2026.3.28 - Privilege Escalation via chat.send to Admin-Class Talk Voice Config
CVSS 7.1
OpenClaw < 2026.3.31 - Configuration Rehydration via Empty-Array Revocation Handling
CVSS 6.5
OpenClaw < 2026.3.31 - Exec Allowlist Bypass via Shell Init-File Options
CVSS 6.7
OpenClaw < 2026.3.31 - Arbitrary DNS Authority Acceptance and Credential Exfiltration via Wide-Area Discovery
CVSS 4.8
OpenClaw < 2026.3.31 - Sandbox Escape via Unrestricted File Sync and Symlink Traversal
CVSS 6.8
OpenClaw < 2026.3.31 - Operator Admin Privilege Escalation via Trusted-Proxy Authentication
CVSS 8.8
OpenClaw < 2026.3.31 - Resource Exhaustion via Unauthenticated MS Teams Webhook Body Parsing
CVSS 7.5
OpenClaw < 2026.4.2 - Timing Side Channel in Shared-Secret Comparison
CVSS 3.7
OpenClaw < 2026.3.31 - Sender Allowlist Bypass via Graph API Thread History
CVSS 5.4
OpenClaw < 2026.3.31 - Arbitrary Host File Read via appendLocalMediaParentRoots Self-Whitelisting
CVSS 5.5
OpenClaw < 2026.3.31 - Path Traversal via Inbound Channel Attachment Path in ACP Dispatch
CVSS 6.5
OpenClaw < 2026.4.2 - Loopback Protection Bypass via Trailing-Dot Localhost in CDP Discovery
CVSS 5.8
OpenClaw < 2026.3.31 - Information Disclosure via Control UI Bootstrap JSON
CVSS 5.3
OpenClaw < 2026.3.31 - Time-of-Check-Time-of-Use (TOCTOU) Vulnerability in Sandbox File Operations
CVSS 5.0
OpenClaw < 2026.3.28 - Agentic Consent Bypass via config.patch
CVSS 8.8
OpenClaw < 2026.3.31 - Webhook Replay Detection Bypass via Base64 Signature Re-encoding
CVSS 5.3
OpenClaw < 2026.3.31 - Remote Code Execution via Node Scope Gate Bypass
CVSS 8.8
OpenClaw < 2026.4.2 - Insufficient Scope in Zalo Webhook Replay Dedupe Keys
CVSS 3.7
OpenShell < 2026.3.28 - Arbitrary Code Execution via Mirror Mode Sandbox File Conversion
CVSS 7.3