Jacob Tomlinson
59 exploits
Active since Jan 2026
OpenClaw < 2026.4.2 - PKCE Verifier Exposure via OAuth State Parameter
CVSS 5.3
OpenClaw < 2026.3.28 - Unauthorized Media Download via Zalo Channel
CVSS 6.5
OpenClaw < 2026.3.28 - Insufficient Scope Validation in node.pair.approve
CVSS 8.1
OpenClaw < 2026.3.28 - Sender Policy Allowlist Bypass via Policy Downgrade in Google Chat and Zalouser Extensions
CVSS 4.3
OpenClaw < 2026.3.28 - Privilege Escalation via Missing Caller Scope Validation in Device Pair Approval
CVSS 9.9
OpenClaw < 2026.3.28 - Brute Force Attack via Missing Rate Limiting on Webhook Shared Secret Authentication
CVSS 6.5
OpenClaw < 2026.3.28 - Incomplete WebSocket Session Termination on Device Removal and Token Revocation
CVSS 8.1
OpenClaw < 2026.3.28 - Server-Side Request Forgery via Unguarded Image Download in fal Provider
CVSS 8.3
Dask distributed <2026.1.0 - XSS
CVSS 6.1