Michael Appel
4 exploits
Active since May 2026
OpenClaw 2026.3.31 < 2026.4.10 - Privilege Escalation via Missed Async Exec Completion Events in Heartbeat Owner Downgrade
CVSS 9.1
OpenClaw < 2026.4.15 - Bearer Token Validation Bypass via Stale SecretRef Resolution
CVSS 8.1
OpenClaw 2026.4.9 < 2026.4.10 - Denial of Service via Oversized WebSocket Frames in Voice-call Realtime Path
CVSS 7.5
OpenClaw 2026.4.7 < 2026.4.10 - Sandbox Media Normalization Bypass via Discord Event Cover Image
CVSS 7.7