Pavan Kumar Gondhi
23 exploits
Active since Apr 2026
OpenClaw 2026.4.5 < 2026.4.20 - MiniMax API Host Override via Workspace dotenv
CVSS 5.0
OpenClaw < 2026.4.15 - Arbitrary Local File Read via Webchat Audio Embedding
CVSS 3.7
OpenClaw < 2026.4.22 - Security Envelope Constraint Bypass in ACP Child Sessions
CVSS 4.3
OpenClaw < 2026.4.20 - Hook Session-Key Bypass via Template Mapping
CVSS 5.3
OpenClaw < 2026.4.10 - Insufficient Access Control in Nostr Profile Mutation Routes
CVSS 6.5
OpenClaw < 2026.4.10 - Insufficient Environment Variable Denylist in Exec Policy
CVSS 8.8
OpenClaw < 2026.4.15 - Authorization Bypass in Matrix Room Control Commands via DM Pairing Store
CVSS 8.8
OpenClaw < 2026.4.22 - Server-Side Request Forgery in Zalo Photo URL Validation
CVSS 8.6
OpenClaw < 2026.4.20 - Server-Side Request Forgery in QQBot Direct Media Upload
CVSS 5.8
OpenClaw 2026.2.22 < 2026.4.12 - Shell-Wrapper Detection Bypass via Environment Variable Assignment Injection
CVSS 8.8
OpenClaw < 2026.4.14 - Internal Page Content Exposure via Browser Snapshot and Screenshot Routes
CVSS 7.7
OpenClaw < 2026.4.14 - Redaction Bypass via sourceConfig and runtimeConfig Aliases
CVSS 6.5
OpenClaw < 2026.4.10 - Time-of-Check-Time-of-Use (TOCTOU) Race Condition in exec Script Preflight Validator
CVSS 2.5
OpenClaw 2026.2.23 < 2026.4.12 - Weakened Exec Approval Binding via busybox and toybox Applet Execution
CVSS 8.8
OpenClaw < 2026.4.10 - Arbitrary Local File Read via QQBot Media Tags
CVSS 8.6
OpenClaw 2026.4.7 < 2026.4.14 - Privilege Escalation via Untrusted Webhook Wake Events
CVSS 9.1
OpenClaw < 2026.4.10 - Path Traversal in screen_record outPath Parameter
CVSS 6.5
OpenClaw < 2026.4.9 - Untrusted Provider Plugin Auto-enablement via Workspace Provider Auth
CVSS 8.8
OpenClaw 2026.4.10 < 2026.4.14 - Missing Sender Authorization in Microsoft Teams SSO Invoke Handler
CVSS 5.3
OpenClaw < 2026.4.12 - Improper Authorization via Empty Approver Lists
CVSS 6.5
OpenClaw 2026.4.7 < 2026.4.15 - Arbitrary File Read via Unvalidated Tool-Result Media Paths
CVSS 5.8
OpenClaw 2026.4.7 < 2026.4.15 - Arbitrary File Read via Unvalidated Tool-Result Media Paths
CVSS 5.8
OpenClaw - Approval Bypass via Environment Variable Normalization
CVSS 7.6