Peter Steinberger
249 exploits
Active since Feb 2026
CodexBar < 0.33.0 Credential Leakage via HTTP Redirect
CVSS 5.3
Summarize < 0.15.1 Path Traversal via slidesDir Parameter
CVSS 7.1
OpenClaw < 2026.4.20 - Server-Side Request Forgery via Browser CDP Profile Creation
CVSS 5.0
OpenClaw < 2026.4.5 - Second-hop SSRF via CDP /json/version WebSocket URL
CVSS 7.7
OpenClaw 2026.3.22 < 2026.4.5 - Symlink Traversal in Remote Marketplace Repository Path Handling
CVSS 6.5
OpenClaw < 2026.2.26 - Approval Bypass via Parent Symlink Current Working Directory Rebind
CVSS 6.1
OpenClaw < 2026.2.22 BlueBubbles - Access Control Bypass via Empty allowFrom Configuration
CVSS 6.5
OpenClaw < 2026.2.26 - Approval Bypass via Parent Symlink Current Working Directory Rebind
CVSS 6.1
OpenClaw < 2026.3.2 - Authentication Bypass via Encoded Path in /api/channels Route
CVSS 6.5
OpenClaw < 2026.2.22 - Incomplete IPv4 Special-Use Range Blocking in SSRF Guard
CVSS 7.4
OpenClaw < 2026.3.31 - Fail-Open Security Scan Bypass in Plugin Installation
CVSS 4.6
OpenClaw < 2026.2.22 BlueBubbles - Access Control Bypass via Empty allowFrom Configuration
CVSS 6.5
OpenClaw < 2026.2.19 - Path Traversal in Feishu Media Temporary File Naming
CVSS 8.2
OpenClaw < 2026.2.26 - Approval Bypass via Parent Symlink Current Working Directory Rebind
CVSS 6.1
OpenClaw < 2026.3.2 - Authentication Bypass via Encoded Path in /api/channels Route
CVSS 6.5
OpenClaw < 2026.2.19 - Arbitrary File Write via Short-Option Bypass in exec Allowlist
CVSS 7.1
OpenClaw < 2026.2.22 - Incomplete IPv4 Special-Use Range Blocking in SSRF Guard
CVSS 7.4
OpenClaw < 2026.2.24 - Arbitrary File Read via Improper Temporary Path Validation in Sandbox
CVSS 6.5
OpenClaw < 2026.3.22 - Remote File URL Acceptance in Windows Media Loaders
CVSS 5.3
OpenClaw < 2026.3.24 - Missing Authorization in /send and /allowlist Chat Commands
CVSS 5.4
OpenClaw < 2026.3.2 - Filesystem Boundary Bypass in Image Tool
CVSS 6.5
OpenClaw < 2026.3.31 - Fail-Open Security Scan Bypass in Plugin Installation
CVSS 4.6
OpenClaw < 2026.2.22 BlueBubbles - Access Control Bypass via Empty allowFrom Configuration
CVSS 6.5
OpenClaw < 2026.2.26 - Approval Bypass via Parent Symlink Current Working Directory Rebind
CVSS 6.1
OpenClaw < 2026.2.26 - Authorization Bypass via DM Pairing-Store Leakage in Signal Group Allowlist
CVSS 3.7