Peter Steinberger
249 exploits
Active since Feb 2026
OpenClaw <2026.2.13 - Command Injection
CVSS 7.6
OpenClaw < 2026.2.19 - Server-Side Request Forgery via Cron Webhook Delivery
CVSS 7.3
OpenClaw < 2026.2.14 - Unauthenticated Webhook Spoofing via Missing Telnyx Signature Verification
CVSS 7.5
OpenClaw macOS 2026.2.6-2026.2.13 - Command Injection
CVSS 6.5
OpenClaw <2026.2.14 - Path Traversal
CVSS 7.5
OpenClaw < 2026.2.14 - Server-Side Request Forgery via Gateway Tool URL Override
CVSS 7.6
OpenClaw 2026.1.8-2026.2.13 - Command Injection
CVSS 8.8
OpenClaw < 2026.2.14 - Server-Side Request Forgery via IPv6 Literal Bypass
CVSS 7.5
OpenClaw <2026.2.14 - Command Injection
CVSS 7.2
OpenClaw <2026.2.14 - Info Disclosure
CVSS 4.3
OpenClaw < 2026.2.14 - Unauthenticated TLS Certificate Pinning Bypass via Discovery Beacon TXT Records
CVSS 6.5
OpenClaw <2026.2.14 - Privilege Escalation
CVSS 6.5
OpenClaw <2026.2.14 - Path Traversal
CVSS 6.5
OpenClaw <2026.2.15 - Command Injection
CVSS 7.8
OpenClaw <2026.2.15 - Privilege Escalation
CVSS 9.8
OpenClaw <2026.2.15 - Info Disclosure
CVSS 5.5
OpenClaw <2026.2.15 - Privilege Escalation
CVSS 5.5
OpenClaw <2026.2.15 - Privilege Escalation
CVSS 3.3
OpenClaw <2026.2.15 - Path Traversal
CVSS 6.7
OpenClaw < 2026.2.15 - Stored Cross-Site Scripting via Assistant Identity Rendering
CVSS 5.8
OpenClaw < 2026.2.14 - Cross-Site Request Forgery via Unvalidated Origin/Referer
CVSS 7.1
OpenClaw <=2026.2.2 - Command Injection
CVSS 3.7
OpenClaw < 2026.2.1 - Insufficient Verification of Telegram Webhook Secret Token
CVSS 7.5
OpenClaw < 2026.1.29 - Authenticated OS Command Injection via PATH Environment Variable
CVSS 8.8