Peter Steinberger
249 exploits
Active since Feb 2026
OpenClaw < 2026.2.23 - Allowlist Exec-Guard Bypass via env -S
CVSS 7.1
OpenClaw < 2026.2.22 - Allowlist Parsing Mismatch in system.run Shell Chains
CVSS 4.8
OpenClaw 2026.2.22 < 2026.2.24 - Authorization Bypass in Synology Chat Plugin via Empty allowedUserIds
CVSS 8.6
OpenClaw < 2026.3.2 - Authentication Bypass via Encoded Path in /api/channels Route
CVSS 6.5
OpenClaw < 2026.2.19 - Arbitrary File Write via Short-Option Bypass in exec Allowlist
CVSS 7.1
OpenClaw < 2026.2.22 - Incomplete IPv4 Special-Use Range Blocking in SSRF Guard
CVSS 7.4
OpenClaw < 2026.2.22 - Symlink Traversal in Avatar Handling
CVSS 5.5
OpenClaw < 2026.2.24 - Arbitrary File Read via Improper Temporary Path Validation in Sandbox
CVSS 6.5
OpenClaw < 2026.2.26 - Improper Authorization via DM Pairing Store Identity Inheritance in Group Allowlist
CVSS 6.5
OpenClaw < 2026.2.22 - Redirect Chain Bypass of Media Host Allowlist in MSTeams Attachment Handling
CVSS 6.0
OpenClaw < 2026.2.24 - Hidden Command Execution via Shell-Wrapper Positional argv Carriers
CVSS 6.4
OpenClaw < 2026.2.26 - Workspace Path Boundary Bypass via Non-existent Symlink
CVSS 7.6
OpenClaw < 2026.2.21 - Missing VNC Authentication in Sandbox Browser noVNC Observer
CVSS 7.7
OpenClaw < 2026.2.26 - Cross-Account Authorization Bypass in DM Pairing Store
CVSS 3.7
OpenClaw < 2026.2.21 - Unauthenticated Webhook Access via Passwordless Fallback in BlueBubbles Plugin
CVSS 4.8
OpenClaw < 2026.2.23 - ACP Permission Auto-Approval Bypass via Untrusted Tool Metadata
CVSS 5.4
OpenClaw < 2026.2.25 - Sender Policy Bypass in Slack Reaction and Pin Event Handlers
CVSS 4.3
OpenClaw < 2026.3.7 - Custom Authorization Header Leakage via Cross-Origin Redirects
CVSS 9.3
OpenClaw < 2026.3.8 - Script Content Modification via Mutable Operand Binding in system.run
CVSS 6.3
OpenClaw < 2026.3.22 - Remote File URL Acceptance in Windows Media Loaders
CVSS 5.3
OpenClaw < 2026.3.23 - Replay Identity Drift via Query-Only Variants in Plivo V2 Verification
CVSS 6.5
OpenClaw < 2026.3.22 - Improper Authentication Verification in Google Chat Webhook
CVSS 5.9
OpenClaw < 2026.3.22 - Policy Confusion via Room Name Collision in Nextcloud Talk
CVSS 4.2
OpenClaw < 2026.3.22 - Unauthenticated Resource Exhaustion via Voice Call Webhook
CVSS 5.3
OpenClaw < 2026.3.22 - Missing Authorization Enforcement in Internal ACP Chat Commands
CVSS 6.5