Peter Steinberger
249 exploits
Active since Feb 2026
OpenClaw < 2026.3.22 - Unbounded Memory Allocation via Remote Media Error Responses
CVSS 5.3
OpenClaw < 2026.3.23 - Authentication Bypass via Local-Direct Requests in Canvas Gateway
CVSS 5.1
OpenClaw < 2026.3.22 - Webhook Path Route Replacement Vulnerability in Synology Chat
CVSS 4.8
OpenClaw < 2026.3.22 - Premature Cite Expansion Before Authorization in Channel and DM
CVSS 7.3
OpenClaw < 2026.3.22 - Privilege Escalation via Self-Declared Scopes in Trusted-Proxy Control UI
CVSS 8.8
OpenClaw < 2026.3.22 - Privilege Escalation via device.pair.approve Scope Validation
CVSS 8.8
OpenClaw < 2026.3.22 - Credential Exposure via baseUrl Fields in Gateway Snapshots
CVSS 6.5
OpenClaw < 2026.3.24 - Missing Authorization in /send and /allowlist Chat Commands
CVSS 5.4
OpenClaw < 2026.3.22 - Arbitrary Code Execution via Unvalidated WebView JavascriptInterface
CVSS 8.8
OpenClaw < 2026.3.22 - Policy Bypass via Unvalidated Queued Node Actions
CVSS 3.7
OpenClaw < 2026.3.22 - Settings Reconciliation Bypass via Empty Allowlist
CVSS 6.5
OpenClaw < 2026.3.22 - Environment Variable Override Bypass via Inconsistent Sanitization
CVSS 7.5
OpenClaw < 2026.3.22 - Unauthorized Action Execution via Callback Dispatch
CVSS 6.5
OpenClaw < 2026.3.24 - Incorrect Authorization in POST /reset-profile via browser.request
CVSS 8.1
OpenClaw < 2026.3.22 - Identity Spoofing via rawInput Tool in ACP Permission Resolution
CVSS 5.7
OpenClaw < 2026.3.22 - XFF Loopback Spoofing Bypass in Canvas Authentication and Rate Limiter
CVSS 6.5
OpenClaw < 2026.3.2 - Filesystem Boundary Bypass in Image Tool
CVSS 6.5
OpenClaw < 2026.3.22 - Unresolved Service Metadata Routing via Bonjour and DNS-SD Discovery
CVSS 4.6
OpenClaw < 2026.3.23 - Insufficient Access Control in Gateway Agent Session Reset
CVSS 8.1
OpenClaw < 2026.3.22 - Missing controlScope Enforcement in Send Action
CVSS 4.3
OpenClaw < 2026.3.22 - Allowlist Bypass via Unregistered Time Dispatch Wrapper
CVSS 8.8
OpenClaw < 2026.3.22 - Webhook Reply Rebinding via Username Resolution in Synology Chat
CVSS 5.9
OpenClaw < 2026.3.31 - Fail-Open Security Scan Bypass in Plugin Installation
CVSS 4.6
OpenClaw < 2026.3.22 - Privilege Escalation via Unbound Bootstrap Setup Codes
CVSS 9.1
OpenClaw < 2026.3.22 - allowProfiles Bypass via Profile Mutation and Runtime Selection
CVSS 8.1