Peter Steinberger
176 exploits
Active since Feb 2026
OpenClaw < 2026.2.22 - Sender Authorization Bypass via Identity Collision in toolsBySender
CVSS 5.9
OpenClaw < 2026.2.19 - Command Injection via Unescaped Environment Variables in Windows Scheduled Task Script Generation
CVSS 6.1
OpenClaw < 2026.2.22 - Allowlist Bypass via Wrapper Binary Unwrapping in system.run
CVSS 7.1
OpenClaw < 2026.3.2 - Arbitrary File Write via ZIP Extraction Parent Symlink Race Condition
CVSS 5.3
OpenClaw < 2026.2.25 - Webhook Replay Attack via Missing Durable Replay Suppression
CVSS 6.5
OpenClaw < 2026.2.22 - Allowlist Bypass via Shell Line-Continuation Command Substitution in system.run
CVSS 7.1
OpenClaw < 2026.2.22 - Authorization Bypass via allow-always Wrapper Persistence
CVSS 6.8
OpenClaw 2026.3.1 < 2026.3.2 - Approval Integrity Bypass via system.run argv Rewriting
CVSS 6.7
OpenClaw < 2026.3.2 - Symlink Traversal in stageSandboxMedia Destination
CVSS 6.1
OpenClaw < 2026.2.26 - Authorization Bypass via DM Pairing-Store Leakage in Signal Group Allowlist
CVSS 3.7
OpenClaw < 2026.2.23 - Allowlist Exec-Guard Bypass via env -S
CVSS 7.1
OpenClaw < 2026.2.22 - Allowlist Parsing Mismatch in system.run Shell Chains
CVSS 4.8
OpenClaw < 2026.2.19 - Local Command Injection via Unsafe cmd Argument Handling in Windows Scheduled Task Script Generation
CVSS 7.1
OpenClaw 2026.1.21 < 2026.2.19 - Command Injection via Windows Shell Fallback in Lobster Extension
CVSS 5.3
OpenClaw < 2026.2.19 - safeBins stdin-only bypass via sort output and recursive grep flags
CVSS 4.4
OpenClaw 2026.2.22 < 2026.2.24 - Authorization Bypass in Synology Chat Plugin via Empty allowedUserIds
CVSS 8.6
OpenClaw < 2026.2.19 - Command Injection via Windows Shell Fallback in Lobster Tool Execution
CVSS 7.1
OpenClaw < 2026.2.21 - Command Injection via cmd.exe /c Trailing Arguments in system.run
CVSS 6.5
OpenClaw < 2026.2.22 - Allowlist Bypass via sort Configuration in safeBins
CVSS 6.7
OpenClaw < 2026.2.22 BlueBubbles - Access Control Bypass via Empty allowFrom Configuration
CVSS 6.5
OpenClaw < 2026.2.19 - Path Traversal in Feishu Media Temporary File Naming
CVSS 8.2
OpenClaw < 2026.2.22 - Gateway Token Disclosure via Chrome CDP Probe
CVSS 6.8
OpenClaw < 2026.2.23 - Exec Approval Bypass via Unrecognized Multiplexer Shell Wrappers
CVSS 7.1
OpenClaw < 2026.2.21 - Environment Variable Injection via Config env.vars
CVSS 6.1
OpenClaw < 2026.2.19 - ReDoS and Regex Injection via Unescaped Feishu Mention Metadata
CVSS 6.5