Peter Steinberger
249 exploits
Active since Feb 2026
OpenClaw <2026.2.14 - Command Injection
CVSS 9.9
OpenClaw < 2026.2.2 - Server-Side Request Forgery via Attachment and Media URL Hydration
CVSS 6.5
OpenClaw 2026.1.29-beta.1-2026.2.14 - Unauthenticated Browser Control Endpoint Access via Sandbox Bridge Server
CVSS 7.7
OpenClaw < 2026.2.14 - Authorization Bypass via Google Chat Webhook Path Ambiguity
CVSS 7.5
OpenClaw <2026.2.2 - Command Injection
CVSS 9.8
OpenClaw 2026.1.14-1-2026.2.2 - Improper Authentication via Display Name and Localpart Matching
CVSS 5.3
OpenClaw < 2026.2.2 - Unauthenticated Device Identity Check Bypass via Gateway WebSocket Connect Handshake
CVSS 8.1
OpenClaw Nextcloud Talk <2026.2.6 - Auth Bypass
CVSS 9.8
OpenClaw <2026.2.13 - Info Disclosure
CVSS 4.8
OpenClaw < 2026.2.14 - Server-Side Request Forgery via Tlon Urbit Extension Authentication
CVSS 8.3
OpenClaw < 2026.2.14 - Cross-Site Request Forgery via OAuth State Validation Bypass
CVSS 7.1
OpenClaw < 2026.2.13 - Unauthenticated Denial of Service via Webhook Request Body Buffering
CVSS 7.5
OpenClaw <2026.2.15 - Cache Poisoning
CVSS 7.5
OpenClaw < 2026.2.14 - Authentication Bypass via Telegram Username Spoofing
CVSS 6.5
OpenClaw <2026.1.30 - Info Disclosure
CVSS 6.5
OpenClaw <2026.2.12 - Path Traversal
CVSS 7.1
OpenClaw 2026.1.5-2026.2.12 - Auth Bypass
CVSS 8.4
OpenClaw 2026.1.16-2 - Path Traversal
CVSS 6.1
OpenClaw < 2026.2.14 - Unauthenticated Webhook Signature Verification Bypass via Ngrok Loopback Compatibility
CVSS 6.5
OpenClaw < 2026.2.14 - Denial of Service via Unbounded URL-Backed Media Fetch
CVSS 7.5
OpenClaw <2026.2.14 - Command Injection
CVSS 8.8
OpenClaw < 2026.2.14 - Denial of Service via Large Base64 Media File Decoding
CVSS 5.5
OpenClaw <2026.2.17 - Privilege Escalation
CVSS 4.3
OpenClaw <=2026.2.17 - Info Disclosure
CVSS 4.4
OpenClaw CLI <2026.2.13 - Privilege Escalation
CVSS 5.3