Vincent Koc
44 exploits
Active since Jun 2022
OpenClaw < 2026.3.31 - Access Control Bypass in Discord Voice Manager via Channel Allowlist
CVSS 5.4
OpenClaw < 2026.3.31 - Discord Voice Ingress Authorization Bypass via Channel and Role Validation Gaps
CVSS 5.4
OpenClaw < 2026.3.31 - Nostr Private Key Exposure via config.get Redaction Bypass
CVSS 6.5
OpenClaw < 2026.3.31 - Environment Variable Bypass in Package Index URL Handling
CVSS 5.3
OpenClaw < 2026.3.31 - Unauthorized Operator Scope Access in Unauthenticated Plugin-Auth Routes
CVSS 8.2
OpenClaw < 2026.3.31 - Environment Variable Override of Plugin Trust Root
CVSS 7.8
OpenClaw < 2026.3.31 - Resource Consumption via Oversized WebSocket Frames in voice-call
CVSS 5.3
OpenClaw < 2026.3.31 - Webhook Replay Cache Cross-Target messageId Scope Bypass
CVSS 4.2
OpenClaw < 2026.3.31 - Sender Allowlist Bypass via Thread History and Quoted Messages
CVSS 5.4
OpenClaw < 2026.3.31 - Disk Exhaustion via Media Download Bypass
CVSS 4.3
OpenClaw 2026.2.19 < 2026.3.31 - Webhook Replay Dedupe Cache Event Suppression via Shared Authentication
CVSS 4.3
OpenClaw < 2026.3.31 - Arbitrary File Write via Symlink Following in SSH Sandbox Tar Upload
CVSS 8.1
OpenClaw < 2026.3.31 - Insufficient Environment Variable Sanitization in Host Execution
CVSS 6.5
OpenClaw < 2026.3.31 - Authentication Rate Limiting Bypass via Fake DeviceToken
CVSS 3.7
OpenClaw < 2026.3.31 - Decompression Bomb Denial of Service via Image Pixel-Limit Guard Bypass
CVSS 6.5
OpenClaw < 2026.3.31 - Arbitrary Hook Code Execution via OPENCLAW_BUNDLED_HOOKS_DIR Environment Variable Override
CVSS 7.8
OpenClaw < 2026.3.31 - Callback Origin Mutation in Plivo Voice-call Replay
CVSS 5.3
OpenClaw < 2026.3.31 - Denial of Service via LINE Webhook Handler Pre-Auth Concurrency
CVSS 5.3
OpenClaw < 2026.3.31 - Authorization Header Leak via Cross-Origin Redirect in Media Download
CVSS 5.3
OpenClaw 2026.2.26 < 2026.3.31 - Denial of Service via Improper Pending Pairing Request Cap Enforcement
CVSS 5.3
OpenClaw < 2026.3.31 - Cross-Site Request Forgery via Missing Browser-Origin Validation in HTTP Operator Endpoints
CVSS 7.1
OpenClaw < 2026.3.31 - Incomplete WebSocket Session Termination in device.token.rotate
CVSS 5.4
OpenClaw < 2026.3.31 - Sandbox Escape via TOCTOU Race in Remote FS Bridge readFile
CVSS 8.2
OpenClaw < 2026.4.2 - Authorization Bypass in Session Termination Endpoint
CVSS 5.4
OpenClaw 2026.3.22 < 2026.3.31 - Forged Nostr DM Pairing State Creation via Signature Verification Bypass
CVSS 5.3