Vincent Koc
44 exploits
Active since Jun 2022
OpenClaw < 2026.3.31 - Sandbox Bypass via Heartbeat Context Inheritance and senderIsOwner Escalation
CVSS 9.9
OpenClaw < 2026.3.31 - Environment Variable Override via Host Exec Policy
CVSS 4.4
OpenClaw < 2026.3.22 - Arbitrary Code Execution via Unvalidated WebView JavascriptInterface
CVSS 8.8
OpenClaw < 2026.3.22 - Policy Bypass via Unvalidated Queued Node Actions
CVSS 3.7
OpenClaw < 2026.3.22 - Settings Reconciliation Bypass via Empty Allowlist
CVSS 6.5
OpenClaw < 2026.3.22 - Unauthorized Action Execution via Callback Dispatch
CVSS 6.5
OpenClaw < 2026.3.22 - Identity Spoofing via rawInput Tool in ACP Permission Resolution
CVSS 5.7
OpenClaw < 2026.3.22 - XFF Loopback Spoofing Bypass in Canvas Authentication and Rate Limiter
CVSS 6.5
OpenClaw < 2026.3.23 - Insufficient Access Control in Gateway Agent Session Reset
CVSS 8.1
OpenClaw < 2026.3.22 - Missing controlScope Enforcement in Send Action
CVSS 4.3
OpenClaw < 2026.3.23 - Replay Identity Drift via Query-Only Variants in Plivo V2 Verification
CVSS 6.5
OpenClaw < 2026.3.22 - Improper Authentication Verification in Google Chat Webhook
CVSS 5.9
OpenClaw < 2026.3.22 - Policy Confusion via Room Name Collision in Nextcloud Talk
CVSS 4.2
OpenClaw < 2026.3.22 - Missing Authorization Enforcement in Internal ACP Chat Commands
CVSS 6.5
OpenClaw < 2026.3.23 - Authentication Bypass via Local-Direct Requests in Canvas Gateway
CVSS 5.1
OpenClaw < 2026.3.22 - Privilege Escalation via device.pair.approve Scope Validation
CVSS 8.8
OpenClaw < 2026.3.22 - Credential Exposure via baseUrl Fields in Gateway Snapshots
CVSS 6.5
OpenClaw < 2026.2.21 - Client IP Spoofing via X-Forwarded-For Header Parsing
CVSS 5.3
Gtm4wp Google Tag Manager < 1.15.1 - XSS
CVSS 6.1