<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Exploit Intel — cwe-78</title><link>https://exploit-intel.com/blog/tags/cwe-78/</link><description>EIP research articles tagged cwe-78.</description><language>en-us</language><atom:link href="https://exploit-intel.com/blog/tags/cwe-78/index.xml" rel="self" type="application/rss+xml"/><lastBuildDate>Mon, 09 Mar 2026 12:00:00 -0400</lastBuildDate><item><title>CVE-2026-28391: OpenClaw Command Injection - The Day I Hacked Myself</title><link>https://exploit-intel.com/blog/posts/cve-2026-28391-openclaw-command-injection-the-day-i-hacked-myself/</link><guid isPermaLink="true">https://exploit-intel.com/blog/posts/cve-2026-28391-openclaw-command-injection-the-day-i-hacked-myself/</guid><description>CVE-2026-28391 is a CVSS 9.8 command injection in OpenClaw &lt; 2026.2.2, caused by a POSIX vs cmd.exe shell-parsing mismatch. Our own suggestion algorithm ranked it as the most interesting CVEForge target. 8/8 bypass vectors confirmed, code execution verified. This is the story of the day our orchestration layer dispatched a full vulnerability assessment against itself.</description><pubDate>Mon, 09 Mar 2026 12:00:00 -0400</pubDate></item></channel></rss>
