MEDIUM5.8CVE-2026-55591Signal K Server: Server-Side Request Forgery via Remote Connection Endpoints
MEDIUM5.4OpenClaw: Empty-scope device re-pairing could confuse caller scope containment
MEDIUM4.2OpenClaw: BlueBubbles sender policy could match mutable conversation identifiers
MEDIUM6.5OpenClaw: memory-wiki shared search could miss session visibility checks
MEDIUM5.5OpenClaw: Config recovery could restore openclaw.json with broad file permissions
MEDIUM4.3OpenClaw: Skill-command dispatch could skip before-tool-call hooks
MEDIUM6.1OpenClaw: Exported session HTML could keep unsafe markdown links
MEDIUM5.3OpenClaw: Slack reaction events could ignore reaction notification settings
MEDIUM4.2OpenClaw: Bootstrap token replay could widen pending pairing scopes
MEDIUM6.5OpenClaw: Hostname checks could treat trailing-dot hosts inconsistently
MEDIUM4.3OpenClaw: Exec allowlist could miss side effects from transparent command wrappers
MEDIUM6.5NL Portal Backend Libraries: Document contents remained downloadable by any logged-in user (incomplete fix of CVE-2026-49463)
LOW2.2BBOT: Symlink-Following Arbitrary Write via github_workflows Module
MEDIUM6.5BBOT: Arbitrary File Write in postman_download Module
LOW3.1BBOT: Server-Side Request Forgery (SSRF) in docker_pull module via WWW-Authenticate realm parsing
MEDIUM5.3BBOT: Path traversal (Zip-Slip) in unarchive module - incomplete fix for CVE-2025-10284
MEDIUM6.6OpenClaw: macOS Swift exec allowlist missed combined POSIX inline flags
MEDIUM5.4Strimzi: Unrestricted access to all Secrets within namespace watched by the Topic operator
MEDIUM6.1marimo contains a reflected cross-site scripting vulnerability in the notebook page
MEDIUM5.9undici vulnerable to cross-user information disclosure via shared cache whitespace bypass
MEDIUM6.0OpenStack Horizon RC file generation does not escape special characters in project names
MEDIUM6.5Apache DolphinScheduler: An incorrect authorization vulnerability allows authenticated users to access alert instances associated with alert groups they do not have permission to access.
MEDIUM6.5Apache DolphinScheduler: Incorrect Authorization vulnerability allows users to access workflow instance information belonging to projects they do not have permission to access.
MEDIUM4.9Apache DolphinScheduler: Incorrect Authorization vulnerability allows users with system login privileges to delete task definitions in unauthorized projects
MEDIUM5.3webpack-dev-server vulnerable to HMR WebSocket interception via permissive user proxies