VulnScope — package-centric CVE lookup- MEDIUM5.8CVE-2026-55591Signal K Server: Server-Side Request Forgery via Remote Connection Endpoints
- CRITICAL9.8gemini-mcp-tool vulnerable to OS command injection and @file exfiltration via prompt quoting (CVE-2026-0755)
- —OpenClaw: Internal/webchat command auth could inherit ownerAllowFrom wildcard state
- MEDIUM5.4OpenClaw: Empty-scope device re-pairing could confuse caller scope containment
- HIGH7.1OpenClaw: Workspace-derived service PATH could influence trash command selection
- HIGH7.1OpenClaw: Workspace .env STATE_DIRECTORY could influence bundled runtime dependency roots
- HIGH8.1OpenClaw: Discord allowFrom could bind to mutable display names
- —OpenClaw: Focus command could miss controlScope enforcement
- HIGH7.1OpenClaw: Workspace .env npm_execpath could influence bundled runtime dependency install
- HIGH7.1OpenClaw: Linux and macOS exec allowlists skipped configured argument patterns
- MEDIUM4.2OpenClaw: BlueBubbles sender policy could match mutable conversation identifiers
- MEDIUM6.5OpenClaw: memory-wiki shared search could miss session visibility checks
- MEDIUM5.5OpenClaw: Config recovery could restore openclaw.json with broad file permissions
- HIGH8.1OpenClaw: Zalo allowFrom could bind to mutable display names
- MEDIUM4.3OpenClaw: Skill-command dispatch could skip before-tool-call hooks
- —OpenClaw: Active Memory write scope could mutate global config
- MEDIUM6.1OpenClaw: Exported session HTML could keep unsafe markdown links
- MEDIUM5.3OpenClaw: Slack reaction events could ignore reaction notification settings
- MEDIUM4.2OpenClaw: Bootstrap token replay could widen pending pairing scopes
- HIGH8.1OpenClaw: Shell positional parameters could weaken strict inline-eval checks
- MEDIUM6.5OpenClaw: Hostname checks could treat trailing-dot hosts inconsistently
- MEDIUM4.3OpenClaw: Exec allowlist could miss side effects from transparent command wrappers
- LOW3.1BBOT: Server-Side Request Forgery (SSRF) in docker_pull module via WWW-Authenticate realm parsing
- MEDIUM5.3BBOT: Path traversal (Zip-Slip) in unarchive module - incomplete fix for CVE-2025-10284
- MEDIUM6.6OpenClaw: macOS Swift exec allowlist missed combined POSIX inline flags