VYPR

openclaw-cn

by OpenClaw

CVEs (5)

  • CVE-2026-19008MedAug 6, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was identified in mf-yang openclaw-cn up to 0.2.1. This issue affects the function assertNoSymlinkEscape of the file src/agents/sandbox-paths.ts of the component apply_patch Tool. Such manipulation leads to link following. It is possible to launch the attack…

  • CVE-2026-19007MedAug 6, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was determined in mf-yang openclaw-cn up to 0.2.1. This vulnerability affects the function isApprovedElevatedSender of the file src/auto-reply/reply/reply-elevated.ts. This manipulation causes improper privilege management. It is possible to initiate the attack…

  • CVE-2026-19006MedAug 6, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was found in mf-yang openclaw-cn 2026.2.5. This affects an unknown part of the file src/agents/bash-tools.exec.ts of the component Ggateway Exec Approval Flow. The manipulation results in incorrect authorization. The attack may be performed from remote. The…

  • CVE-2026-17458MedJul 26, 2026
    risk 0.00cvss 6.3epss 0.00

    A vulnerability was found in mf-yang openclaw-cn up to 0.2.1. This affects the function clickViaPlaywright of the file src/browser/routes/agent.act.ts of the component Browser Control HTTP API. Performing a manipulation results in server-side request forgery. It is possible to…

  • CVE-2026-17457MedJul 26, 2026
    risk 0.00cvss 4.3epss 0.00

    A vulnerability has been found in mf-yang openclaw-cn up to 0.2.1. Affected by this issue is the function assertBrowserNavigationAllowed of the file src/browser/navigation-guard.ts of the component Scheme Handler. Such manipulation of the argument url leads to information…