VYPR

diagnostics-prometheus

by OpenClaw

CVEs (1)

  • CVE-2026-100525MedSep 26, 2026
    risk 0.21cvss 4.3epss —

    The OpenClaw Prometheus diagnostics plugin (@openclaw/diagnostics-prometheus) before version 2026.9.3 does not enforce the operator.read scope on its authenticated metrics endpoint. In deployments using an identity-bearing Gateway authentication mode such as trusted-proxy, a…