VYPR

clawhub

by OpenClaw

CVEs (5)

  • CVE-2026-100602MedSep 26, 2026
    risk 0.35cvss 6.5epss —

    ClawHub (openclaw/clawhub application/backend) contains a missing authorization check in the changelog preview feature. A signed-in caller can invoke the public skills:generateChangelogPreview action for a skill they are not authorized to access; the previous version is read…

  • CVE-2026-100604MedSep 26, 2026
    risk 0.28cvss 5.4epss —

    ClawHub (openclaw/clawhub) contains an incorrect authorization vulnerability in the ClawHub application/backend: an organization-owned skill retains the ownerUserId of its original publisher, and transfer and lifecycle authorization checks trust that historical user before…

  • CVE-2026-100603MedSep 26, 2026
    risk 0.28cvss 5.4epss —

    ClawHub (openclaw/clawhub) application/backend contains a flaw in the skill report moderation flow: four distinct ordinary authenticated accounts can report a visible skill and trigger automatic hiding (moderationStatus: hidden) of that skill from the catalog without any…

  • CVE-2026-100601MedSep 26, 2026
    risk 0.27cvss 5.3epss —

    ClawHub (openclaw/clawhub) application/backend contains a server-side request forgery vulnerability in the public profile preview's image fetching. The preview accepts a user-supplied image URL and checks the textual hostname against private-address patterns, but does not…

  • CVE-2026-100600MedSep 26, 2026
    risk 0.27cvss 5.3epss —

    ClawHub (the openclaw/clawhub application/backend) does not bind anonymous HTTP API requests to a trusted caller identity, so all direct anonymous API requests share a single default quota allowance. A remote, unauthenticated caller can drain that shared allowance and thereby…