CRITICAL
GHSASUPPLY-CHAINCVE-2026-50027
2026-07-02
Missing authentication on API endpoints allows unauthenticated memory read/write/delete, potentially leading to data exposure and unauthorized access.
HIGH
NVDSUPPLY-CHAINCVE-2026-8147
2026-07-02
Vulnerability allows authenticated users to bypass experiment-level authorization controls, exposing sensitive data and allowing unauthorized modifications.
HIGH
GHSASUPPLY-CHAINCVE-2026-52830
2026-07-02
An attacker can access the Telegram account represented by the default session file without knowing a generated bearer token.
2026-07-02
Fail-open authorization in the MCP tool layer allows malicious agents to perform cross-task and cross-session mutations.
HIGH
GHSASUPPLY-CHAINCVE-2026-53818
2026-07-02
A vulnerability in OpenClaw could allow non-owner callers to skip owner-only tool policy, potentially leading to unauthorized behavior.
HIGH
GHSASUPPLY-CHAINCVE-2026-53814
2026-07-02
A caller with the hook token could cause the spawned CLI runtime to see or call MCP tools that should have been owner-only.
2026-07-02
A vulnerability in OpenClaw could allow an attacker to bypass denylists and gain broader command reach.