MEDIUM5.8CVE-2026-55591Signal K Server: Server-Side Request Forgery via Remote Connection Endpoints
MEDIUM5.4OpenClaw: Empty-scope device re-pairing could confuse caller scope containment
MEDIUM4.2OpenClaw: BlueBubbles sender policy could match mutable conversation identifiers
MEDIUM6.5OpenClaw: memory-wiki shared search could miss session visibility checks
MEDIUM5.5OpenClaw: Config recovery could restore openclaw.json with broad file permissions
MEDIUM4.3OpenClaw: Skill-command dispatch could skip before-tool-call hooks
MEDIUM6.1OpenClaw: Exported session HTML could keep unsafe markdown links
MEDIUM5.3OpenClaw: Slack reaction events could ignore reaction notification settings
MEDIUM4.2OpenClaw: Bootstrap token replay could widen pending pairing scopes
MEDIUM6.5OpenClaw: Hostname checks could treat trailing-dot hosts inconsistently
MEDIUM4.3OpenClaw: Exec allowlist could miss side effects from transparent command wrappers
MEDIUM6.5NL Portal Backend Libraries: Document contents remained downloadable by any logged-in user (incomplete fix of CVE-2026-49463)
MEDIUM6.6OpenClaw: macOS Swift exec allowlist missed combined POSIX inline flags
MEDIUM5.4Strimzi: Unrestricted access to all Secrets within namespace watched by the Topic operator
MEDIUM5.9undici vulnerable to cross-user information disclosure via shared cache whitespace bypass
MEDIUM6.5Apache DolphinScheduler: An incorrect authorization vulnerability allows authenticated users to access alert instances associated with alert groups they do not have permission to access.
MEDIUM6.5Apache DolphinScheduler: Incorrect Authorization vulnerability allows users to access workflow instance information belonging to projects they do not have permission to access.
MEDIUM4.9Apache DolphinScheduler: Incorrect Authorization vulnerability allows users with system login privileges to delete task definitions in unauthorized projects
MEDIUM5.3webpack-dev-server vulnerable to HMR WebSocket interception via permissive user proxies
MEDIUM5.3Multer vulnerable to Denial of Service via incomplete cleanup of aborted uploads
MEDIUM6.1Chrome DevTools for agents: daemon.pid write follows symlinks in /tmp fallback runtime directory
MEDIUM4.4Pi Agent: Pi loads project-local extensions without approval
LOW2.2Pi Agent: Race condition in Pi auth.json writes could expose stored credentials
LOW2.5Pi Agent: Potential XSS in HTML session exports via Markdown URL sanitization bypass
MEDIUM5.9n8n: Denial of Service via ZIP decompression in webhook workflow