VulnScope — package-centric CVE lookup- LOW3.7CVE-2026-35648EPSS 0.03%OpenClaw may have stale policy enforcement for queued node actions
- LOW3.7EPSS 0.02%h3: Missing Path Segment Boundary Check in `mount()` Causes Middleware Execution on Unrelated Prefix-Matching Routes
- LOW2.7EPSS 0.03%StudioCMS REST getUsers Exposes Owner Account Records to Admin Tokens
- LOW2.5EPSS 0.02%OpenClaw: Unavailable local auth SecretRefs could fall through to remote credentials in local mode
- LOW3.1EPSS 0.01%Keycloak vulnerable to authorization bypass via the Admin API
- LOW2.0EPSS 0.01%@backstage/plugin-scaffolder-backend Vulnerable to Potential Session Token Exfiltration via Log Redaction Bypass
- LOW2.7EPSS 0.01%Backstage vulnerable to potential reading of SCM URLs using built in token
- LOW3.7EPSS 0.04%OpenClaw has cross-account DM pairing authorization bypass via unscoped pairing store access
- LOW3.4EPSS 0.02%Dark Reader gives users the ability to request style sheets from local web servers
- LOW3.7EPSS 0.04%OpenClaw: Discord DM reaction ingress missed dmPolicy/allowFrom checks in restricted setups
- LOW3.3EPSS 0.02%@tootallnate/once vulnerable to Incorrect Control Flow Scoping
- LOW2.6EPSS 0.04%OpenClaw Node system.run approval context-binding weakness in approval-enabled host=node flows
- LOW3.3EPSS 0.02%OpenClaw's Control UI Static File Handler Follows Symlinks and Allows Out-of-Root File Read
- LOW3.7EPSS 0.04%OpenClaw has Signal group allowlist authorization bypass via DM pairing-store leakage
- LOW3.6EPSS 0.02%OpenClaw safeBins stdin-only bypass via sort output and recursive grep flags
- LOW3.7EPSS 0.04%OpenClaw Affected by Remote Code Execution via System Prompt Injection in Slack Channel Descriptions
- LOW3.7EPSS 0.05%qs's arrayLimit bypass in comma parsing allows denial of service
- LOW2.9EPSS 0.01%ajv has ReDoS when using `$data` option
- LOW3.7EPSS 0.01%webpack buildHttp: allowedUris allow-list bypass via URL userinfo (@) leading to build-time SSRF behavior
- LOW3.7EPSS 0.01%webpack buildHttp HttpUriPlugin allowedUris bypass via HTTP redirects → SSRF + cache persistence
- LOW3.7EPSS 0.02%Fastify Vulnerable to DoS via Unbounded Memory Allocation in sendWebStream
- LOW3.5EPSS 0.04%Backstage has a Possible SSRF when reading from allowed URL's in `backend.reading.allow`
- LOW3.7EPSS 0.07%Lobe Chat has IDOR in Knowledge Base File Removal that Allows Cross User File Deletion
- LOW3.7EPSS 0.06%Outray cli is vulnerable to race conditions in tunnels creation
- LOW3.5EPSS 0.08%QuestDB UI's Web Console is Vulnerable to Cross-Site Scripting