Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Wentao He

#23254of 57,474
11.6Total CVSS
Vulnerabilities · 2
Medium
2
PT-2026-102775
6.3
2026-09-29
Openclaw · Openclaw · CVE-2026-102806
**Name of the Vulnerable Software and Affected Versions** OpenClaw versions prior to 2026.9.5 **Description** An incorrect authorization issue exists in the Gateway's local media root allowlist, which compromises filesystem isolation between sandboxed sessions. This allows sandboxed sessions or untrusted content to trigger the Gateway to read files from shared workspace directories or sibling session sandboxes via media pipeline functions that do not properly restrict reads to the active session. **Recommendations** Update to version 2026.9.5.
PT-2026-102776
5.3
2026-09-29
Openclaw · Openclaw · CVE-2026-102807
**Name of the Vulnerable Software and Affected Versions** OpenClaw versions prior to 2026.9.4 **Description** An incorrect authorization issue exists in the `mcp.app.view()` method. This flaw allows operators with `operator.read` tokens to obtain a standalone ticket and redeem it at the MCP app view endpoint to execute state-changing tools that should require `operator.write` scope. **Recommendations** Update OpenClaw to version 2026.9.4 or later. As a temporary mitigation, restrict access to the `mcp.app.view()` method for users with read-only permissions.