CVE-2026-35643
High Severity
Description
OpenClaw before 2026.3.22 contains an unvalidated WebView JavascriptInterface vulnerability allowing attackers to inject arbitrary instructions. Untrusted pages ...
Related Vulnerabilities
- CVE-2026-40103: Vikunja: Scoped API tokens with projects.background permission can delete project backgrounds MEDIUM
- CVE-2026-35657: OpenClaw before 2026.3.25 contains an authorization bypass vulnerability in the HTTP /sessions/:sess HIGH
- CVE-2026-35641: OpenClaw before 2026.3.24 contains an arbitrary code execution vulnerability in local plugin and hoo HIGH
- CVE-2026-6026: A security flaw has been discovered in Totolink A7100RU 7.4cu.2313_b20191024. This vulnerability aff CRITICAL
- CVE-2026-34480: Apache Log4j Core's XmlLayout https://logging.apache.org/log4j/2.x/manual/layouts.html#XmlLayout , i MEDIUM
Related Coverage
Threat Actors