CVE-2026-35667
Medium Severity
Description
OpenClaw before 2026.3.24 contains an incomplete fix for CVE-2026-27486 where the !stop chat command uses an unpatched killProcessTree function from shell-util...
Related Vulnerabilities
- CVE-2026-40154: PraisonAI is a multi-agent teams system. Prior to 4.5.128, PraisonAI treats remotely fetched templat CRITICAL
- CVE-2026-35664: OpenClaw before 2026.3.25 contains an authentication bypass vulnerability in raw card send surface t MEDIUM
- CVE-2026-23780: An issue was discovered in BMC Control-M/MFT 9.0.20 through 9.0.22. A SQL injection vulnerability in HIGH
- CVE-2026-33455: Livestatus injection in the monitoring quicksearch in Checkmk <2.5.0b4 allows an authenticated attac MEDIUM
- CVE-2026-35666: OpenClaw before 2026.3.22 contains an allowlist bypass vulnerability in system.run approvals that fa HIGH
Related Coverage
Threat Actors