CVE-2026-35643
High Severity
Description
OpenClaw before 2026.3.22 contains an unvalidated WebView JavascriptInterface vulnerability allowing attackers to inject arbitrary instructions. Untrusted pages ...
Related Vulnerabilities
- CVE-2026-4057: The Download Manager plugin for WordPress is vulnerable to unauthorized modification of data due to MEDIUM
- CVE-2026-35651: OpenClaw versions 2026.2.13 through 2026.3.24 contain an ANSI escape sequence injection vulnerabilit MEDIUM
- CVE-2026-39315: Unhead has a hasDangerousProtocol() bypass via leading-zero padded HTML entities in useHeadSafe() MEDIUM
- CVE-2026-34971: Wasmtime: Miscompiled guest heap access enables sandbox escape on aarch64 Cranelift MEDIUM
- CVE-2026-6067: A heap buffer overflow vulnerability exists in the Netwide Assembler (NASM) due to a lack of bounds HIGH
Related Coverage
Threat Actors