CVE-2026-35643
High Severity
Description
OpenClaw before 2026.3.22 contains an unvalidated WebView JavascriptInterface vulnerability allowing attackers to inject arbitrary instructions. Untrusted pages ...
Related Vulnerabilities
- CVE-2026-5466: wolfSSL's ECCSI signature verifier `wc_VerifyEccsiHash` decodes the `r` and `s` scalars from the sig HIGH
- CVE-2026-35648: OpenClaw before 2026.3.22 contains a policy bypass vulnerability where queued node actions are not r LOW
- CVE-2026-35670: OpenClaw before 2026.3.22 contains a webhook reply delivery vulnerability that allows attackers to r MEDIUM
- CVE-2026-40199: Net::CIDR::Lite versions before 0.23 for Perl mishandles IPv4 mapped IPv6 addresses, which may allow MEDIUM
- CVE-2026-5772: A 1-byte stack buffer over-read was identified in the MatchDomainName function (src/internal.c) duri LOW
Related Coverage
Threat Actors