CVE-2026-35643
High Severity
Description
OpenClaw before 2026.3.22 contains an unvalidated WebView JavascriptInterface vulnerability allowing attackers to inject arbitrary instructions. Untrusted pages ...
Related Vulnerabilities
- CVE-2026-40178: ajenti.plugin.core has race conditions in 2FA MEDIUM
- CVE-2026-6069: NASM’s disasm() function contains a stack based buffer overflow when formatting disassembly output, HIGH
- CVE-2026-40156: PraisonAI is a multi-agent teams system. Prior to 4.5.128, PraisonAI automatically loads a file name HIGH
- CVE-2026-40354: Flatpak xdg-desktop-portal before 1.20.4 and 1.21.x before 1.21.1 allows any Flatpak app to trash an LOW
- CVE-2026-40153: PraisonAIAgents is a multi-agent teams system. Prior to 1.5.128, the execute_command function in she HIGH
Related Coverage
Threat Actors