CVE-2026-35651
Medium Severity
Description
OpenClaw versions 2026.2.13 through 2026.3.24 contain an ANSI escape sequence injection vulnerability in approval prompts that allows attackers to spoof termin...
Related Vulnerabilities
- CVE-2026-40223: In systemd 258 before 260, a local unprivileged user can trigger an assert when a Delegate=yes and U MEDIUM
- CVE-2026-5503: In TLSX_EchChangeSNI, the ctx->extensions branch set extensions unconditionally even when TLSX_Find MEDIUM
- CVE-2026-22750: When configuring SSL bundles in Spring Cloud Gateway by using the configuration property spring.ssl. HIGH
- CVE-2026-35643: OpenClaw before 2026.3.22 contains an unvalidated WebView JavascriptInterface vulnerability allowing HIGH
- CVE-2026-40194: phpseclib has a variable-time HMAC comparison in SSH2::get_binary_packet() using != instead of hash_ LOW
Related Coverage
Threat Actors