Monitor vulnerabilities that affect your stack.
Sign up free to get alerts when software you use is affected.
CVE Vulnerabilities - 3 April 2026
RSS122 vulnerabilities published on 3 April 2026
Severity:
Discord Voice Chat Security Flaw in OpenClaw Allows Unauthorized Access
GHSA-x2m8-53h4-6hch
A security flaw in OpenClaw, a Discord bot, allows hackers to bypass security checks and access voice chat channels without permission. This issue affects all versions of OpenClaw up to and including ...
7.3
Discord Integration in OpenClaw Misclassifies Group Messages as Direct Messages
GHSA-6336-qqw9-v6x6
A bug in OpenClaw's Discord integration causes group messages to be incorrectly identified as direct messages, which can lead to unintended consequences in your messaging setup. This issue affects ver...
7.3
OpenClaw diffs viewer misclassifies proxied remote requests when `allowRemoteViewer` is disabled
GHSA-3xv9-89fm-7h4r
The OpenClaw diffs viewer incorrectly identifies remote requests as local requests when a security setting is turned off, potentially allowing unauthorized access to sensitive data. This is a relative...
7.3
Discord Voice Manager Allows Unauthorized Access
GHSA-cqgw-44wg-44rf
The Discord voice manager in OpenClaw does not properly control access to voice channels, allowing unauthorized members to join and participate in voice conversations. This could lead to sensitive inf...
7.3
OpenClaw: Untrusted Model Can Hijack Compiler Binaries
GHSA-g8xp-qx39-9jq9
A security flaw in OpenClaw allows an untrusted model to replace critical compiler binaries, which could potentially lead to malicious code being executed. This issue affects versions of OpenClaw up t...
7.3
OpenClaw: Workspace .env File Can Override Trust Settings
GHSA-qcj9-wwgw-6gm8
A high-risk issue exists in OpenClaw versions up to 2026.3.28, where a workspace's .env file can override the trust settings for bundled plugins. This could allow an attacker to gain unauthorized acce...
7.3
Tornado Web Server Cookie Attribute Data Injection
CVE-2026-35536
A security weakness in Tornado's cookie handling could allow an attacker to manipulate cookie settings. This could lead to unauthorized access to sensitive information. Update to Tornado 6.5.5 or late...
7.2
Ajenti: Non-Admin Users Can Install Custom Packages
GHSA-73jv-44c3-j5p2
CVE-2026-35175
A user with a valid login can install custom packages without needing admin privileges. This is fixed in version 2.2.15. Upgrade to this version to fix the issue.
7.2
Ech0: Unauthenticated SSRF in GetWebsiteTitle allows access to internal services and cloud metadata
GHSA-cqgf-f4x7-g6wc
CVE-2026-35037
## Summary
The `GET /api/website/title` endpoint accepts an arbitrary URL via the `website_url` query parameter and makes a server-side HTTP request to it without any validation of the target host or...
7.2
OpenClaw: Files and Credentials Can Be Stolen by Malicious Apps
GHSA-57gh-m6rq-54cf
A security issue in OpenClaw allows malicious apps to read files and steal sensitive information, including login credentials. This issue affects versions of OpenClaw up to 2026.3.28. To fix it, updat...
7.2
Antrea Fails to Encrypt IPv6 Traffic in Dual-Stack Clusters
GHSA-qcmw-8mm4-4p28
CVE-2026-34992
If you use Antrea with dual-stack networking and encryption, some data may be sent unencrypted. This is a security risk, especially for sensitive information. To fix this, update to Antrea version 2.6...
7.1
Kedro: Malicious File Access Through Version String
GHSA-6326-w46w-ppjw
CVE-2026-35167
A security risk exists in Kedro's file loading feature. An attacker could use a specially crafted version string to access files outside the intended directory, potentially leading to unauthorized dat...
7.1
macOS OpenClaw Allows Attackers to Steal User Credentials
GHSA-q9w8-cf67-r238
A vulnerability in the macOS OpenClaw package allows attackers who are on the same network as the user to trick the system into thinking they are a trusted authority and steal the user's login credent...
7.1
OpenClaw Media Parsing Flaw Allows Unauthorized File Access
GHSA-f6pf-4gjx-c94r
A security flaw in OpenClaw version 2026.3.24 and earlier allows attackers to read arbitrary files on your server. This means that a malicious user could potentially access sensitive data they shouldn...
7.1
Electron Apps Crash or Malfunction on Windows or macOS
GHSA-jjp3-mq3x-295m
CVE-2026-34770
Some Electron-based apps may crash or malfunction when using power-saving features on Windows or macOS. This is due to a software bug that affects apps that use power-saving alerts. To fix the issue, ...
7.0
OpenClaw: Leaks Gateway Credentials After Trust Decline
GHSA-9f4w-67g7-mqwv
If you use OpenClaw, a bug can allow an attacker to keep access to your account even if you decline a new endpoint. This is because OpenClaw doesn't properly remove the endpoint when you decline it. T...
6.9
Telegram audio transcription can waste resources for unauthorized senders in OpenClaw
GHSA-m6fx-m8hc-572m
An update to the OpenClaw software allows unauthorized Telegram group senders to use up your resources, such as CPU and storage. This is not a direct security threat, but it can cause financial issues...
6.9
OpenClaw: Large Voice Call WebSocket Frames Can Cause Resource Consumption
GHSA-2w79-r9g8-wmcr
A medium-severity issue in OpenClaw's voice call feature allows an attacker to cause resource consumption by sending large WebSocket frames before they are fully validated. This issue affects versions...
6.9
OpenClaw exposes sensitive information through its control interface
GHSA-hr8g-2q7x-3f4w
A recent update to OpenClaw's control interface inadvertently exposed sensitive information, such as version numbers and agent IDs. This information disclosure is not a major security risk, but it cou...
6.9
OpenClaw can be crashed by huge images
GHSA-w85g-3h6x-4xh2
A bug in OpenClaw's image processing can cause it to crash when dealing with extremely large images, leading to a denial-of-service (DoS) situation. This affects users who rely on OpenClaw for image p...
6.9
Discord Audio Transcription Leaks Sensitive Info Before Authorization
GHSA-hhff-fj5f-qg48
The OpenClaw package for Discord audio transcription processes sensitive audio data before checking if the user is authorized, which could potentially expose confidential information. This issue has b...
6.9
OpenClaw Startup Can Restore Revoked Settings After Restart
GHSA-3pm9-5j7m-59vc
An earlier version of OpenClaw could restore revoked settings after a restart, allowing unauthorized access. This has been fixed in version 2026.3.31. Update to the latest version to ensure security a...
6.8
Electron: Unsecured Node.js Integration in Shared Processes
GHSA-xwr5-m59h-vwqr
CVE-2026-34775
Electron apps that enable Node.js integration in shared processes may be vulnerable to security risks. If you use Electron, avoid enabling Node.js integration in apps that open child windows or embed ...
6.8
Electron Apps on macOS Can Be Hijacked by Malicious Files
GHSA-5rqw-r77c-jp79
CVE-2026-34779
Some Electron apps on macOS can be tricked into running malicious AppleScript code if the user agrees to move the app to the Applications folder. This is a risk if your Electron app uses the `app.move...
6.5
Shynet Password Reset Flow Allows Host Header Manipulation
CVE-2026-35507
An attacker can manipulate the password reset process by controlling the Host header in Shynet, potentially leading to account takeover. Users of Shynet versions prior to 0.14.0 should update to the l...
6.4