Monitor vulnerabilities that affect your stack. Sign up free to get alerts when software you use is affected.

CVE Vulnerabilities - 3 April 2026

RSS

134 vulnerabilities published on 3 April 2026

Severity:
Electron Apps on macOS Can Be Hijacked by Malicious Files
GHSA-5rqw-r77c-jp79 CVE-2026-34779
Some Electron apps on macOS can be tricked into running malicious AppleScript code if the user agrees to move the app to the Applications folder. This is a risk if your Electron app uses the `app.move...
6.5
Shynet Password Reset Flow Allows Host Header Manipulation
CVE-2026-35507
An attacker can manipulate the password reset process by controlling the Host header in Shynet, potentially leading to account takeover. Users of Shynet versions prior to 0.14.0 should update to the l...
6.4
OpenClaw Diffs Viewer Misclassifies Remote Requests as Local
GHSA-3xv9-89fm-7h4r
OpenClaw's diffs viewer can incorrectly identify some remote requests as coming from the same machine, even when it shouldn't. This could allow unauthorized access to certain features. Update OpenClaw...
6.3
Telegram App: Unsecured Accounts Can Be Tricked into Trusting Malicious Users
GHSA-f693-58pc-2gfr
The Telegram app's OpenClaw package, used in some versions of the app, allows malicious users to trick accounts into trusting them without verifying their identity. This means a user could pretend to ...
6.3
OpenClaw: Fake Device Tokens Can Bypass Login Limits
GHSA-6p8r-6m93-557f
The OpenClaw software has a flaw that allows an attacker to bypass the limit on how many times a device can try to log in to a shared account. This could be a problem for companies that use weak passw...
6.3
Roundcube Webmail allows malicious HTML in email attachments
CVE-2026-35539
A security issue in Roundcube Webmail can allow an attacker to inject malicious code into a user's browser if they preview a specific type of email attachment. This could potentially lead to unauthori...
6.1
OpenClaw: Malicious Variables Can Execute Code on Your System
GHSA-cg7q-fg22-4g98
The OpenClaw software is not properly cleaning up environment variables that could be used by malicious code to execute on your system. This means a hacker could potentially take control of your syste...
6.0
OpenClaw: Unauthorized access to media downloads through redirects
GHSA-68v4-hmwv-f43h
A security issue in OpenClaw allows unauthorized access to media downloads if an attacker redirects a user to a malicious website. This can happen if the user has previously logged in to OpenClaw and ...
6.0
Electron: Malicious Service Worker Can Inject Fake Data
GHSA-xj5x-m3f3-5x3h CVE-2026-34778
A malicious service worker can trick Electron apps into accepting fake data by manipulating the results of executeJavaScript(). To fix this, developers should not rely on executeJavaScript() for secur...
5.9
Electron Apps: Malicious Header Injection Through Custom Protocol Handlers
GHSA-4p4r-m79c-wq3v CVE-2026-34767
Some Electron apps that handle custom protocols or modify web request headers may be vulnerable to malicious header injection. This can allow an attacker to manipulate cookies, content security polici...
5.9
Electron: Download Dialog Crashes Apps When Closing a Session
GHSA-9w97-2464-8783 CVE-2026-34772
If you use Electron to create apps that allow users to download files, be aware that closing a session while a download dialog is open can crash your app. To fix this, avoid closing a session while a ...
5.8
Roundcube Webmail 1.6.0 Has Security Flaw in Email Styles
CVE-2026-35540
If a hacker sends a malicious email to a user, it could potentially allow them to access internal network resources or extract sensitive information. This is because the webmail software doesn't prope...
5.4
Electron: Malicious IFrame Can Get Unrestricted Browser Permissions
GHSA-r5p7-gp4j-qhrx CVE-2026-34777
A security issue in Electron's permission system could allow malicious content within an iframe to gain access to browser features like screen control, keyboard control, and external links. To fix thi...
5.4
Shynet allows malicious scripts to run on user's browser
CVE-2026-35508
Shynet's template filters can be tricked into executing malicious code on users' browsers. This means attackers can steal sensitive information or take control of users' accounts. Update to version 0....
5.4
Roundcube Webmail: Image Blocking Bypass via SVG Content
CVE-2026-35545
If you use Roundcube Webmail, an attacker may be able to bypass the image blocking feature and potentially access sensitive information or compromise security settings. This is possible if you receive...
5.3
Roundcube Webmail: Malicious Email Messages Can Bypass Security Features
CVE-2026-35544
Some versions of Roundcube Webmail don't properly filter out malicious code in emails. This could allow an attacker to bypass security features and potentially harm your users. Update to the latest ve...
5.3
Roundcube Webmail: Malicious SVG Images Can Bypass Image Blocking
CVE-2026-35543
Attackers can use specially crafted SVG images in emails to bypass Roundcube Webmail's image blocking feature, potentially allowing them to disclose sensitive information or bypass security controls. ...
5.3
Roundcube Webmail: Bypassing Image Blocking in Emails
CVE-2026-35542
A security issue in Roundcube Webmail allows hackers to secretly load images from the internet into emails, potentially revealing sensitive information or allowing unauthorized access. This affects ve...
5.3
DOMPurify's attribute check can be bypassed allowing XSS
GHSA-cjmm-f4jc-qw8r
An attacker can exploit a weakness in the way DOMPurify handles attribute checks to inject malicious code into web pages. This could allow an attacker to execute code on your website if users click on...
5.3
DOMPurify: Event Handlers Bypassed with Prototype Pollution
GHSA-cj63-jhhr-wcxv
DOMPurify, a library that cleans up user input, has a security issue that can allow hackers to inject malicious code into a website. This happens when a specific setting is enabled, allowing an attack...
5.3
D-Tale: Public Servers at Risk of Remote Code Attack
GHSA-436g-fhfc-9g5w CVE-2026-35052
If you're running D-Tale publicly and use a redis or shelf storage layer, attackers could potentially take control of your server. This is a serious threat, so it's essential to update to the latest v...
5.3
Discord Chat Vulnerability in OpenClaw: Group DMs Misclassified
GHSA-6336-qqw9-v6x6
A bug in the OpenClaw library for Discord integration can mistakenly identify group messages as direct messages. This could lead to unintended access or confusion. Update to version 2026.3.31 or later...
5.3
Discord Slash Commands Can Bypass Channel Restrictions for Authorized Users
GHSA-rvvf-6vh3-9j43
Some authorized Discord users can bypass channel restrictions on group direct messages when using Discord slash commands. This issue affects the OpenClaw package and can be fixed by updating to versio...
5.3
Discord Voice Manager on OpenClaw Allows Unapproved Access
GHSA-cqgw-44wg-44rf
A security issue in OpenClaw's Discord voice manager allows unauthorized users to join voice channels even if they're not on an approved access list. This could let unwanted users listen in on sensiti...
5.3
OpenClaw: Malicious Files Can Be Read from Anywhere on the System
GHSA-58q2-7r52-jq62
OpenClaw, a library used by many applications, has a security flaw that allows hackers to read any file on a computer. This could expose sensitive information. To fix this, update OpenClaw to version ...
5.3