Cantina 🪐[verified]@cantinaxyzDisclosure
A new high‑severity allowlist bypass vulnerability (CVE‑2026‑26325) was discovered in OpenClaw’s npm package by Cantina’s AI Code Analyzer, with a brief technical breakdown linked in the tweet.
Spearbit[verified]@spearbitPatch
The announcement notes a high vulnerability (CVE-2026-26325) in the @OpenClaw npm package and confirms that the team has acknowledged and patched it.
Apogee | DevSecOps Web3[verified]@0xApogeeDisclosure
The post announces a high‑severity allowlist bypass in the OpenClaw npm package that could allow execution of arbitrary commands.
Coyote Security Scanner[verified]@CoyoteSecureGeneral
The post announces a development update adding new CVE checks to OpenClaw, listing the CVEs and their brief descriptions, but does not mention PoC, exploit code, active exploitation, patches, or false positives.
Mike Leffer[verified]@mikelefferPatch
The text announces CVE-2026-26325 in openclaw, explains the issue, and provides the patch version v2026.2.14 to mitigate the vulnerability.
CVE@CVEnewGeneral
The excerpt notes a mismatch issue in OpenClaw’s command handling for CVE-2026-26325, but offers no concrete PoC, exploit, or patch details.