
CVE-2026-28448 OpenClaw versions 2026.1.29 prior to 2026.2.1 contain a vulnerability in the Twitch plugin (must be installed and enabled) in which it fails to enforce the allowFrom … https://www.cve.org/CVERecord?id=CVE-2026-28448
Post summary
CVE-2026-28448 highlights a vulnerability in OpenClaw’s Twitch plugin that fails to enforce allowFrom restrictions in versions prior to 2026.2.1.

