
CVE-2026-28477 OpenClaw versions prior to 2026.2.14 contain an oauth state validation bypass vulnerability in the manual Chutes login flow that allows attackers to bypass CSRF prote… https://www.cve.org/CVERecord?id=CVE-2026-28477
Post summary
The text announces vulnerability CVE‑2026‑28477, outlining its technical details and the affected OpenClaw versions, but provides no exploit code, PoC, or evidence of active exploitation.

