VulnTracker[verified]@vuln_trackerDisclosure
A Tweet announces six newly disclosed, high‑severity CVEs for OpenClaw, offering CVSS scores and brief vulnerability descriptors, but no proof of concept, active exploitation, patch details, or false‑positive claims.
RedPacket Security@RedPacketSecGeneral
The tweet only references a CVE alert link for CVE-2026-31994 without providing detailed technical or exploitation information.
CVEarity@CVEarityDisclosure
The tweet announces CVE-2026-31994, highlighting its severity of 7.1 and high risk level, but provides no technical, exploit, or patch details.
CVE@CVEnewDisclosure
OpenClaw versions prior to 2026.2.19 are vulnerable to local command injection through unsafe handling of cmd meta characters in scheduled task script generation, with no PoC, exploit, or patch mentioned.
Vulmon Vulnerability Feed@VulmonFeedsDisclosure
The entry announces CVE-2026-31994, a local command injection flaw in OpenClaw’s Windows scheduled task script generation. No PoC, exploit code, patch information, or active exploitation evidence is provided.