Ryx[verified]@PadhiyarRushiDisclosure
The tweet announces four critical OpenClaw vulnerabilities and their exploitation chain, notes a patch released in 2026.4.22, but does not confirm active exploitation or provide PoC code.
motch | セキュリティ🛡️[verified]@motch_devDisclosure
The tweet announces a series of high‑scoring CVEs (2026‑44112 – 44118) and outlines a four‑step evasion chain, but it does not reference PoCs, exploitation tools, patches, or active attacks.
Ben Miller[verified]@bensenDisclosure
Four Claw Chain vulnerabilities were disclosed, patched, and linked to GitHub advisories.
إبراهيم بوحيمد | Ibrahim Buhaimed[verified]@buhaimediDisclosure
The post describes the TOCTOU race condition underlying CVE‑2026‑44112, illustrating how an attacker can alter data between check and execution, but offers no PoC, exploit, patch, or evidence of active exploitation.
Cyera[verified]@cyera_ioDisclosure
Cyera Research announced four chainable vulnerabilities in openclaw, highlighting CVE‑2026‑44112 as a critical sandbox escape (CVSS 9.6). The tweet contains no exploit code, patches, or evidence of active exploitation.
HumanAIFusion[verified]@humanaifusionDisclosure
The post reports CVE-2026-44112 as a critical TOCTOU write‑escape flaw affecting OpenClaw and Hermes‑Agent across various terminal backends, detailing how symlink races enable writes outside the mount root.
CiberInteligencia Chile[verified]@esecintelclPatch
The post announces OpenClaw vulnerabilities enabling data theft, privilege escalation, and persistence, and recommends updating to version 2026.4.22 to block exploitation.
IntegSec[verified]@integ_secGeneral
The snippet only references the CVE in an article title, offering no concrete details or actionable information.