Mehdi Belckadi[verified]@MBelckadiPatch
The post details CVE‑2026‑44115, highlighting key API‑key leakage, a large number of exposed instances, and emphasizes a preventive solution based on API constraints rather than patching OpenClaw.
HumanAIFusion[verified]@humanaifusionDisclosure
The post announces CVE‑2026‑44115, a Heredoc Shell Expansion Bypass with CVSS 8.8, offering technical details of the flaw but no PoC, exploit, patch, or evidence of active exploitation.
إبراهيم بوحيمد | Ibrahim Buhaimed[verified]@buhaimediDisclosure
The post highlights a flaw in Heredoc handling that allows hidden variables to trigger token and API key leaks, but it provides no PoC, exploitable code, or patch information.
Mehdi Belckadi[verified]@MBelckadiGeneral
The post discusses CVE‑2026‑44115 as a spec‑level credential leakage issue affecting 245k instances, without mentioning PoC, exploit code, patches, or active exploitation.
Mehdi Belckadi[verified]@MBelckadiDisclosure
The statement outlines CVE‑2026‑44115 as an OpenClaw flaw leaking API keys through apparently safe paths, noting 245,000 exposed instances and attributing the issue to agent access without declared invariants, but provides no PoC, exploit code, patch, or evidence of active exploitation.
Brandon()[verified]@brandonbangoDisclosure
The announcement lists four critical and high‑severity CVEs affecting OpenClaw Chain, providing CVSS scores but no additional technical, exploit, or patch details.
CVE@CVEnewDisclosure
The text announces CVE-2026-44115, providing basic technical details about an exec allowlist bypass in OpenClaw via unquoted heredoc bodies, but does not mention a PoC, exploit code, active use, or patch.
Vulmon Vulnerability Feed@VulmonFeedsDisclosure
The notice announces a shell expansion bypass vulnerability in OpenClaw versions prior to 2026.4.22, specifically through heredoc bodies.