Ryx[verified]@PadhiyarRushiDisclosure
The post discloses four new OpenClaw vulnerabilities with technical details and a patch date, but offers no evidence of active exploitation or explicit exploit code.
HumanAIFusion[verified]@humanaifusionDisclosure
The text announces a new privilege escalation flaw (CVE‑2026‑44118) with CVSS 7.8 High affecting MCP loopback functionality in OpenClaw and Hermes‑Agent, urging immediate audit.
إبراهيم بوحيمد | Ibrahim Buhaimed[verified]@buhaimediDisclosure
The post announces CVE‑2026‑44118, explaining how OpenClaw’s API blindly trusts a client‑supplied flag to grant ownership privileges, but does not provide PoC, exploit, patch, or exploitation evidence.
Brandon()[verified]@brandonbangoDisclosure
The post announces OpenClaw Chain vulnerabilities (CVE-2026-44112 through CVE-2026-44113) with high CVSS scores, indicating a disclosure of severe weaknesses but lacking PoC, exploit code, or active exploitation evidence.
The Hacker News@TheHackersNewsPatch
A CVE-2026-44118 flaw allows attackers to spoof ownership and achieve persistence via sandbox escapes, and a patch (OpenClaw 2026.4.22) is now available to mitigate the issue.
yottajunaid@yottajunaidDisclosure
The tweet announces CVE-2026-44118, explains it tricks the agent by spoofing ownership to gain full control without credentials, and urges users to apply patch 2026.4.22.
⚡🛡️ Evan Pappas@HevalonDisclosure
The tweet announces the discovery of OpenClaw CVE‑2026‑44118, where the runtime trusts a client‑controlled flag, allowing unauthorized actions.
CVE@CVEnewDisclosure
CVE‑2026‑44118 allows non‑owner loopback clients in OpenClaw to gain privileged context by exploiting spoofable bearer tokens in request headers, exposing an authentication bypass vulnerability.