Known Vulnerable Dependency: clawdbot==2026.1.24 — 4 advisory(ies): CVE-2026-26328 (OpenClaw iMessage group allowlist authorization inherited DM pairing-store ident); CVE-2026-25253 (OpenClaw/Clawdbot has 1-Click RCE via Authentication Token Exfiltration From gat); CVE-2026-24763 (OpenClaw/Clawdbot Docker Execution has Authenticated Command Injection via PATH ) +1 more
High
- Category
- Supply Chain
- Confidence
- 95% confidence
- Finding
- clawdbot==2026.1.24
