Known Vulnerable Dependency: openclaw==2026.4.0 — 10 advisory(ies): CVE-2026-41913 (OpenClaw: Concurrent async auth attempts can bypass the intended shared-secret r); CVE-2026-43526 (OpenClaw: QQBot reply media URL handling could trigger SSRF and re-upload fetche); CVE-2026-43530 (OpenClaw: busybox and toybox applet execution weakened exec approval binding) +7 more
High
- Category
- Supply Chain
- Confidence
- 90% confidence
- Finding
- The skill declares compatibility with OpenClaw >=2026.4.0, and the static analysis indicates that version 2026.4.0 is affected by multiple known advisories including auth bypass, SSRF, and weakened execution approval binding. Even though this package.json does not directly install dependencies, advertising or targeting a vulnerable runtime can expose the skill to exploitation when deployed in that environment.
