Vulnerabilities
Vulnerable Software
Openclaw:  >> Openclaw  >> 2026.4.21  Security Vulnerabilities
OpenClaw before 2026.4.22 derives loopback MCP owner context from spoofable server-issued bearer tokens in request headers. Non-owner loopback clients can present themselves as owner to bypass owner-gated operations by manipulating the sender-owner header metadata.
CVSS Score
8.5
EPSS Score
0.001
Published
2026-05-06


Contact Us

Shodan ® - All rights reserved