CVE-2026-8634Critical· 9.1▾ MidnightCrabbox: environment variable exposure vulnerability
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 50.1 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 21.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.7%
Crabbox prior to v0.12.0 contains an environment variable exposure vulnerability that allows attackers with access to a malicious or compromised repository to forward local secrets such as API tokens, cloud credentials, and broker tokens into the remote command environment. Attackers can exploit overly permissive environment variable allowlisting in repo-local Crabbox configuration to serialize sensitive environment variables into remote command execution, exposing credentials to the remote environment.
github.com/openclaw/crabbox < 0.12.0Upgrade to a patched release:
github.com/openclaw/crabbox 0.12.0Connected by shared product, vendor, weakness, or advisory.
CVE-2026-91836Low· 2.8A flaw has been found in OpenClaw ClawScan up to 0.1.6
CVE-2026-91835Low· 2.8A vulnerability was detected in OpenClaw ClawScan up to 0.1.6
CVE-2026-62196High· 8.3OpenClaw versions 2026.3.22 before 2026.6.6 contain an authorization bypass vulnerability where WhatsApp group IDs can satisfy elevated sender allowlists
GHSA-2q7j-2vhx-56g8High· 8.1OpenClaw Feishu tools could ignore per-account disablement
GHSA-w8wf-3qvj-6xqfHigh· 8.1OpenClaw Feishu permission tools could ignore per-account disablement
CVE-2026-35630High· 8.0OpenClaw: QQBot native approval buttons did not enforce configured approver identity