VulnSea

crabbox vulnerabilities

CVEs whose affected-version data names the crabbox package (go). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

3 CVEsRSS

CVE-2026-8621High· 8.8
4mo ago

Crabbox prior to v0.12.0 contains an authentication bypass vulnerability that allows non-admin shared-token callers to impersonate other owners or organizations by spoofing identity headers

Crabbox prior to v0.12.0 contains an authentication bypass vulnerability that allows non-admin shared-token callers to impersonate other owners or organizations by spoofing identity headers. Attackers can inject malicious X-Crabbox-Owner…

▾ Twilightopenclaw · crabboxEPSS 0.69%via NVD
CVE-2026-8634Critical· 9.1PoC
4mo ago

Crabbox prior to v0.12.0 contains an environment variable exposure vulnerability that allows attackers with access to a malicious or compromised repository to forward local secrets such as API tokens, cloud credentials, and broker tokens…

Crabbox prior to v0.12.0 contains an environment variable exposure vulnerability that allows attackers with access to a malicious or compromised repository to forward local secrets such as API tokens, cloud credentials, and broker tokens…

▾ Abyssalopenclaw · crabboxEPSS 1.0%via NVD
CVE-2026-45224High· 7.1
5mo ago

Crabbox before 0.9.0 contains a path traversal vulnerability in the Islo provider's workspace path resolution that allows attackers to supply absolute or relative paths that resolve outside the intended /workspace directory

Crabbox before 0.9.0 contains a path traversal vulnerability in the Islo provider's workspace path resolution that allows attackers to supply absolute or relative paths that resolve outside the intended /workspace directory. Attackers ca…

▾ Twilightopenclaw · crabboxEPSS 0.19%via NVD
crabbox vulnerabilities (CVEs) · VulnSea