5
CVE-2026-90712
- EPSS 0.32%
- Veröffentlicht 14.09.2026 11:45:10
- Zuletzt bearbeitet 14.09.2026 20:56:48
- Erkennungen
Gitlawb openclaude xAI OAuth Callback xaiOAuthCallback.ts waitForCallback denial of service
A vulnerability was identified in Gitlawb openclaude up to 0.30.0. Impacted is the function waitForCallback of the file src/services/api/xaiOAuthCallback.ts of the component xAI OAuth Callback Handler. The manipulation of the argument Error leads to denial of service. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerGitlawb
≫
Produkt
openclaude
Version
0.1
Status
affected
Version
0.2
Status
affected
Version
0.3
Status
affected
Version
0.4
Status
affected
Version
0.5
Status
affected
Version
0.6
Status
affected
Version
0.7
Status
affected
Version
0.8
Status
affected
Version
0.9
Status
affected
Version
0.10
Status
affected
Version
0.11
Status
affected
Version
0.12
Status
affected
Version
0.13
Status
affected
Version
0.14
Status
affected
Version
0.15
Status
affected
Version
0.16
Status
affected
Version
0.17
Status
affected
Version
0.18
Status
affected
Version
0.19
Status
affected
Version
0.20
Status
affected
Version
0.21
Status
affected
Version
0.22
Status
affected
Version
0.23
Status
affected
Version
0.24
Status
affected
Version
0.25
Status
affected
Version
0.26
Status
affected
Version
0.27
Status
affected
Version
0.28
Status
affected
Version
0.29
Status
affected
Version
0.30.0
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.32% | 0.248 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| cna@vuldb.com | 2.1 | 0 | 0 |
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
|
| cna@vuldb.com | 4.3 | 2.8 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
|
| cna@vuldb.com | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:N/I:N/A:P
|
CWE-404 Improper Resource Shutdown or Release
The product does not release or incorrectly releases a resource before it is made available for re-use.
https://vuldb.com/vuln/403266
https://vuldb.com/vuln/403266/cti
https://vuldb.com/cve/CVE-2026-90712
https://vuldb.com/submit/918715
https://github.com/Gitlawb/openclaude/issues/2101
https://github.com/Gitlawb/openclaude/