- EPSS 0.32%
- Veröffentlicht 14.09.2026 11:45:10
- Zuletzt bearbeitet 14.09.2026 20:56:48
A vulnerability was identified in Gitlawb openclaude up to 0.30.0. Impacted is the function waitForCallback of the file src/services/api/xaiOAuthCallback.ts of the component xAI OAuth Callback Handler. The manipulation of the argument Error leads to ...
CVE-2026-42073
- EPSS 0.22%
- Veröffentlicht 02.06.2026 15:38:53
- Zuletzt bearbeitet 22.07.2026 19:10:00
OpenClaude is an open-source coding-agent command line interface for cloud and local model providers. Prior to version 0.5.1, the OpenClaude MCP authentication flow starts a temporary local HTTP server to handle OAuth callbacks. To prevent CSRF attac...
CVE-2026-42074
- EPSS 0.54%
- Veröffentlicht 02.06.2026 15:38:24
- Zuletzt bearbeitet 22.07.2026 19:10:00
OpenClaude is an open-source coding-agent command line interface for cloud and local model providers. Prior to version 0.5.1, the dangerouslyDisableSandbox parameter is exposed as part of the BashTool input schema, meaning the LLM (an untrusted princ...
CVE-2026-35570
- EPSS 0.23%
- Veröffentlicht 20.04.2026 23:24:08
- Zuletzt bearbeitet 23.04.2026 18:37:09
OpenClaude is an open-source coding-agent command line interface for cloud and local model providers. Versions prior to 0.5.1 have a logic flaw in `bashToolHasPermission()` inside `src/tools/BashTool/bashPermissions.ts`. When the sandbox auto-allow f...