call
117 known vulnerabilities · 1 critical · 10 high
Parse Server's GraphQL "Did you mean ...?" validation suggestions disclose schema to unauthenticated callers
OpenClaude MCP OAuth Callback: State Check Bypass via error Param Leads to DoS
OpenClaw: Gateway `agent` calls could override the workspace boundary
OpenClaw: Voice-call Plivo replay mutates in-process callback origin before replay rejection
OpenZeppelin Contracts TransparentUpgradeableProxy clashing selector calls may not be delegated
Malicious code in @tinyspeck/calls-desktop-interop (npm)
OpenClaw has an inbound allowlist policy bypass in voice-call extension (empty caller ID + suffix matching)
OpenClaw's voice-call Twilio webhook replay could bypass manager dedupe because normalized event IDs were randomized per parse
Improperly Controlled Modification of Dynamically-Determined Object Attributes in casperjs
OpenClaw: Gateway HTTP /sessions/:sessionKey/kill Reaches Admin Kill Path Without Caller Scope Binding
OpenClaw Twilio voice-call webhook auth bypass when ngrok loopback compatibility is enabled
Duplicate Advisory: OpenClaw: /pair approve command path omitted caller scope subsetting and reopened device pairing escalation
OpenClaw: Slack interactive callbacks could skip configured sender checks in some shared-workspace flows
grunt-util-property 0.0.2 function call can add/modify properties of Object.prototype using a __proto__ payload
OpenClaw: Voice-call Plivo V3 webhook replay key uses unsorted URL, allowing replay via query-parameter reordering
OpenClaw: Shared-secret comparison call sites leaked length information through timing
OpenClaw: Telegram DM-Scoped Inline Button Callbacks Bypass DM Pairing and Mutate Session State
Malicious code in auth0-react-03-calling-an-api (npm)
Feathers has an open redirect in OAuth callback enables account takeover
Duplicate Advisory: OpenClaw's voice-call Twilio webhook replay could bypass manager dedupe because normalized event IDs were randomized per parse
Improperly Controlled Modification of Dynamically-Determined Object Attributes in express-mock-middleware
OpenZeppelin Contracts and Contracts Upgradeable duplicated execution of subcalls in v4.9.4
Malicious code in fed-callnative (npm)
tRPC has possible prototype pollution in `experimental_nextAppDirCaller`
Vega XSS via expression abusing vlSelectionTuples function array map calls in environments with satisfactory function gadgets in the global scope
Malicious code in callrail_eks (npm)
Malicious code in truecaller-profile-validation (npm)
OpenClaw optional voice-call plugin: webhook verification may be bypassed behind certain proxy configurations
NextAuth.js default redirect callback vulnerable to open redirects
OpenClaw: Mattermost callback dispatch allowed non-allowlisted sender actions
Reflected XSS from the callback handler's error query parameter
locutus call_user_func_array vulnerable to Remote Code Execution (RCE) due to Code Injection
matrix-js-sdk vulnerable to invisible eavesdropping in group calls
jose vulnerable to resource exhaustion via specifically crafted JWE with compressed plaintext
http-proxy-middleware can call writeBody twice because "else if" is not used
OpenClaw: /pair approve command path omitted caller scope subsetting and reopened device pairing escalation
Improperly Controlled Modification of Dynamically-Determined Object Attributes in utilitify
OpenClaw: Write-scoped callers could reach admin-only session reset logic through `agent`
OpenClaw: Voice-call realtime WebSocket accepted oversized frames
n8n Has Authorization Bypass in OAuth Callback via N8N_SKIP_AUTH_ON_OAUTH_CALLBACK
OpenZeppelin Contracts's Cross chain utilities for Arbitrum L2 see EOA calls as cross chain calls
OpenClaw voice-call media stream validated streams after upgrade, which could allow pre-start unauthenticated sockets to increase resource pressure
OpenClaw: Feishu Raw Card Send Surface Can Mint Legacy Card Callbacks That Bypass DM Pairing
Budibase Improper Control of Dynamically-Managed Code Resources vulnerability
Malicious code in infobip-calls-showcase (npm)
OpenClaw: Gateway agent /reset exposes admin session reset to operator.write callers
OpenClaw: Voice-call still parses large WebSocket frames before start validation (Incomplete fix for CVE-2026-32062)
Duplicate Advisory: OpenClaw: Voice-call Plivo replay mutates in-process callback origin before replay rejection
OpenClaw's voice-call Twilio replay dedupe now bound to authenticated webhook identity
Malicious code in callwithchat (npm)
Malicious code in callback-hook (npm)
Improperly Controlled Modification of Dynamically-Determined Object Attributes in querymen
mathjs Allows Improperly Controlled Modification of Dynamically-Determined Object Attributes
OpenClaw: Gateway Plugin HTTP Auth Grants Unrestricted operator.admin Runtime Scope to All Callers
Cloudflare Agents is Vulnerable to Reflected Cross-Site Scripting in the AI Playground's OAuth callback handler
Malicious code in @aircall-ecosystem/integrations-msteams-frontend (npm)
OpenClaw is vulnerable to unauthenticated resource exhaustion through its voice call webhook handling
Malicious code in @naugtur/callhome (npm)
Improper Control of Dynamically-Managed Code Resources in config-shield
n8n-MCP: Sensitive MCP tool-call arguments logged on authenticated requests in HTTP mode
Nodemailer’s addressparser is vulnerable to DoS caused by recursive calls
Malicious code in iv-api-call-tracker (npm)
Malicious code in managed-vip-2-by-kristen-callihan-on-iphone-full-volumes- (npm)
Malicious code in calling-component-bindings (npm)
Malicious code in calling-stateful-client (npm)
Malicious code in housecall-ui (npm)
Malicious code in ally-call-wait-time (npm)
Malicious code in react-native-phone-call (npm)
Improperly Controlled Modification of Dynamically-Determined Object Attributes in vega-util
Malicious code in com.sendbird.calls (npm)
SandboxJS has a sandbox escape via Function.caller leakage of internal call op
Malicious code in run-topologically (npm)
Duplicate Advisory: OpenClaw is vulnerable to unauthenticated resource exhaustion through its voice call webhook handling
Malicious code in rhynocallbackpackage (npm)
Network-AI missing authentication on MCP HTTP endpoint, which allows unauthenticated privileged tool calls
Better Auth: OAuth callback accepts mismatched `state` when cookie-backed state storage is used without PKCE
OpenClaw: Paired-device pairing actions were not limited to the caller device
OpenClaw: node.pair.approve missing callerScopes validation allows low-privilege operator to approve malicious nodes
Malicious code in prisma-callback (npm)
Electron: Use-after-free in offscreen child window paint callback
Malicious code in callrail-package-cleanup (npm)
Trubo: Login callback CSRF/session fixation
Malicious code in @antoncallahan/aws-user-helper (npm)
Beter Auth has an Open Redirect via Scheme-Less Callback Parameter
Malicious code in discord-json-scaller (npm)
@nocobase/plugin-collection-sql: SQL Validation Bypass Through Missing `checkSQL` Call
Malicious code in syntax-class-constructor-call (npm)
Malicious code in housecallpro (npm)
Element Call reports full URLs of visited pages to analytics server
JOSE vulnerable to resource exhaustion via specifically crafted JWE
Malicious code in ethers-multicall-utils (npm)
Electron: Use-after-free in download save dialog callback
Cordova Plugin InAppBrowser: iOS: Arbitrary Cordova callback IDs can be dispatched without validation from InAppBrowser WebViews.
OpenClaw: Skill-command dispatch could skip before-tool-call hooks
OpenClaw: Empty-scope device re-pairing could confuse caller scope containment
Duplicate Advisory: Tool group policy callers could accept unvalidated group IDs
OpenClaw: Tool group policy callers could accept unvalidated group IDs
Duplicate Advisory: Empty-scope device re-pairing could confuse caller scope containment
npm PraisonAI MCPServer exposes unauthenticated HTTP tools/call
Duplicate Advisory: Skill-command dispatch could skip before-tool-call hooks
Malicious code in quickstart-calls-chat-integration (npm)
minimatch ReDoS: nested *() extglobs generate catastrophically backtracking regular expressions
Electron: Use-after-free in WebContents fullscreen, pointer-lock, and keyboard-lock permission callbacks
Electron: Use-after-free in offscreen shared texture release() callback
npm PraisonAI AgentLoop onToolCall approval runs after tool execution
Malicious code in availab-le-alb-um-zip-26387-this-is-the-second-album-of-a-band-called-adebisi-shank-pdmrd-ikxtvt (npm)
Malicious code in 3cx-call-control-apps (npm)