nteract
25 known vulnerabilities · 1 critical · 0 high
Malicious code in @bmg-web-features/bmg-user-interaction-tracker (npm)
OpenClaw: Browser press/type interaction routes missed complete navigation guard coverage
OpenClaw: Slack interactive callbacks could skip configured sender checks in some shared-workspace flows
OpenClaw: Discord Component Interaction Misclassifies Group DM as Direct Message
Malicious code in pet-profile-micro-interaction (npm)
OpenClaw: Existing-session browser interaction routes bypassed SSRF policy enforcement
OpenClaw: Browser interaction routes could pivot into local CDP and regain file reads
File upload local preview can run embedded scripts after user interaction
OpenClaw: Sandbox noVNC helper route exposed interactive browser session credentials
OpenClaw has Browser SSRF Policy Bypass via Interaction-Triggered Navigation
Malicious code in twilio-live-interactive-audio (npm)
OpenClaw's Discord component interaction ingress skips guild/channel policy enforcement
Malicious code in @voiceflow/dtos-interact (npm)
Malicious code in interaction-tracing (npm)
Malicious code in interaction-tracing-metrics (npm)
Malicious code in user-interaction-service (npm)
Malicious code in cx-hub-interaction-lib (npm)
Malicious code in etherscancontractinteraction (npm)
Malicious code in rt-interactive-card-collection (npm)
Malicious code in twilio-live-interactive-video (npm)
Malicious code in interactive-app (npm)
Malicious code in ml-interactive-data-augmentation (npm)
Malicious code in cx-hub-interaction-ui-lib (npm)