AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-06T08:16:30.087Z and has not been modified since then. The vulnerability affects mf-yang openclaw-cn up to version 0.2.1, specifically the function assertNoSymlinkEscape in src/agents/sandbox-paths.ts. This issue allows for link following and can be exploited remotely. The project was informed early [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-06T07:16:29.947Z and has not been modified since then. The vulnerability affects the isApprovedElevatedSender function in mf-yang openclaw-cn up to version 0.2.1, leading to improper privilege management. This vulnerability allows for remote attacks. The project was informed of the problem early thr [truncated]
A server-side request forgery vulnerability was found in mf-yang openclaw-cn up to 0.2.1, affecting the Browser Control HTTP API, specifically the clickViaPlaywright function in src/browser/routes/agent.act.ts. The vulnerability allows for remote attacks and has been made public. Users should be aware of this vulnerability and take necessary precautions to protect their systems. This vulnerability has a C [truncated]
A vulnerability has been found in mf-yang openclaw-cn up to 0.2.1. Affected by this issue is the function assertBrowserNavigationAllowed of the file src/browser/navigation-guard.ts of the component Scheme Handler. Such manipulation of the argument url leads to information disclosure. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. The project was info [truncated]