The OpenClaw Dashboard contains a stored cross-site scripting vulnerability that allows unauthenticated remote attackers to execute arbitrary JavaScript in the administrator's browser session by injecting HTML markup into agent transcript messages processed through the sessions API. This vulnerability can lead to theft of session tokens and unauthorized calls to authenticated administrative endpoints, inc [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-30T21:18:12.490Z and has not been modified since then. The NVD entry is currently Received. OpenClaw Dashboard v3.0.0 contains a stored cross-site scripting vulnerability that allows unauthenticated remote attackers to inject arbitrary HTML and script payloads by submitting a crafted username in a f [truncated]
A security flaw has been discovered in tugcantopaloglu godot-mcp 2.0.0. Affected by this vulnerability is the function validatePath of the file build/index.js of the component run_project. The manipulation of the argument projectPath results in path traversal. Local attack is a requirement. The vulnerability has a CVSS score of 1.9 and a severity of LOW. Upgrading to version 3.0.0 addresses this issue. Th [truncated]