PatchSiren

tugcantopaloglu CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH tugcantopaloglu CVE published 2026-07-30

CVE-2026-66421

The OpenClaw Dashboard contains a stored cross-site scripting vulnerability that allows unauthenticated remote attackers to execute arbitrary JavaScript in the administrator's browser session by injecting HTML markup into agent transcript messages processed through the sessions API. This vulnerability can lead to theft of session tokens and unauthorized calls to authenticated administrative endpoints, inc [truncated]

CRITICAL tugcantopaloglu CVE published 2026-07-30

CVE-2026-66418

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-30T21:18:12.490Z and has not been modified since then. The NVD entry is currently Received. OpenClaw Dashboard v3.0.0 contains a stored cross-site scripting vulnerability that allows unauthenticated remote attackers to inject arbitrary HTML and script payloads by submitting a crafted username in a f [truncated]

LOW tugcantopaloglu CVE published 2026-07-13

CVE-2026-15522

A security flaw has been discovered in tugcantopaloglu godot-mcp 2.0.0. Affected by this vulnerability is the function validatePath of the file build/index.js of the component run_project. The manipulation of the argument projectPath results in path traversal. Local attack is a requirement. The vulnerability has a CVSS score of 1.9 and a severity of LOW. Upgrading to version 3.0.0 addresses this issue. Th [truncated]