clawsmith.com/signal/openclaw-april-cve-batch-priv-esc-path-traversal-hn
โ IssueWide OpenSecurityLive
OpenClaw April CVE Batch Expands: 13+ HIGH-Severity CVEs Including Privilege Escalation, Path Traversal, SSRF
April 2026 OpenClaw CVE batch grows to 13+ vulnerabilities including CVE-2026-35669 (CVSS 8.8 gateway plugin priv-esc), CVE-2026-35625 (silent auth reconnect priv-esc to RCE), CVE-2026-35660 (/reset access control bypass), CVE-2026-35629 (SSRF in channel extensions), CVE-2026-35668 (sandbox path traversal). All fixed in v2026.3.25.
Product Idea from this Signal
A reverse proxy that enforces scope boundaries on OpenClaw gateway plugin routes and normalizes sandbox file paths before forwarding
770 โฒSECURITYPROXYOPEN-SOURCEDEVTOOL
CompetitiveView Opportunity โ
Score Breakdown
HN
770
Social Proof 1 sources
Frequently Asked Questions
Virality Score
770
across 1 platforms
Details
Signalissue
EcosystemSecurity
Sources1
Platforms1
Updated54 min ago
Trendโ stable
Top ideas
All ideas โRelated signals
All signals โ