New MCP server — Bring vulnerability intelligence into your AI
Live vulnerability intelligence

Vulnerability Intelligence Center

Track, prioritise and act on the vulnerabilities that actually threaten your external attack surface — CVEs, exploits, EPSS, CISA KEV and trending attacks, unified in one continuously updated feed.

Try , or .

Live feed

0 CVE available

Streaming live from the Patrowl Intelligence API.

CVE-2026-100589
today

OpenClaw versions before 2026.7.1 contain a sandbox bypass vulnerability in the browser tool that allows sandboxed sessions to access paired node browser actions despite allowHostControl=false configuration. Attackers with control over sandboxed agent input can select a paired node and perform host browser operations, inspecting or manipulating the connected browser profile and its authenticated state.

6.4
CVE-2026-100560
today

OpenClaw versions before 2026.8.1 contain an authorization bypass vulnerability where Allow Always approvals for exact commands persist as path-only grants on macOS and Linux. Attackers can reuse the same executable with different arguments to execute commands without triggering new approval prompts, potentially accessing files or internal services.

5.8
CVE-2026-100594
today

OpenClaw versions before 2026.7.1 contain an authorization bypass vulnerability in the /export-trajectory endpoint that allows non-owner senders to request and receive owner-only trajectory bundles. Attackers can access prompts, model messages, tool schemas, runtime events, and local path metadata from affected sessions by exploiting insufficient authorization checks.

5.5
CVE-2026-100582
today

OpenClaw channel plugins (@openclaw/msteams, @openclaw/feishu, @openclaw/matrix, and @openclaw/googlechat) before 2026.8.1 do not enforce the configured channel read allowlist for caller-supplied explicit read targets in message, reaction, pin, member, and related metadata read actions. A lower-trust sender or a steered agent with access to a channel read action can therefore retrieve content or metadata from channels or rooms excluded by the operator's read policy; the practical impact depends on the permissions held by the connected bot account. The issue is fixed in 2026.8.1.

5.5
CVE-2026-100556
today

OpenClaw (npm package openclaw) versions >= 2026.5.2 and < 2026.8.1 contain an incorrect authorization vulnerability in WhatsApp group handling. A group sender who is admitted for ordinary messages but denied by commands.allowFrom or owner command authorization can issue the /new <model> command to reset the shared group session and persist a provider and model override. This allows a command-denied group member to select a provider and model already permitted by the operator for subsequent turns in the shared group session, potentially changing provider routing, cost, data flow, or availability. It does not allow adding a new provider or host command execution. The issue is fixed in version 2026.8.1.

4.7
CVE-2026-100568
today

OpenClaw versions before 2026.8.1 fail to properly restrict access to operator command cron jobs, allowing model-visible agent callers to read and execute ownerless command jobs. Attackers can inspect stored environment variables and force-run disabled or unscheduled command jobs to access secrets and execute operator-authored commands.

6.4
CVE-2026-100580
today

OpenClaw (npm package 'openclaw') before 2026.7.1 improperly handles case sensitivity in the model-facing cron tool: a mixed-case payload kind can pass the agent-facing shell-execution guard and later normalize into a command job. An actor able to steer a tool-enabled agent can therefore create a persistent cron job that executes attacker-selected commands with the privileges of the OpenClaw process user, resulting in access to host files and credentials and impact to scheduled service availability. The issue is limited to cron jobs created or edited through the model-facing cron tool; direct CLI and authorized Gateway scheduling surfaces are trusted operator controls. Fixed in 2026.7.1.

6.4
CVE-2026-100590
today

OpenClaw before 2026.7.1 contains an authorization bypass vulnerability in the /voice set command that allows non-owner external-channel senders to persist Gateway voice configuration. Attackers with command access can change the voice used by Talk responses for the configured provider, affecting configuration integrity without exposing credentials or granting additional host capabilities.

4.7
CVE-2026-100596
today

OpenClaw versions before 2026.7.1 fail to properly authorize non-owner users executing MCP configuration changes through /mcp set and /mcp unset commands. Attackers can persist arbitrary stdio MCP commands that execute with OpenClaw process privileges when configuration loads, compromising host confidentiality, integrity, and availability.

6.4
CVE-2026-100562
today

OpenClaw versions before 2026.8.1 contain an authorization bypass vulnerability in the sessions.create endpoint that allows operator.write callers to modify session configurations reserved for operator.admin scope. Attackers with write-scoped credentials can change existing session model, provider, thinking level, and auth-profile settings to redirect traffic and bypass administrative access controls.

4.7

Discover

Map your entire external attack surface automatically — domains, IPs, services and shadow IT.

Detect

Continuously match exposures against new CVEs, public exploits and CISA KEV entries.

Remediate

Prioritise with the Patrowl EASM risk score and act on what truly matters first.

Monitor

Stay ahead with real-time alerts the moment a threat starts trending.

The platform

Continuously protect what you expose on the Internet

Patrowl turns raw vulnerability data into prioritised, actionable intelligence — so your team spends time fixing what attackers will actually use.

0M

Assets monitored

0M

Vulnerabilities analysed

0x

Faster remediation

Built for Claude · Open source

Turn Claude into a vulnerability analyst

patrowl-cve-analyst pulls correlated CVE, CVSS, EPSS, CISA KEV, public-exploit and trending-attack data from Patrowl Intelligence — and produces decision-grade risk briefs in seconds.

  • One prompt, full picture — CVSS, EPSS, KEV, public exploits and trending attacks correlated in a single call.
  • Decision-grade output. A risk verdict and remediation window, not raw JSON to parse.
  • Works in Claude Code, Claude Desktop or any Claude app — drop the skill in and prompt.
~/patrowl-cve-analyst
$ claude
> Use the patrowl-cve-analyst skill —
  brief me on CVE-2025-41115

┌─ Patrowl risk brief ───────────────────────┐
│  EASM score   8.7 / 10   high              │
│  CVSS v4.0    9.1        v3.1   8.7      │
│  EPSS         12.4%      KEV    no       │
│  Public PoCs  2          Remote yes      │
│                                            │
│  Verdict Patch within 7 days. Trending     │
│          exploitation observed in the wild. │
└────────────────────────────────────────────┘

More than 100 companies trust us

European Investment BankMGEN SolutionForvis MazarsColasHeetchXplorEuropean Investment BankMGEN SolutionForvis MazarsColasHeetchXplor

Take 15 minutes to discover our platform with our experts

PatrowlIntel platform screenshot