Known Vulnerabilities for Ai-gateway by Helicone
Listed below are 10 of the newest known vulnerabilities associated with "Ai-gateway" by "Helicone".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-100592 json | OpenClaw is an agent gateway distributed via npm. In versions >= 2026.4.10 and < 2026.7.1, persistent memory dreaming mutatio... | Not Provided | 2026-09-26 | 2026-09-26 |
| CVE-2026-100591 json | OpenClaw is an npm-distributed agent gateway. In versions before 2026.7.1, the global Active Memory toggle mutations could om... | Not Provided | 2026-09-26 | 2026-09-26 |
| CVE-2026-100590 json | OpenClaw before 2026.7.1 contains an authorization bypass vulnerability in the /voice set command that allows non-owner exter... | Not Provided | 2026-09-26 | 2026-09-26 |
| CVE-2026-100588 json | OpenClaw (npm package 'openclaw') before 2026.7.1 does not enforce the administrator scope requirement on browser control whe... | Not Provided | 2026-09-26 | 2026-09-26 |
| CVE-2026-100584 json | OpenClaw is an npm-distributed agent runtime. In versions >= 2026.2.26 and < 2026.7.1, PowerShell command analysis on Windows... | Not Provided | 2026-09-26 | 2026-09-26 |
| CVE-2026-100581 json | OpenClaw for iOS before 2026.8.11 stores Gateway credentials as cleartext JSON in App Group UserDefaults instead of the devic... | Not Provided | 2026-09-26 | 2026-09-26 |
| CVE-2026-100580 json | OpenClaw (npm package 'openclaw') before 2026.7.1 improperly handles case sensitivity in the model-facing cron tool: a mixed-... | Not Provided | 2026-09-26 | 2026-09-26 |
| CVE-2026-100579 json | OpenClaw (npm package 'openclaw') before 2026.7.1 incorrectly trusts requester provenance in message.action. In identity-bear... | Not Provided | 2026-09-26 | 2026-09-26 |
| CVE-2026-100578 json | OpenClaw (npm package `openclaw`) before 2026.7.1 fails to restrict owner-only infrastructure tools exposed through the chat.... | Not Provided | 2026-09-26 | 2026-09-26 |
| CVE-2026-100567 json | OpenClaw is an agent gateway distributed as the npm package 'openclaw'. In versions >= 2026.4.5 and < 2026.8.1, the Gateway v... | Not Provided | 2026-09-26 | 2026-09-26 |