Known Vulnerabilities for Gateway by Aviatrix
Listed below are 3 of the newest known vulnerabilities associated with "Gateway" by "Aviatrix".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-41300 json | OpenClaw before 2026.3.31 contains a trust-decline vulnerability that preserves attacker-discovered endpoints in remote onboa... | Not Provided | 2026-04-21 | 2026-04-20 |
| CVE-2026-41299 json | OpenClaw before 2026.3.28 contains an authorization bypass vulnerability in the chat.send gateway method where ACP-only prove... | Not Provided | 2026-04-21 | 2026-04-20 |
| CVE-2026-40503 json | OpenHarness prior to commit dd1d235 contains a path traversal vulnerability that allows remote gateway users with chat access... | Not Provided | 2026-04-16 | 2026-04-16 |
| CVE-2026-40502 json | OpenHarness prior to commit dd1d235 contains a command injection vulnerability that allows remote gateway users with chat acc... | Not Provided | 2026-04-16 | 2026-04-16 |
| CVE-2026-40149 json | PraisonAI is a multi-agent teams system. Prior to 4.5.128, the gateway's /api/approval/allow-list endpoint permits unauthenti... | Not Provided | 2026-04-09 | 2026-04-13 |
| CVE-2026-40073 json | SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. Prior to 2.57.1, under cert... | Not Provided | 2026-04-10 | 2026-04-13 |
| CVE-2026-40045 json | OpenClaw before 2026.4.2 accepts non-loopback cleartext ws:// gateway endpoints and transmits stored gateway credentials over... | Not Provided | 2026-04-21 | 2026-04-20 |
| CVE-2026-35669 json | OpenClaw before 2026.3.25 contains a privilege escalation vulnerability in gateway-authenticated plugin HTTP routes that inco... | Not Provided | 2026-04-10 | 2026-04-10 |
| CVE-2026-35660 json | OpenClaw before 2026.3.23 contains an insufficient access control vulnerability in the Gateway agent /reset endpoint that all... | Not Provided | 2026-04-10 | 2026-04-13 |
| CVE-2026-35645 json | OpenClaw before 2026.3.25 contains a privilege escalation vulnerability in the gateway plugin subagent fallback deleteSession... | Not Provided | 2026-04-09 | 2026-04-10 |