Known Vulnerabilities for Matrix by Openclaw
Listed below are 10 of the newest known vulnerabilities associated with "Matrix" by "Openclaw".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-100582 json | OpenClaw channel plugins (@openclaw/msteams, @openclaw/feishu, @openclaw/matrix, and @openclaw/googlechat) before 2026.8.1 do... | Not Provided | 2026-09-26 | 2026-09-26 |
| CVE-2026-100541 json | OpenClaw's Matrix integration (npm package @openclaw/matrix) versions >= 2026.2.2 and < 2026.8.1 lowercase complete Matrix us... | Not Provided | 2026-09-26 | 2026-09-26 |
| CVE-2026-97526 json | In the Linux kernel, the following vulnerability has been resolved: s390/pai: Support CPU hotplug for PMU PAI The command '... | Not Provided | 2026-09-25 | 2026-09-25 |
| CVE-2026-94277 json | MISP's galaxy matrix statistics view (app/View/Users/statistics_galaxymatrix.ctp) renders the galaxy name directly into HTML ... | Not Provided | 2026-09-21 | 2026-09-21 |
| CVE-2026-92589 json | Craft CMS 5.0.0 through 5.10.12 (fixed in 5.10.13) contains a broken access control flaw in the nested-elements reorder endpo... | Not Provided | 2026-09-16 | 2026-09-18 |
| CVE-2026-89959 json | In the Linux kernel, the following vulnerability has been resolved: s390/vfio-ap: Fix control domain removal in vfio_ap_mdev... | Not Provided | 2026-09-16 | 2026-09-16 |
| CVE-2026-89460 json | In the Linux kernel, the following vulnerability has been resolved: s390/cpum_cf: Handle CPU hotplug via prepare/dead callba... | Not Provided | 2026-09-11 | 2026-09-14 |
| CVE-2026-88048 json | Tesseract is an open source OCR engine. In version 5.5.3 and earlier, FullyConnected::DeSerialize in src/lstm/fullyconnected.... | Not Provided | 2026-09-10 | 2026-09-11 |
| CVE-2026-85610 json | OpenPanel before 2.3.0 fails to properly validate chart formula expressions, allowing authenticated project members with read... | Not Provided | 2026-09-04 | 2026-09-10 |
| CVE-2026-76395 json | In Splunk AI Toolkit versions below 6.0.0, a user who holds the "power" Splunk role could execute arbitrary code on the Splun... | Not Provided | 2026-08-19 | 2026-08-26 |