Known Vulnerabilities for Zero-channel Plus by Zero-channel Plus Project
Listed below are 1 of the newest known vulnerabilities associated with "Zero-channel Plus" by "Zero-channel Plus Project".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-56696 json | OpenHarness /issue and /pr_comments slash commands lack remote_invocable=False protection, allowing remote channel senders to... | Not Provided | 2026-06-23 | 2026-06-23 |
| CVE-2026-56694 json | NanoClaw before 2.1.0 contains a privilege escalation vulnerability in the channel-registration approval flow where handleCha... | Not Provided | 2026-06-23 | 2026-06-23 |
| CVE-2026-56323 json | Capgo before 12.128.2 contains an information disclosure vulnerability in the /functions/v1/channel_self endpoint that allows... | Not Provided | 2026-06-22 | 2026-06-23 |
| CVE-2026-56322 json | Capgo before 12.128.2 contains an information disclosure vulnerability in the unauthenticated /updates endpoint that resolves... | Not Provided | 2026-06-23 | 2026-06-23 |
| CVE-2026-56314 json | Capgo before 12.128.12 fails to filter deleted app versions when joining channels during /updates resolution, allowing delete... | Not Provided | 2026-06-22 | 2026-06-23 |
| CVE-2026-54817 json | Authentication Bypass Using an Alternate Path or Channel vulnerability in FluxBuilder MStore API allows Password Recovery Exp... | Not Provided | 2026-06-17 | 2026-06-17 |
| CVE-2026-54324 json | Daytona is a secure and elastic infrastructure runtime for AI-generated code execution and agent workflows. Prior to 0.185.0,... | Not Provided | 2026-06-23 | 2026-06-23 |
| CVE-2026-54316 json | Claude Code is an agentic coding tool. From 0.2.54 until 2.1.163, because the hostname huggingface.co was pre-approved as a ... | Not Provided | 2026-06-23 | 2026-06-23 |
| CVE-2026-53854 json | OpenClaw before 2026.4.25 contains a privilege escalation vulnerability in internal and webchat command authentication that a... | Not Provided | 2026-06-16 | 2026-06-16 |
| CVE-2026-53837 json | OpenClaw before 2026.5.6 contains an improper access control vulnerability in Mattermost event handlers that fails to validat... | Not Provided | 2026-06-12 | 2026-06-15 |