CVE-2026-100602

CVE-2026-100602 published: ClawHub (openclaw/clawhub application/backend) contains a missing authorization check in the changelog preview feature. A signed-in caller can invoke the public skills:generateChangelogPreview action for a skill they are not authorized to access; the previo...

View full NVD advisory → ← Back to CVE watch