Robuta

https://advisories.gitlab.com/npm/openclaw/GHSA-354r-7mfh-7rh2/ OpenClaw: Discord DM reaction ingress missed dmPolicy/allowFrom checks in restricted setups |... https://advisories.gitlab.com/npm/openclaw/CVE-2026-32021/ OpenClaw has a Feishu allowFrom authorization bypass via display-name collision | GitLab Advisory... CVE-2026-32021 OpenClaw has a Feishu allowFrom authorization bypass via display-name collision: Feishu allowlist authorization could be bypassed by... https://advisories.gitlab.com/npm/openclaw/GHSA-f693-58pc-2gfr/ OpenClaw: Telegram legacy allowFrom migration fans default-account trust into all named accounts |... GHSA-f693-58pc-2gfr OpenClaw: Telegram legacy allowFrom migration fans default-account trust into all named accounts: Telegram legacy allowFrom migration fans... https://advisories.gitlab.com/npm/openclaw/CVE-2026-22170/ OpenClaw: BlueBubbles (optional plugin) pairing/allowlist mismatch when allowFrom is empty | GitLab... CVE-2026-22170 OpenClaw: BlueBubbles (optional plugin) pairing/allowlist mismatch when allowFrom is empty: BlueBubbles is an optional OpenClaw channel plugin.... https://advisories.gitlab.com/npm/openclaw/CVE-2026-28448/ OpenClaw Twitch allowFrom is not enforced in optional plugin, unauthorized chat users can trigger... CVE-2026-28448 OpenClaw Twitch allowFrom is not enforced in optional plugin, unauthorized chat users can trigger agent pipeline: In the optional Twitch channel...