Tag
high
threat
npm PraisonAI SandboxExecutor Network Isolation Bypass Vulnerability (GHSA-gqmf-56h7-rrpf)
2 rules 3 TTPsThe npm package `praisonai` versions 1.2.3 through 1.7.1 contain a network isolation bypass vulnerability (GHSA-gqmf-56h7-rrpf) in its `SandboxExecutor` component's `network-isolated` mode, allowing non-proxy-aware client commands to establish direct network connections, leading to potential data exfiltration and access to internal services.
praisonai
vulnerability
npm
sandbox
network-bypass
ghsa
2r
3t
high
advisory
OpenClaw Sandbox Browser CDP Relay Vulnerability Exposing DevTools Protocol
2 rules 2 TTPsOpenClaw versions prior to 2026.4.10 are vulnerable to a configuration issue where the sandbox browser CDP relay could bind too broadly, exposing Chrome DevTools Protocol access outside the intended local/sandbox source range, potentially allowing unauthorized access to browser DevTools.
openclaw
cdp
devtools
sandbox
exposure
2r
2t