Gitlawb maintains a narrowly scoped product portfolio centered on OpenClaude, where the durable vulnerability signal reflects application-layer weaknesses across access control, authentication, and input handling, including improper pathname validation, cross-site request forgery, and missing authentication barriers for critical functions. The exposure pattern also spans resource-consumption boundaries, consistent with the demands of a web-application security posture; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Gitlawb over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-42074CRITICAL OpenClaude is an open-source coding-agent command line interface for cloud and local model providers. Prior to version 0.5.1, the dangerouslyDisableSandbox parameter is exposed as | Jun 2, 2026 | 9.8 | 38 | NO | NO |
CVE-2026-35570HIGH OpenClaude is an open-source coding-agent command line interface for cloud and local model providers. Versions prior to 0.5.1 have a logic flaw in `bashToolHasPermission()` inside | Apr 21, 2026 | 8.4 | 28 | NO | NO |
CVE-2026-42073MEDIUM OpenClaude is an open-source coding-agent command line interface for cloud and local model providers. Prior to version 0.5.1, the OpenClaude MCP authentication flow starts a tempor | Jun 2, 2026 | 6.5 | 26 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Gitlawb.
Media articles that mention a CVE ID that affects a product developed by Gitlawb — matched by CVE ID, not by vendor name.