bug-bounty480
google297
xss277
microsoft249
facebook211
rce159
apple150
exploit136
bragging-post102
account-takeover98
malware94
csrf84
cve79
privilege-escalation74
authentication-bypass65
stored-xss65
writeup61
reflected-xss57
browser54
react53
ssrf51
phishing50
dos50
input-validation49
cloudflare49
access-control49
cross-site-scripting48
node46
aws46
smart-contract45
docker45
sql-injection45
ethereum44
defi43
web-security43
web-application42
supply-chain42
oauth41
web339
burp-suite36
lfi34
vulnerability-disclosure34
idor34
html-injection33
smart-contract-vulnerability32
race-condition32
clickjacking31
reverse-engineering31
information-disclosure30
csp-bypass30
0
3/10
Researcher found a chain of vulnerabilities in Legal Robot: HTML injection leading to open redirect via META refresh tags, combined with a misconfigured WebSocket Origin header allowing CSRF attacks from different origins. The vulnerability chain required no XSS execution due to CSP but achieved account logout and malicious script execution through forced redirects.
csrf
html-injection
open-redirect
csp-bypass
websocket-security
origin-misconfiguration
vulnerability-chaining
bug-bounty
bragging-post
Legal Robot
HackerOne
Armaan Pathan
0
4/10
Opinion piece critiquing Meta's acquisition of Moltbook and OpenAI's hiring of OpenClaw creator Peter Steinberger, highlighting severe security vulnerabilities in both platforms including unauthenticated database access, remote code execution (CVE-2026-25253), secret key exposure, and malware in the OpenClaw skills marketplace.
ai-agents
security-vulnerability
remote-code-execution
authentication-bypass
misconfiguration
api-security
supply-chain-security
marketplace-malware
websocket-security
secret-exposure
default-configuration
Moltbook
OpenClaw
Meta
OpenAI
Peter Steinberger
CVE-2026-25253
Gal Nagli
Wiz
Supabase
NanoClaw
TrustClaw
Carapace AI
The Colony
Clawstr
4Claw
Kevin Breen
Immersive