Published security advisories for Crawdad and supported frameworks.
Cross-site WebSocket hijacking vulnerability in OpenClaw allowed remote code execution through a malicious link.