Not verified
OpenClaw CVE-2026-31992
An allowlist bypass scored 9.9 on CVSS and was described as a full guardrail bypass.
2026-03
Not verified
Whether prompts, spend, and model output are bounded so one visitor cannot run up the bill.
Needs the code
Prompt handling, spend limits and output checks happen inside a server call. From outside, a model that costs a tenth of a cent and one that costs a dollar look identical.
Send a long input to your AI feature repeatedly and watch the provider spend for the hour.
A reviewer sends long and hostile inputs, watches spend for the hour, and reads how model output is used.
See what a Launch Review coversAn allowlist bypass scored 9.9 on CVSS and was described as a full guardrail bypass.
ShipReady is not a penetration test or a security certification. No automated check can prove an application is secure.
Last updated September 20, 2026