Claude Code flaws allow remote code execution and API key theft via untrusted repositories; three bugs fixed across 2025–2026 releases.
A critical OpenClaw flaw allowed malicious websites to connect to locally running agents, brute-force passwords without ...