Skip to content

CatchClaw v5.2.0 — 72-Module Full CVE Coverage

Latest

Choose a tag to compare

@Coff0xc Coff0xc released this 23 Mar 19:36
· 2 commits to master since this release

What's New in v5.2.0

13 New CVE-Targeted Exploit Modules (59 → 72)

Module CVE / Source Description
gateway_hijack CVE-2026-25253 (CVSS 8.8) gatewayURL WebSocket hijacking → Token theft
safebins_bypass CVE-2026-28363 (CVSS 9.9) GNU long-option abbreviation bypass → RCE
ws_auth_brute CVE-2026-32025 WebSocket auth brute-force
localhost_trust ClawJacked localhost implicit trust bypass
guest_mode_abuse Conscia Audit Guest Mode dangerous API exposure
mdns_leak Conscia Audit mDNS/HTTP configuration parameter leakage
skill_supply_chain ClawHavoc Malicious skill supply chain detection
voice_ext_rce CVE-2026-28446 (CVSS 9.8) Voice Extension RCE
env_inject CVE-2026-32056 Environment variable injection
ipv6_ssrf_bypass IPv4-mapped IPv6 SSRF bypass
msg_platform_spoof Telegram/Discord/Matrix identity spoofing
librechat_probe CVE-2025-69222/69220/54868 LibreChat multi-CVE probe
lobechat_probe CVE-2026-23733 LobeChat Mermaid XSS→RCE

New Features

  • Multi-target scanning — CIDR notation, IP ranges, comma-separated targets, target file (-f)
  • Port scanning & service discovery — TCP connect scan + OpenClaw fingerprinting
  • 200+ external payloads — SSRF, injection, prompt injection, auth bypass, XSS (YAML)
  • CLI enhancements--profile, --severity-filter, --format (json/html/markdown), --dry-run
  • HTML report (dark-themed, self-contained) + Markdown report output
  • TOML profile presets (quick/stealth/full)
  • Release CI — automated multi-platform builds (Linux/macOS/Windows)
  • 110 unit tests (up from 38)

Fixes

  • MinGW linker failure on CJK/bracket paths
  • log_clean()/log_outcome() signature mismatch across 59 modules
  • Various config serde defaults, test escaping, Unicode char count

Full Changelog: v5.1.0...v5.2.0

Full Changelog: v5.1.0...v5.2.0