Skip to content

mf-yang vulnerabilities

3 CVEs tracked

The vendor mf-yang appears in recent reporting primarily through the 'openclaw-cn' repository, highlighting multiple authorization and information leakage issues. The main themes revolve around flaws in web navigation guardrails, execution approval flows, and auto-reply functions. Defenders should focus on CVE-2026-17457 (information disclosure), CVE-2026-19006 (incorrect authorization), and CVE-2026-19007 (improper privilege management). These vulnerabilities pose risks of unauthorized information access and privilege escalation in systems utilizing the 'openclaw-cn' component.

This vendor's CVEs3

This hub is built from skopnix's own reporting on mf-yang: the overview is AI-written from that coverage and every CVE links to its grounded explainer. KEV status comes from CISA's Known Exploited Vulnerabilities catalog and EPSS from FIRST — vendor, version and score details are never invented.