2 Total advisories
2 Vulnerabilities
0 Malware
Dependency scanning
Check whether @openclaw/voice-call is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
HIGH 7.5
CVE-2026-32062
OpenClaw voice-call media stream validated streams after upgrade, which could allow pre-start unauthenticated sockets to increase resource pressure
MEDIUM 5.9
CVE-2026-28465
OpenClaw optional voice-call plugin: webhook verification may be bypassed behind certain proxy configurations
Browse more npm advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes