The probability is the direct output of the EPSS model, and conveys an overall sense of the threat of exploitation in the wild. The percentile measures the EPSS probability relative to all known EPSS scores. Note: This data is updated daily, relying on the latest available EPSS model version. Check out the EPSS documentation for more details.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsLearn about Missing Authorization vulnerabilities in an interactive lesson.
Start learningUpgrade @openclaw/diagnostics-prometheus to version 2026.9.3 or higher.
@openclaw/diagnostics-prometheus is an OpenClaw diagnostics Prometheus exporter for runtime metrics.
Affected versions of this package are vulnerable to Missing Authorization via the authenticated metrics endpoint, which does not enforce the operator.read scope. An authenticated caller whose effective role lacks read access can retrieve the diagnostics document, disclosing operational metrics to an identity intentionally limited below read access. Ordinary read methods correctly reject the same identity, but the Prometheus endpoint bypasses this scope check entirely.
Note: This is only exploitable in deployments using an identity-bearing Gateway authentication mode such as trusted-proxy. Shared-secret Gateway callers already hold the full operator scope and are not affected.
Disable the Prometheus endpoint, or ensure every identity that can reach it is intended to hold the operator.read scope.