๐Ÿ›ก๏ธ OpenClaw CVE & Security Advisory Tracker

June 13, 2026 ยท View on GitHub

Total Advisories CVEs Assigned CVEs Published Reserved
Critical High Medium Low Awaiting CVE

An automated tracker that continuously monitors OpenClaw security advisories across the GitHub Advisory Database, repo-level security advisories, and the CVE V5 (cvelistV5) registry. Every hour it pulls the latest data, reconciles GHSA โ†’ CVE publication state, and regenerates this dashboard so you always have an up-to-date picture of the project's vulnerability landscape.

Last updated: 2026-06-13 12:45 UTC ยท MIT License ยท Full Advisory List ยท Security Policy ยท Data: cvelistV5 + Advisory DB ยท Updates hourly


Published CVEs ยท Pipeline ยท Advisories ยท Categories ยท Insights ยท Identity


๐Ÿ—๏ธ Project Identity

FieldValue
Current NameOpenClaw
Previous NamesMoltbot (second name), Clawdbot (original name)
Repositoryopenclaw/openclaw
npm Packageopenclaw (formerly clawdbot)
AuthorPeter Steinberger (steipete)
Search terms for CVE discovery

To find all CVEs, search for: openclaw, clawdbot, moltbot, clawhub, pkg:npm/clawdbot, pkg:npm/openclaw


๐Ÿš€ CVEs Published in cvelistV5 (48)

These CVEs have full records in the CVEProject/cvelistV5 repository:

CVE IDSeverityCVSSTitleCWEPublished
CVE-2026-28466Critical9.4OpenClaw < 2026.2.14 - Remote Code Execution via Node Invoke Approval BypassCWE-8632026-03-05
CVE-2026-43534Critical9.3OpenClaw < 2026.4.10 - Unsanitized External Input in Agent Hook EventsCWE-3452026-05-05
CVE-2026-32918Critical9.2OpenClaw < 2026.3.11 - Session Sandbox Escape via session_status ToolCWE-8632026-03-29
CVE-2026-32917Critical9.2OpenClaw < 2026.3.13 - Remote Command Injection via Unsanitized iMessage Attachment Paths in SCPCWE-782026-03-31
CVE-2026-43585Critical9.2OpenClaw: Gateway HTTP endpoints re-resolve bearer auth after SecretRef rotationCWE-6722026-05-06
CVE-2026-44109Critical9.2OpenClaw: Feishu webhook and card-action validation now fail closedCWE-11882026-05-06
CVE-2026-41386Critical9.1OpenClaw < 2026.3.22 - Privilege Escalation via Unbound Bootstrap Setup CodesCWE-6482026-04-28
CVE-2026-43533High8.9OpenClaw < 2026.4.10 - Arbitrary Local File Read via QQBot Media TagsCWE-232026-05-05
CVE-2026-25253High8.8OpenClaw/Clawdbot has 1-Click RCE via Authentication Token Exfiltration From gatewayUrlCWE-6692026-02-01
CVE-2026-24763High8.8OpenClaw/Clawdbot Docker Execution has Authenticated Command Injection via PATH Environment VariableCWE-782026-02-02
CVE-2026-32913High8.8OpenClaw < 2026.3.7 - Custom Authorization Header Leakage via Cross-Origin RedirectsCWE-5222026-03-23
CVE-2026-41296High8.8OpenClaw < 2026.3.31 - Sandbox Escape via TOCTOU Race in Remote FS Bridge readFileCWE-3672026-04-20
CVE-2026-28478High8.7OpenClaw affected by denial of service via unbounded webhook request body bufferingCWE-7702026-03-05
CVE-2026-32042High8.7OpenClaw < 2026.2.25 - Privilege Escalation via Unpaired Device Identity in Shared Gateway AuthenticationCWE-8632026-03-21
CVE-2026-32051High8.7OpenClaw < 2026.3.1 - Authorization Bypass in Agent Runs via Owner-Only Tool AccessCWE-8632026-03-21
CVE-2026-33573High8.7OpenClaw < 2026.3.11 - Workspace Boundary Bypass via Agent RPC ParametersCWE-6682026-03-29
CVE-2026-41405High8.7OpenClaw < 2026.3.31 - Resource Exhaustion via Unauthenticated MS Teams Webhook Body ParsingCWE-4082026-04-28
CVE-2026-42434High8.7OpenClaw: Sandboxed agents could escape exec routing via host=node overrideCWE-8632026-05-05
CVE-2026-43530High8.7OpenClaw: busybox and toybox applet execution weakened exec approval bindingCWE-8632026-05-05
CVE-2026-44115High8.7OpenClaw < 2026.4.22 - Shell Expansion Bypass in Unquoted Heredocs via Exec AllowlistCWE-1842026-05-06
CVE-2026-53814High8.7OpenClaw < 2026.5.20 - Privilege Escalation via Hook-Triggered CLI MCP Tool AuthorityCWE-2662026-06-11
CVE-2026-32920High8.6OpenClaw < 2026.3.12 - Arbitrary Code Execution via Auto-Discovery of Workspace PluginsCWE-8292026-03-31
CVE-2026-33579High8.6OpenClaw < 2026.3.28 - Privilege Escalation via Missing Caller Scope Validation in Device Pair ApprovalCWE-8632026-03-31
CVE-2026-53823High8.6OpenClaw < 2026.5.3 - Privilege Escalation via Mutable Slack Display Names in allowFromCWE-2902026-06-12
CVE-2026-44118High8.5OpenClaw < 2026.4.22 - Owner Context Spoofing via Bearer Token HeaderCWE-2902026-05-06
CVE-2026-44114High8.5OpenClaw: Workspace dotenv could override runtime-control environment variablesCWE-1842026-05-06
CVE-2026-45004High8.4OpenClaw vulnerable to arbitrary code execution via attacker-controlled setup-api.js loaded from cwd during env-key resolutionCWE-4272026-05-11
CVE-2026-31998High8.3OpenClaw 2026.2.22 < 2026.2.24 - Authorization Bypass in Synology Chat Plugin via Empty allowedUserIdsCWE-8632026-03-19
CVE-2026-35618High8.3OpenClaw < 2026.3.23 - Replay Identity Drift via Query-Only Variants in Plivo V2 VerificationCWE-2942026-04-09
CVE-2026-43526High8.3OpenClaw: QQBot reply media URL handling could trigger SSRF and re-upload fetched bytesCWE-9182026-05-05
CVE-2026-28469High8.2OpenClaw Google Chat shared-path webhook target ambiguity allowed cross-account policy-context misroutingCWE-6392026-03-05
CVE-2026-29611High8.2OpenClaw < 2026.2.14 - Local File Inclusion via mediaPath Parameter in BlueBubbles Media HandlingCWE-732026-03-05
CVE-2026-25157High7.8OpenClaw/Clawdbot has OS Command Injection via Project Root Path in sshNodeCommandCWE-782026-02-04
CVE-2026-27002High7.7OpenClaw: Docker container escape via unvalidated bind mount config injectionCWE-2502026-02-19
CVE-2026-32048High7.7OpenClaw < 2026.3.1 - Sandbox Escape via Cross-Agent sessions_spawnCWE-7322026-03-21
CVE-2026-43569High7.7OpenClaw: Workspace provider auth choices could auto-enable untrusted provider pluginsCWE-8292026-05-05
CVE-2026-43571High7.7OpenClaw: Channel setup catalog lookups could include untrusted workspace plugin shadowsCWE-8292026-05-05
CVE-2026-44110High7.7OpenClaw: Matrix room control-command authorization no longer trusts DM pairing-store entriesCWE-8632026-05-06
CVE-2026-53807High7.7OpenClaw < 2026.5.6 - Authorization Bypass in Telegram Interactive Callbacks via commands.allowFromCWE-8632026-06-11
CVE-2026-41353High7.6OpenClaw < 2026.3.22 - allowProfiles Bypass via Profile Mutation and Runtime SelectionCWE-4722026-04-23
CVE-2026-43535High7.6OpenClaw < 2026.4.14 - Authorization Context Reuse in Collect-Mode Queue BatchesCWE-2662026-05-05
CVE-2026-26316High7.5OpenClaw has BlueBubbles webhook auth bypass via loopback proxy trustCWE-8632026-02-19
CVE-2026-26324High7.5OpenClaw has a SSRF guard bypass via full-form IPv4-mapped IPv6 (loopback / metadata reachable)CWE-9182026-02-19
CVE-2026-22179High7.5OpenClaw < 2026.2.22 - Allowlist Bypass via Command Substitution in system.runCWE-782026-03-18
CVE-2026-32025High7.5OpenClaw < 2026.2.25 - Password Brute-Force via Browser-Origin WebSocket Authentication BypassCWE-3072026-03-19
CVE-2026-28458High7.4OpenClaw's Browser Relay /cdp websocket is missing auth which could allow cross-tab cookie accessCWE-3062026-03-05
CVE-2026-34512High7.2OpenClaw < 2026.3.25 - Improper Access Control in /sessions/:sessionKey/kill EndpointCWE-8632026-04-09
CVE-2026-26317High7.1OpenClaw affected by cross-site request forgery (CSRF) through loopback browser mutation endpointsCWE-3522026-02-19
CVE-2026-26327High7.1OpenClaw allows unauthenticated discovery TXT records to steer routing and TLS pinningCWE-3452026-02-19
CVE-2026-32008High7.1OpenClaw < 2026.2.21 - Arbitrary Local File Read via Browser Navigation GuardCWE-6102026-03-19
CVE-2026-32976High7.1OpenClaw < 2026.3.11 - Account-Scoped configWrites Policy Bypass via Channel CommandsCWE-6392026-03-31
CVE-2026-35644High7.1OpenClaw < 2026.3.22 - Credential Exposure via baseUrl Fields in Gateway SnapshotsCWE-3122026-04-09
CVE-2026-35636High7.1OpenClaw 2026.3.11 < 2026.3.25 - Session Isolation Bypass via sessionId ResolutionCWE-6962026-04-09
CVE-2026-41368High7.1OpenClaw < 2026.3.28 - Environment Variable Disclosure via jq $ENV Filter BypassCWE-6682026-04-27
CVE-2026-41385High7.1OpenClaw < 2026.3.31 - Nostr Private Key Exposure via config.get Redaction BypassCWE-3122026-04-28
CVE-2026-42433High7.1OpenClaw: Matrix profile config persistence was reachable from operator.write message toolsCWE-8622026-05-05
CVE-2026-43567High7.1OpenClaw < 2026.4.10 - Path Traversal in screen_record outPath ParameterCWE-8622026-05-05
CVE-2026-43568High7.1OpenClaw 2026.4.5 < 2026.4.10 - Privilege Escalation via Memory Dreaming Configuration in /dreaming EndpointCWE-8622026-05-05
CVE-2026-41380High7OpenClaw < 2026.3.28 - Arbitrary Execution Allowlist via Wrapper Carrier ExecutablesCWE-8072026-04-28
CVE-2026-43531High7OpenClaw < 2026.4.9 - Environment Variable Injection via Workspace .env FileCWE-152026-05-05
CVE-2026-22178Medium6.9OpenClaw < 2026.2.19 - ReDoS and Regex Injection via Unescaped Feishu Mention MetadataCWE-13332026-03-18
CVE-2026-28480Medium6.9OpenClaw Telegram allowlist authorization accepted mutable usernamesCWE-2902026-03-05
CVE-2026-32975Medium6.9OpenClaw < 2026.3.12 - Weak Authorization via Mutable Group Names in Zalouser AllowlistCWE-8072026-03-29
CVE-2026-35626Medium6.9OpenClaw < 2026.3.22 - Unauthenticated Resource Exhaustion via Voice Call WebhookCWE-4052026-04-09
CVE-2026-34426Medium6.9OpenClaw - Approval Bypass via Environment Variable NormalizationCWE-1842026-04-02
CVE-2026-35647Medium6.9OpenClaw < 2026.3.25 - Direct Message Policy Bypass via Verification NoticesCWE-2882026-04-10
CVE-2026-41300Medium6.9OpenClaw < 2026.3.31 - Attacker-Discovered Endpoint Preservation in Remote OnboardingCWE-3722026-04-20
CVE-2026-41331Medium6.9OpenClaw < 2026.3.31 - Resource Consumption via Unauthorized Telegram Audio Preflight TranscriptionCWE-4082026-04-20
CVE-2026-35664Medium6.9OpenClaw < 2026.3.25 - DM Pairing Bypass via Legacy Card CallbacksCWE-2882026-04-10
CVE-2026-41374Medium6.9OpenClaw < 2026.3.31 - Resource Consumption via Discord Audio Preflight Before Member AuthorizationCWE-4082026-04-28
CVE-2026-41400Medium6.9OpenClaw < 2026.3.31 - Resource Consumption via Oversized WebSocket Frames in voice-callCWE-7702026-04-28
CVE-2026-44116Medium6.9OpenClaw < 2026.4.22 - Server-Side Request Forgery in Zalo Photo URL ValidationCWE-9182026-05-06
CVE-2026-53818Medium6.9OpenClaw < 2026.4.24 - Owner-Only Tool Policy Bypass via MCP LoopbackCWE-8622026-06-11
CVE-2026-29612Medium6.8OpenClaw < 2026.2.14 - Denial of Service via Large Base64 Media File DecodingCWE-7702026-03-05
CVE-2026-26972Medium6.7OpenClaw has a Path Traversal in Browser Download FunctionalityCWE-222026-02-19
CVE-2026-28452Medium6.7OpenClaw affected by denial of service through unguarded archive extraction allowing high expansion/resource abuse (ZIP/TAR)CWE-7702026-03-05
CVE-2026-26328Medium6.5OpenClaw iMessage group allowlist authorization inherited DM pairing-store identitiesCWE-284, CWE-8632026-02-19
CVE-2026-28449Medium6.3OpenClaw < 2026.2.25 - Webhook Replay Attack via Missing Durable Replay SuppressionCWE-2942026-03-19
CVE-2026-35628Medium6.3OpenClaw < 2026.3.25 - Brute-Force Attack via Missing Telegram Webhook Rate LimitingCWE-3072026-04-09
CVE-2026-35646Medium6.3OpenClaw < 2026.3.25 - Pre-Authentication Rate-Limit Bypass in Webhook Token ValidationCWE-3072026-04-09
CVE-2026-35649Medium6.3OpenClaw < 2026.3.22 - Settings Reconciliation Bypass via Empty AllowlistCWE-1832026-04-10
CVE-2026-35635Medium6.3OpenClaw < 2026.3.22 - Webhook Path Route Replacement Vulnerability in Synology ChatCWE-7062026-04-09
CVE-2026-41333Medium6.3OpenClaw < 2026.3.31 - Authentication Rate Limiting Bypass via Fake DeviceTokenCWE-7992026-04-23
CVE-2026-41389Medium6.3OpenClaw: Webchat media embedding enforces local-root containment for tool-result filesCWE-732026-04-20
CVE-2026-41913Medium6.3OpenClaw < 2026.4.4 - Rate-Limit Bypass via Concurrent Async Authentication AttemptsCWE-3622026-04-28
CVE-2026-43527Medium6.3OpenClaw: Browser SSRF policy default allowed private-network navigationCWE-918, CWE-11882026-05-05
CVE-2026-44117Medium6.3OpenClaw < 2026.4.20 - Server-Side Request Forgery in QQBot Direct Media UploadCWE-9182026-05-06
CVE-2026-44999Medium6.3OpenClaw < 2026.4.20 - Improper Trust Labeling in Isolated Cron Awareness EventsCWE-3452026-05-11
CVE-2026-45002Medium6.3OpenClaw < 2026.4.20 - Hook Session-Key Bypass via Template MappingCWE-8632026-05-11
CVE-2026-35645Medium6.1OpenClaw < 2026.3.25 - Privilege Escalation via Synthetic operator.admin in deleteSessionCWE-6482026-04-09
CVE-2026-32039Medium6OpenClaw < 2026.2.22 - Sender Authorization Bypass via Identity Collision in toolsBySenderCWE-6392026-03-19
CVE-2026-35622Medium6OpenClaw < 2026.3.22 - Improper Authentication Verification in Google Chat WebhookCWE-2902026-04-09
CVE-2026-42429Medium6OpenClaw < 2026.4.8 - Privilege Escalation via Gateway Plugin HTTP AuthenticationCWE-8632026-04-28
CVE-2026-43570Medium6OpenClaw contains a symlink traversal vulnerabilityCWE-612026-05-05
CVE-2026-44112Medium6OpenClaw < 2026.4.22 - Symlink Swap Race Condition in OpenShell FS Bridge WritesCWE-3672026-05-06
CVE-2026-44113Medium6OpenClaw: OpenShell FS bridge reads pin and verify the opened file before returning bytesCWE-3672026-05-06
CVE-2026-53830Medium6OpenClaw < 2026.4.22 - Webhook Secret Revocation Bypass via secrets.reloadCWE-6132026-06-12
CVE-2026-53838Medium6OpenClaw < 2026.5.27 - Node Pairing State Mutation via ReconnectionCWE-3672026-06-12
CVE-2026-28481Medium5.9OpenClaw < 2026.2.1 - Bearer Token Leakage via MS Teams Attachment Downloader Suffix MatchingCWE-2012026-03-05
CVE-2026-32054Medium5.9OpenClaw < 2026.2.25 - Symlink Traversal in Browser Trace/Download Path HandlingCWE-592026-03-21
CVE-2026-45005Medium5.9OpenClaw < 2026.4.23 - Webhook Route Secret Cache Not Invalidated After RotationCWE-6722026-05-11
CVE-2026-31999Medium5.8OpenClaw 2026.2.26 < 2026.3.1 - Current Working Directory Injection via Windows Wrapper Resolution FallbackCWE-782026-03-19
CVE-2026-32000Medium5.8OpenClaw < 2026.2.19 - Command Injection via Windows Shell Fallback in Lobster Tool ExecutionCWE-782026-03-19
CVE-2026-31995Medium5.8OpenClaw 2026.1.21 < 2026.2.19 - Command Injection via Windows Shell Fallback in Lobster ExtensionCWE-782026-03-19
CVE-2026-32988Medium5.8OpenClaw < 2026.3.11 - Sandbox Boundary Bypass via Unvalidated Temporary File CreationCWE-3672026-03-31
CVE-2026-41332Medium5.8OpenClaw < 2026.3.28 - Code Execution via Missing Environment Variable BlocklistCWE-1842026-04-23
CVE-2026-41360Medium5.4OpenClaw < 2026.4.2 - Approval Integrity Bypass in pnpm dlx Local Script BindingCWE-3672026-04-23
CVE-2026-44995Medium5.4OpenClaw: MCP stdio server env could load dangerous startup variables from workspace configCWE-8292026-05-11
CVE-2026-26326Medium5.3OpenClaw skills.status could leak secrets to operator.read clientsCWE-2002026-02-19
CVE-2026-32899Medium5.3OpenClaw < 2026.2.25 - Sender Policy Bypass in Slack Reaction and Pin Event HandlersCWE-8632026-03-21
CVE-2026-41909Medium5.3OpenClaw < 2026.4.20 - Improper Authorization in Paired-Device Pairing ActionsCWE-8632026-04-23
CVE-2026-35634Medium5.1OpenClaw < 2026.3.23 - Authentication Bypass via Local-Direct Requests in Canvas GatewayCWE-2882026-04-09
CVE-2026-42436Medium4.9OpenClaw < 2026.4.14 - Internal Page Content Exposure via Browser Snapshot and Screenshot RoutesCWE-8622026-05-05
CVE-2026-42439Medium4.9OpenClaw < 2026.4.10 - SSRF Policy Bypass in Browser Tabs Action RoutesCWE-8622026-05-05
CVE-2026-43532Medium4.9OpenClaw 2026.4.7 < 2026.4.10 - Sandbox Media Normalization Bypass via Discord Event Cover ImageCWE-1842026-05-05
CVE-2026-42438Medium4.9OpenClaw: Sender policy bypass in host media attachment reads allows unauthorized local file disclosureCWE-8632026-05-05
CVE-2026-43573Medium4.9OpenClaw: Existing-session browser interaction routes bypassed SSRF policy enforcementCWE-862, CWE-9182026-05-05
CVE-2026-43576Medium4.9OpenClaw < 2026.4.5 - Second-hop SSRF via CDP /json/version WebSocket URLCWE-601, CWE-9182026-05-06
CVE-2026-43580Medium4.9OpenClaw: Browser press/type interaction routes missed complete navigation guard coverageCWE-8622026-05-06
CVE-2026-43582Medium4.9OpenClaw < 2026.4.10 - DNS Rebinding SSRF via Hostname Validation BypassCWE-3672026-05-06
CVE-2026-27007Medium4.8OpenClaw's sandbox config hash sorted primitive arrays and suppressed needed container recreationCWE-12542026-02-19
CVE-2026-44992Medium4.1OpenClaw 2026.4.5 < 2026.4.20 - MiniMax API Host Override via Workspace dotenvCWE-4412026-05-11
CVE-2026-45003Medium4.1OpenClaw: Workspace dotenv files cannot override connector endpoint hostsCWE-4412026-05-11
CVE-2026-32006Low2.3OpenClaw < 2026.2.26 - Authorization Bypass via DM Pairing-Store Fallback in Group AllowlistCWE-8632026-03-19
CVE-2026-34507Low2.3OpenClaw < 2026.4.29 - Policy Bypass in QQBot Admin Commands via DM-only and allowFrom ChecksCWE-8632026-05-29
CVE-2026-35617Low2.3OpenClaw < 2026.3.25 - Authorization Bypass via Group Policy Rebinding with Mutable Space displayNameCWE-8072026-04-09
CVE-2026-35648Low2.3OpenClaw < 2026.3.22 - Policy Bypass via Unvalidated Queued Node ActionsCWE-3672026-04-10
CVE-2026-41347Low2.3OpenClaw < 2026.3.31 - Cross-Site Request Forgery via Missing Browser-Origin Validation in HTTP Operator EndpointsCWE-3522026-04-23
CVE-2026-41358Low2.3OpenClaw < 2026.4.2 - Sender Allowlist Bypass via Slack Thread ContextCWE-3462026-04-23
CVE-2026-41916Low2.3OpenClaw < 2026.4.8 - Stale Authentication State via Config ReloadCWE-6132026-04-28
CVE-2026-41908Low2.3OpenClaw < 2026.4.20 - Scope Enforcement Bypass in Assistant-Media RouteCWE-8632026-04-23
CVE-2026-44111Low2.3OpenClaw < 2026.4.15 - Arbitrary Markdown File Read via QMD memory_getCWE-1832026-05-06
CVE-2026-44993Low2.3OpenClaw < 2026.4.20 - Direct Message Misclassification in Feishu Card ActionsCWE-1842026-05-11
CVE-2026-44997Low2.3OpenClaw < 2026.4.22 - Security Envelope Constraint Bypass in ACP Child SessionsCWE-2662026-05-11
CVE-2026-44991Low2.3OpenClaw: Owner-enforced commands could accept wildcard channel senders as command ownersCWE-8632026-05-11
CVE-2026-53826Low2.3OpenClaw < 2026.4.26 - Information Disclosure via Sandboxed Session SpawnCWE-6682026-06-12
CVE-2026-31991Low2OpenClaw < 2026.2.26 - Authorization Bypass via DM Pairing-Store Leakage in Signal Group AllowlistCWE-8632026-03-19
CVE-2026-32058Low2OpenClaw < 2026.2.26 - Approval Context-Binding Weakness in system.run via host=nodeCWE-8632026-03-21
๐Ÿ“– Detailed CVE Analysis (click to expand)

CVE-2026-28466 โ€” OpenClaw < 2026.2.14 - Remote Code Execution via Node Invoke Approval Bypass

FieldDetail
CVSS9.4 (CRITICAL) โ€” CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
CWECWE-863 (Incorrect Authorization)
Affected< 2026.2.14
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-gv46-4xfq-jv58

OpenClaw versions prior to 2026.2.14 contain a vulnerability in the gateway in which it fails to sanitize internal approval fields in node.invoke parameters, allowing authenticated clients to bypass exec approval gating for system.run commands. Attackers with valid gateway credentials can inject approval control fields to execute arbitrary commands on connected node hosts, potentially compromising developer workstations and CI runners.

References:


CVE-2026-43534 โ€” OpenClaw < 2026.4.10 - Unsanitized External Input in Agent Hook Events

FieldDetail
CVSS9.3 (CRITICAL) โ€” CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
CWECWE-345 (CWE-345: Insufficient Verification of Data Authenticity)
Affected< 2026.4.10
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-7g8c-cfr3-vqqr

OpenClaw before 2026.4.10 contains an input validation vulnerability that allows external hook metadata to be enqueued as trusted system events. Attackers can supply malicious hook names to escalate untrusted input into higher-trust agent context.

References:


CVE-2026-32918 โ€” OpenClaw < 2026.3.11 - Session Sandbox Escape via session_status Tool

FieldDetail
CVSS9.2 (CRITICAL) โ€” CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N
CWECWE-863 (Incorrect Authorization)
Affected< 2026.3.11
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-wcxr-59v9-rxr8

OpenClaw before 2026.3.11 contains a session sandbox escape vulnerability in the session_status tool that allows sandboxed subagents to access parent or sibling session state. Attackers can supply arbitrary sessionKey values to read or modify session data outside their sandbox scope, including persisted model overrides.

References:


CVE-2026-32917 โ€” OpenClaw < 2026.3.13 - Remote Command Injection via Unsanitized iMessage Attachment Paths in SCP

FieldDetail
CVSS9.2 (CRITICAL) โ€” CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CWECWE-78 (Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'))
Affected< 2026.3.13
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-g2f6-pwvx-r275

OpenClaw before 2026.3.13 contains a remote command injection vulnerability in the iMessage attachment staging flow that allows attackers to execute arbitrary commands on configured remote hosts. The vulnerability exists because unsanitized remote attachment paths containing shell metacharacters are passed directly to the SCP remote operand without validation, enabling command execution when remote attachment staging is enabled.

References:


CVE-2026-43585 โ€” OpenClaw: Gateway HTTP endpoints re-resolve bearer auth after SecretRef rotation

FieldDetail
CVSS9.2 (CRITICAL) โ€” CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CWECWE-672 (Operation on a Resource after Expiration or Release)
Affected< 2026.4.15
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-xmxx-7p24-h892

OpenClaw before 2026.4.15 captures resolved bearer-auth configuration at startup, allowing revoked tokens to remain valid after SecretRef rotation. Gateway HTTP and WebSocket handlers fail to re-resolve authentication per-request, enabling attackers to use rotated-out bearer tokens for unauthorized gateway access.

References:


CVE-2026-44109 โ€” OpenClaw: Feishu webhook and card-action validation now fail closed

FieldDetail
CVSS9.2 (CRITICAL) โ€” CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CWECWE-1188 (CWE-1188 Initialization of a Resource with an Insecure Default)
Affected< 2026.4.15
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-xh72-v6v9-mwhc

OpenClaw before 2026.4.15 contains an authentication bypass vulnerability in Feishu webhook and card-action validation that allows unauthenticated requests to reach command dispatch. Missing encryptKey configuration and blank callback tokens fail open instead of rejecting requests, enabling attackers to bypass signature verification and replay protection to execute arbitrary commands.

References:


CVE-2026-41386 โ€” OpenClaw < 2026.3.22 - Privilege Escalation via Unbound Bootstrap Setup Codes

FieldDetail
CVSS9.1 (CRITICAL) โ€” CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
CWECWE-648 (CWE-648: Incorrect Use of Privileged APIs)
Affected< 2026.3.22
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-gg9v-mgcp-v6m7

OpenClaw before 2026.3.22 contains a privilege escalation vulnerability where bootstrap setup codes are not bound to intended device roles and scopes during pairing. Attackers can exploit this during first-use device pairing to escalate privileges beyond their intended role and scope.

References:


CVE-2026-43533 โ€” OpenClaw < 2026.4.10 - Arbitrary Local File Read via QQBot Media Tags

FieldDetail
CVSS8.9 (HIGH) โ€” CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N
CWECWE-23 (CWE-23: Relative Path Traversal)
Affected< 2026.4.10
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-66r7-m7xm-v49h

OpenClaw before 2026.4.10 contains an arbitrary file read vulnerability in QQBot media tags that allows attackers to reference host-local paths outside the intended media storage boundary. Attackers can craft malicious reply text containing media tags to disclose arbitrary local files through outbound media handling.

References:


CVE-2026-25253 โ€” OpenClaw/Clawdbot has 1-Click RCE via Authentication Token Exfiltration From gatewayUrl

FieldDetail
CVSS8.8 (HIGH) โ€” CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CWECWE-669 (CWE-669 Incorrect Resource Transfer Between Spheres)
Affected< 2026.1.29
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-g8p2-7wf7-98mq

OpenClaw (aka clawdbot or Moltbot) before 2026.1.29 obtains a gatewayUrl value from a query string and automatically makes a WebSocket connection without prompting, sending a token value.

Naming note: Uses all three names in description. packageURL still references pkg:npm/clawdbot. References:


CVE-2026-24763 โ€” OpenClaw/Clawdbot Docker Execution has Authenticated Command Injection via PATH Environment Variable

FieldDetail
CVSS8.8 (HIGH) โ€” CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWECWE-78 (CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'))
Affected< 2026.1.29
Vendor/Productclawdbot / clawdbot
AdvisoryGHSA-mc68-q9jw-2h3v

OpenClaw (formerly Clawdbot) is a personal AI assistant you run on your own devices. Prior to 2026.1.29, a command injection vulnerability existed in OpenClawโ€™s Docker sandbox execution mechanism due to unsafe handling of the PATH environment variable when constructing shell commands. An authenticated user able to control environment variables could influence command execution within the container context. This vulnerability is fixed in 2026.1.29.

Naming note: Uses old name clawdbot/clawdbot as vendor/product. References:


CVE-2026-32913 โ€” OpenClaw < 2026.3.7 - Custom Authorization Header Leakage via Cross-Origin Redirects

FieldDetail
CVSS8.8 (HIGH) โ€” CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:L/SI:L/SA:N
CWECWE-522 (CWE-522 Insufficiently Protected Credentials)
Affected< 2026.3.7
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-6mgf-v5j7-45cr

OpenClaw before 2026.3.7 contains an improper header validation vulnerability in fetchWithSsrFGuard that forwards custom authorization headers across cross-origin redirects. Attackers can trigger redirects to different origins to intercept sensitive headers like X-Api-Key and Private-Token intended for the original destination.

References:


CVE-2026-41296 โ€” OpenClaw < 2026.3.31 - Sandbox Escape via TOCTOU Race in Remote FS Bridge readFile

FieldDetail
CVSS8.8 (HIGH) โ€” CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N
CWECWE-367 (CWE-367: Time-of-check Time-of-use (TOCTOU) Race Condition)
Affected< 2026.3.31
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-9p3r-hh9g-5cmg

OpenClaw before 2026.3.31 contains a time-of-check-time-of-use race condition in the remote filesystem bridge readFile function that allows sandbox escape. Attackers can exploit the separate path validation and file read operations to bypass sandbox restrictions and read arbitrary files.

References:


CVE-2026-28478 โ€” OpenClaw affected by denial of service via unbounded webhook request body buffering

FieldDetail
CVSS8.7 (HIGH) โ€” CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
CWECWE-770 (Allocation of Resources Without Limits or Throttling)
Affected< 2026.2.13
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-q447-rj3r-2cgh

OpenClaw versions prior to 2026.2.13 contain a denial of service vulnerability in webhook handlers that buffer request bodies without strict byte or time limits. Remote unauthenticated attackers can send oversized JSON payloads or slow uploads to webhook endpoints causing memory pressure and availability degradation.

References:


CVE-2026-32042 โ€” OpenClaw < 2026.2.25 - Privilege Escalation via Unpaired Device Identity in Shared Gateway Authentication

FieldDetail
CVSS8.7 (HIGH) โ€” CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CWECWE-863 (CWE-863: Incorrect Authorization)
Affected< 2026.2.25
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-553v-f69r-656j

OpenClaw versions 2026.2.22 prior to 2026.2.25 contain a privilege escalation vulnerability allowing unpaired device identities to bypass operator pairing requirements and self-assign elevated operator scopes including operator.admin. Attackers with valid shared gateway authentication can present a self-signed unpaired device identity to request and obtain higher operator scopes before pairing approval is granted.

References:


CVE-2026-32051 โ€” OpenClaw < 2026.3.1 - Authorization Bypass in Agent Runs via Owner-Only Tool Access

FieldDetail
CVSS8.7 (HIGH) โ€” CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CWECWE-863 (CWE-863: Incorrect Authorization)
Affected< 2026.3.1
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-jr6x-2q95-fh2g

OpenClaw versions prior to 2026.3.1 contain an authorization mismatch vulnerability that allows authenticated callers with operator.write scope to invoke owner-only tool surfaces including gateway and cron through agent runs in scoped-token deployments. Attackers with write-scope access can perform control-plane actions beyond their intended authorization level by exploiting inconsistent owner-only gating during agent execution.

References:


CVE-2026-33573 โ€” OpenClaw < 2026.3.11 - Workspace Boundary Bypass via Agent RPC Parameters

FieldDetail
CVSS8.7 (HIGH) โ€” CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CWECWE-668 (Exposure of Resource to Wrong Sphere)
Affected< 2026.3.11
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-2rqg-gjgv-84jm

OpenClaw before 2026.3.11 contains an authorization bypass vulnerability in the gateway agent RPC that allows authenticated operators with operator.write permission to override workspace boundaries by supplying attacker-controlled spawnedBy and workspaceDir values. Remote operators can escape the configured workspace boundary and execute arbitrary file and exec operations from any process-accessible directory.

References:


CVE-2026-41405 โ€” OpenClaw < 2026.3.31 - Resource Exhaustion via Unauthenticated MS Teams Webhook Body Parsing

FieldDetail
CVSS8.7 (HIGH) โ€” CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
CWECWE-408 (CWE-408: Incorrect Behavior Order: Early Amplification)
Affected< 2026.3.31
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-p464-m8x6-vhv8

OpenClaw before 2026.3.31 parses MS Teams webhook request bodies before performing JWT validation, allowing unauthenticated attackers to trigger resource exhaustion. Remote attackers can send malicious Teams webhook payloads to exhaust server resources by bypassing authentication checks.

References:


CVE-2026-42434 โ€” OpenClaw: Sandboxed agents could escape exec routing via host=node override

FieldDetail
CVSS8.7 (HIGH) โ€” CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CWECWE-863 (CWE-863: Incorrect Authorization)
Affected< 2026.4.10
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-736r-jwj6-4w23

OpenClaw versions 2026.4.5 before 2026.4.10 contain a sandbox escape vulnerability allowing sandboxed agents to override exec routing by specifying host=node. Attackers can bypass sandbox boundaries and route execution to remote nodes instead of intended sandbox paths.

References:


CVE-2026-43530 โ€” OpenClaw: busybox and toybox applet execution weakened exec approval binding

FieldDetail
CVSS8.7 (HIGH) โ€” CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CWECWE-863 (CWE-863: Incorrect Authorization)
Affected< 2026.4.12
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-2cq5-mf3v-mx44

OpenClaw versions 2026.2.23 before 2026.4.12 contain a weakened exec approval binding vulnerability in busybox and toybox applet execution that allows attackers to obscure which applet would actually run. Attackers can exploit opaque multi-call binaries to bypass exec approval mechanisms and weaken risk classification of unsafe applet invocations.

References:


CVE-2026-44115 โ€” OpenClaw < 2026.4.22 - Shell Expansion Bypass in Unquoted Heredocs via Exec Allowlist

FieldDetail
CVSS8.7 (HIGH) โ€” CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CWECWE-184 (CWE-184: Incomplete List of Disallowed Inputs)
Affected< 2026.4.22
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-x3h8-jrgh-p8jx

OpenClaw before 2026.4.22 contains an exec allowlist analysis vulnerability allowing shell expansion hiding in unquoted heredoc bodies. Attackers can bypass allowlist validation by embedding shell expansion tokens in heredoc bodies to execute unapproved commands at runtime.

References:


CVE-2026-53814 โ€” OpenClaw < 2026.5.20 - Privilege Escalation via Hook-Triggered CLI MCP Tool Authority

FieldDetail
CVSS8.7 (HIGH) โ€” CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N
CWECWE-266 (Incorrect Privilege Assignment)
Affected< 2026.5.20
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-6fvr-66p3-3qj4

OpenClaw before 2026.5.20 contains a privilege escalation vulnerability where hook-triggered agent runs incorrectly receive owner-scoped MCP loopback authority instead of hook-appropriate scope. Attackers with a valid hook token can exploit the /hooks/agent endpoint to cause spawned CLI runtimes to access or invoke owner-only MCP tools, potentially executing privileged actions like persistent cron state modifications.

References:


CVE-2026-32920 โ€” OpenClaw < 2026.3.12 - Arbitrary Code Execution via Auto-Discovery of Workspace Plugins

FieldDetail
CVSS8.6 (HIGH) โ€” CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CWECWE-829 (Inclusion of Functionality from Untrusted Control Sphere)
Affected< 2026.3.12
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-99qw-6mr3-36qr

OpenClaw before 2026.3.12 automatically discovers and loads plugins from .OpenClaw/extensions/ without explicit trust verification, allowing arbitrary code execution. Attackers can execute malicious code by including crafted workspace plugins in cloned repositories that execute when users run OpenClaw from the directory.

References:


CVE-2026-33579 โ€” OpenClaw < 2026.3.28 - Privilege Escalation via Missing Caller Scope Validation in Device Pair Approval

FieldDetail
CVSS8.6 (HIGH) โ€” CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
CWECWE-863 (CWE-863 Incorrect Authorization)
Affected< 2026.3.28
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-hc5h-pmr3-3497

OpenClaw before 2026.3.28 contains a privilege escalation vulnerability in the /pair approve command path that fails to forward caller scopes into the core approval check. A caller with pairing privileges but without admin privileges can approve pending device requests asking for broader scopes including admin access by exploiting the missing scope validation in extensions/device-pair/index.ts and src/infra/device-pairing.ts.

References:


CVE-2026-53823 โ€” OpenClaw < 2026.5.3 - Privilege Escalation via Mutable Slack Display Names in allowFrom

FieldDetail
CVSS8.6 (HIGH) โ€” CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
CWECWE-290 (Authentication Bypass by Spoofing)
Affected< 2026.5.3
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-c29c-2q9c-pc86

OpenClaw before 2026.5.3 contains a privilege escalation vulnerability in the allowFrom feature that binds to mutable Slack display names. Attackers with Slack account access can change display name metadata to match policy entries, potentially gaining unauthorized agent access intended for other identities.

References:


CVE-2026-44118 โ€” OpenClaw < 2026.4.22 - Owner Context Spoofing via Bearer Token Header

FieldDetail
CVSS8.5 (HIGH) โ€” CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CWECWE-290 (CWE-290: Authentication Bypass by Spoofing)
Affected< 2026.4.22
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-r6xh-pqhr-v4xh

OpenClaw before 2026.4.22 derives loopback MCP owner context from spoofable server-issued bearer tokens in request headers. Non-owner loopback clients can present themselves as owner to bypass owner-gated operations by manipulating the sender-owner header metadata.

References:


CVE-2026-44114 โ€” OpenClaw: Workspace dotenv could override runtime-control environment variables

FieldDetail
CVSS8.5 (HIGH) โ€” CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CWECWE-184 (CWE-184: Incomplete List of Disallowed Inputs)
Affected< 2026.4.20
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-hxvm-xjvf-93f3

OpenClaw before 2026.4.20 fails to properly reserve the OPENCLAW_ runtime-control environment namespace in workspace dotenv files, allowing attackers to override critical runtime variables. Malicious workspaces can set variables like OPENCLAW_GIT_DIR to manipulate trusted OpenClaw runtime behavior during source-update or installer flows.

References:


CVE-2026-45004 โ€” OpenClaw vulnerable to arbitrary code execution via attacker-controlled setup-api.js loaded from cwd during env-key resolution

FieldDetail
CVSS8.4 (HIGH) โ€” CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CWECWE-427 (Uncontrolled Search Path Element)
Affected< 2026.4.23
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-r39h-4c2p-3jxp

OpenClaw before 2026.4.23 contains an arbitrary code execution vulnerability in the bundled plugin setup resolver that loads setup-api.js from process.cwd() during provider setup metadata resolution. Attackers can execute arbitrary JavaScript under the current user account by placing a malicious extensions//setup-api.js file in a repository and convincing a user to run OpenClaw commands from that directory.

References:


CVE-2026-31998 โ€” OpenClaw 2026.2.22 < 2026.2.24 - Authorization Bypass in Synology Chat Plugin via Empty allowedUserIds

FieldDetail
CVSS8.3 (HIGH) โ€” CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N
CWECWE-863 (CWE-863: Incorrect Authorization)
Affected< 2026.2.24
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-gw85-xp4q-5gp9

OpenClaw versions 2026.2.22 and 2026.2.23 contain an authorization bypass vulnerability in the synology-chat channel plugin where dmPolicy set to allowlist with empty allowedUserIds fails open. Attackers with Synology sender access can bypass authorization checks and trigger unauthorized agent dispatch and downstream tool actions.

References:


CVE-2026-35618 โ€” OpenClaw < 2026.3.23 - Replay Identity Drift via Query-Only Variants in Plivo V2 Verification

FieldDetail
CVSS8.3 (HIGH) โ€” CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N
CWECWE-294 (CWE-294 Authentication Bypass by Capture-replay)
Affected< 2026.3.23
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-cg6c-q2hx-69h7

OpenClaw before 2026.3.23 contains a replay identity vulnerability in Plivo V2 signature verification that allows attackers to bypass replay protection by modifying query parameters. The verification path derives replay keys from the full URL including query strings instead of the canonicalized base URL, enabling attackers to mint new verified request keys through unsigned query-only changes to signed requests.

References:


CVE-2026-43526 โ€” OpenClaw: QQBot reply media URL handling could trigger SSRF and re-upload fetched bytes

FieldDetail
CVSS8.3 (HIGH) โ€” CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N
CWECWE-918 (CWE-918 Server-Side Request Forgery (SSRF))
Affected< 2026.4.12
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-2767-2q9v-9326

OpenClaw before 2026.4.12 contains a server-side request forgery vulnerability in QQBot reply media URL handling that allows attackers to fetch arbitrary content. Attackers can exploit this by providing malicious media URLs that trigger SSRF requests, with fetched bytes subsequently re-uploaded through the channel.

References:


CVE-2026-28469 โ€” OpenClaw Google Chat shared-path webhook target ambiguity allowed cross-account policy-context misrouting

FieldDetail
CVSS8.2 (HIGH) โ€” CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
CWECWE-639 (Authorization Bypass Through User-Controlled Key)
Affected< 2026.2.14
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-rq6g-px6m-c248

OpenClaw versions prior to 2026.2.14 contain a webhook routing vulnerability in the Google Chat monitor component that allows cross-account policy context misrouting when multiple webhook targets share the same HTTP path. Attackers can exploit first-match request verification semantics to process inbound webhook events under incorrect account contexts, bypassing intended allowlists and session policies.

References:


CVE-2026-29611 โ€” OpenClaw < 2026.2.14 - Local File Inclusion via mediaPath Parameter in BlueBubbles Media Handling

FieldDetail
CVSS8.2 (HIGH) โ€” CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
CWECWE-73 (External Control of File Name or Path)
Affected< 2026.2.14
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-rwj8-p9vq-25gv

OpenClaw versions prior to 2026.2.14 contain a local file inclusion vulnerability in BlueBubbles extension (must be installed and enabled) media path handling that allows attackers to read arbitrary files from the local filesystem. The sendBlueBubblesMedia function fails to validate mediaPath parameters against an allowlist, enabling attackers to request sensitive files like /etc/passwd and exfiltrate them as media attachments.

References:


CVE-2026-25157 โ€” OpenClaw/Clawdbot has OS Command Injection via Project Root Path in sshNodeCommand

FieldDetail
CVSS7.8 (HIGH) โ€” CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
CWECWE-78 (CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'))
Affected< 2026.1.29
Vendor/Productopenclaw / openclaw
AdvisoryGHSA-q284-4pvr-m585

OpenClaw is a personal AI assistant. Prior to version 2026.1.29, there is an OS command injection vulnerability via the Project Root Path in sshNodeCommand. The sshNodeCommand function constructed a shell script without properly escaping the user-supplied project path in an error message. When the cd command failed, the unescaped path was interpolated directly into an echo statement, allowing arbitrary command execution on the remote SSH host. The parseSSHTarget function did not validate that SSH target strings could not begin with a dash. An attacker-supplied target like -oProxyCommand=... would be interpreted as an SSH configuration flag rather than a hostname, allowing arbitrary command execution on the local machine. This issue has been patched in version 2026.1.29.


CVE-2026-27002 โ€” OpenClaw: Docker container escape via unvalidated bind mount config injection

FieldDetail
CVSS7.7 (HIGH) โ€” CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CWECWE-250 (CWE-250: Execution with Unnecessary Privileges)
Affected< 2026.2.15
Vendor/Productopenclaw / openclaw
AdvisoryGHSA-w235-x559-36mg

OpenClaw is a personal AI assistant. Prior to version 2026.2.15, a configuration injection issue in the Docker tool sandbox could allow dangerous Docker options (bind mounts, host networking, unconfined profiles) to be applied, enabling container escape or host data access. OpenClaw 2026.2.15 blocks dangerous sandbox Docker settings and includes runtime enforcement when building docker create args; config-schema validation for network=host, seccompProfile=unconfined, apparmorProfile=unconfined; and security audit findings to surface dangerous sandbox docker config. As a workaround, do not configure agents.*.sandbox.docker.binds to mount system directories or Docker socket paths, keep agents.*.sandbox.docker.network at none (default) or bridge, and do not use unconfined for seccomp/AppArmor profiles.

References:


CVE-2026-32048 โ€” OpenClaw < 2026.3.1 - Sandbox Escape via Cross-Agent sessions_spawn

FieldDetail
CVSS7.7 (HIGH) โ€” CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CWECWE-732 (CWE-732: Incorrect Permission Assignment for Critical Resource)
Affected< 2026.3.1
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-p7gr-f84w-hqg5

OpenClaw versions prior to 2026.3.1 fail to enforce sandbox inheritance during cross-agent sessions_spawn operations, allowing sandboxed sessions to create child processes under unsandboxed agents. An attacker with a sandboxed session can exploit this to spawn child runtimes with sandbox.mode set to off, bypassing runtime confinement restrictions.

References:


CVE-2026-43569 โ€” OpenClaw: Workspace provider auth choices could auto-enable untrusted provider plugins

FieldDetail
CVSS7.7 (HIGH) โ€” CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CWECWE-829 (CWE-829: Inclusion of Functionality from Untrusted Control Sphere)
Affected< 2026.4.9
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-939r-rj45-g2rj

OpenClaw before 2026.4.9 contains an authentication bypass vulnerability allowing untrusted workspace plugins to be auto-enabled during non-interactive onboarding when provider auth choices are shadowed. Attackers can exploit this by crafting malicious workspace plugins that are automatically selected and enabled during authentication setup without explicit user consent.

References:


CVE-2026-43571 โ€” OpenClaw: Channel setup catalog lookups could include untrusted workspace plugin shadows

FieldDetail
CVSS7.7 (HIGH) โ€” CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CWECWE-829 (CWE-829: Inclusion of Functionality from Untrusted Control Sphere)
Affected< 2026.4.10
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-82qx-6vj7-p8m2

OpenClaw before 2026.4.10 contains a plugin trust bypass vulnerability that allows channel setup catalog lookups to resolve workspace plugin shadows before bundled channel plugins. Attackers can exploit this by crafting malicious workspace plugins that bypass intended trust gates during setup-time plugin loading.

References:


CVE-2026-44110 โ€” OpenClaw: Matrix room control-command authorization no longer trusts DM pairing-store entries

FieldDetail
CVSS7.7 (HIGH) โ€” CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CWECWE-863 (CWE-863: Incorrect Authorization)
Affected< 2026.4.15
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-2gvc-4f3c-2855

OpenClaw before 2026.4.15 contains an authorization bypass vulnerability in Matrix room control-command authorization that trusts DM pairing-store entries. Attackers with DM-paired sender IDs can execute room control commands without being in configured allowlists by posting in bot rooms, potentially enabling privileged OpenClaw behavior.

References:


CVE-2026-53807 โ€” OpenClaw < 2026.5.6 - Authorization Bypass in Telegram Interactive Callbacks via commands.allowFrom

FieldDetail
CVSS7.7 (HIGH) โ€” CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CWECWE-863 (Incorrect Authorization)
Affected< 2026.5.6
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-w5ww-7chg-mxcq

OpenClaw before 2026.5.6 contains an authorization bypass vulnerability in Telegram interactive callbacks that allows authenticated users to skip commands.allowFrom validation. Attackers can invoke affected callbacks to mark themselves as authorized senders before allowlist checks are applied, triggering command behavior outside configured Telegram sender restrictions.

References:


CVE-2026-41353 โ€” OpenClaw < 2026.3.22 - allowProfiles Bypass via Profile Mutation and Runtime Selection

FieldDetail
CVSS7.6 (HIGH) โ€” CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
CWECWE-472 (CWE-472 External Control of Assumed-Immutable Web Parameter)
Affected< 2026.3.22
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-h5hg-h7rr-gpf3

OpenClaw before 2026.3.22 contains an access control bypass vulnerability in the allowProfiles feature that allows attackers to circumvent profile restrictions through persistent profile mutation and runtime profile selection. Remote attackers can exploit this by manipulating browser proxy profiles at runtime to access restricted profiles and bypass intended access controls.

References:


CVE-2026-43535 โ€” OpenClaw < 2026.4.14 - Authorization Context Reuse in Collect-Mode Queue Batches

FieldDetail
CVSS7.6 (HIGH) โ€” CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
CWECWE-266 (CWE-266: Incorrect Privilege Assignment)
Affected< 2026.4.14
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-jwrq-8g5x-5fhm

OpenClaw before 2026.4.14 contains an authorization context reuse vulnerability in collect-mode queue batches that allows messages from different senders to inherit the final sender's authorization context. Attackers can exploit this by sending multiple queued messages to drain batches using a more privileged sender's context, causing earlier messages to execute with elevated permissions.

References:


CVE-2026-26316 โ€” OpenClaw has BlueBubbles webhook auth bypass via loopback proxy trust

FieldDetail
CVSS7.5 (HIGH) โ€” CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CWECWE-863 (CWE-863: Incorrect Authorization)
Affected< 2026.2.13
Vendor/Productopenclaw / @openclaw/bluebubbles
AdvisoryGHSA-pchc-86f6-8758

OpenClaw is a personal AI assistant. Prior to 2026.2.13, the optional BlueBubbles iMessage channel plugin could accept webhook requests as authenticated based only on the TCP peer address being loopback (127.0.0.1, ::1, ::ffff:127.0.0.1) even when the configured webhook secret was missing or incorrect. This does not affect the default iMessage integration unless BlueBubbles is installed and enabled. Version 2026.2.13 contains a patch. Other mitigations include setting a non-empty BlueBubbles webhook password and avoiding deployments where a public-facing reverse proxy forwards to a loopback-bound Gateway without strong upstream authentication.

References:


CVE-2026-26324 โ€” OpenClaw has a SSRF guard bypass via full-form IPv4-mapped IPv6 (loopback / metadata reachable)

FieldDetail
CVSS7.5 (HIGH) โ€” CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CWECWE-918 (CWE-918: Server-Side Request Forgery (SSRF))
Affected< 2026.2.14
Vendor/Productopenclaw / openclaw
AdvisoryGHSA-jrvc-8ff5-2f9f

OpenClaw is a personal AI assistant. Prior to version 2026.2.14, OpenClaw's SSRF protection could be bypassed using full-form IPv4-mapped IPv6 literals such as 0:0:0:0:0:ffff:7f00:1 (which is 127.0.0.1). This could allow requests that should be blocked (loopback / private network / link-local metadata) to pass the SSRF guard. Version 2026.2.14 patches the issue.

References:


CVE-2026-22179 โ€” OpenClaw < 2026.2.22 - Allowlist Bypass via Command Substitution in system.run

FieldDetail
CVSS7.5 (HIGH) โ€” CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CWECWE-78 (Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78))
Affected< 2026.2.22
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-9p38-94jf-hgjj

OpenClaw versions prior to 2026.2.22 in macOS node-host system.run contain an allowlist bypass vulnerability that allows remote attackers to execute non-allowlisted commands by exploiting improper parsing of command substitution tokens. Attackers can craft shell payloads with command substitution syntax within double-quoted text to bypass security restrictions and execute arbitrary commands on the system.

References:


CVE-2026-32025 โ€” OpenClaw < 2026.2.25 - Password Brute-Force via Browser-Origin WebSocket Authentication Bypass

FieldDetail
CVSS7.5 (HIGH) โ€” CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CWECWE-307 (CWE-307 Improper Restriction of Excessive Authentication Attempts)
Affected< 2026.2.25
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-jmmg-jqc7-5qf4

OpenClaw versions prior to 2026.2.25 contain an authentication hardening gap in browser-origin WebSocket clients that allows attackers to bypass origin checks and auth throttling on loopback deployments. An attacker can trick a user into opening a malicious webpage and perform password brute-force attacks against the gateway to establish an authenticated operator session and invoke control-plane methods.

References:


FieldDetail
CVSS7.4 (HIGH) โ€” CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
CWECWE-306 (Missing Authentication for Critical Function)
Affected< 2026.2.1
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-mr32-vwc2-5j6h

OpenClaw version 2026.1.20 prior to 2026.2.1 contains a vulnerability in the Browser Relay (extension must be installed and enabled) /cdp WebSocket endpoint in which it does not require authentication tokens, allowing websites to connect via loopback and access sensitive data. Attackers can exploit this by connecting to ws://127.0.0.1:18792/cdp to steal session cookies and execute JavaScript in other browser tabs.

References:


CVE-2026-34512 โ€” OpenClaw < 2026.3.25 - Improper Access Control in /sessions/:sessionKey/kill Endpoint

FieldDetail
CVSS7.2 (HIGH) โ€” CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N
CWECWE-863 (CWE-863: Incorrect Authorization)
Affected< 2026.3.25
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-9p93-7j67-5pc2

OpenClaw before 2026.3.25 contains an improper access control vulnerability in the HTTP /sessions/:sessionKey/kill route that allows any bearer-authenticated user to invoke admin-level session termination functions without proper scope validation. Attackers can exploit this by sending authenticated requests to kill arbitrary subagent sessions via the killSubagentRunAdmin function, bypassing ownership and operator scope restrictions.

References:


CVE-2026-26317 โ€” OpenClaw affected by cross-site request forgery (CSRF) through loopback browser mutation endpoints

FieldDetail
CVSS7.1 (HIGH) โ€” CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L
CWECWE-352 (CWE-352: Cross-Site Request Forgery (CSRF))
Affected<= 2026.1.24-3
Vendor/Productopenclaw / clawdbot
AdvisoryGHSA-3fqr-4cg8-h96q

OpenClaw is a personal AI assistant. Prior to 2026.2.14, browser-facing localhost mutation routes accepted cross-origin browser requests without explicit Origin/Referer validation. Loopback binding reduces remote exposure but does not prevent browser-initiated requests from malicious origins. A malicious website can trigger unauthorized state changes against a victim's local OpenClaw browser control plane (for example opening tabs, starting/stopping the browser, mutating storage/cookies) if the browser control service is reachable on loopback in the victim's browser context. Starting in version 2026.2.14, mutating HTTP methods (POST/PUT/PATCH/DELETE) are rejected when the request indicates a non-loopback Origin/Referer (or Sec-Fetch-Site: cross-site). Other mitigations include enabling browser control auth (token/password) and avoid running with auth disabled.

Naming note: Uses old name openclaw/clawdbot as vendor/product. References:


CVE-2026-26327 โ€” OpenClaw allows unauthenticated discovery TXT records to steer routing and TLS pinning

FieldDetail
CVSS7.1 (HIGH) โ€” CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
CWECWE-345 (CWE-345: Insufficient Verification of Data Authenticity)
Affected< 2026.2.14
Vendor/Productopenclaw / openclaw
AdvisoryGHSA-pv58-549p-qh99

OpenClaw is a personal AI assistant. Discovery beacons (Bonjour/mDNS and DNS-SD) include TXT records such as lanHost, tailnetDns, gatewayPort, and gatewayTlsSha256. TXT records are unauthenticated. Prior to version 2026.2.14, some clients treated TXT values as authoritative routing/pinning inputs. iOS and macOS used TXT-provided host hints (lanHost/tailnetDns) and ports (gatewayPort) to build the connection URL. iOS and Android allowed the discovery-provided TLS fingerprint (gatewayTlsSha256) to override a previously stored TLS pin. On a shared/untrusted LAN, an attacker could advertise a rogue _openclaw-gw._tcp service. This could cause a client to connect to an attacker-controlled endpoint and/or accept an attacker certificate, potentially exfiltrating Gateway credentials (auth.token / auth.password) during connection. As of time of publication, the iOS and Android apps are alpha/not broadly shipped (no public App Store / Play Store release). Practical impact is primarily limited to developers/testers running those builds, plus any other shipped clients relying on discovery on a shared/untrusted LAN. Version 2026.2.14 fixes the issue. Clients now prefer the resolved service endpoint (SRV + A/AAAA) over TXT-provided routing hints. Discovery-provided fingerprints no longer override stored TLS pins. In iOS/Android, first-time TLS pins require explicit user confirmation (fingerprint shown; no silent TOFU) and discovery-based direct connects are TLS-only. In Android, hostname verification is no longer globally disabled (only bypassed when pinning).

References:


CVE-2026-32008 โ€” OpenClaw < 2026.2.21 - Arbitrary Local File Read via Browser Navigation Guard

FieldDetail
CVSS7.1 (HIGH) โ€” CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
CWECWE-610 (CWE-610: Externally Controlled Reference to a Resource in Another Sphere)
Affected< 2026.2.21
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-45cg-2683-gfmq

OpenClaw versions prior to 2026.2.21 contain an improper URL scheme validation vulnerability in the assertBrowserNavigationAllowed() function that allows authenticated users with browser-tool access to navigate to file:// URLs. Attackers can exploit this by accessing local files readable by the OpenClaw process user through browser snapshot and extraction actions to exfiltrate sensitive data.

References:


CVE-2026-32976 โ€” OpenClaw < 2026.3.11 - Account-Scoped configWrites Policy Bypass via Channel Commands

FieldDetail
CVSS7.1 (HIGH) โ€” CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
CWECWE-639 (Authorization Bypass Through User-Controlled Key)
Affected< 2026.3.11
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-8jhh-jcqg-mj5p

OpenClaw before 2026.3.11 contains an authorization bypass vulnerability allowing channel commands to mutate protected sibling-account configuration despite configWrites restrictions. Attackers with authorized access on one account can execute channel commands like /config set channels..accounts. to modify configuration on target accounts with configWrites: false.

References:


CVE-2026-35644 โ€” OpenClaw < 2026.3.22 - Credential Exposure via baseUrl Fields in Gateway Snapshots

FieldDetail
CVSS7.1 (HIGH) โ€” CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
CWECWE-312 (CWE-312: Cleartext Storage of Sensitive Information)
Affected< 2026.3.22
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-ppwq-6v66-5m6j

OpenClaw before 2026.3.22 contains an information disclosure vulnerability that allows attackers with operator.read scope to expose credentials embedded in channel baseUrl and httpUrl fields. Attackers can access gateway snapshots via config.get and channels.status endpoints to retrieve sensitive authentication information from URL userinfo components.

References:


CVE-2026-35636 โ€” OpenClaw 2026.3.11 < 2026.3.25 - Session Isolation Bypass via sessionId Resolution

FieldDetail
CVSS7.1 (HIGH) โ€” CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
CWECWE-696 (CWE-696: Incorrect Behavior Order)
Affected< *
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-q2qc-744p-66r2

OpenClaw versions 2026.3.11 through 2026.3.24 contain a session isolation bypass vulnerability where session_status resolves sessionId to canonical session keys before enforcing visibility checks. Sandboxed child sessions can exploit this to access parent or sibling sessions that should be blocked by explicit sessionKey restrictions.

References:


CVE-2026-41368 โ€” OpenClaw < 2026.3.28 - Environment Variable Disclosure via jq $ENV Filter Bypass

FieldDetail
CVSS7.1 (HIGH) โ€” CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
CWECWE-668 (CWE-668: Exposure of Resource to Wrong Sphere)
Affected< 2026.3.28
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-jccr-rrw2-vc8h

OpenClaw before 2026.3.28 contains an environment variable disclosure vulnerability in the jq safe-bin policy that fails to block the ENVfilter.Attackerscanbypasssafeโˆ’binrestrictionsbyusingENV filter. Attackers can bypass safe-bin restrictions by using ENV in jq programs to access sensitive environment variables that should be restricted.

References:


CVE-2026-41385 โ€” OpenClaw < 2026.3.31 - Nostr Private Key Exposure via config.get Redaction Bypass

FieldDetail
CVSS7.1 (HIGH) โ€” CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
CWECWE-312 (CWE-312: Cleartext Storage of Sensitive Information)
Affected< 2026.3.31
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-jjw7-3vjf-fg5j

OpenClaw before 2026.3.31 stores Nostr privateKey as plaintext in configuration, allowing exposure through config.get method calls that bypass redaction mechanisms. Attackers can retrieve unredacted configuration data to obtain plaintext signing keys used for Nostr protocol operations.

References:


CVE-2026-42433 โ€” OpenClaw: Matrix profile config persistence was reachable from operator.write message tools

FieldDetail
CVSS7.1 (HIGH) โ€” CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
CWECWE-862 (CWE-862 Missing Authorization)
Affected< 2026.4.10
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-7jp6-r74r-995q

OpenClaw before 2026.4.10 contains an authorization bypass vulnerability allowing operator.write message-tool paths to access Matrix profile persistence requiring admin-level authority. Attackers can exploit insufficient access controls to mutate persistent profile configuration through non-owner message-tool runs.

References:


CVE-2026-43567 โ€” OpenClaw < 2026.4.10 - Path Traversal in screen_record outPath Parameter

FieldDetail
CVSS7.1 (HIGH) โ€” CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
CWECWE-862 (CWE-862 Missing Authorization)
Affected< 2026.4.10
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-jf25-7968-h2h5

OpenClaw before 2026.4.10 contains a path traversal vulnerability in the screen_record tool's outPath parameter that bypasses workspace-only filesystem guards. Attackers can exploit this by specifying an outPath outside the workspace boundary to write files to unintended locations on the system.

References:


CVE-2026-43568 โ€” OpenClaw 2026.4.5 < 2026.4.10 - Privilege Escalation via Memory Dreaming Configuration in /dreaming Endpoint

FieldDetail
CVSS7.1 (HIGH) โ€” CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
CWECWE-862 (CWE-862 Missing Authorization)
Affected< 2026.4.10
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-5gjc-grvm-m88j

OpenClaw versions 2026.4.5 before 2026.4.10 contain a privilege escalation vulnerability allowing write-scoped operators to modify persistent memory dreaming settings. Attackers with write-scoped gateway access can toggle admin-class configuration mutations through the /dreaming endpoint to escalate privileges.

References:


CVE-2026-41380 โ€” OpenClaw < 2026.3.28 - Arbitrary Execution Allowlist via Wrapper Carrier Executables

FieldDetail
CVSS7 (HIGH) โ€” CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CWECWE-807 (CWE-807 Reliance on Untrusted Inputs in a Security Decision)
Affected< 2026.3.28
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-p4x4-2r7f-wjxg

OpenClaw before 2026.3.28 contains an execution approval vulnerability in exec-approvals-allowlist.ts that allows allow-always persistence to trust wrapper carrier executables instead of invoked targets. Attackers can exploit positional carrier executable routing through dispatch wrappers to establish broader allowlist entries than intended, weakening execution approval boundaries.

References:


CVE-2026-43531 โ€” OpenClaw < 2026.4.9 - Environment Variable Injection via Workspace .env File

FieldDetail
CVSS7 (HIGH) โ€” CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CWECWE-15 (CWE-15: External Control of System or Configuration Setting)
Affected< 2026.4.9
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-7wv4-cc7p-jhxc

OpenClaw before 2026.4.9 contains an environment variable injection vulnerability allowing malicious workspace .env files to set runtime-control variables. Attackers can inject variables affecting update sources, gateway URLs, ClawHub resolution, and browser executable paths to compromise application behavior.

References:


CVE-2026-22178 โ€” OpenClaw < 2026.2.19 - ReDoS and Regex Injection via Unescaped Feishu Mention Metadata

FieldDetail
CVSS6.9 (MEDIUM) โ€” CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N
CWECWE-1333 (CWE-1333)
Affected< 2026.2.19
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-c6hr-w26q-c636

OpenClaw versions prior to 2026.2.19 construct RegExp objects directly from unescaped Feishu mention metadata in the stripBotMention function, allowing regex injection and denial of service. Attackers can craft nested-quantifier patterns or metacharacters in mention metadata to trigger catastrophic backtracking, block message processing, or remove unintended content before model processing.

References:


CVE-2026-28480 โ€” OpenClaw Telegram allowlist authorization accepted mutable usernames

FieldDetail
CVSS6.9 (MEDIUM) โ€” CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
CWECWE-290 (Authentication Bypass by Spoofing)
Affected< 2026.2.14
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-mj5r-hh7j-4gxf

OpenClaw versions prior to 2026.2.14 contain an authorization bypass vulnerability where Telegram allowlist matching accepts mutable usernames instead of immutable numeric sender IDs. Attackers can spoof identity by obtaining recycled usernames to bypass allowlist restrictions and interact with bots as unauthorized senders.

References:


CVE-2026-32975 โ€” OpenClaw < 2026.3.12 - Weak Authorization via Mutable Group Names in Zalouser Allowlist

FieldDetail
CVSS6.9 (MEDIUM) โ€” CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
CWECWE-807 (Reliance on Untrusted Inputs in a Security Decision)
Affected< 2026.3.12
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-f5mf-3r52-r83w

OpenClaw before 2026.3.12 contains a weak authorization vulnerability in Zalouser allowlist mode that matches mutable group display names instead of stable group identifiers. Attackers can create groups with identical names to allowlisted groups to bypass channel authorization and route messages from unintended groups to the agent.

References:


CVE-2026-35626 โ€” OpenClaw < 2026.3.22 - Unauthenticated Resource Exhaustion via Voice Call Webhook

FieldDetail
CVSS6.9 (MEDIUM) โ€” CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
CWECWE-405 (CWE-405 Asymmetric Resource Consumption (Amplification))
Affected< 2026.3.22
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-rm59-992w-x2mv

OpenClaw before 2026.3.22 contains an unauthenticated resource exhaustion vulnerability in voice call webhook handling that buffers request bodies before provider signature checks. Attackers can send large or malicious webhook requests to exhaust server resources without authentication by bypassing signature validation.

References:


CVE-2026-34426 โ€” OpenClaw - Approval Bypass via Environment Variable Normalization

FieldDetail
CVSS6.9 (MEDIUM) โ€” CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N
CWECWE-184 (CWE-184 Incomplete List of Disallowed Inputs)
Affected< b57b680c0c34de907d57f60c38fb358e82aef8f7
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-98ch-45wp-ch47

OpenClaw versions prior to commit b57b680ย contain an approval bypass vulnerability due to inconsistent environment variable normalization between approval and execution paths, allowing attackers to inject attacker-controlled environment variables into execution without approval system validation. Attackers can exploit differing normalization logic to discard non-portable keys during approval processing while accepting them at execution time, bypassing operator review and potentially influencing runtime behavior including execution of attacker-controlled binaries.

References:


CVE-2026-35647 โ€” OpenClaw < 2026.3.25 - Direct Message Policy Bypass via Verification Notices

FieldDetail
CVSS6.9 (MEDIUM) โ€” CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
CWECWE-288 (CWE-288: Authentication Bypass Using an Alternate Path or Channel)
Affected< 2026.3.25
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-9wqx-g2cw-vc7r

OpenClaw before 2026.3.25 contains an access control vulnerability where verification notices bypass DM policy checks and reply to unpaired peers. Attackers can send verification notices to users outside allowed direct message policies by exploiting insufficient access validation before message transmission.

References:


CVE-2026-41300 โ€” OpenClaw < 2026.3.31 - Attacker-Discovered Endpoint Preservation in Remote Onboarding

FieldDetail
CVSS6.9 (MEDIUM) โ€” CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
CWECWE-372 (CWE-372: Incomplete Internal State Distinction)
Affected< 2026.3.31
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-9f4w-67g7-mqwv

OpenClaw before 2026.3.31 contains a trust-decline vulnerability that preserves attacker-discovered endpoints in remote onboarding flows. Attackers can route gateway credentials to malicious endpoints by having their discovered URL survive the trust decline process into manual prompts requiring operator acceptance.

References:


CVE-2026-41331 โ€” OpenClaw < 2026.3.31 - Resource Consumption via Unauthorized Telegram Audio Preflight Transcription

FieldDetail
CVSS6.9 (MEDIUM) โ€” CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
CWECWE-408 (CWE-408: Incorrect Behavior Order: Early Amplification)
Affected< 2026.3.31
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-m6fx-m8hc-572m

OpenClaw before 2026.3.31 contains a resource consumption vulnerability in Telegram audio preflight transcription that allows unauthorized group senders to trigger transcription processing. Attackers can exploit insufficient allowlist enforcement to cause resource or billing consumption by initiating audio preflight operations before authorization checks are applied.

References:


CVE-2026-35664 โ€” OpenClaw < 2026.3.25 - DM Pairing Bypass via Legacy Card Callbacks

FieldDetail
CVSS6.9 (MEDIUM) โ€” CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
CWECWE-288 (CWE-288: Authentication Bypass Using an Alternate Path or Channel)
Affected< 2026.3.25
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-77w2-crqv-cmv3

OpenClaw before 2026.3.25 contains an authentication bypass vulnerability in raw card send surface that allows unpaired recipients to mint legacy callback payloads. Attackers can send raw card commands to bypass DM pairing restrictions and reach callback handling without proper authorization.

References:


CVE-2026-41374 โ€” OpenClaw < 2026.3.31 - Resource Consumption via Discord Audio Preflight Before Member Authorization

FieldDetail
CVSS6.9 (MEDIUM) โ€” CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
CWECWE-408 (CWE-408: Incorrect Behavior Order: Early Amplification)
Affected< 2026.3.31
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-hhff-fj5f-qg48

OpenClaw before 2026.3.31 performs Discord audio preflight transcription before validating member authorization, allowing unauthenticated attackers to consume resources. Remote attackers can trigger audio preflight processing without member allowlist validation to cause resource exhaustion.

References:


CVE-2026-41400 โ€” OpenClaw < 2026.3.31 - Resource Consumption via Oversized WebSocket Frames in voice-call

FieldDetail
CVSS6.9 (MEDIUM) โ€” CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
CWECWE-770 (CWE-770: Allocation of Resources Without Limits or Throttling)
Affected< 2026.3.31
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-2w79-r9g8-wmcr

OpenClaw before 2026.3.31 contains an incomplete fix for CVE-2026-32062 where the voice-call component parses large WebSocket frames before start validation. Remote attackers can send oversized pre-start WebSocket frames to cause resource consumption and denial of service.

References:


CVE-2026-44116 โ€” OpenClaw < 2026.4.22 - Server-Side Request Forgery in Zalo Photo URL Validation

FieldDetail
CVSS6.9 (MEDIUM) โ€” CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:H/SI:N/SA:N
CWECWE-918 (CWE-918 Server-Side Request Forgery (SSRF))
Affected< 2026.4.22
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-2hh7-c75g-qj2r

OpenClaw before 2026.4.22 contains a server-side request forgery vulnerability in the Zalo plugin's sendPhoto function that fails to validate outbound photo URLs through the SSRF guard. Attackers can bypass SSRF protection by providing malicious photo URLs to the Zalo Bot API, enabling unauthorized access to internal resources.

References:


CVE-2026-53818 โ€” OpenClaw < 2026.4.24 - Owner-Only Tool Policy Bypass via MCP Loopback

FieldDetail
CVSS6.9 (MEDIUM) โ€” CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N
CWECWE-862 (Missing Authorization)
Affected< 2026.4.24
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-rj6p-xmxr-qj4h

OpenClaw before 2026.4.24 contains an authorization bypass vulnerability in the MCP loopback feature that allows non-owner callers to skip owner-only tool policies and before-tool-call hooks. Attackers can invoke owner-only behavior through the affected loopback path to execute restricted tools when the feature is enabled and reachable.

References:


CVE-2026-29612 โ€” OpenClaw < 2026.2.14 - Denial of Service via Large Base64 Media File Decoding

FieldDetail
CVSS6.8 (MEDIUM) โ€” CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
CWECWE-770 (Allocation of Resources Without Limits or Throttling)
Affected< 2026.2.14
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-w2cg-vxx6-5xjg

OpenClaw versions prior to 2026.2.14 decode base64-backed media inputs into buffers before enforcing decoded-size budget limits, allowing attackers to trigger large memory allocations. Remote attackers can supply oversized base64 payloads to cause memory pressure and denial of service.

References:


CVE-2026-26972 โ€” OpenClaw has a Path Traversal in Browser Download Functionality

FieldDetail
CVSS6.7 (MEDIUM) โ€” CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CWECWE-22 (CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'))
Affected< >= 2026.1.12, < 2026.2.13
Vendor/Productopenclaw / openclaw
AdvisoryGHSA-xwjm-j929-xq7c

OpenClaw is a personal AI assistant. In versions 2026.1.12 through 2026.2.12, OpenClaw browser download helpers accepted an unsanitized output path. When invoked via the browser control gateway routes, this allowed path traversal to write downloads outside the intended OpenClaw temp downloads directory. This issue is not exposed via the AI agent tool schema (no download action). Exploitation requires authenticated CLI access or an authenticated gateway RPC token. Version 2026.2.13 fixes the issue.

References:


CVE-2026-28452 โ€” OpenClaw affected by denial of service through unguarded archive extraction allowing high expansion/resource abuse (ZIP/TAR)

FieldDetail
CVSS6.7 (MEDIUM) โ€” CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
CWECWE-770 (Allocation of Resources Without Limits or Throttling)
Affected< 2026.2.14
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-h89v-j3x9-8wqj

OpenClaw versions prior to 2026.2.14 contain a denial of service vulnerability in the extractArchive function within src/infra/archive.ts that allows attackers to consume excessive CPU, memory, and disk resources through high-expansion ZIP and TAR archives. Remote attackers can trigger resource exhaustion by providing maliciously crafted archive files during install or update operations, causing service degradation or system unavailability.

References:


CVE-2026-26328 โ€” OpenClaw iMessage group allowlist authorization inherited DM pairing-store identities

FieldDetail
CVSS6.5 (MEDIUM) โ€” CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
CWECWE-284 (CWE-284: Improper Access Control), CWE-863 (CWE-863: Incorrect Authorization)
Affected<= 2026.1.24-3
Vendor/Productopenclaw / clawdbot
AdvisoryGHSA-g34w-4xqq-h79m

OpenClaw is a personal AI assistant. Prior to version 2026.2.14, under iMessage groupPolicy=allowlist, group authorization could be satisfied by sender identities coming from the DM pairing store, broadening DM trust into group contexts. Version 2026.2.14 fixes the issue.

Naming note: Uses old name openclaw/clawdbot as vendor/product. References:


CVE-2026-28449 โ€” OpenClaw < 2026.2.25 - Webhook Replay Attack via Missing Durable Replay Suppression

FieldDetail
CVSS6.3 (MEDIUM) โ€” CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N
CWECWE-294 (CWE-294 Authentication Bypass by Capture-replay)
Affected< 2026.2.25
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-r9q5-c7qc-p26w

OpenClaw versions prior to 2026.2.25 lack durable replay state for Nextcloud Talk webhook events, allowing valid signed webhook requests to be replayed without suppression. Attackers can capture and replay previously valid signed webhook requests to trigger duplicate inbound message processing and cause integrity or availability issues.

References:


CVE-2026-35628 โ€” OpenClaw < 2026.3.25 - Brute-Force Attack via Missing Telegram Webhook Rate Limiting

FieldDetail
CVSS6.3 (MEDIUM) โ€” CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
CWECWE-307 (CWE-307 Improper Restriction of Excessive Authentication Attempts)
Affected< 2026.3.25
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-vcx4-4qxg-mfp4

OpenClaw before 2026.3.25 contains a missing rate limiting vulnerability in Telegram webhook authentication that allows attackers to brute-force weak webhook secrets. The vulnerability enables repeated authentication guesses without throttling, permitting attackers to systematically guess webhook secrets through brute-force attacks.

References:


CVE-2026-35646 โ€” OpenClaw < 2026.3.25 - Pre-Authentication Rate-Limit Bypass in Webhook Token Validation

FieldDetail
CVSS6.3 (MEDIUM) โ€” CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
CWECWE-307 (CWE-307 Improper Restriction of Excessive Authentication Attempts)
Affected< 2026.3.25
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-mf5g-6r6f-ghhm

OpenClaw before 2026.3.25 contains a pre-authentication rate-limit bypass vulnerability in webhook token validation that allows attackers to brute-force weak webhook secrets. The vulnerability exists because invalid webhook tokens are rejected without throttling repeated authentication attempts, enabling attackers to guess weak tokens through rapid successive requests.

References:


CVE-2026-35649 โ€” OpenClaw < 2026.3.22 - Settings Reconciliation Bypass via Empty Allowlist

FieldDetail
CVSS6.3 (MEDIUM) โ€” CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
CWECWE-183 (CWE-183: Permissive List of Allowed Inputs)
Affected< 2026.3.22
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-pw7h-9g6p-c378

OpenClaw before 2026.3.22 contains a settings reconciliation vulnerability that allows attackers to bypass intended deny-all revocations by exploiting empty allowlist handling. The vulnerability treats explicit empty allowlists as unset during reconciliation, silently undoing intended access control denials and restoring previously revoked permissions.

References:


CVE-2026-35635 โ€” OpenClaw < 2026.3.22 - Webhook Path Route Replacement Vulnerability in Synology Chat

FieldDetail
CVSS6.3 (MEDIUM) โ€” CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
CWECWE-706 (CWE-706: Use of Incorrectly-Resolved Name or Reference)
Affected< 2026.3.22
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-rqp8-q22p-5j9q

OpenClaw before 2026.3.22 contains a webhook path route replacement vulnerability in the Synology Chat extension that allows attackers to collapse multi-account configurations onto shared webhook paths. Attackers can exploit inherited or duplicate webhook paths to bypass per-account DM access control policies and replace route ownership across accounts.

References:


CVE-2026-41333 โ€” OpenClaw < 2026.3.31 - Authentication Rate Limiting Bypass via Fake DeviceToken

FieldDetail
CVSS6.3 (MEDIUM) โ€” CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
CWECWE-799 (Improper Control of Interaction Frequency)
Affected< 2026.3.31
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-6p8r-6m93-557f

OpenClaw before 2026.3.31 contains an authentication rate limiting bypass vulnerability that allows attackers to circumvent shared authentication protections using fake device tokens. Attackers can exploit the mixed WebSocket authentication flow to bypass rate limiting controls and conduct brute force attacks against weak shared passwords.

References:


CVE-2026-41389 โ€” OpenClaw: Webchat media embedding enforces local-root containment for tool-result files

FieldDetail
CVSS6.3 (MEDIUM) โ€” CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N
CWECWE-73 (CWE-73: External Control of File Name or Path)
Affected< 2026.4.15
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-mr34-9552-qr95

OpenClaw versions 2026.4.7 before 2026.4.15 fail to enforce local-root containment on tool-result media paths, allowing arbitrary local and UNC file access. Attackers can craft malicious tool-result media references to trigger host-side file reads or Windows network path access, potentially disclosing sensitive files or exposing credentials.

References:


CVE-2026-41913 โ€” OpenClaw < 2026.4.4 - Rate-Limit Bypass via Concurrent Async Authentication Attempts

FieldDetail
CVSS6.3 (MEDIUM) โ€” CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
CWECWE-362 (CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition'))
Affected< 2026.4.4
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-25wv-8phj-8p7r

OpenClaw before 2026.4.4 contains a race condition vulnerability in shared-secret authentication that allows concurrent asynchronous requests to bypass the per-key rate-limit budget. Attackers can exploit this by sending multiple simultaneous authentication attempts to circumvent intended rate-limiting protections on Tailscale-capable paths.

References:


CVE-2026-43527 โ€” OpenClaw: Browser SSRF policy default allowed private-network navigation

FieldDetail
CVSS6.3 (MEDIUM) โ€” CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N
CWECWE-918 (CWE-918 Server-Side Request Forgery (SSRF)), CWE-1188 (CWE-1188 Initialization of a Resource with an Insecure Default)
Affected< 2026.4.14
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-53vx-pmqw-863c

OpenClaw before 2026.4.14 contains a server-side request forgery vulnerability in browser SSRF policy that allows private-network navigation by default. Attackers can exploit this misconfiguration to access internal services or metadata endpoints through browser-driven requests.

References:


CVE-2026-44117 โ€” OpenClaw < 2026.4.20 - Server-Side Request Forgery in QQBot Direct Media Upload

FieldDetail
CVSS6.3 (MEDIUM) โ€” CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N
CWECWE-918 (CWE-918 Server-Side Request Forgery (SSRF))
Affected< 2026.4.20
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-c4qg-j8jg-42q5

OpenClaw before 2026.4.20 contains a server-side request forgery vulnerability in QQBot direct media upload that skips URL validation. Attackers can bypass SSRF protections by sending crafted image URLs to uploadC2CMedia and uploadGroupMedia endpoints to relay unintended requests.

References:


CVE-2026-44999 โ€” OpenClaw < 2026.4.20 - Improper Trust Labeling in Isolated Cron Awareness Events

FieldDetail
CVSS6.3 (MEDIUM) โ€” CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
CWECWE-345 (Insufficient Verification of Data Authenticity)
Affected< 2026.4.20
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-57r2-h2wj-g887

OpenClaw before 2026.4.20 fails to properly preserve untrusted labels for isolated cron awareness events, allowing webhook-triggered cron agent output to be recorded as trusted system events. Attackers can exploit this trust-labeling issue to strengthen prompt-injection attacks by rendering untrusted events as trusted System events.

References:


CVE-2026-45002 โ€” OpenClaw < 2026.4.20 - Hook Session-Key Bypass via Template Mapping

FieldDetail
CVSS6.3 (MEDIUM) โ€” CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
CWECWE-863 (Incorrect Authorization)
Affected< 2026.4.20
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-2xcp-x87w-q377

OpenClaw before 2026.4.20 contains a hook session-key bypass vulnerability that allows attackers to circumvent the hooks.allowRequestSessionKey opt-in restriction. Attackers can render externally influenced session keys through templated hook mappings to bypass webhook routing isolation controls.

References:


CVE-2026-35645 โ€” OpenClaw < 2026.3.25 - Privilege Escalation via Synthetic operator.admin in deleteSession

FieldDetail
CVSS6.1 (MEDIUM) โ€” CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N
CWECWE-648 (CWE-648: Incorrect Use of Privileged APIs)
Affected< 2026.3.25
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-h4jx-hjr3-fhgc

OpenClaw before 2026.3.25 contains a privilege escalation vulnerability in the gateway plugin subagent fallback deleteSession function that uses a synthetic operator.admin runtime scope. Attackers can exploit this by triggering session deletion without a request-scoped client to execute privileged operations with unintended administrative scope.

References:


CVE-2026-32039 โ€” OpenClaw < 2026.2.22 - Sender Authorization Bypass via Identity Collision in toolsBySender

FieldDetail
CVSS6 (MEDIUM) โ€” CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N
CWECWE-639 (CWE-639 Authorization Bypass Through User-Controlled Key)
Affected< 2026.2.22
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-wpph-cjgr-7c39

OpenClaw versions prior to 2026.2.22 contain an authorization bypass vulnerability in the toolsBySender group policy matching that allows attackers to inherit elevated tool permissions through identifier collision attacks. Attackers can exploit untyped sender keys by forcing collisions with mutable identity values such as senderName or senderUsername to bypass sender-authorization policies and gain unauthorized access to privileged tools.

References:


CVE-2026-35622 โ€” OpenClaw < 2026.3.22 - Improper Authentication Verification in Google Chat Webhook

FieldDetail
CVSS6 (MEDIUM) โ€” CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N
CWECWE-290 (CWE-290: Authentication Bypass by Spoofing)
Affected< 2026.3.22
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-mp66-rf4f-mhh8

OpenClaw before 2026.3.22 contains an improper authentication verification vulnerability in Google Chat app-url webhook handling that accepts add-on principals outside intended deployment bindings. Attackers can bypass webhook authentication by providing non-deployment add-on principals to execute unauthorized actions through the Google Chat integration.

References:


CVE-2026-42429 โ€” OpenClaw < 2026.4.8 - Privilege Escalation via Gateway Plugin HTTP Authentication

FieldDetail
CVSS6 (MEDIUM) โ€” CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N
CWECWE-863 (CWE-863: Incorrect Authorization)
Affected< 2026.4.8
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-4f8g-77mw-3rxc

OpenClaw before 2026.4.8 contains a privilege escalation vulnerability in the gateway plugin HTTP authentication mechanism that widens identity-bearing operator.read requests into runtime operator.write permissions. Attackers can exploit this by sending read-scoped requests through the gateway auth route to gain unauthorized write access to runtime operations.

References:


FieldDetail
CVSS6 (MEDIUM) โ€” CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
CWECWE-61 (CWE-61 UNIX Symbolic Link (Symlink) Following)
Affected< 2026.4.5
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-cr8r-7g2h-6wr6

OpenClaw versions 2026.3.22 before 2026.4.5 contain a symlink traversal vulnerability in remote marketplace repository path handling that allows attackers to escape the expected repository root. Attackers can exploit this by providing crafted symlink paths to access files outside the intended repository directory.

References:


FieldDetail
CVSS6 (MEDIUM) โ€” CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
CWECWE-367 (CWE-367: Time-of-check Time-of-use (TOCTOU) Race Condition)
Affected< 2026.4.22
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-wppj-c6mr-83jj

OpenClaw before 2026.4.22 contains a time-of-check/time-of-use race condition in OpenShell sandbox filesystem writes that allows attackers to redirect writes outside the intended mount root. Attackers can exploit symlink swaps during filesystem operations to bypass sandbox restrictions and write files outside the local mount root.

References:


CVE-2026-44113 โ€” OpenClaw: OpenShell FS bridge reads pin and verify the opened file before returning bytes

FieldDetail
CVSS6 (MEDIUM) โ€” CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
CWECWE-367 (CWE-367: Time-of-check Time-of-use (TOCTOU) Race Condition)
Affected< 2026.4.22
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-5h3g-6xhh-rg6p

OpenClaw before 2026.4.22 contains a time-of-check/time-of-use race condition in the OpenShell filesystem bridge that allows attackers to read files outside the intended mount root. Attackers can exploit symlink swaps during filesystem operations to bypass sandbox restrictions and access unauthorized file contents.

References:


CVE-2026-53830 โ€” OpenClaw < 2026.4.22 - Webhook Secret Revocation Bypass via secrets.reload

FieldDetail
CVSS6 (MEDIUM) โ€” CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
CWECWE-613 (Insufficient Session Expiration)
Affected< 2026.4.22
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-275c-xpvc-jgfw

OpenClaw before 2026.4.22 contains a webhook secret revocation bypass vulnerability allowing callers with old Slack and Zalo webhook secrets to remain active after secrets.reload. Attackers can exploit the stale-secret window to deliver webhook events after operator-expected secret revocation, potentially accepting previous credentials.

References:


CVE-2026-53838 โ€” OpenClaw < 2026.5.27 - Node Pairing State Mutation via Reconnection

FieldDetail
CVSS6 (MEDIUM) โ€” CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
CWECWE-367 (Time-of-check Time-of-use (TOCTOU) Race Condition)
Affected< 2026.5.27
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-83w9-h5wv-j9xm

OpenClaw before 2026.5.27 contains a state mutation vulnerability in node pairing reconnection that allows paired nodes to confuse approval scope decisions. Attackers can exploit reconnection logic to restore or present broader node authority than intended, potentially bypassing approval restrictions.

References:


CVE-2026-28481 โ€” OpenClaw < 2026.2.1 - Bearer Token Leakage via MS Teams Attachment Downloader Suffix Matching

FieldDetail
CVSS5.9 (MEDIUM) โ€” CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
CWECWE-201 (Insertion of Sensitive Information Into Sent Data)
Affected< 0
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-7vwx-582j-j332

OpenClaw versions 2026.1.30 and earlier, contain an information disclosure vulnerability, patched in 2026.2.1, in the MS Teams attachment downloader (optional extension must be enabled) that leaks bearer tokens to allowlisted suffix domains. When retrying downloads after receiving 401 or 403 responses, the application sends Authorization bearer tokens to untrusted hosts matching the permissive suffix-based allowlist, enabling token theft.

References:


FieldDetail
CVSS5.9 (MEDIUM) โ€” CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N
CWECWE-59 (CWE-59: Improper Link Resolution Before File Access ('Link Following'))
Affected< 2026.2.25
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-36h3-7c54-j27r

OpenClaw versions prior to 2026.2.25 contain a symlink traversal vulnerability in browser trace and download output path handling that allows local attackers to escape the managed temp root directory. An attacker with local access can create symlinks to route file writes outside the intended temp directory, enabling arbitrary file overwrite on the affected system.

References:


CVE-2026-45005 โ€” OpenClaw < 2026.4.23 - Webhook Route Secret Cache Not Invalidated After Rotation

FieldDetail
CVSS5.9 (MEDIUM) โ€” CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N
CWECWE-672 (Operation on a Resource after Expiration or Release)
Affected< 2026.4.23
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-q8ff-7ffm-m3r9

OpenClaw before 2026.4.23 caches resolved webhook route secrets backed by SecretRef values, allowing stale secrets to remain valid after rotation and reload. Attackers with previously valid webhook route secrets can continue authenticating requests and invoking configured webhook task flows until gateway or plugin restart.

References:


CVE-2026-31999 โ€” OpenClaw 2026.2.26 < 2026.3.1 - Current Working Directory Injection via Windows Wrapper Resolution Fallback

FieldDetail
CVSS5.8 (MEDIUM) โ€” CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N
CWECWE-78 (Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78))
Affected< 2026.3.1
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-6f6j-wx9w-ff4j

OpenClaw versions 2026.2.26 prior to 2026.3.1 on Windows contain a current working directory injection vulnerability in wrapper resolution for .cmd/.bat files that allows attackers to influence execution behavior through cwd manipulation. Remote attackers can exploit improper shell execution fallback mechanisms to achieve command execution integrity loss by controlling the current working directory during wrapper resolution.

References:


CVE-2026-32000 โ€” OpenClaw < 2026.2.19 - Command Injection via Windows Shell Fallback in Lobster Tool Execution

FieldDetail
CVSS5.8 (MEDIUM) โ€” CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N
CWECWE-78 (Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78))
Affected< 2026.2.19
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-7fcc-cw49-xm78

OpenClaw versions prior to 2026.2.19 contain a command injection vulnerability in the Lobster extension tool execution that uses Windows shell fallback with shell: true after spawn failures. Attackers can inject shell metacharacters in command arguments to execute arbitrary commands when subprocess launch fails with EINVAL or ENOENT errors.

References:


CVE-2026-31995 โ€” OpenClaw 2026.1.21 < 2026.2.19 - Command Injection via Windows Shell Fallback in Lobster Extension

FieldDetail
CVSS5.8 (MEDIUM) โ€” CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N
CWECWE-78 (Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78))
Affected< 2026.2.19
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-fg3m-vhrr-8gj6

OpenClaw versions 2026.1.21 prior to 2026.2.19 contain a command injection vulnerability in the Lobster extension's Windows shell fallback mechanism that allows attackers to inject arbitrary commands through tool-provided arguments. When spawn failures trigger shell fallback with shell: true, attackers can exploit cmd.exe command interpretation to execute malicious commands by controlling workflow arguments.

References:


CVE-2026-32988 โ€” OpenClaw < 2026.3.11 - Sandbox Boundary Bypass via Unvalidated Temporary File Creation

FieldDetail
CVSS5.8 (MEDIUM) โ€” CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N
CWECWE-367 (Time-of-check Time-of-use (TOCTOU) Race Condition)
Affected< 2026.3.11
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-mj4p-rc52-m843

OpenClaw before 2026.3.11 contains a sandbox boundary bypass vulnerability in fs-bridge staged writes where temporary file creation and population are not pinned to a verified parent directory. Attackers can exploit a race condition in parent-path alias changes to write attacker-controlled bytes outside the intended validated path before the final guarded replace step executes.

References:


CVE-2026-41332 โ€” OpenClaw < 2026.3.28 - Code Execution via Missing Environment Variable Blocklist

FieldDetail
CVSS5.8 (MEDIUM) โ€” CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N
CWECWE-184 (CWE-184: Incomplete List of Disallowed Inputs)
Affected< 2026.3.28
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-m866-6qv5-p2fg

OpenClaw before 2026.3.28 contains an environment variable sanitization vulnerability where GIT_TEMPLATE_DIR and AWS_CONFIG_FILE are not blocked in the host-env blocklist. Attackers can exploit approved exec requests to redirect git or AWS CLI behavior through attacker-controlled configuration files to execute untrusted code or load malicious credentials.

References:


CVE-2026-41360 โ€” OpenClaw < 2026.4.2 - Approval Integrity Bypass in pnpm dlx Local Script Binding

FieldDetail
CVSS5.4 (MEDIUM) โ€” CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CWECWE-367 (CWE-367: Time-of-check Time-of-use (TOCTOU) Race Condition)
Affected< 2026.4.2
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-w6wx-jq6j-6mcj

OpenClaw before 2026.4.2 contains an approval integrity vulnerability in pnpm dlx that fails to bind local script operands consistently with pnpm exec flows. Attackers can replace approved local scripts before execution without invalidating the approval plan, allowing execution of modified script contents.

References:


CVE-2026-44995 โ€” OpenClaw: MCP stdio server env could load dangerous startup variables from workspace config

FieldDetail
CVSS5.4 (MEDIUM) โ€” CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CWECWE-829 (Inclusion of Functionality from Untrusted Control Sphere)
Affected< 2026.4.20
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-mj59-h3q9-ghfh

OpenClaw before 2026.4.20 contains an improper environment variable validation vulnerability in MCP stdio server configuration that allows attackers to execute arbitrary code. Malicious workspace configurations can pass dangerous startup variables like NODE_OPTIONS, LD_PRELOAD, or BASH_ENV to spawned MCP server processes, enabling code injection when operators start sessions using those servers.

References:


CVE-2026-26326 โ€” OpenClaw skills.status could leak secrets to operator.read clients

FieldDetail
CVSS5.3 (MEDIUM) โ€” CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
CWECWE-200 (CWE-200: Exposure of Sensitive Information to an Unauthorized Actor)
Affected< 2026.2.14
Vendor/Productopenclaw / openclaw
AdvisoryGHSA-8mh7-phf8-xgfm

OpenClaw is a personal AI assistant. Prior to version 2026.2.14, skills.status could disclose secrets to operator.read clients by returning raw resolved config values in configChecks for skill requires.config paths. Version 2026.2.14 stops including raw resolved config values in requirement checks (return only { path, satisfied }) and narrows the Discord skill requirement to the token key. In addition to upgrading, users should rotate any Discord tokens that may have been exposed to read-scoped clients.

References:


CVE-2026-32899 โ€” OpenClaw < 2026.2.25 - Sender Policy Bypass in Slack Reaction and Pin Event Handlers

FieldDetail
CVSS5.3 (MEDIUM) โ€” CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
CWECWE-863 (CWE-863: Incorrect Authorization)
Affected< 2026.2.25
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-rm2p-j3r7-4x4j

OpenClaw versions prior to 2026.2.25 fail to consistently apply sender-policy checks to reaction_* and pin_* non-message events before adding them to system-event context. Attackers can bypass configured DM policies and channel user allowlists to inject unauthorized reaction and pin events from restricted senders.

References:


CVE-2026-41909 โ€” OpenClaw < 2026.4.20 - Improper Authorization in Paired-Device Pairing Actions

FieldDetail
CVSS5.3 (MEDIUM) โ€” CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
CWECWE-863 (CWE-863 Incorrect Authorization)
Affected< 2026.4.20
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-xrq9-jm7v-g9h7

OpenClaw before 2026.4.20 contains an improper authorization vulnerability in paired-device pairing management that allows limited-scope sessions to enumerate and act on pairing requests. Attackers with paired-device access can approve or operate on unrelated pending device requests within the same gateway scope.

References:


CVE-2026-35634 โ€” OpenClaw < 2026.3.23 - Authentication Bypass via Local-Direct Requests in Canvas Gateway

FieldDetail
CVSS5.1 (MEDIUM) โ€” CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
CWECWE-288 (CWE-288: Authentication Bypass Using an Alternate Path or Channel)
Affected< 2026.3.23
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-6mqc-jqh6-x8fc

OpenClaw before 2026.3.23 contains an authentication bypass vulnerability in the Canvas gateway where authorizeCanvasRequest() unconditionally allows local-direct requests without validating bearer tokens or canvas capabilities. Attackers can send unauthenticated loopback HTTP and WebSocket requests to Canvas routes to bypass authentication and gain unauthorized access.

References:


CVE-2026-42436 โ€” OpenClaw < 2026.4.14 - Internal Page Content Exposure via Browser Snapshot and Screenshot Routes

FieldDetail
CVSS4.9 (MEDIUM) โ€” CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N
CWECWE-862 (CWE-862 Missing Authorization)
Affected< 2026.4.14
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-c4qm-58hj-j6pj

OpenClaw before 2026.4.14 contains an improper access control vulnerability in browser snapshot, screenshot, and tab routes that fail to consistently validate the final browser target after navigation. Authenticated callers can bypass SSRF restrictions to expose internal or disallowed page content by exploiting route-driven navigation without proper policy re-validation.

References:


CVE-2026-42439 โ€” OpenClaw < 2026.4.10 - SSRF Policy Bypass in Browser Tabs Action Routes

FieldDetail
CVSS4.9 (MEDIUM) โ€” CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:H/SI:N/SA:N
CWECWE-862 (CWE-862 Missing Authorization)
Affected< 2026.4.10
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-rj2p-j66c-mgqh

OpenClaw before 2026.4.10 contains a server-side request forgery policy bypass vulnerability in the browser tabs action select and close routes. Attackers can bypass configured browser SSRF policy protections by exploiting the /tabs/action endpoint to perform unauthorized tab navigation operations.

References:


CVE-2026-43532 โ€” OpenClaw 2026.4.7 < 2026.4.10 - Sandbox Media Normalization Bypass via Discord Event Cover Image

FieldDetail
CVSS4.9 (MEDIUM) โ€” CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N
CWECWE-184 (CWE-184: Incomplete List of Disallowed Inputs)
Affected< 2026.4.10
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-c9h3-5p7r-mrjh

OpenClaw versions 2026.4.7 before 2026.4.10 fail to normalize Discord event cover image parameters in sandbox media processing. Attackers can bypass media normalization to inject host-local media references into channel action paths expecting normalized media.

References:


CVE-2026-42438 โ€” OpenClaw: Sender policy bypass in host media attachment reads allows unauthorized local file disclosure

FieldDetail
CVSS4.9 (MEDIUM) โ€” CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:H/SI:N/SA:N
CWECWE-863 (CWE-863: Incorrect Authorization)
Affected< 2026.4.10
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-jhpv-5j76-m56h

OpenClaw versions 2026.4.9 before 2026.4.10 contain a sender policy bypass vulnerability in the outbound host-media attachment read helper that allows unauthorized local file disclosure. Attackers with denied read access via toolsBySender or group policy can trigger host-media attachment loading to bypass sender and group-scoped authorization boundaries and retrieve readable local files through the outbound media path.

References:


CVE-2026-43573 โ€” OpenClaw: Existing-session browser interaction routes bypassed SSRF policy enforcement

FieldDetail
CVSS4.9 (MEDIUM) โ€” CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N
CWECWE-862 (CWE-862 Missing Authorization), CWE-918 (CWE-918 Server-Side Request Forgery (SSRF))
Affected< 2026.4.10
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-527m-976r-jf79

OpenClaw before 2026.4.10 contains a server-side request forgery policy bypass vulnerability in existing-session browser interaction routes. Attackers can bypass SSRF navigation guards to interact with or navigate to unauthorized targets without policy enforcement.

References:


CVE-2026-43576 โ€” OpenClaw < 2026.4.5 - Second-hop SSRF via CDP /json/version WebSocket URL

FieldDetail
CVSS4.9 (MEDIUM) โ€” CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N
CWECWE-601 (CWE-601 URL Redirection to Untrusted Site ('Open Redirect')), CWE-918 (CWE-918 Server-Side Request Forgery (SSRF))
Affected< 2026.4.5
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-f7fh-qg34-x2xh

OpenClaw before 2026.4.5 contains a server-side request forgery vulnerability in the CDP /json/version WebSocket endpoint that allows attackers to pivot to untrusted second-hop targets. The webSocketDebuggerUrl response field is not properly validated, enabling attackers to redirect connections to arbitrary hosts and perform SSRF-style attacks.

References:


CVE-2026-43580 โ€” OpenClaw: Browser press/type interaction routes missed complete navigation guard coverage

FieldDetail
CVSS4.9 (MEDIUM) โ€” CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N
CWECWE-862 (CWE-862 Missing Authorization)
Affected< 2026.4.10
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-536q-mj95-h29h

OpenClaw before 2026.4.10 contains an incomplete navigation guard vulnerability that allows attackers to trigger navigation without complete SSRF policy enforcement. Browser press/type style interactions, including pressKey and type submit flows, can bypass post-action security checks to execute unauthorized navigation.

References:


CVE-2026-43582 โ€” OpenClaw < 2026.4.10 - DNS Rebinding SSRF via Hostname Validation Bypass

FieldDetail
CVSS4.9 (MEDIUM) โ€” CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N
CWECWE-367 (CWE-367: Time-of-check Time-of-use (TOCTOU) Race Condition)
Affected< 2026.4.10
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-xq94-r468-qwgj

OpenClaw before 2026.4.10 contains a server-side request forgery vulnerability in browser navigation policy that allows attackers to bypass hostname validation through DNS rebinding attacks. Attackers can exploit inconsistent hostname resolution between validation and actual network requests to pivot to internal resources via unallowlisted hostname URLs.

References:


CVE-2026-27007 โ€” OpenClaw's sandbox config hash sorted primitive arrays and suppressed needed container recreation

FieldDetail
CVSS4.8 (MEDIUM) โ€” CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
CWECWE-1254 (CWE-1254: Incorrect Comparison Logic Granularity)
Affected< 2026.2.15
Vendor/Productopenclaw / openclaw
AdvisoryGHSA-xxvh-5hwj-42pp

OpenClaw is a personal AI assistant. Prior to version 2026.2.15, normalizeForHash in src/agents/sandbox/config-hash.ts recursively sorted arrays that contained only primitive values. This made order-sensitive sandbox configuration arrays hash to the same value even when order changed. In OpenClaw sandbox flows, this hash is used to decide whether existing sandbox containers should be recreated. As a result, order-only config changes (for example Docker dns and binds array order) could be treated as unchanged and stale containers could be reused. This is a configuration integrity issue affecting sandbox recreation behavior. Starting in version 2026.2.15, array ordering is preserved during hash normalization; only object key ordering remains normalized for deterministic hashing.

References:


CVE-2026-44992 โ€” OpenClaw 2026.4.5 < 2026.4.20 - MiniMax API Host Override via Workspace dotenv

FieldDetail
CVSS4.1 (MEDIUM) โ€” CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
CWECWE-441 (Unintended Proxy or Intermediary ('Confused Deputy'))
Affected< 2026.4.20
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-h2vw-ph2c-jvwf

OpenClaw versions 2026.4.5 before 2026.4.20 contain an environment variable injection vulnerability allowing workspace dotenv to override MINIMAX_API_HOST. Attackers can redirect credentialed MiniMax API requests to attacker-controlled origins, exposing the MiniMax API key in Authorization headers.

References:


CVE-2026-45003 โ€” OpenClaw: Workspace dotenv files cannot override connector endpoint hosts

FieldDetail
CVSS4.1 (MEDIUM) โ€” CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
CWECWE-441 (Unintended Proxy or Intermediary ('Confused Deputy'))
Affected< 2026.4.22
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-55cf-xx38-4p9p

OpenClaw before 2026.4.22 allows workspace dotenv files to override connector endpoint hosts for Matrix, Mattermost, IRC, and Synology connectors. Attackers with workspace access can redirect runtime traffic to malicious endpoints by setting endpoint variables in dotenv files.

References:


CVE-2026-32006 โ€” OpenClaw < 2026.2.26 - Authorization Bypass via DM Pairing-Store Fallback in Group Allowlist

FieldDetail
CVSS2.3 (LOW) โ€” CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
CWECWE-863 (CWE-863: Incorrect Authorization)
Affected< 2026.2.26
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-25pw-4h6w-qwvm

OpenClaw versions prior to 2026.2.26 contain an authorization bypass vulnerability where DM pairing-store identities are incorrectly treated as group allowlist identities when dmPolicy=pairing and groupPolicy=allowlist. Remote attackers can send messages and reactions as DM-paired identities without explicit groupAllowFrom membership to bypass group sender authorization checks.

References:


CVE-2026-34507 โ€” OpenClaw < 2026.4.29 - Policy Bypass in QQBot Admin Commands via DM-only and allowFrom Checks

FieldDetail
CVSS2.3 (LOW) โ€” CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
CWECWE-863 (Incorrect Authorization)
Affected< 2026.4.29
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-w4v6-g3wm-w36c

OpenClaw before 2026.4.29 contains a policy bypass vulnerability in QQBot admin commands that allows authenticated senders to skip DM-only and allowFrom policy checks. Attackers can route admin commands from unauthorized senders or contexts to execute restricted behavior that policy should have blocked.

References:


CVE-2026-35617 โ€” OpenClaw < 2026.3.25 - Authorization Bypass via Group Policy Rebinding with Mutable Space displayName

FieldDetail
CVSS2.3 (LOW) โ€” CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
CWECWE-807 (CWE-807 Reliance on Untrusted Inputs in a Security Decision)
Affected< 2026.3.25
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-52q4-3xjc-6778

OpenClaw before 2026.3.25 contains an authorization bypass vulnerability in Google Chat group policy enforcement that relies on mutable space display names. Attackers can rebind group policies by changing or colliding space display names to gain unauthorized access to protected resources.

References:


CVE-2026-35648 โ€” OpenClaw < 2026.3.22 - Policy Bypass via Unvalidated Queued Node Actions

FieldDetail
CVSS2.3 (LOW) โ€” CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
CWECWE-367 (CWE-367: Time-of-check Time-of-use (TOCTOU) Race Condition)
Affected< 2026.3.22
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-wj55-88gf-x564

OpenClaw before 2026.3.22 contains a policy bypass vulnerability where queued node actions are not revalidated against current command policy when delivered. Attackers can exploit stale allowlists or declarations that survive policy tightening to execute unauthorized commands.

References:


CVE-2026-41347 โ€” OpenClaw < 2026.3.31 - Cross-Site Request Forgery via Missing Browser-Origin Validation in HTTP Operator Endpoints

FieldDetail
CVSS2.3 (LOW) โ€” CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:L
CWECWE-352 (CWE-352 Cross-Site Request Forgery (CSRF))
Affected< 2026.3.31
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-mhr7-2xmv-4c4q

OpenClaw before 2026.3.31 lacks browser-origin validation in HTTP operator endpoints when operating in trusted-proxy mode, allowing cross-site request forgery attacks. Attackers can exploit this by sending malicious requests from a browser in trusted-proxy deployments to perform unauthorized actions on HTTP operator endpoints.

References:


CVE-2026-41358 โ€” OpenClaw < 2026.4.2 - Sender Allowlist Bypass via Slack Thread Context

FieldDetail
CVSS2.3 (LOW) โ€” CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
CWECWE-346 (CWE-346: Origin Validation Error)
Affected< 2026.4.2
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-qm77-8qjp-4vcm

OpenClaw before 2026.4.2 fails to filter Slack thread context by sender allowlist, allowing non-allowlisted messages to enter agent context. Attackers can inject unauthorized thread messages through allowlisted user replies to bypass sender access controls and manipulate model context.

References:


CVE-2026-41916 โ€” OpenClaw < 2026.4.8 - Stale Authentication State via Config Reload

FieldDetail
CVSS2.3 (LOW) โ€” CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
CWECWE-613 (CWE-613: Insufficient Session Expiration)
Affected< 2026.4.8
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-68x5-xx89-w9mm

OpenClaw before 2026.4.8 contains an authentication state management vulnerability where the resolvedAuth closure becomes stale after configuration reload. Newly accepted gateway connections continue using outdated resolved auth state, allowing attackers to bypass authentication controls through config reload operations.

References:


CVE-2026-41908 โ€” OpenClaw < 2026.4.20 - Scope Enforcement Bypass in Assistant-Media Route

FieldDetail
CVSS2.3 (LOW) โ€” CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
CWECWE-863 (CWE-863 Incorrect Authorization)
Affected< 2026.4.20
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-v8qf-fr4g-28p2

OpenClaw before 2026.4.20 contains a scope enforcement bypass vulnerability in the assistant-media route that allows trusted-proxy callers without operator.read scope to access protected assistant-media files and metadata. Attackers can bypass identity-bearing HTTP auth path scope validation to retrieve sensitive media content within allowed media roots.

References:


CVE-2026-44111 โ€” OpenClaw < 2026.4.15 - Arbitrary Markdown File Read via QMD memory_get

FieldDetail
CVSS2.3 (LOW) โ€” CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
CWECWE-183 (CWE-183: Permissive List of Allowed Inputs)
Affected< 2026.4.15
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-f934-5rqf-xx47

OpenClaw before 2026.4.15 contains an arbitrary file read vulnerability in the QMD backend memory_get function that allows callers to read any Markdown files within the workspace root. Attackers with access to the memory tool can bypass path restrictions by providing arbitrary workspace Markdown paths to read files outside canonical memory locations or indexed QMD result sets.

References:


CVE-2026-44993 โ€” OpenClaw < 2026.4.20 - Direct Message Misclassification in Feishu Card Actions

FieldDetail
CVSS2.3 (LOW) โ€” CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
CWECWE-184 (Incomplete List of Disallowed Inputs)
Affected< 2026.4.20
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-72q8-jcmc-97wx

OpenClaw before 2026.4.20 contains a message classification vulnerability in Feishu card-action callbacks that misclassifies direct messages as group conversations. Attackers can bypass dmPolicy enforcement by triggering card-action flows in direct message conversations that should have been blocked by restrictive policies.

References:


CVE-2026-44997 โ€” OpenClaw < 2026.4.22 - Security Envelope Constraint Bypass in ACP Child Sessions

FieldDetail
CVSS2.3 (LOW) โ€” CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
CWECWE-266 (Incorrect Privilege Assignment)
Affected< 2026.4.22
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-q3jj-46pq-826r

OpenClaw before 2026.4.22 contains a security envelope constraint bypass vulnerability allowing restricted subagents to spawn ACP child sessions that fail to inherit depth, child-count limits, control scope, or target-agent restrictions. Attackers can exploit this by spawning child sessions that bypass subagent-only constraints, potentially escalating privileges or accessing restricted resources.

References:


CVE-2026-44991 โ€” OpenClaw: Owner-enforced commands could accept wildcard channel senders as command owners

FieldDetail
CVSS2.3 (LOW) โ€” CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
CWECWE-863 (Incorrect Authorization)
Affected< 2026.4.21
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-c28g-vh7m-fm7v

OpenClaw before 2026.4.21 contains an authorization bypass vulnerability in command-auth.ts that allows non-owner senders to execute owner-enforced slash commands when wildcard inbound senders are configured without explicit owner allowFrom settings. Attackers can exploit this by sending commands like /send, /config, or /debug on affected channels to bypass owner-only command authorization checks.

References:


CVE-2026-53826 โ€” OpenClaw < 2026.4.26 - Information Disclosure via Sandboxed Session Spawn

FieldDetail
CVSS2.3 (LOW) โ€” CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
CWECWE-668 (Exposure of Resource to Wrong Sphere)
Affected< 2026.4.26
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-6c4r-g249-wv3c

OpenClaw before 2026.4.26 contains an information disclosure vulnerability in sandboxed session spawning that exposes the real workspace path to child prompts. Attackers can exploit this by spawning child sessions from sandboxed parents to reveal host workspace location or related memory context to child models.

References:


CVE-2026-31991 โ€” OpenClaw < 2026.2.26 - Authorization Bypass via DM Pairing-Store Leakage in Signal Group Allowlist

FieldDetail
CVSS2 (LOW) โ€” CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
CWECWE-863 (CWE-863: Incorrect Authorization)
Affected< 2026.2.26
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-wm8r-w8pf-2v6w

OpenClaw versions prior to 2026.2.26 contain an authorization bypass vulnerability where Signal group allowlist policy incorrectly accepts sender identities from DM pairing-store approvals. Attackers can exploit this boundary weakness by obtaining DM pairing approval to bypass group allowlist checks and gain unauthorized group access.

References:


CVE-2026-32058 โ€” OpenClaw < 2026.2.26 - Approval Context-Binding Weakness in system.run via host=node

FieldDetail
CVSS2 (LOW) โ€” CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
CWECWE-863 (CWE-863: Incorrect Authorization)
Affected< 2026.2.26
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-hjvp-qhm6-wrh2

OpenClaw versions prior to 2026.2.26 contain an approval context-binding weakness in system.run execution flows with host=node that allows reuse of previously approved requests with modified environment variables. Attackers with access to an approval id can exploit this by reusing an approval with changed env input, bypassing execution-integrity controls in approval-enabled workflows.

References:



โณ CVE Publication Pipeline

Of 48 GHSAs with CVE IDs, 48 are fully published and 0 remain RESERVED.

graph LR
    A["1๏ธโƒฃ GitHub Reserves<br/>CVE ID<br/><b>RESERVED</b>"] --> B["2๏ธโƒฃ GHSA Goes Public<br/>with CVE ID Shown"]
    B --> C["3๏ธโƒฃ CNA Submits<br/>CVE Record via<br/>CVE Services<br/><b>PUBLISHED</b>"]
    C --> D["4๏ธโƒฃ cvelistV5 Bot<br/>Commits JSON File"]

    style A fill:#fee,stroke:#c33,color:#333
    style B fill:#fff3cd,stroke:#856404,color:#333
    style C fill:#d4edda,stroke:#155724,color:#333
    style D fill:#cce5ff,stroke:#004085,color:#333
CVE IDStatecvelistV5GHSA PublishedCNA
CVE-2026-24763โœ… PUBLISHEDโœ…2026-02-02GitHub_M
CVE-2026-25157โœ… PUBLISHEDโœ…2026-02-02GitHub_M
CVE-2026-25253โœ… PUBLISHEDโœ…2026-02-02mitre
CVE-2026-26317โœ… PUBLISHEDโœ…2026-02-18GitHub_M
CVE-2026-26328โœ… PUBLISHEDโœ…2026-02-18GitHub_M
CVE-2026-28452โœ… PUBLISHEDโœ…2026-02-18VulnCheck
CVE-2026-28458โœ… PUBLISHEDโœ…2026-02-17VulnCheck
CVE-2026-28469โœ… PUBLISHEDโœ…2026-02-18VulnCheck
CVE-2026-28478โœ… PUBLISHEDโœ…2026-02-18VulnCheck
CVE-2026-28480โœ… PUBLISHEDโœ…2026-02-18VulnCheck
CVE-2026-29612โœ… PUBLISHEDโœ…2026-02-18VulnCheck
CVE-2026-41358โœ… PUBLISHEDโœ…2026-05-04VulnCheck
CVE-2026-41389โœ… PUBLISHEDโœ…2026-04-17VulnCheck
CVE-2026-41908โœ… PUBLISHEDโœ…2026-04-25VulnCheck
CVE-2026-42433โœ… PUBLISHEDโœ…2026-04-17VulnCheck
CVE-2026-42434โœ… PUBLISHEDโœ…2026-04-17VulnCheck
CVE-2026-42438โœ… PUBLISHEDโœ…2026-04-17VulnCheck
CVE-2026-42439โœ… PUBLISHEDโœ…2026-04-17VulnCheck
CVE-2026-43526โœ… PUBLISHEDโœ…2026-04-17VulnCheck
CVE-2026-43527โœ… PUBLISHEDโœ…2026-04-17VulnCheck
CVE-2026-43530โœ… PUBLISHEDโœ…2026-04-17VulnCheck
CVE-2026-43533โœ… PUBLISHEDโœ…2026-04-17VulnCheck
CVE-2026-43567โœ… PUBLISHEDโœ…2026-04-17VulnCheck
CVE-2026-43569โœ… PUBLISHEDโœ…2026-04-17VulnCheck
CVE-2026-43570โœ… PUBLISHEDโœ…2026-05-05VulnCheck
CVE-2026-43571โœ… PUBLISHEDโœ…2026-04-17VulnCheck
CVE-2026-43573โœ… PUBLISHEDโœ…2026-04-17VulnCheck
CVE-2026-43576โœ… PUBLISHEDโœ…2026-04-17VulnCheck
CVE-2026-43580โœ… PUBLISHEDโœ…2026-04-17VulnCheck
CVE-2026-43582โœ… PUBLISHEDโœ…2026-04-17VulnCheck
CVE-2026-43585โœ… PUBLISHEDโœ…2026-04-17VulnCheck
CVE-2026-44109โœ… PUBLISHEDโœ…2026-04-17VulnCheck
CVE-2026-44110โœ… PUBLISHEDโœ…2026-04-17VulnCheck
CVE-2026-44112โœ… PUBLISHEDโœ…2026-05-04VulnCheck
CVE-2026-44113โœ… PUBLISHEDโœ…2026-05-04VulnCheck
CVE-2026-44114โœ… PUBLISHEDโœ…2026-04-25VulnCheck
CVE-2026-44116โœ… PUBLISHEDโœ…2026-05-04VulnCheck
CVE-2026-44117โœ… PUBLISHEDโœ…2026-04-25VulnCheck
CVE-2026-44118โœ… PUBLISHEDโœ…2026-05-04VulnCheck
CVE-2026-44991โœ… PUBLISHEDโœ…2026-04-29VulnCheck
CVE-2026-44992โœ… PUBLISHEDโœ…2026-04-25VulnCheck
CVE-2026-44995โœ… PUBLISHEDโœ…2026-04-25VulnCheck
CVE-2026-44997โœ… PUBLISHEDโœ…2026-05-04VulnCheck
CVE-2026-44999โœ… PUBLISHEDโœ…2026-04-25VulnCheck
CVE-2026-45002โœ… PUBLISHEDโœ…2026-04-25VulnCheck
CVE-2026-45003โœ… PUBLISHEDโœ…2026-05-04VulnCheck
CVE-2026-45004โœ… PUBLISHEDโœ…2026-05-05VulnCheck
CVE-2026-45005โœ… PUBLISHEDโœ…2026-05-05VulnCheck

๐Ÿ”‘ Key Insights

InsightDetail
Dominant Weakness43% of categorized issues relate to Allowlist Bypass (40/93)
V5 Sync Rate48/48 CVE IDs (100%) have full cvelistV5 records
Advisory Velocity186 security advisories across 2026-02-02 โ†’ 2026-05-11
Top Severity4 Critical + 45 High = 49 high-impact issues (26%)

Vulnerability Categories

CategoryCountExamples
OS Command Injection (CWE-78)22PATH injection, SSH command injection, Docker exec, keychain writes
Path Traversal (CWE-22)7MEDIA: paths, plugin install, browser downloads, Zip Slip, transcript paths
SSRF11Image tool fetch, Feishu extension, attachment/media URLs, IPv6 bypass
Auth Bypass / Missing Auth4WebSocket config.apply, webhook verification, browser relay, sandbox bridge
Allowlist Bypass40Telegram usernames, Matrix displayName, Slack DM, Twitch, voice-call
Injection (XSS/CSRF/Prompt)6XSS in Control UI, prompt injection via Slack/CWD/logs, CSRF
Denial of Service3Unbounded media fetch, webhook body buffering, archive expansion

๐Ÿ“‹ All Security Advisories (186)

Critical & High Severity

GHSACVESeverityTitlePublished
GHSA-xpr6-2hgm-4wwpโ€”HighDuplicate Advisory: OpenClaw vulnerable to arbitrary code execution via attacker-controlled setup-api.js loaded from cwd during env-key resolution2026-05-11
GHSA-9r9j-3r2w-fg3vโ€”HighDuplicate Advisory: OpenClaw: Workspace dotenv could override runtime-control environment variables2026-05-06
GHSA-35vf-vw9f-q3crโ€”HighDuplicate Advisory: OpenClaw: MCP loopback owner context is derived from server-issued bearer tokens2026-05-06
GHSA-m8wm-r5vq-qjpgโ€”CriticalDuplicate Advisory: OpenClaw: Gateway HTTP endpoints re-resolve bearer auth after SecretRef rotation2026-05-06
GHSA-xrgf-r9gr-jjjfโ€”HighDuplicate Advisory: OpenClaw: Exec environment denylist missed high-risk interpreter startup variables2026-05-06
GHSA-cjg8-85gj-v9q2โ€”CriticalDuplicate Advisory: OpenClaw: Feishu webhook and card-action validation now fail closed2026-05-06
GHSA-79rr-5c85-xvw3โ€”HighDuplicate Advisory: OpenClaw: Matrix room control-command authorization no longer trusts DM pairing-store entries2026-05-06
GHSA-r39h-4c2p-3jxpCVE-2026-45004HighOpenClaw vulnerable to arbitrary code execution via attacker-controlled setup-api.js loaded from cwd during env-key resolution2026-05-05
GHSA-cwj3-vqpp-pmxrโ€”HighOpenClaw's gateway config mutation guard allowed unsafe model-driven config writes2026-05-05
GHSA-r6xh-pqhr-v4xhCVE-2026-44118HighOpenClaw: MCP loopback owner context is derived from server-issued bearer tokens2026-05-04
GHSA-5mh4-3rv3-fpcfโ€”HighDuplicate Advisory: OpenClaw: Host exec environment sanitization misses package, registry, Docker, compiler, and TLS override variables2026-04-28
GHSA-5799-3xg7-rfrvโ€”HighDuplicate Advisory: OpenClaw: SSH sandbox tar upload follows symlinks, enabling arbitrary file write on remote host2026-04-28
GHSA-hxvm-xjvf-93f3CVE-2026-44114HighOpenClaw: Workspace dotenv could override runtime-control environment variables2026-04-25
GHSA-394x-274p-mqc6โ€”HighDuplicate Advisory: OpenClaw: Gateway operator.write Can Reach Admin-Class Telegram Config and Cron Persistence via send2026-04-24
GHSA-7vq9-42cc-33j4โ€”HighDuplicate Advisory: OpenClaw: Device-Paired Node Skips Node Scope Gate โ†’ Host RCE.md2026-04-24
GHSA-gv2f-q4wp-fvh5โ€”HighDuplicate Advisory: OpenClaw: CLI Remote Onboarding Persists Unauthenticated Discovery Endpoint and Exfiltrates Gateway Credentials2026-04-24
GHSA-jx3c-247h-cxwpโ€”HighDuplicate Advisory: OpenClaw: Workspace .env can override the bundled hooks root and load attacker hook code2026-04-24
GHSA-xh72-v6v9-mwhcCVE-2026-44109CriticalOpenClaw: Feishu webhook and card-action validation now fail closed2026-04-17
GHSA-2gvc-4f3c-2855CVE-2026-44110HighOpenClaw: Matrix room control-command authorization no longer trusts DM pairing-store entries2026-04-17
GHSA-xmxx-7p24-h892CVE-2026-43585CriticalOpenClaw: Gateway HTTP endpoints re-resolve bearer auth after SecretRef rotation2026-04-17
GHSA-66r7-m7xm-v49hCVE-2026-43533HighOpenClaw: QQBot media tags could read arbitrary local files through reply text2026-04-17
GHSA-2cq5-mf3v-mx44CVE-2026-43530HighOpenClaw: busybox and toybox applet execution weakened exec approval binding2026-04-17
GHSA-7jp6-r74r-995qCVE-2026-42433HighOpenClaw: Matrix profile config persistence was reachable from operator.write message tools2026-04-17
GHSA-736r-jwj6-4w23CVE-2026-42434HighOpenClaw: Sandboxed agents could escape exec routing via host=node override2026-04-17
GHSA-939r-rj45-g2rjCVE-2026-43569HighOpenClaw: Workspace provider auth choices could auto-enable untrusted provider plugins2026-04-17
GHSA-82qx-6vj7-p8m2CVE-2026-43571HighOpenClaw: Channel setup catalog lookups could include untrusted workspace plugin shadows2026-04-17
GHSA-525j-hqq2-66r4โ€”HighOpenClaw: Sandbox browser CDP relay could expose DevTools protocol on 0.0.0.02026-04-17
GHSA-rq6g-px6m-c248CVE-2026-28469HighOpenClaw Google Chat shared-path webhook target ambiguity allowed cross-account policy-context misrouting2026-02-18
GHSA-3fqr-4cg8-h96qCVE-2026-26317HighOpenClaw affected by cross-site request forgery (CSRF) through loopback browser mutation endpoints2026-02-18
GHSA-q447-rj3r-2cghCVE-2026-28478HighOpenClaw affected by denial of service via unbounded webhook request body buffering2026-02-18
GHSA-mr32-vwc2-5j6hCVE-2026-28458HighOpenClaw's Browser Relay /cdp websocket is missing auth which could allow cross-tab cookie access2026-02-17
GHSA-q284-4pvr-m585CVE-2026-25157HighOpenClaw/Clawdbot has OS Command Injection via Project Root Path in sshNodeCommand2026-02-02
GHSA-g8p2-7wf7-98mqCVE-2026-25253HighOpenClaw/Clawdbot has 1-Click RCE via Authentication Token Exfiltration From gatewayUrl2026-02-02
GHSA-mc68-q9jw-2h3vCVE-2026-24763HighOpenClaw/Clawdbot Docker Execution has Authenticated Command Injection via PATH Environment Variable2026-02-02
GHSA-r2c6-8jc8-g32wโ€”HighDuplicate Advisory: 1-Click RCE via Authentication Token Exfiltration From gatewayUrl2026-02-02

Medium Severity

GHSACVESeverityTitlePublished
GHSA-v8j2-5f9p-fmh4โ€”MediumDuplicate Advisory: OpenClaw's Webhooks SecretRef route secret remains valid after rotation/reload2026-05-11
GHSA-5jgm-f9wr-9qm7โ€”MediumDuplicate Advisory: OpenClaw: Workspace dotenv files cannot override connector endpoint hosts2026-05-11
GHSA-9j32-3m66-mc4mโ€”MediumDuplicate Advisory: OpenClaw: Hook mapping templates could bypass hook session-key opt-in2026-05-11
GHSA-m5j2-r859-r5cvโ€”MediumDuplicate Advisory: OpenClaw: Isolated cron awareness events were recorded as trusted system events2026-05-11
GHSA-4mhr-cxr4-2prmโ€”MediumDuplicate Advisory: OpenClaw: Workspace dotenv MiniMax host override could redirect credentialed requests2026-05-11
GHSA-p3m6-jr2h-hhxjโ€”MediumDuplicate Advisory: OpenClaw: MCP stdio server env could load dangerous startup variables from workspace config2026-05-11
GHSA-6f72-9gxx-98mjโ€”MediumDuplicate Advisory: OpenClaw: OpenShell FS bridge writes stay pinned to the sandbox mount root2026-05-06
GHSA-frr5-j3mh-h9chโ€”MediumDuplicate Advisory: OpenClaw: OpenShell FS bridge reads pin and verify the opened file before returning bytes2026-05-06
GHSA-qvmw-h675-h7qgโ€”MediumDuplicate Advisory: OpenClaw validates Zalo outbound photo URLs through the SSRF guard2026-05-06
GHSA-r747-33r4-rmjwโ€”MediumDuplicate Advisory: OpenClaw: QQBot direct media upload skipped URL SSRF validation2026-05-06
GHSA-82rm-qcfx-2v78โ€”MediumDuplicate Advisory: OpenClaw: Delivery queue recovery could lose group tool-policy context for media replay2026-05-06
GHSA-w7rc-vvgx-pj45โ€”MediumDuplicate Advisory: OpenClaw: Browser SSRF hostname validation could be bypassed by DNS rebinding2026-05-06
GHSA-3r56-7hhr-vfg9โ€”MediumDuplicate Advisory: OpenClaw: CDP /json/version WebSocket URL could pivot to untrusted second-hop targets2026-05-06
GHSA-wwwc-f646-vj2jโ€”MediumDuplicate Advisory: OpenClaw: Browser press/type interaction routes missed complete navigation guard coverage2026-05-06
GHSA-q8ff-7ffm-m3r9CVE-2026-45005MediumOpenClaw's Webhooks SecretRef route secret remains valid after rotation/reload2026-05-05
GHSA-35mw-5vvr-vrxcCVE-2026-43570MediumOpenClaw contains a symlink traversal vulnerability2026-05-05
GHSA-5h3g-6xhh-rg6pCVE-2026-44113MediumOpenClaw: OpenShell FS bridge reads pin and verify the opened file before returning bytes2026-05-04
GHSA-wppj-c6mr-83jjCVE-2026-44112MediumOpenClaw: OpenShell FS bridge writes stay pinned to the sandbox mount root2026-05-04
GHSA-55cf-xx38-4p9pCVE-2026-45003MediumOpenClaw: Workspace dotenv files cannot override connector endpoint hosts2026-05-04
GHSA-q3jj-46pq-826rCVE-2026-44997MediumOpenClaw's ACP child sessions inherit subagent security envelope constraints2026-05-04
GHSA-2hh7-c75g-qj2rCVE-2026-44116MediumOpenClaw validates Zalo outbound photo URLs through the SSRF guard2026-05-04
GHSA-93rg-2xm5-2p9vโ€”MediumOpenClaw's Gateway Control UI bootstrap config required Gateway auth2026-05-04
GHSA-x3h8-jrgh-p8jxโ€”MediumOpenClaw's exec allowlist analysis rejects shell expansion in unquoted heredocs2026-05-04
GHSA-c28g-vh7m-fm7vCVE-2026-44991MediumOpenClaw: Owner-enforced commands could accept wildcard channel senders as command owners2026-04-29
GHSA-gfg9-5357-hv4cโ€”MediumOpenClaw: Webchat audio embedding could read local files without local-root containment2026-04-29
GHSA-f5fm-9jmp-c88rโ€”MediumDuplicate Advisory: OpenClaw: Trailing-dot localhost CDP hosts could bypass remote loopback protections2026-04-28
GHSA-8pf2-vj79-4wxgโ€”MediumDuplicate Advisory: OpenClaw: MSTeams thread history bypasses sender allowlist via Graph API2026-04-28
GHSA-qp56-gp47-jwj3โ€”MediumDuplicate Advisory: OpenClaw: Feishu extension resolveUploadInput bypasses file-system sandbox and allows arbitrary file reads via upload_image2026-04-28
GHSA-h2vw-ph2c-jvwfCVE-2026-44992MediumOpenClaw: Workspace dotenv MiniMax host override could redirect credentialed requests2026-04-25
GHSA-c4qg-j8jg-42q5CVE-2026-44117MediumOpenClaw: QQBot direct media upload skipped URL SSRF validation2026-04-25
GHSA-mj59-h3q9-ghfhCVE-2026-44995MediumOpenClaw: MCP stdio server env could load dangerous startup variables from workspace config2026-04-25
GHSA-2xcp-x87w-q377CVE-2026-45002MediumOpenClaw: Hook mapping templates could bypass hook session-key opt-in2026-04-25
GHSA-7jm2-g593-4qrcโ€”MediumOpenClaw: Agent gateway config mutations could change protected operator settings2026-04-25
GHSA-qrp5-gfw2-gxv4โ€”MediumOpenClaw: Bundled MCP/LSP tools could bypass configured tool policy2026-04-25
GHSA-72q8-jcmc-97wxโ€”MediumOpenClaw: Feishu card actions could misclassify DMs and skip dmPolicy2026-04-25
GHSA-m563-373q-885cโ€”MediumDuplicate Advisory: OpenClaw: OpenShell mirror mode can convert untrusted sandbox files into explicitly enabled workspace hooks and execute them on the host during gateway startup2026-04-24
GHSA-6477-wvjj-47v6โ€”MediumDuplicate Advisory: OpenClaw: Zalo replay dedupe keys could suppress messages across chats or senders2026-04-24
GHSA-m958-864j-xq5wโ€”MediumDuplicate Advisory: OpenClaw: Telnyx Webhook Replay Detection Bypass via Base64 Signature Re-encoding2026-04-24
GHSA-mf69-r24q-ghhrโ€”MediumDuplicate Advisory: OpenClaw: Pairing pending-request caps were enforced per channel instead of per account2026-04-24
GHSA-v3c2-39fm-jq4hโ€”MediumDuplicate Advisory: OpenClaw: Gateway operator.write can reach admin-only persisted verboseLevel via chat.send /verbose2026-04-24
GHSA-2hv5-4h3g-4hjvโ€”MediumDuplicate Advisory: OpenClaw: LINE webhook handler lacks shared pre-auth concurrency budget before signature verification2026-04-24
GHSA-cw28-63x4-37c3โ€”MediumDuplicate Advisory: OpenClaw: Voice-call Plivo replay mutates in-process callback origin before replay rejection2026-04-24
GHSA-fjm8-mgc9-mf65โ€”MediumDuplicate Advisory: OpenClaw Has a Gateway Control Interface Information Disclosure Vulnerability2026-04-24
GHSA-r7p2-r9g4-4xphโ€”MediumDuplicate Advisory: OpenClaw: Gateway hello snapshots exposed host config and state paths to non-admin clients2026-04-24
GHSA-w9f5-8q83-qwpxโ€”MediumDuplicate Advisory: OpenClaw: Fake DeviceToken Bypasses Shared Auth Rate Limiting2026-04-24
GHSA-wcm7-94wg-h74hโ€”MediumDuplicate Advisory: OpenClaw host-env blocklist missing GIT_TEMPLATE_DIR and AWS_CONFIG_FILE allows code execution via env override2026-04-24
GHSA-qc5j-2mqx-x83qโ€”MediumDuplicate Advisory: OpenClaw: Webchat media embedding enforces local-root containment for tool-result files2026-04-20
GHSA-mr34-9552-qr95CVE-2026-41389MediumOpenClaw: Webchat media embedding enforces local-root containment for tool-result files2026-04-17
GHSA-f7fh-qg34-x2xhCVE-2026-43576MediumOpenClaw: CDP /json/version WebSocket URL could pivot to untrusted second-hop targets2026-04-17
GHSA-jhpv-5j76-m56hCVE-2026-42438MediumOpenClaw: Sender policy bypass in host media attachment reads allows unauthorized local file disclosure2026-04-17
GHSA-536q-mj95-h29hCVE-2026-43580MediumOpenClaw: Browser press/type interaction routes missed complete navigation guard coverage2026-04-17
GHSA-527m-976r-jf79CVE-2026-43573MediumOpenClaw: Existing-session browser interaction routes bypassed SSRF policy enforcement2026-04-17
GHSA-rj2p-j66c-mgqhCVE-2026-42439MediumOpenClaw: Browser tabs action select and close routes bypassed SSRF policy2026-04-17
GHSA-jf25-7968-h2h5CVE-2026-43567MediumOpenClaw: screen_record outPath bypassed workspace-only filesystem guard2026-04-17
GHSA-53vx-pmqw-863cCVE-2026-43527MediumOpenClaw: Browser SSRF policy default allowed private-network navigation2026-04-17
GHSA-xq94-r468-qwgjCVE-2026-43582MediumOpenClaw: Browser SSRF hostname validation could be bypassed by DNS rebinding2026-04-17
GHSA-2767-2q9v-9326CVE-2026-43526MediumOpenClaw: QQBot reply media URL handling could trigger SSRF and re-upload fetched bytes2026-04-17
GHSA-f934-5rqf-xx47โ€”MediumOpenClaw: QMD memory_get restricts reads to canonical or indexed memory paths2026-04-17
GHSA-qmwg-qprg-3j38โ€”MediumOpenClaw: Browser interaction routes could pivot into local CDP and regain file reads2026-04-17
GHSA-f3h5-h452-vp3jโ€”MediumOpenClaw: Nostr profile mutation routes allowed operator.write config persistence2026-04-17
GHSA-mj5r-hh7j-4gxfCVE-2026-28480MediumOpenClaw Telegram allowlist authorization accepted mutable usernames2026-02-18
GHSA-h89v-j3x9-8wqjCVE-2026-28452MediumOpenClaw affected by denial of service through unguarded archive extraction allowing high expansion/resource abuse (ZIP/TAR)2026-02-18
GHSA-w2cg-vxx6-5xjgCVE-2026-29612MediumOpenClaw: denial of service through large base64 media files allocating large buffers before limit checks2026-02-18
GHSA-g34w-4xqq-h79mCVE-2026-26328MediumOpenClaw iMessage group allowlist authorization inherited DM pairing-store identities2026-02-18

Low Severity

GHSACVESeverityTitlePublished
GHSA-p3pv-c954-9m6fโ€”LowDuplicate Advisory: OpenClaw: Owner-enforced commands could accept wildcard channel senders as command owners2026-05-11
GHSA-w626-296m-8f85โ€”LowDuplicate Advisory: OpenClaw's ACP child sessions inherit subagent security envelope constraints2026-05-11
GHSA-qm77-8qjp-4vcmCVE-2026-41358LowOpenClaw: Slack thread context could include messages from non-allowlisted senders2026-05-04
GHSA-57r2-h2wj-g887CVE-2026-44999LowOpenClaw: Isolated cron awareness events were recorded as trusted system events2026-04-25
GHSA-v8qf-fr4g-28p2CVE-2026-41908LowOpenClaw: Assistant media route missed scope enforcement for trusted-proxy authorization2026-04-25
GHSA-j4c5-89f5-f3pmโ€”LowOpenClaw: Browser CDP profile creation skipped strict-mode SSRF checks2026-04-25
GHSA-xrq9-jm7v-g9h7โ€”LowOpenClaw: Paired-device pairing actions were not limited to the caller device2026-04-25
GHSA-7hrg-5w46-5r2xโ€”LowDuplicate Advisory: OpenClaw: Slack thread context could include messages from non-allowlisted senders2026-04-24
GHSA-wwc3-c577-533mโ€”LowDuplicate Advisory: OpenClaw: Gateway device.token.rotate does not terminate active WebSocket sessions after credential rotation2026-04-24
GHSA-qgp3-3rj7-qqq4โ€”LowDuplicate Advisory: OpenClaw: Discord Slash Commands Bypass Group DM Channel Allowlist2026-04-24
GHSA-2xp4-qhr4-xqm2โ€”LowDuplicate Advisory: OpenClaw: HTTP operator endpoints lack browser-origin validation in trusted-proxy mode2026-04-24
GHSA-pr66-whqj-rq5pโ€”LowDuplicate Advisory: OpenClaw: Discord Component Interaction Misclassifies Group DM as Direct Message2026-04-24
GHSA-qgx9-6px9-7p75โ€”LowDuplicate Advisory: OpenClaw: Assistant media route missed scope enforcement for trusted-proxy authorization2026-04-23
GHSA-chm2-m3w2-wcxmโ€”LowOpenClaw Google Chat spoofing access with allowlist authorized mutable email principal despite sender-ID mismatch2026-02-17

Repo-Only Advisories (~73 more)

These advisories are listed on the repo security page but not yet indexed in the GitHub Advisory Database. See the full advisory list for details.

Show 73 repo-only advisories
GHSASeverityTitlePublished
GHSA-2hfg-4fh4-qp7fHighBrowser act interactions could bypass private-network navigation checks2026-05-28
GHSA-3c6j-hq33-3jv4HighPaired nodes could forge exec lifecycle events without system.run provenance2026-05-28
GHSA-6fvr-66p3-3qj4HighHook-triggered CLI runs could receive owner MCP tool authority2026-05-28
GHSA-8372-7vhw-cm6qHighconfig.get redaction bypass through sourceConfig and runtimeConfig aliases2026-04-16
GHSA-chr9-m4q2-76hwHighControl UI locality spoofing could mint a durable admin device token2026-05-28
GHSA-hw9r-h9mr-4jffHighScoped chat.send route inheritance could bypass admin command scope gates2026-05-28
GHSA-mgq6-vr84-7m2jHighQQBot native approval buttons did not enforce configured approver identity2026-05-28
GHSA-mhq8-78pj-5j79HighPOSIX node system.run safe-bin allowlist could be widened by shell expansion2026-05-28
GHSA-q99w-vh6v-q3v7HighPairing-scoped device session could restore revoked node token authority2026-05-28
GHSA-qjpc-qf9m-xwmrHighTrusted-proxy Control UI WebSocket accepted client-declared scopes before pairing2026-05-28
GHSA-rjxq-qqhf-8hwhHighMCP Streamable HTTP redirects could forward configured custom headers to another origin2026-05-28
GHSA-v2ww-5rh7-2h5vHighLinux and macOS exec allowlists skipped configured argument patterns2026-05-28
GHSA-xr4f-mjxj-w6w5HighNon-owner chat senders could issue device-pairing bootstrap codes2026-05-28
GHSA-xww8-gqvh-92x9HighExec approval display truncation could hide the command being approved2026-05-28
GHSA-24vr-rprv-67rfMediumWorkspace .env npm_execpath could influence bundled runtime dependency install2026-05-28
GHSA-275c-xpvc-jgfwMediumSlack and Zalo webhook secrets could remain active after secrets.reload2026-05-28
GHSA-2j8v-hwgc-x698MediumShell wrapper argv could change between approval and execution2026-05-28
GHSA-4hpg-mp64-x7xqMediumInternal/webchat command auth could inherit ownerAllowFrom wildcard state2026-05-28
GHSA-4m3v-q747-pc6hMediumMattermost slash token revocation could lag until monitor refresh2026-05-28
GHSA-5cj2-3jr2-5h77MediumShell positional parameters could weaken strict inline-eval checks2026-05-28
GHSA-6c4r-g249-wv3cMediumSandboxed session spawn could expose the real workspace path to child prompts2026-05-28
GHSA-72fw-cqh5-f324Mediummemory-wiki shared search could miss session visibility checks2026-05-28
GHSA-77pv-3w4q-vrj5MediumQQBot pre-dispatch slash commands could skip allowFrom checks2026-05-28
GHSA-77q5-rr5v-x43qMediumTrusted retry endpoint checks could match hostname prefixes2026-05-28
GHSA-7hxm-f538-3xp6MediumMatrix allowFrom could bind to mutable display names2026-05-28
GHSA-83w9-h5wv-j9xmMediumNode pairing reconnection could confuse approval scope state2026-05-28
GHSA-8c59-hr4w-qg69MediumZalo allowFrom could bind to mutable display names2026-05-28
GHSA-8mg9-j9cf-54cjMediumEmpty-scope device re-pairing could confuse caller scope containment2026-05-28
GHSA-8wg3-5mcm-fjq8MediumWorkspace .env could override Homebrew executable selection for skill install flows2026-05-28
GHSA-985f-72mj-8gf7MediumTool group policy callers could accept unvalidated group IDs2026-05-28
GHSA-9v8j-9c9g-w66cMediumBootstrap token replay could widen pending pairing scopes2026-05-28
GHSA-c226-q6fx-6j6cMediummacOS Swift exec allowlist missed combined POSIX inline flags2026-05-28
GHSA-c29c-2q9c-pc86MediumSlack allowFrom could bind to mutable display names2026-05-28
GHSA-c4qm-58hj-j6pjMediumBrowser snapshot and screenshot routes could expose internal page content after navigation2026-04-16
GHSA-ccwh-wwpp-6wg5MediumHost environment sanitizer missed two Node.js control variables2026-05-28
GHSA-cqwv-9qjx-vxw2MediumSkill Workshop apply flow could override pending approval2026-05-28
GHSA-cw4q-gqg5-g38hMediumDiscord allowFrom could bind to mutable display names2026-05-28
GHSA-cwpp-5962-q4f6MediumExec allowlist could miss side effects from transparent command wrappers2026-05-28
GHSA-f397-5vjw-v2c2MediumShell inline-command parsing could miss an allowlist check2026-05-28
GHSA-fq9j-vw4w-fr6vMediumWorkspace .env CLOUDSDK_PYTHON could influence Gmail setup gcloud execution2026-05-28
GHSA-g2hm-779g-vm32MediumHeartbeat owner downgrade missed untrusted webhook wake events2026-04-16
GHSA-gp79-m99v-gjmhMediumMattermost handlers could fall open when channel type was missing2026-05-28
GHSA-grc3-2j34-p6gmMediummessage.action forwarding could send Gateway credentials to model-supplied loopback URLs2026-05-28
GHSA-gxg4-2rrr-jhc7MediumHostname checks could treat trailing-dot hosts inconsistently2026-05-28
GHSA-hcm3-8f6r-6xwgMediumBrowser debug/export routes could reuse already-open blocked tabs2026-05-28
GHSA-j472-gf56-x589MediumPowerShell encoded-command aliases could miss exec allowlist checks2026-05-28
GHSA-jvm4-4j77-39p6MediumQQBot streaming command could mutate config without explicit allowFrom2026-05-28
GHSA-jwrq-8g5x-5fhmMediumCollect-mode queue batches could reuse the last sender authorization context2026-04-16
GHSA-mpc8-jxjh-qpghMediumFocus command could miss controlScope enforcement2026-05-28
GHSA-p2fh-f5fc-44hrMediummemory-wiki ingest could read local files with operator.write scope2026-05-28
GHSA-p39j-x9h5-q66mMediumEmbedded runner policy could be confused by provider aliases2026-05-28
GHSA-p73f-w79w-jqr5MediumNative command authorization could skip owner-command enforcement2026-05-28
GHSA-q7q8-3mgw-q67rMediumMessage read actions could skip channel allowlist checks2026-05-28
GHSA-qh2f-99mv-mrcfMediumBundle MCP loopback could miss its exec denylist on session spawn2026-05-28
GHSA-r77c-2cmr-7p47MediumDelivery queue recovery could lose group tool-policy context for media replay2026-04-16
GHSA-rggc-m335-3wvjMediumSame-host trusted-proxy deployments could accept local forged identity headers2026-05-28
GHSA-rj6p-xmxr-qj4hMediumMCP loopback could skip owner-only tool policy for non-owner callers2026-05-28
GHSA-rwp6-7w3q-75fqMediumConfig recovery could restore openclaw.json with broad file permissions2026-05-28
GHSA-rx78-29qr-5hq8MediumWorkspace-derived service PATH could influence trash command selection2026-05-28
GHSA-v6r2-jh58-xx6wMediumMarketplace runtime extension metadata could point at unscanned payloads2026-05-28
GHSA-v8cx-933x-r976MediumFake package roots could influence memory-core artifact loading2026-05-28
GHSA-vxx3-6hc9-7cc3MediumCombined POSIX shell options could confuse exec revalidation2026-05-28
GHSA-w4v6-g3wm-w36cMediumQQBot admin commands could skip DM-only and allowFrom policy2026-05-28
GHSA-w5ww-7chg-mxcqMediumTelegram interactive callbacks could skip commands.allowFrom2026-05-28
GHSA-w9hf-3pp7-pvxvMediumExported session HTML could keep unsafe markdown links2026-05-28
GHSA-wc84-j36w-pw4xMediumWorkspace .env STATE_DIRECTORY could influence bundled runtime dependency roots2026-05-28
GHSA-wv26-j37q-2g7pMediumSlack plugin approvals used the exec approver gate for plugin actions2026-05-28
GHSA-x629-46cc-7xgwMediumActive Memory write scope could mutate global config2026-05-28
GHSA-3wqp-prf6-2m72LowFeishu dynamic-agent bindings could miss configWrites enforcement2026-05-28
GHSA-68xw-r643-9p5wLowSkill-command dispatch could skip before-tool-call hooks2026-05-28
GHSA-8j37-5w68-wj2gLowBlueBubbles sender policy could match mutable conversation identifiers2026-05-28
GHSA-fcvx-5cxc-v5p8LowSlack reaction events could ignore reaction notification settings2026-05-28
GHSA-gc9r-867r-j85fLowMicrosoft Teams SSO invoke handler missed sender authorization checks2026-04-16

Naming Inconsistencies

The OpenClaw project has been renamed multiple times, causing inconsistencies across CVE records:

CVEvendorproductpackageURLDescription Names
CVE-2026-28466OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-43534OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-32918OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-32917OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-43585OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-44109OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-41386OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-43533OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-25253OpenClawOpenClawpkg:npm/clawdbotOpenClaw / clawdbot / Moltbot
CVE-2026-24763clawdbotclawdbotโ€”OpenClaw (formerly Clawdbot)
CVE-2026-32913OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-41296OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-28478OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-32042OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-32051OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-33573OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-41405OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-42434OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-43530OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-44115OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-53814OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-32920OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-33579OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-53823OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-44118OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-44114OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-45004OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-31998OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-35618OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-43526OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-28469OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-29611OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-25157openclawopenclawโ€”OpenClaw
CVE-2026-27002openclawopenclawโ€”OpenClaw
CVE-2026-32048OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-43569OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-43571OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-44110OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-53807OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-41353OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-43535OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-26316openclaw@openclaw/bluebubblesโ€”OpenClaw
CVE-2026-26324openclawopenclawโ€”OpenClaw
CVE-2026-22179OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-32025OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-28458OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-34512OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-26317openclawclawdbotโ€”OpenClaw (formerly Clawdbot)
CVE-2026-26327openclawopenclawโ€”OpenClaw
CVE-2026-32008OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-32976OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-35644OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-35636OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-41368OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-41385OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-42433OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-43567OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-43568OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-41380OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-43531OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-22178OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-28480OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-32975OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-35626OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-34426OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-35647OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-41300OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-41331OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-35664OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-41374OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-41400OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-44116OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-53818OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-29612OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-26972openclawopenclawโ€”OpenClaw
CVE-2026-28452OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-26328openclawclawdbotโ€”OpenClaw (formerly Clawdbot)
CVE-2026-28449OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-35628OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-35646OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-35649OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-35635OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-41333OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-41389OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-41913OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-43527OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-44117OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-44999OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-45002OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-35645OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-32039OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-35622OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-42429OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-43570OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-44112OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-44113OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-53830OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-53838OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-28481OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-32054OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-45005OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-31999OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-32000OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-31995OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-32988OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-41332OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-41360OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-44995OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-26326openclawopenclawโ€”OpenClaw
CVE-2026-32899OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-41909OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-35634OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-42436OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-42439OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-43532OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-42438OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-43573OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-43576OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-43580OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-43582OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-27007openclawopenclawโ€”OpenClaw
CVE-2026-44992OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-45003OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-32006OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-34507OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-35617OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-35648OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-41347OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-41358OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-41916OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-41908OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-44111OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-44993OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-44997OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-44991OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-53826OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-31991OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-32058OpenClawOpenClawpkg:npm/openclawOpenClaw

Data Sources

SourceURL
CVE List v5CVEProject/cvelistV5
GitHub Advisory DBgithub.com/advisories
Repo Security Tabopenclaw/openclaw/security
CVE Services APIhttps://cveawg.mitre.org/api/cve-id/{CVE-ID}

Auto-generated by update_readme.py ยท Updated hourly via GitHub Actions
Data: ghsa-advisories.json ยท cves.json ยท cve-pipeline-status.json

Maintained by Jerry Gamblin ยท OpenClawCVEs