๐ก๏ธ OpenClaw CVE & Security Advisory Tracker
June 13, 2026 ยท View on GitHub
An automated tracker that continuously monitors OpenClaw security advisories across the GitHub Advisory Database, repo-level security advisories, and the CVE V5 (cvelistV5) registry. Every hour it pulls the latest data, reconciles GHSA โ CVE publication state, and regenerates this dashboard so you always have an up-to-date picture of the project's vulnerability landscape.
Last updated: 2026-06-13 12:45 UTC ยท MIT License ยท Full Advisory List ยท Security Policy ยท Data: cvelistV5 + Advisory DB ยท Updates hourly
Published CVEs ยท Pipeline ยท Advisories ยท Categories ยท Insights ยท Identity
๐๏ธ Project Identity
| Field | Value |
|---|---|
| Current Name | OpenClaw |
| Previous Names | Moltbot (second name), Clawdbot (original name) |
| Repository | openclaw/openclaw |
| npm Package | openclaw (formerly clawdbot) |
| Author | Peter Steinberger (steipete) |
Search terms for CVE discovery
To find all CVEs, search for: openclaw, clawdbot, moltbot, clawhub, pkg:npm/clawdbot, pkg:npm/openclaw
๐ CVEs Published in cvelistV5 (48)
These CVEs have full records in the CVEProject/cvelistV5 repository:
| CVE ID | Severity | CVSS | Title | CWE | Published |
|---|---|---|---|---|---|
| CVE-2026-28466 | 9.4 | OpenClaw < 2026.2.14 - Remote Code Execution via Node Invoke Approval Bypass | CWE-863 | 2026-03-05 | |
| CVE-2026-43534 | 9.3 | OpenClaw < 2026.4.10 - Unsanitized External Input in Agent Hook Events | CWE-345 | 2026-05-05 | |
| CVE-2026-32918 | 9.2 | OpenClaw < 2026.3.11 - Session Sandbox Escape via session_status Tool | CWE-863 | 2026-03-29 | |
| CVE-2026-32917 | 9.2 | OpenClaw < 2026.3.13 - Remote Command Injection via Unsanitized iMessage Attachment Paths in SCP | CWE-78 | 2026-03-31 | |
| CVE-2026-43585 | 9.2 | OpenClaw: Gateway HTTP endpoints re-resolve bearer auth after SecretRef rotation | CWE-672 | 2026-05-06 | |
| CVE-2026-44109 | 9.2 | OpenClaw: Feishu webhook and card-action validation now fail closed | CWE-1188 | 2026-05-06 | |
| CVE-2026-41386 | 9.1 | OpenClaw < 2026.3.22 - Privilege Escalation via Unbound Bootstrap Setup Codes | CWE-648 | 2026-04-28 | |
| CVE-2026-43533 | 8.9 | OpenClaw < 2026.4.10 - Arbitrary Local File Read via QQBot Media Tags | CWE-23 | 2026-05-05 | |
| CVE-2026-25253 | 8.8 | OpenClaw/Clawdbot has 1-Click RCE via Authentication Token Exfiltration From gatewayUrl | CWE-669 | 2026-02-01 | |
| CVE-2026-24763 | 8.8 | OpenClaw/Clawdbot Docker Execution has Authenticated Command Injection via PATH Environment Variable | CWE-78 | 2026-02-02 | |
| CVE-2026-32913 | 8.8 | OpenClaw < 2026.3.7 - Custom Authorization Header Leakage via Cross-Origin Redirects | CWE-522 | 2026-03-23 | |
| CVE-2026-41296 | 8.8 | OpenClaw < 2026.3.31 - Sandbox Escape via TOCTOU Race in Remote FS Bridge readFile | CWE-367 | 2026-04-20 | |
| CVE-2026-28478 | 8.7 | OpenClaw affected by denial of service via unbounded webhook request body buffering | CWE-770 | 2026-03-05 | |
| CVE-2026-32042 | 8.7 | OpenClaw < 2026.2.25 - Privilege Escalation via Unpaired Device Identity in Shared Gateway Authentication | CWE-863 | 2026-03-21 | |
| CVE-2026-32051 | 8.7 | OpenClaw < 2026.3.1 - Authorization Bypass in Agent Runs via Owner-Only Tool Access | CWE-863 | 2026-03-21 | |
| CVE-2026-33573 | 8.7 | OpenClaw < 2026.3.11 - Workspace Boundary Bypass via Agent RPC Parameters | CWE-668 | 2026-03-29 | |
| CVE-2026-41405 | 8.7 | OpenClaw < 2026.3.31 - Resource Exhaustion via Unauthenticated MS Teams Webhook Body Parsing | CWE-408 | 2026-04-28 | |
| CVE-2026-42434 | 8.7 | OpenClaw: Sandboxed agents could escape exec routing via host=node override | CWE-863 | 2026-05-05 | |
| CVE-2026-43530 | 8.7 | OpenClaw: busybox and toybox applet execution weakened exec approval binding | CWE-863 | 2026-05-05 | |
| CVE-2026-44115 | 8.7 | OpenClaw < 2026.4.22 - Shell Expansion Bypass in Unquoted Heredocs via Exec Allowlist | CWE-184 | 2026-05-06 | |
| CVE-2026-53814 | 8.7 | OpenClaw < 2026.5.20 - Privilege Escalation via Hook-Triggered CLI MCP Tool Authority | CWE-266 | 2026-06-11 | |
| CVE-2026-32920 | 8.6 | OpenClaw < 2026.3.12 - Arbitrary Code Execution via Auto-Discovery of Workspace Plugins | CWE-829 | 2026-03-31 | |
| CVE-2026-33579 | 8.6 | OpenClaw < 2026.3.28 - Privilege Escalation via Missing Caller Scope Validation in Device Pair Approval | CWE-863 | 2026-03-31 | |
| CVE-2026-53823 | 8.6 | OpenClaw < 2026.5.3 - Privilege Escalation via Mutable Slack Display Names in allowFrom | CWE-290 | 2026-06-12 | |
| CVE-2026-44118 | 8.5 | OpenClaw < 2026.4.22 - Owner Context Spoofing via Bearer Token Header | CWE-290 | 2026-05-06 | |
| CVE-2026-44114 | 8.5 | OpenClaw: Workspace dotenv could override runtime-control environment variables | CWE-184 | 2026-05-06 | |
| CVE-2026-45004 | 8.4 | OpenClaw vulnerable to arbitrary code execution via attacker-controlled setup-api.js loaded from cwd during env-key resolution | CWE-427 | 2026-05-11 | |
| CVE-2026-31998 | 8.3 | OpenClaw 2026.2.22 < 2026.2.24 - Authorization Bypass in Synology Chat Plugin via Empty allowedUserIds | CWE-863 | 2026-03-19 | |
| CVE-2026-35618 | 8.3 | OpenClaw < 2026.3.23 - Replay Identity Drift via Query-Only Variants in Plivo V2 Verification | CWE-294 | 2026-04-09 | |
| CVE-2026-43526 | 8.3 | OpenClaw: QQBot reply media URL handling could trigger SSRF and re-upload fetched bytes | CWE-918 | 2026-05-05 | |
| CVE-2026-28469 | 8.2 | OpenClaw Google Chat shared-path webhook target ambiguity allowed cross-account policy-context misrouting | CWE-639 | 2026-03-05 | |
| CVE-2026-29611 | 8.2 | OpenClaw < 2026.2.14 - Local File Inclusion via mediaPath Parameter in BlueBubbles Media Handling | CWE-73 | 2026-03-05 | |
| CVE-2026-25157 | 7.8 | OpenClaw/Clawdbot has OS Command Injection via Project Root Path in sshNodeCommand | CWE-78 | 2026-02-04 | |
| CVE-2026-27002 | 7.7 | OpenClaw: Docker container escape via unvalidated bind mount config injection | CWE-250 | 2026-02-19 | |
| CVE-2026-32048 | 7.7 | OpenClaw < 2026.3.1 - Sandbox Escape via Cross-Agent sessions_spawn | CWE-732 | 2026-03-21 | |
| CVE-2026-43569 | 7.7 | OpenClaw: Workspace provider auth choices could auto-enable untrusted provider plugins | CWE-829 | 2026-05-05 | |
| CVE-2026-43571 | 7.7 | OpenClaw: Channel setup catalog lookups could include untrusted workspace plugin shadows | CWE-829 | 2026-05-05 | |
| CVE-2026-44110 | 7.7 | OpenClaw: Matrix room control-command authorization no longer trusts DM pairing-store entries | CWE-863 | 2026-05-06 | |
| CVE-2026-53807 | 7.7 | OpenClaw < 2026.5.6 - Authorization Bypass in Telegram Interactive Callbacks via commands.allowFrom | CWE-863 | 2026-06-11 | |
| CVE-2026-41353 | 7.6 | OpenClaw < 2026.3.22 - allowProfiles Bypass via Profile Mutation and Runtime Selection | CWE-472 | 2026-04-23 | |
| CVE-2026-43535 | 7.6 | OpenClaw < 2026.4.14 - Authorization Context Reuse in Collect-Mode Queue Batches | CWE-266 | 2026-05-05 | |
| CVE-2026-26316 | 7.5 | OpenClaw has BlueBubbles webhook auth bypass via loopback proxy trust | CWE-863 | 2026-02-19 | |
| CVE-2026-26324 | 7.5 | OpenClaw has a SSRF guard bypass via full-form IPv4-mapped IPv6 (loopback / metadata reachable) | CWE-918 | 2026-02-19 | |
| CVE-2026-22179 | 7.5 | OpenClaw < 2026.2.22 - Allowlist Bypass via Command Substitution in system.run | CWE-78 | 2026-03-18 | |
| CVE-2026-32025 | 7.5 | OpenClaw < 2026.2.25 - Password Brute-Force via Browser-Origin WebSocket Authentication Bypass | CWE-307 | 2026-03-19 | |
| CVE-2026-28458 | 7.4 | OpenClaw's Browser Relay /cdp websocket is missing auth which could allow cross-tab cookie access | CWE-306 | 2026-03-05 | |
| CVE-2026-34512 | 7.2 | OpenClaw < 2026.3.25 - Improper Access Control in /sessions/:sessionKey/kill Endpoint | CWE-863 | 2026-04-09 | |
| CVE-2026-26317 | 7.1 | OpenClaw affected by cross-site request forgery (CSRF) through loopback browser mutation endpoints | CWE-352 | 2026-02-19 | |
| CVE-2026-26327 | 7.1 | OpenClaw allows unauthenticated discovery TXT records to steer routing and TLS pinning | CWE-345 | 2026-02-19 | |
| CVE-2026-32008 | 7.1 | OpenClaw < 2026.2.21 - Arbitrary Local File Read via Browser Navigation Guard | CWE-610 | 2026-03-19 | |
| CVE-2026-32976 | 7.1 | OpenClaw < 2026.3.11 - Account-Scoped configWrites Policy Bypass via Channel Commands | CWE-639 | 2026-03-31 | |
| CVE-2026-35644 | 7.1 | OpenClaw < 2026.3.22 - Credential Exposure via baseUrl Fields in Gateway Snapshots | CWE-312 | 2026-04-09 | |
| CVE-2026-35636 | 7.1 | OpenClaw 2026.3.11 < 2026.3.25 - Session Isolation Bypass via sessionId Resolution | CWE-696 | 2026-04-09 | |
| CVE-2026-41368 | 7.1 | OpenClaw < 2026.3.28 - Environment Variable Disclosure via jq $ENV Filter Bypass | CWE-668 | 2026-04-27 | |
| CVE-2026-41385 | 7.1 | OpenClaw < 2026.3.31 - Nostr Private Key Exposure via config.get Redaction Bypass | CWE-312 | 2026-04-28 | |
| CVE-2026-42433 | 7.1 | OpenClaw: Matrix profile config persistence was reachable from operator.write message tools | CWE-862 | 2026-05-05 | |
| CVE-2026-43567 | 7.1 | OpenClaw < 2026.4.10 - Path Traversal in screen_record outPath Parameter | CWE-862 | 2026-05-05 | |
| CVE-2026-43568 | 7.1 | OpenClaw 2026.4.5 < 2026.4.10 - Privilege Escalation via Memory Dreaming Configuration in /dreaming Endpoint | CWE-862 | 2026-05-05 | |
| CVE-2026-41380 | 7 | OpenClaw < 2026.3.28 - Arbitrary Execution Allowlist via Wrapper Carrier Executables | CWE-807 | 2026-04-28 | |
| CVE-2026-43531 | 7 | OpenClaw < 2026.4.9 - Environment Variable Injection via Workspace .env File | CWE-15 | 2026-05-05 | |
| CVE-2026-22178 | 6.9 | OpenClaw < 2026.2.19 - ReDoS and Regex Injection via Unescaped Feishu Mention Metadata | CWE-1333 | 2026-03-18 | |
| CVE-2026-28480 | 6.9 | OpenClaw Telegram allowlist authorization accepted mutable usernames | CWE-290 | 2026-03-05 | |
| CVE-2026-32975 | 6.9 | OpenClaw < 2026.3.12 - Weak Authorization via Mutable Group Names in Zalouser Allowlist | CWE-807 | 2026-03-29 | |
| CVE-2026-35626 | 6.9 | OpenClaw < 2026.3.22 - Unauthenticated Resource Exhaustion via Voice Call Webhook | CWE-405 | 2026-04-09 | |
| CVE-2026-34426 | 6.9 | OpenClaw - Approval Bypass via Environment Variable Normalization | CWE-184 | 2026-04-02 | |
| CVE-2026-35647 | 6.9 | OpenClaw < 2026.3.25 - Direct Message Policy Bypass via Verification Notices | CWE-288 | 2026-04-10 | |
| CVE-2026-41300 | 6.9 | OpenClaw < 2026.3.31 - Attacker-Discovered Endpoint Preservation in Remote Onboarding | CWE-372 | 2026-04-20 | |
| CVE-2026-41331 | 6.9 | OpenClaw < 2026.3.31 - Resource Consumption via Unauthorized Telegram Audio Preflight Transcription | CWE-408 | 2026-04-20 | |
| CVE-2026-35664 | 6.9 | OpenClaw < 2026.3.25 - DM Pairing Bypass via Legacy Card Callbacks | CWE-288 | 2026-04-10 | |
| CVE-2026-41374 | 6.9 | OpenClaw < 2026.3.31 - Resource Consumption via Discord Audio Preflight Before Member Authorization | CWE-408 | 2026-04-28 | |
| CVE-2026-41400 | 6.9 | OpenClaw < 2026.3.31 - Resource Consumption via Oversized WebSocket Frames in voice-call | CWE-770 | 2026-04-28 | |
| CVE-2026-44116 | 6.9 | OpenClaw < 2026.4.22 - Server-Side Request Forgery in Zalo Photo URL Validation | CWE-918 | 2026-05-06 | |
| CVE-2026-53818 | 6.9 | OpenClaw < 2026.4.24 - Owner-Only Tool Policy Bypass via MCP Loopback | CWE-862 | 2026-06-11 | |
| CVE-2026-29612 | 6.8 | OpenClaw < 2026.2.14 - Denial of Service via Large Base64 Media File Decoding | CWE-770 | 2026-03-05 | |
| CVE-2026-26972 | 6.7 | OpenClaw has a Path Traversal in Browser Download Functionality | CWE-22 | 2026-02-19 | |
| CVE-2026-28452 | 6.7 | OpenClaw affected by denial of service through unguarded archive extraction allowing high expansion/resource abuse (ZIP/TAR) | CWE-770 | 2026-03-05 | |
| CVE-2026-26328 | 6.5 | OpenClaw iMessage group allowlist authorization inherited DM pairing-store identities | CWE-284, CWE-863 | 2026-02-19 | |
| CVE-2026-28449 | 6.3 | OpenClaw < 2026.2.25 - Webhook Replay Attack via Missing Durable Replay Suppression | CWE-294 | 2026-03-19 | |
| CVE-2026-35628 | 6.3 | OpenClaw < 2026.3.25 - Brute-Force Attack via Missing Telegram Webhook Rate Limiting | CWE-307 | 2026-04-09 | |
| CVE-2026-35646 | 6.3 | OpenClaw < 2026.3.25 - Pre-Authentication Rate-Limit Bypass in Webhook Token Validation | CWE-307 | 2026-04-09 | |
| CVE-2026-35649 | 6.3 | OpenClaw < 2026.3.22 - Settings Reconciliation Bypass via Empty Allowlist | CWE-183 | 2026-04-10 | |
| CVE-2026-35635 | 6.3 | OpenClaw < 2026.3.22 - Webhook Path Route Replacement Vulnerability in Synology Chat | CWE-706 | 2026-04-09 | |
| CVE-2026-41333 | 6.3 | OpenClaw < 2026.3.31 - Authentication Rate Limiting Bypass via Fake DeviceToken | CWE-799 | 2026-04-23 | |
| CVE-2026-41389 | 6.3 | OpenClaw: Webchat media embedding enforces local-root containment for tool-result files | CWE-73 | 2026-04-20 | |
| CVE-2026-41913 | 6.3 | OpenClaw < 2026.4.4 - Rate-Limit Bypass via Concurrent Async Authentication Attempts | CWE-362 | 2026-04-28 | |
| CVE-2026-43527 | 6.3 | OpenClaw: Browser SSRF policy default allowed private-network navigation | CWE-918, CWE-1188 | 2026-05-05 | |
| CVE-2026-44117 | 6.3 | OpenClaw < 2026.4.20 - Server-Side Request Forgery in QQBot Direct Media Upload | CWE-918 | 2026-05-06 | |
| CVE-2026-44999 | 6.3 | OpenClaw < 2026.4.20 - Improper Trust Labeling in Isolated Cron Awareness Events | CWE-345 | 2026-05-11 | |
| CVE-2026-45002 | 6.3 | OpenClaw < 2026.4.20 - Hook Session-Key Bypass via Template Mapping | CWE-863 | 2026-05-11 | |
| CVE-2026-35645 | 6.1 | OpenClaw < 2026.3.25 - Privilege Escalation via Synthetic operator.admin in deleteSession | CWE-648 | 2026-04-09 | |
| CVE-2026-32039 | 6 | OpenClaw < 2026.2.22 - Sender Authorization Bypass via Identity Collision in toolsBySender | CWE-639 | 2026-03-19 | |
| CVE-2026-35622 | 6 | OpenClaw < 2026.3.22 - Improper Authentication Verification in Google Chat Webhook | CWE-290 | 2026-04-09 | |
| CVE-2026-42429 | 6 | OpenClaw < 2026.4.8 - Privilege Escalation via Gateway Plugin HTTP Authentication | CWE-863 | 2026-04-28 | |
| CVE-2026-43570 | 6 | OpenClaw contains a symlink traversal vulnerability | CWE-61 | 2026-05-05 | |
| CVE-2026-44112 | 6 | OpenClaw < 2026.4.22 - Symlink Swap Race Condition in OpenShell FS Bridge Writes | CWE-367 | 2026-05-06 | |
| CVE-2026-44113 | 6 | OpenClaw: OpenShell FS bridge reads pin and verify the opened file before returning bytes | CWE-367 | 2026-05-06 | |
| CVE-2026-53830 | 6 | OpenClaw < 2026.4.22 - Webhook Secret Revocation Bypass via secrets.reload | CWE-613 | 2026-06-12 | |
| CVE-2026-53838 | 6 | OpenClaw < 2026.5.27 - Node Pairing State Mutation via Reconnection | CWE-367 | 2026-06-12 | |
| CVE-2026-28481 | 5.9 | OpenClaw < 2026.2.1 - Bearer Token Leakage via MS Teams Attachment Downloader Suffix Matching | CWE-201 | 2026-03-05 | |
| CVE-2026-32054 | 5.9 | OpenClaw < 2026.2.25 - Symlink Traversal in Browser Trace/Download Path Handling | CWE-59 | 2026-03-21 | |
| CVE-2026-45005 | 5.9 | OpenClaw < 2026.4.23 - Webhook Route Secret Cache Not Invalidated After Rotation | CWE-672 | 2026-05-11 | |
| CVE-2026-31999 | 5.8 | OpenClaw 2026.2.26 < 2026.3.1 - Current Working Directory Injection via Windows Wrapper Resolution Fallback | CWE-78 | 2026-03-19 | |
| CVE-2026-32000 | 5.8 | OpenClaw < 2026.2.19 - Command Injection via Windows Shell Fallback in Lobster Tool Execution | CWE-78 | 2026-03-19 | |
| CVE-2026-31995 | 5.8 | OpenClaw 2026.1.21 < 2026.2.19 - Command Injection via Windows Shell Fallback in Lobster Extension | CWE-78 | 2026-03-19 | |
| CVE-2026-32988 | 5.8 | OpenClaw < 2026.3.11 - Sandbox Boundary Bypass via Unvalidated Temporary File Creation | CWE-367 | 2026-03-31 | |
| CVE-2026-41332 | 5.8 | OpenClaw < 2026.3.28 - Code Execution via Missing Environment Variable Blocklist | CWE-184 | 2026-04-23 | |
| CVE-2026-41360 | 5.4 | OpenClaw < 2026.4.2 - Approval Integrity Bypass in pnpm dlx Local Script Binding | CWE-367 | 2026-04-23 | |
| CVE-2026-44995 | 5.4 | OpenClaw: MCP stdio server env could load dangerous startup variables from workspace config | CWE-829 | 2026-05-11 | |
| CVE-2026-26326 | 5.3 | OpenClaw skills.status could leak secrets to operator.read clients | CWE-200 | 2026-02-19 | |
| CVE-2026-32899 | 5.3 | OpenClaw < 2026.2.25 - Sender Policy Bypass in Slack Reaction and Pin Event Handlers | CWE-863 | 2026-03-21 | |
| CVE-2026-41909 | 5.3 | OpenClaw < 2026.4.20 - Improper Authorization in Paired-Device Pairing Actions | CWE-863 | 2026-04-23 | |
| CVE-2026-35634 | 5.1 | OpenClaw < 2026.3.23 - Authentication Bypass via Local-Direct Requests in Canvas Gateway | CWE-288 | 2026-04-09 | |
| CVE-2026-42436 | 4.9 | OpenClaw < 2026.4.14 - Internal Page Content Exposure via Browser Snapshot and Screenshot Routes | CWE-862 | 2026-05-05 | |
| CVE-2026-42439 | 4.9 | OpenClaw < 2026.4.10 - SSRF Policy Bypass in Browser Tabs Action Routes | CWE-862 | 2026-05-05 | |
| CVE-2026-43532 | 4.9 | OpenClaw 2026.4.7 < 2026.4.10 - Sandbox Media Normalization Bypass via Discord Event Cover Image | CWE-184 | 2026-05-05 | |
| CVE-2026-42438 | 4.9 | OpenClaw: Sender policy bypass in host media attachment reads allows unauthorized local file disclosure | CWE-863 | 2026-05-05 | |
| CVE-2026-43573 | 4.9 | OpenClaw: Existing-session browser interaction routes bypassed SSRF policy enforcement | CWE-862, CWE-918 | 2026-05-05 | |
| CVE-2026-43576 | 4.9 | OpenClaw < 2026.4.5 - Second-hop SSRF via CDP /json/version WebSocket URL | CWE-601, CWE-918 | 2026-05-06 | |
| CVE-2026-43580 | 4.9 | OpenClaw: Browser press/type interaction routes missed complete navigation guard coverage | CWE-862 | 2026-05-06 | |
| CVE-2026-43582 | 4.9 | OpenClaw < 2026.4.10 - DNS Rebinding SSRF via Hostname Validation Bypass | CWE-367 | 2026-05-06 | |
| CVE-2026-27007 | 4.8 | OpenClaw's sandbox config hash sorted primitive arrays and suppressed needed container recreation | CWE-1254 | 2026-02-19 | |
| CVE-2026-44992 | 4.1 | OpenClaw 2026.4.5 < 2026.4.20 - MiniMax API Host Override via Workspace dotenv | CWE-441 | 2026-05-11 | |
| CVE-2026-45003 | 4.1 | OpenClaw: Workspace dotenv files cannot override connector endpoint hosts | CWE-441 | 2026-05-11 | |
| CVE-2026-32006 | 2.3 | OpenClaw < 2026.2.26 - Authorization Bypass via DM Pairing-Store Fallback in Group Allowlist | CWE-863 | 2026-03-19 | |
| CVE-2026-34507 | 2.3 | OpenClaw < 2026.4.29 - Policy Bypass in QQBot Admin Commands via DM-only and allowFrom Checks | CWE-863 | 2026-05-29 | |
| CVE-2026-35617 | 2.3 | OpenClaw < 2026.3.25 - Authorization Bypass via Group Policy Rebinding with Mutable Space displayName | CWE-807 | 2026-04-09 | |
| CVE-2026-35648 | 2.3 | OpenClaw < 2026.3.22 - Policy Bypass via Unvalidated Queued Node Actions | CWE-367 | 2026-04-10 | |
| CVE-2026-41347 | 2.3 | OpenClaw < 2026.3.31 - Cross-Site Request Forgery via Missing Browser-Origin Validation in HTTP Operator Endpoints | CWE-352 | 2026-04-23 | |
| CVE-2026-41358 | 2.3 | OpenClaw < 2026.4.2 - Sender Allowlist Bypass via Slack Thread Context | CWE-346 | 2026-04-23 | |
| CVE-2026-41916 | 2.3 | OpenClaw < 2026.4.8 - Stale Authentication State via Config Reload | CWE-613 | 2026-04-28 | |
| CVE-2026-41908 | 2.3 | OpenClaw < 2026.4.20 - Scope Enforcement Bypass in Assistant-Media Route | CWE-863 | 2026-04-23 | |
| CVE-2026-44111 | 2.3 | OpenClaw < 2026.4.15 - Arbitrary Markdown File Read via QMD memory_get | CWE-183 | 2026-05-06 | |
| CVE-2026-44993 | 2.3 | OpenClaw < 2026.4.20 - Direct Message Misclassification in Feishu Card Actions | CWE-184 | 2026-05-11 | |
| CVE-2026-44997 | 2.3 | OpenClaw < 2026.4.22 - Security Envelope Constraint Bypass in ACP Child Sessions | CWE-266 | 2026-05-11 | |
| CVE-2026-44991 | 2.3 | OpenClaw: Owner-enforced commands could accept wildcard channel senders as command owners | CWE-863 | 2026-05-11 | |
| CVE-2026-53826 | 2.3 | OpenClaw < 2026.4.26 - Information Disclosure via Sandboxed Session Spawn | CWE-668 | 2026-06-12 | |
| CVE-2026-31991 | 2 | OpenClaw < 2026.2.26 - Authorization Bypass via DM Pairing-Store Leakage in Signal Group Allowlist | CWE-863 | 2026-03-19 | |
| CVE-2026-32058 | 2 | OpenClaw < 2026.2.26 - Approval Context-Binding Weakness in system.run via host=node | CWE-863 | 2026-03-21 |
๐ Detailed CVE Analysis (click to expand)
CVE-2026-28466 โ OpenClaw < 2026.2.14 - Remote Code Execution via Node Invoke Approval Bypass
| Field | Detail |
|---|---|
| CVSS | 9.4 (CRITICAL) โ CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H |
| CWE | CWE-863 (Incorrect Authorization) |
| Affected | < 2026.2.14 |
| Vendor/Product | OpenClaw / OpenClaw |
| Advisory | GHSA-gv46-4xfq-jv58 |
OpenClaw versions prior to 2026.2.14 contain a vulnerability in the gateway in which it fails to sanitize internal approval fields in node.invoke parameters, allowing authenticated clients to bypass exec approval gating for system.run commands. Attackers with valid gateway credentials can inject approval control fields to execute arbitrary commands on connected node hosts, potentially compromising developer workstations and CI runners.
References:
- Patch Commit #1
- Patch Commit #2
- Patch Commit #3
- Patch Commit #4
- VulnCheck Advisory: OpenClaw < 2026.2.14 - Remote Code Execution via Node Invoke Approval Bypass
CVE-2026-43534 โ OpenClaw < 2026.4.10 - Unsanitized External Input in Agent Hook Events
| Field | Detail |
|---|---|
| CVSS | 9.3 (CRITICAL) โ CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N |
| CWE | CWE-345 (CWE-345: Insufficient Verification of Data Authenticity) |
| Affected | < 2026.4.10 |
| Vendor/Product | OpenClaw / OpenClaw |
| Advisory | GHSA-7g8c-cfr3-vqqr |
OpenClaw before 2026.4.10 contains an input validation vulnerability that allows external hook metadata to be enqueued as trusted system events. Attackers can supply malicious hook names to escalate untrusted input into higher-trust agent context.
References:
- Patch Commit
- VulnCheck Advisory: OpenClaw < 2026.4.10 - Unsanitized External Input in Agent Hook Events
CVE-2026-32918 โ OpenClaw < 2026.3.11 - Session Sandbox Escape via session_status Tool
| Field | Detail |
|---|---|
| CVSS | 9.2 (CRITICAL) โ CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N |
| CWE | CWE-863 (Incorrect Authorization) |
| Affected | < 2026.3.11 |
| Vendor/Product | OpenClaw / OpenClaw |
| Advisory | GHSA-wcxr-59v9-rxr8 |
OpenClaw before 2026.3.11 contains a session sandbox escape vulnerability in the session_status tool that allows sandboxed subagents to access parent or sibling session state. Attackers can supply arbitrary sessionKey values to read or modify session data outside their sandbox scope, including persisted model overrides.
References:
CVE-2026-32917 โ OpenClaw < 2026.3.13 - Remote Command Injection via Unsanitized iMessage Attachment Paths in SCP
| Field | Detail |
|---|---|
| CVSS | 9.2 (CRITICAL) โ CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
| CWE | CWE-78 (Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')) |
| Affected | < 2026.3.13 |
| Vendor/Product | OpenClaw / OpenClaw |
| Advisory | GHSA-g2f6-pwvx-r275 |
OpenClaw before 2026.3.13 contains a remote command injection vulnerability in the iMessage attachment staging flow that allows attackers to execute arbitrary commands on configured remote hosts. The vulnerability exists because unsanitized remote attachment paths containing shell metacharacters are passed directly to the SCP remote operand without validation, enabling command execution when remote attachment staging is enabled.
References:
- Patch Commit
- VulnCheck Advisory: OpenClaw < 2026.3.13 - Remote Command Injection via Unsanitized iMessage Attachment Paths in SCP
CVE-2026-43585 โ OpenClaw: Gateway HTTP endpoints re-resolve bearer auth after SecretRef rotation
| Field | Detail |
|---|---|
| CVSS | 9.2 (CRITICAL) โ CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
| CWE | CWE-672 (Operation on a Resource after Expiration or Release) |
| Affected | < 2026.4.15 |
| Vendor/Product | OpenClaw / OpenClaw |
| Advisory | GHSA-xmxx-7p24-h892 |
OpenClaw before 2026.4.15 captures resolved bearer-auth configuration at startup, allowing revoked tokens to remain valid after SecretRef rotation. Gateway HTTP and WebSocket handlers fail to re-resolve authentication per-request, enabling attackers to use rotated-out bearer tokens for unauthorized gateway access.
References:
- Patch Commit
- VulnCheck Advisory: OpenClaw < 2026.4.15 - Bearer Token Validation Bypass via Stale SecretRef Resolution
CVE-2026-44109 โ OpenClaw: Feishu webhook and card-action validation now fail closed
| Field | Detail |
|---|---|
| CVSS | 9.2 (CRITICAL) โ CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
| CWE | CWE-1188 (CWE-1188 Initialization of a Resource with an Insecure Default) |
| Affected | < 2026.4.15 |
| Vendor/Product | OpenClaw / OpenClaw |
| Advisory | GHSA-xh72-v6v9-mwhc |
OpenClaw before 2026.4.15 contains an authentication bypass vulnerability in Feishu webhook and card-action validation that allows unauthenticated requests to reach command dispatch. Missing encryptKey configuration and blank callback tokens fail open instead of rejecting requests, enabling attackers to bypass signature verification and replay protection to execute arbitrary commands.
References:
- Patch Commit
- VulnCheck Advisory: OpenClaw < 2026.4.15 - Authentication Bypass in Feishu Webhook and Card-Action Validation
CVE-2026-41386 โ OpenClaw < 2026.3.22 - Privilege Escalation via Unbound Bootstrap Setup Codes
| Field | Detail |
|---|---|
| CVSS | 9.1 (CRITICAL) โ CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N |
| CWE | CWE-648 (CWE-648: Incorrect Use of Privileged APIs) |
| Affected | < 2026.3.22 |
| Vendor/Product | OpenClaw / OpenClaw |
| Advisory | GHSA-gg9v-mgcp-v6m7 |
OpenClaw before 2026.3.22 contains a privilege escalation vulnerability where bootstrap setup codes are not bound to intended device roles and scopes during pairing. Attackers can exploit this during first-use device pairing to escalate privileges beyond their intended role and scope.
References:
- Patch Commit
- VulnCheck Advisory: OpenClaw < 2026.3.22 - Privilege Escalation via Unbound Bootstrap Setup Codes
CVE-2026-43533 โ OpenClaw < 2026.4.10 - Arbitrary Local File Read via QQBot Media Tags
| Field | Detail |
|---|---|
| CVSS | 8.9 (HIGH) โ CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N |
| CWE | CWE-23 (CWE-23: Relative Path Traversal) |
| Affected | < 2026.4.10 |
| Vendor/Product | OpenClaw / OpenClaw |
| Advisory | GHSA-66r7-m7xm-v49h |
OpenClaw before 2026.4.10 contains an arbitrary file read vulnerability in QQBot media tags that allows attackers to reference host-local paths outside the intended media storage boundary. Attackers can craft malicious reply text containing media tags to disclose arbitrary local files through outbound media handling.
References:
- Patch Commit
- VulnCheck Advisory: OpenClaw < 2026.4.10 - Arbitrary Local File Read via QQBot Media Tags
CVE-2026-25253 โ OpenClaw/Clawdbot has 1-Click RCE via Authentication Token Exfiltration From gatewayUrl
| Field | Detail |
|---|---|
| CVSS | 8.8 (HIGH) โ CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
| CWE | CWE-669 (CWE-669 Incorrect Resource Transfer Between Spheres) |
| Affected | < 2026.1.29 |
| Vendor/Product | OpenClaw / OpenClaw |
| Advisory | GHSA-g8p2-7wf7-98mq |
OpenClaw (aka clawdbot or Moltbot) before 2026.1.29 obtains a gatewayUrl value from a query string and automatically makes a WebSocket connection without prompting, sending a token value.
Naming note: Uses all three names in description. packageURL still references
pkg:npm/clawdbot. References:
CVE-2026-24763 โ OpenClaw/Clawdbot Docker Execution has Authenticated Command Injection via PATH Environment Variable
| Field | Detail |
|---|---|
| CVSS | 8.8 (HIGH) โ CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| CWE | CWE-78 (CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')) |
| Affected | < 2026.1.29 |
| Vendor/Product | clawdbot / clawdbot |
| Advisory | GHSA-mc68-q9jw-2h3v |
OpenClaw (formerly Clawdbot) is a personal AI assistant you run on your own devices. Prior to 2026.1.29, a command injection vulnerability existed in OpenClawโs Docker sandbox execution mechanism due to unsafe handling of the PATH environment variable when constructing shell commands. An authenticated user able to control environment variables could influence command execution within the container context. This vulnerability is fixed in 2026.1.29.
Naming note: Uses old name
clawdbot/clawdbotas vendor/product. References:
- https://github.com/openclaw/openclaw/commit/771f23d36b95ec2204cc9a0054045f5d8439ea75
- https://github.com/openclaw/openclaw/releases/tag/v2026.1.29
CVE-2026-32913 โ OpenClaw < 2026.3.7 - Custom Authorization Header Leakage via Cross-Origin Redirects
| Field | Detail |
|---|---|
| CVSS | 8.8 (HIGH) โ CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:L/SI:L/SA:N |
| CWE | CWE-522 (CWE-522 Insufficiently Protected Credentials) |
| Affected | < 2026.3.7 |
| Vendor/Product | OpenClaw / OpenClaw |
| Advisory | GHSA-6mgf-v5j7-45cr |
OpenClaw before 2026.3.7 contains an improper header validation vulnerability in fetchWithSsrFGuard that forwards custom authorization headers across cross-origin redirects. Attackers can trigger redirects to different origins to intercept sensitive headers like X-Api-Key and Private-Token intended for the original destination.
References:
CVE-2026-41296 โ OpenClaw < 2026.3.31 - Sandbox Escape via TOCTOU Race in Remote FS Bridge readFile
| Field | Detail |
|---|---|
| CVSS | 8.8 (HIGH) โ CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N |
| CWE | CWE-367 (CWE-367: Time-of-check Time-of-use (TOCTOU) Race Condition) |
| Affected | < 2026.3.31 |
| Vendor/Product | OpenClaw / OpenClaw |
| Advisory | GHSA-9p3r-hh9g-5cmg |
OpenClaw before 2026.3.31 contains a time-of-check-time-of-use race condition in the remote filesystem bridge readFile function that allows sandbox escape. Attackers can exploit the separate path validation and file read operations to bypass sandbox restrictions and read arbitrary files.
References:
- Patch Commit
- VulnCheck Advisory: OpenClaw < 2026.3.31 - Sandbox Escape via TOCTOU Race in Remote FS Bridge readFile
CVE-2026-28478 โ OpenClaw affected by denial of service via unbounded webhook request body buffering
| Field | Detail |
|---|---|
| CVSS | 8.7 (HIGH) โ CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
| CWE | CWE-770 (Allocation of Resources Without Limits or Throttling) |
| Affected | < 2026.2.13 |
| Vendor/Product | OpenClaw / OpenClaw |
| Advisory | GHSA-q447-rj3r-2cgh |
OpenClaw versions prior to 2026.2.13 contain a denial of service vulnerability in webhook handlers that buffer request bodies without strict byte or time limits. Remote unauthenticated attackers can send oversized JSON payloads or slow uploads to webhook endpoints causing memory pressure and availability degradation.
References:
- Patch Commit
- VulnCheck Advisory: OpenClaw < 2026.2.13 - Denial of Service via Unbounded Webhook Request Body Buffering
CVE-2026-32042 โ OpenClaw < 2026.2.25 - Privilege Escalation via Unpaired Device Identity in Shared Gateway Authentication
| Field | Detail |
|---|---|
| CVSS | 8.7 (HIGH) โ CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
| CWE | CWE-863 (CWE-863: Incorrect Authorization) |
| Affected | < 2026.2.25 |
| Vendor/Product | OpenClaw / OpenClaw |
| Advisory | GHSA-553v-f69r-656j |
OpenClaw versions 2026.2.22 prior to 2026.2.25 contain a privilege escalation vulnerability allowing unpaired device identities to bypass operator pairing requirements and self-assign elevated operator scopes including operator.admin. Attackers with valid shared gateway authentication can present a self-signed unpaired device identity to request and obtain higher operator scopes before pairing approval is granted.
References:
- Patch Commit
- VulnCheck Advisory: OpenClaw < 2026.2.25 - Privilege Escalation via Unpaired Device Identity in Shared Gateway Authentication
CVE-2026-32051 โ OpenClaw < 2026.3.1 - Authorization Bypass in Agent Runs via Owner-Only Tool Access
| Field | Detail |
|---|---|
| CVSS | 8.7 (HIGH) โ CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
| CWE | CWE-863 (CWE-863: Incorrect Authorization) |
| Affected | < 2026.3.1 |
| Vendor/Product | OpenClaw / OpenClaw |
| Advisory | GHSA-jr6x-2q95-fh2g |
OpenClaw versions prior to 2026.3.1 contain an authorization mismatch vulnerability that allows authenticated callers with operator.write scope to invoke owner-only tool surfaces including gateway and cron through agent runs in scoped-token deployments. Attackers with write-scope access can perform control-plane actions beyond their intended authorization level by exploiting inconsistent owner-only gating during agent execution.
References:
CVE-2026-33573 โ OpenClaw < 2026.3.11 - Workspace Boundary Bypass via Agent RPC Parameters
| Field | Detail |
|---|---|
| CVSS | 8.7 (HIGH) โ CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
| CWE | CWE-668 (Exposure of Resource to Wrong Sphere) |
| Affected | < 2026.3.11 |
| Vendor/Product | OpenClaw / OpenClaw |
| Advisory | GHSA-2rqg-gjgv-84jm |
OpenClaw before 2026.3.11 contains an authorization bypass vulnerability in the gateway agent RPC that allows authenticated operators with operator.write permission to override workspace boundaries by supplying attacker-controlled spawnedBy and workspaceDir values. Remote operators can escape the configured workspace boundary and execute arbitrary file and exec operations from any process-accessible directory.
References:
CVE-2026-41405 โ OpenClaw < 2026.3.31 - Resource Exhaustion via Unauthenticated MS Teams Webhook Body Parsing
| Field | Detail |
|---|---|
| CVSS | 8.7 (HIGH) โ CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
| CWE | CWE-408 (CWE-408: Incorrect Behavior Order: Early Amplification) |
| Affected | < 2026.3.31 |
| Vendor/Product | OpenClaw / OpenClaw |
| Advisory | GHSA-p464-m8x6-vhv8 |
OpenClaw before 2026.3.31 parses MS Teams webhook request bodies before performing JWT validation, allowing unauthenticated attackers to trigger resource exhaustion. Remote attackers can send malicious Teams webhook payloads to exhaust server resources by bypassing authentication checks.
References:
- Patch Commit
- VulnCheck Advisory: OpenClaw < 2026.3.31 - Resource Exhaustion via Unauthenticated MS Teams Webhook Body Parsing
CVE-2026-42434 โ OpenClaw: Sandboxed agents could escape exec routing via host=node override
| Field | Detail |
|---|---|
| CVSS | 8.7 (HIGH) โ CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
| CWE | CWE-863 (CWE-863: Incorrect Authorization) |
| Affected | < 2026.4.10 |
| Vendor/Product | OpenClaw / OpenClaw |
| Advisory | GHSA-736r-jwj6-4w23 |
OpenClaw versions 2026.4.5 before 2026.4.10 contain a sandbox escape vulnerability allowing sandboxed agents to override exec routing by specifying host=node. Attackers can bypass sandbox boundaries and route execution to remote nodes instead of intended sandbox paths.
References:
- Patch Commit
- VulnCheck Advisory: OpenClaw 2026.4.5 < 2026.4.10 - Sandbox Escape via host Parameter Override in Exec Routing
CVE-2026-43530 โ OpenClaw: busybox and toybox applet execution weakened exec approval binding
| Field | Detail |
|---|---|
| CVSS | 8.7 (HIGH) โ CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
| CWE | CWE-863 (CWE-863: Incorrect Authorization) |
| Affected | < 2026.4.12 |
| Vendor/Product | OpenClaw / OpenClaw |
| Advisory | GHSA-2cq5-mf3v-mx44 |
OpenClaw versions 2026.2.23 before 2026.4.12 contain a weakened exec approval binding vulnerability in busybox and toybox applet execution that allows attackers to obscure which applet would actually run. Attackers can exploit opaque multi-call binaries to bypass exec approval mechanisms and weaken risk classification of unsafe applet invocations.
References:
- Patch Commit
- VulnCheck Advisory: OpenClaw 2026.2.23 < 2026.4.12 - Weakened Exec Approval Binding via busybox and toybox Applet Execution
CVE-2026-44115 โ OpenClaw < 2026.4.22 - Shell Expansion Bypass in Unquoted Heredocs via Exec Allowlist
| Field | Detail |
|---|---|
| CVSS | 8.7 (HIGH) โ CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
| CWE | CWE-184 (CWE-184: Incomplete List of Disallowed Inputs) |
| Affected | < 2026.4.22 |
| Vendor/Product | OpenClaw / OpenClaw |
| Advisory | GHSA-x3h8-jrgh-p8jx |
OpenClaw before 2026.4.22 contains an exec allowlist analysis vulnerability allowing shell expansion hiding in unquoted heredoc bodies. Attackers can bypass allowlist validation by embedding shell expansion tokens in heredoc bodies to execute unapproved commands at runtime.
References:
- Patch Commit
- VulnCheck Advisory: OpenClaw < 2026.4.22 - Shell Expansion Bypass in Unquoted Heredocs via Exec Allowlist
CVE-2026-53814 โ OpenClaw < 2026.5.20 - Privilege Escalation via Hook-Triggered CLI MCP Tool Authority
| Field | Detail |
|---|---|
| CVSS | 8.7 (HIGH) โ CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N |
| CWE | CWE-266 (Incorrect Privilege Assignment) |
| Affected | < 2026.5.20 |
| Vendor/Product | OpenClaw / OpenClaw |
| Advisory | GHSA-6fvr-66p3-3qj4 |
OpenClaw before 2026.5.20 contains a privilege escalation vulnerability where hook-triggered agent runs incorrectly receive owner-scoped MCP loopback authority instead of hook-appropriate scope. Attackers with a valid hook token can exploit the /hooks/agent endpoint to cause spawned CLI runtimes to access or invoke owner-only MCP tools, potentially executing privileged actions like persistent cron state modifications.
References:
CVE-2026-32920 โ OpenClaw < 2026.3.12 - Arbitrary Code Execution via Auto-Discovery of Workspace Plugins
| Field | Detail |
|---|---|
| CVSS | 8.6 (HIGH) โ CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
| CWE | CWE-829 (Inclusion of Functionality from Untrusted Control Sphere) |
| Affected | < 2026.3.12 |
| Vendor/Product | OpenClaw / OpenClaw |
| Advisory | GHSA-99qw-6mr3-36qr |
OpenClaw before 2026.3.12 automatically discovers and loads plugins from .OpenClaw/extensions/ without explicit trust verification, allowing arbitrary code execution. Attackers can execute malicious code by including crafted workspace plugins in cloned repositories that execute when users run OpenClaw from the directory.
References:
CVE-2026-33579 โ OpenClaw < 2026.3.28 - Privilege Escalation via Missing Caller Scope Validation in Device Pair Approval
| Field | Detail |
|---|---|
| CVSS | 8.6 (HIGH) โ CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N |
| CWE | CWE-863 (CWE-863 Incorrect Authorization) |
| Affected | < 2026.3.28 |
| Vendor/Product | OpenClaw / OpenClaw |
| Advisory | GHSA-hc5h-pmr3-3497 |
OpenClaw before 2026.3.28 contains a privilege escalation vulnerability in the /pair approve command path that fails to forward caller scopes into the core approval check. A caller with pairing privileges but without admin privileges can approve pending device requests asking for broader scopes including admin access by exploiting the missing scope validation in extensions/device-pair/index.ts and src/infra/device-pairing.ts.
References:
- Patch Commit
- VulnCheck Advisory: OpenClaw < 2026.3.28 - Privilege Escalation via Missing Caller Scope Validation in Device Pair Approval
CVE-2026-53823 โ OpenClaw < 2026.5.3 - Privilege Escalation via Mutable Slack Display Names in allowFrom
| Field | Detail |
|---|---|
| CVSS | 8.6 (HIGH) โ CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N |
| CWE | CWE-290 (Authentication Bypass by Spoofing) |
| Affected | < 2026.5.3 |
| Vendor/Product | OpenClaw / OpenClaw |
| Advisory | GHSA-c29c-2q9c-pc86 |
OpenClaw before 2026.5.3 contains a privilege escalation vulnerability in the allowFrom feature that binds to mutable Slack display names. Attackers with Slack account access can change display name metadata to match policy entries, potentially gaining unauthorized agent access intended for other identities.
References:
CVE-2026-44118 โ OpenClaw < 2026.4.22 - Owner Context Spoofing via Bearer Token Header
| Field | Detail |
|---|---|
| CVSS | 8.5 (HIGH) โ CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
| CWE | CWE-290 (CWE-290: Authentication Bypass by Spoofing) |
| Affected | < 2026.4.22 |
| Vendor/Product | OpenClaw / OpenClaw |
| Advisory | GHSA-r6xh-pqhr-v4xh |
OpenClaw before 2026.4.22 derives loopback MCP owner context from spoofable server-issued bearer tokens in request headers. Non-owner loopback clients can present themselves as owner to bypass owner-gated operations by manipulating the sender-owner header metadata.
References:
- Patch Commit
- VulnCheck Advisory: OpenClaw < 2026.4.22 - Owner Context Spoofing via Bearer Token Header
CVE-2026-44114 โ OpenClaw: Workspace dotenv could override runtime-control environment variables
| Field | Detail |
|---|---|
| CVSS | 8.5 (HIGH) โ CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
| CWE | CWE-184 (CWE-184: Incomplete List of Disallowed Inputs) |
| Affected | < 2026.4.20 |
| Vendor/Product | OpenClaw / OpenClaw |
| Advisory | GHSA-hxvm-xjvf-93f3 |
OpenClaw before 2026.4.20 fails to properly reserve the OPENCLAW_ runtime-control environment namespace in workspace dotenv files, allowing attackers to override critical runtime variables. Malicious workspaces can set variables like OPENCLAW_GIT_DIR to manipulate trusted OpenClaw runtime behavior during source-update or installer flows.
References:
- Patch Commit
- VulnCheck Advisory: OpenClaw < 2026.4.20 - Environment Variable Namespace Collision via Workspace dotenv
CVE-2026-45004 โ OpenClaw vulnerable to arbitrary code execution via attacker-controlled setup-api.js loaded from cwd during env-key resolution
| Field | Detail |
|---|---|
| CVSS | 8.4 (HIGH) โ CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
| CWE | CWE-427 (Uncontrolled Search Path Element) |
| Affected | < 2026.4.23 |
| Vendor/Product | OpenClaw / OpenClaw |
| Advisory | GHSA-r39h-4c2p-3jxp |
OpenClaw before 2026.4.23 contains an arbitrary code execution vulnerability in the bundled plugin setup resolver that loads setup-api.js from process.cwd() during provider setup metadata resolution. Attackers can execute arbitrary JavaScript under the current user account by placing a malicious extensions/
References:
- Patch Commit
- VulnCheck Advisory: OpenClaw < 2026.4.23 - Arbitrary Code Execution via setup-api.js in Current Working Directory
CVE-2026-31998 โ OpenClaw 2026.2.22 < 2026.2.24 - Authorization Bypass in Synology Chat Plugin via Empty allowedUserIds
| Field | Detail |
|---|---|
| CVSS | 8.3 (HIGH) โ CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N |
| CWE | CWE-863 (CWE-863: Incorrect Authorization) |
| Affected | < 2026.2.24 |
| Vendor/Product | OpenClaw / OpenClaw |
| Advisory | GHSA-gw85-xp4q-5gp9 |
OpenClaw versions 2026.2.22 and 2026.2.23 contain an authorization bypass vulnerability in the synology-chat channel plugin where dmPolicy set to allowlist with empty allowedUserIds fails open. Attackers with Synology sender access can bypass authorization checks and trigger unauthorized agent dispatch and downstream tool actions.
References:
- Patch Commit
- Patch Commit
- VulnCheck Advisory: OpenClaw 2026.2.22 < 2026.2.24 - Authorization Bypass in Synology Chat Plugin via Empty allowedUserIds
CVE-2026-35618 โ OpenClaw < 2026.3.23 - Replay Identity Drift via Query-Only Variants in Plivo V2 Verification
| Field | Detail |
|---|---|
| CVSS | 8.3 (HIGH) โ CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N |
| CWE | CWE-294 (CWE-294 Authentication Bypass by Capture-replay) |
| Affected | < 2026.3.23 |
| Vendor/Product | OpenClaw / OpenClaw |
| Advisory | GHSA-cg6c-q2hx-69h7 |
OpenClaw before 2026.3.23 contains a replay identity vulnerability in Plivo V2 signature verification that allows attackers to bypass replay protection by modifying query parameters. The verification path derives replay keys from the full URL including query strings instead of the canonicalized base URL, enabling attackers to mint new verified request keys through unsigned query-only changes to signed requests.
References:
- Patch Commit #1
- Patch Commit #2
- VulnCheck Advisory: OpenClaw < 2026.3.23 - Replay Identity Drift via Query-Only Variants in Plivo V2 Verification
CVE-2026-43526 โ OpenClaw: QQBot reply media URL handling could trigger SSRF and re-upload fetched bytes
| Field | Detail |
|---|---|
| CVSS | 8.3 (HIGH) โ CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N |
| CWE | CWE-918 (CWE-918 Server-Side Request Forgery (SSRF)) |
| Affected | < 2026.4.12 |
| Vendor/Product | OpenClaw / OpenClaw |
| Advisory | GHSA-2767-2q9v-9326 |
OpenClaw before 2026.4.12 contains a server-side request forgery vulnerability in QQBot reply media URL handling that allows attackers to fetch arbitrary content. Attackers can exploit this by providing malicious media URLs that trigger SSRF requests, with fetched bytes subsequently re-uploaded through the channel.
References:
- Patch Commit (1)
- Patch Commit (2)
- VulnCheck Advisory: OpenClaw < 2026.4.12 - Server-Side Request Forgery via QQBot Reply Media URL Handling
CVE-2026-28469 โ OpenClaw Google Chat shared-path webhook target ambiguity allowed cross-account policy-context misrouting
| Field | Detail |
|---|---|
| CVSS | 8.2 (HIGH) โ CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N |
| CWE | CWE-639 (Authorization Bypass Through User-Controlled Key) |
| Affected | < 2026.2.14 |
| Vendor/Product | OpenClaw / OpenClaw |
| Advisory | GHSA-rq6g-px6m-c248 |
OpenClaw versions prior to 2026.2.14 contain a webhook routing vulnerability in the Google Chat monitor component that allows cross-account policy context misrouting when multiple webhook targets share the same HTTP path. Attackers can exploit first-match request verification semantics to process inbound webhook events under incorrect account contexts, bypassing intended allowlists and session policies.
References:
- Patch Commit
- VulnCheck Advisory: OpenClaw < 2026.2.14 - Cross-Account Policy Context Misrouting via Shared Webhook Path Ambiguity
CVE-2026-29611 โ OpenClaw < 2026.2.14 - Local File Inclusion via mediaPath Parameter in BlueBubbles Media Handling
| Field | Detail |
|---|---|
| CVSS | 8.2 (HIGH) โ CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
| CWE | CWE-73 (External Control of File Name or Path) |
| Affected | < 2026.2.14 |
| Vendor/Product | OpenClaw / OpenClaw |
| Advisory | GHSA-rwj8-p9vq-25gv |
OpenClaw versions prior to 2026.2.14 contain a local file inclusion vulnerability in BlueBubbles extension (must be installed and enabled) media path handling that allows attackers to read arbitrary files from the local filesystem. The sendBlueBubblesMedia function fails to validate mediaPath parameters against an allowlist, enabling attackers to request sensitive files like /etc/passwd and exfiltrate them as media attachments.
References:
- Patch Commit
- VulnCheck Advisory: OpenClaw < 2026.2.14 - Local File Inclusion via mediaPath Parameter in BlueBubbles Media Handling
CVE-2026-25157 โ OpenClaw/Clawdbot has OS Command Injection via Project Root Path in sshNodeCommand
| Field | Detail |
|---|---|
| CVSS | 7.8 (HIGH) โ CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H |
| CWE | CWE-78 (CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')) |
| Affected | < 2026.1.29 |
| Vendor/Product | openclaw / openclaw |
| Advisory | GHSA-q284-4pvr-m585 |
OpenClaw is a personal AI assistant. Prior to version 2026.1.29, there is an OS command injection vulnerability via the Project Root Path in sshNodeCommand. The sshNodeCommand function constructed a shell script without properly escaping the user-supplied project path in an error message. When the cd command failed, the unescaped path was interpolated directly into an echo statement, allowing arbitrary command execution on the remote SSH host. The parseSSHTarget function did not validate that SSH target strings could not begin with a dash. An attacker-supplied target like -oProxyCommand=... would be interpreted as an SSH configuration flag rather than a hostname, allowing arbitrary command execution on the local machine. This issue has been patched in version 2026.1.29.
CVE-2026-27002 โ OpenClaw: Docker container escape via unvalidated bind mount config injection
| Field | Detail |
|---|---|
| CVSS | 7.7 (HIGH) โ CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
| CWE | CWE-250 (CWE-250: Execution with Unnecessary Privileges) |
| Affected | < 2026.2.15 |
| Vendor/Product | openclaw / openclaw |
| Advisory | GHSA-w235-x559-36mg |
OpenClaw is a personal AI assistant. Prior to version 2026.2.15, a configuration injection issue in the Docker tool sandbox could allow dangerous Docker options (bind mounts, host networking, unconfined profiles) to be applied, enabling container escape or host data access. OpenClaw 2026.2.15 blocks dangerous sandbox Docker settings and includes runtime enforcement when building docker create args; config-schema validation for network=host, seccompProfile=unconfined, apparmorProfile=unconfined; and security audit findings to surface dangerous sandbox docker config. As a workaround, do not configure agents.*.sandbox.docker.binds to mount system directories or Docker socket paths, keep agents.*.sandbox.docker.network at none (default) or bridge, and do not use unconfined for seccomp/AppArmor profiles.
References:
- https://github.com/openclaw/openclaw/commit/887b209db47f1f9322fead241a1c0b043fd38339
- https://github.com/openclaw/openclaw/releases/tag/v2026.2.15
CVE-2026-32048 โ OpenClaw < 2026.3.1 - Sandbox Escape via Cross-Agent sessions_spawn
| Field | Detail |
|---|---|
| CVSS | 7.7 (HIGH) โ CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
| CWE | CWE-732 (CWE-732: Incorrect Permission Assignment for Critical Resource) |
| Affected | < 2026.3.1 |
| Vendor/Product | OpenClaw / OpenClaw |
| Advisory | GHSA-p7gr-f84w-hqg5 |
OpenClaw versions prior to 2026.3.1 fail to enforce sandbox inheritance during cross-agent sessions_spawn operations, allowing sandboxed sessions to create child processes under unsandboxed agents. An attacker with a sandboxed session can exploit this to spawn child runtimes with sandbox.mode set to off, bypassing runtime confinement restrictions.
References:
CVE-2026-43569 โ OpenClaw: Workspace provider auth choices could auto-enable untrusted provider plugins
| Field | Detail |
|---|---|
| CVSS | 7.7 (HIGH) โ CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
| CWE | CWE-829 (CWE-829: Inclusion of Functionality from Untrusted Control Sphere) |
| Affected | < 2026.4.9 |
| Vendor/Product | OpenClaw / OpenClaw |
| Advisory | GHSA-939r-rj45-g2rj |
OpenClaw before 2026.4.9 contains an authentication bypass vulnerability allowing untrusted workspace plugins to be auto-enabled during non-interactive onboarding when provider auth choices are shadowed. Attackers can exploit this by crafting malicious workspace plugins that are automatically selected and enabled during authentication setup without explicit user consent.
References:
- Patch Commit
- VulnCheck Advisory: OpenClaw < 2026.4.9 - Untrusted Provider Plugin Auto-enablement via Workspace Provider Auth
CVE-2026-43571 โ OpenClaw: Channel setup catalog lookups could include untrusted workspace plugin shadows
| Field | Detail |
|---|---|
| CVSS | 7.7 (HIGH) โ CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
| CWE | CWE-829 (CWE-829: Inclusion of Functionality from Untrusted Control Sphere) |
| Affected | < 2026.4.10 |
| Vendor/Product | OpenClaw / OpenClaw |
| Advisory | GHSA-82qx-6vj7-p8m2 |
OpenClaw before 2026.4.10 contains a plugin trust bypass vulnerability that allows channel setup catalog lookups to resolve workspace plugin shadows before bundled channel plugins. Attackers can exploit this by crafting malicious workspace plugins that bypass intended trust gates during setup-time plugin loading.
References:
- Patch Commit
- VulnCheck Advisory: OpenClaw < 2026.4.10 - Untrusted Workspace Plugin Shadow Resolution in Channel Setup
CVE-2026-44110 โ OpenClaw: Matrix room control-command authorization no longer trusts DM pairing-store entries
| Field | Detail |
|---|---|
| CVSS | 7.7 (HIGH) โ CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
| CWE | CWE-863 (CWE-863: Incorrect Authorization) |
| Affected | < 2026.4.15 |
| Vendor/Product | OpenClaw / OpenClaw |
| Advisory | GHSA-2gvc-4f3c-2855 |
OpenClaw before 2026.4.15 contains an authorization bypass vulnerability in Matrix room control-command authorization that trusts DM pairing-store entries. Attackers with DM-paired sender IDs can execute room control commands without being in configured allowlists by posting in bot rooms, potentially enabling privileged OpenClaw behavior.
References:
- Patch Commit (1)
- Patch Commit (2)
- VulnCheck Advisory: OpenClaw < 2026.4.15 - Authorization Bypass in Matrix Room Control Commands via DM Pairing Store
CVE-2026-53807 โ OpenClaw < 2026.5.6 - Authorization Bypass in Telegram Interactive Callbacks via commands.allowFrom
| Field | Detail |
|---|---|
| CVSS | 7.7 (HIGH) โ CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
| CWE | CWE-863 (Incorrect Authorization) |
| Affected | < 2026.5.6 |
| Vendor/Product | OpenClaw / OpenClaw |
| Advisory | GHSA-w5ww-7chg-mxcq |
OpenClaw before 2026.5.6 contains an authorization bypass vulnerability in Telegram interactive callbacks that allows authenticated users to skip commands.allowFrom validation. Attackers can invoke affected callbacks to mark themselves as authorized senders before allowlist checks are applied, triggering command behavior outside configured Telegram sender restrictions.
References:
CVE-2026-41353 โ OpenClaw < 2026.3.22 - allowProfiles Bypass via Profile Mutation and Runtime Selection
| Field | Detail |
|---|---|
| CVSS | 7.6 (HIGH) โ CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N |
| CWE | CWE-472 (CWE-472 External Control of Assumed-Immutable Web Parameter) |
| Affected | < 2026.3.22 |
| Vendor/Product | OpenClaw / OpenClaw |
| Advisory | GHSA-h5hg-h7rr-gpf3 |
OpenClaw before 2026.3.22 contains an access control bypass vulnerability in the allowProfiles feature that allows attackers to circumvent profile restrictions through persistent profile mutation and runtime profile selection. Remote attackers can exploit this by manipulating browser proxy profiles at runtime to access restricted profiles and bypass intended access controls.
References:
- Patch Commit
- VulnCheck Advisory: OpenClaw < 2026.3.22 - allowProfiles Bypass via Profile Mutation and Runtime Selection
CVE-2026-43535 โ OpenClaw < 2026.4.14 - Authorization Context Reuse in Collect-Mode Queue Batches
| Field | Detail |
|---|---|
| CVSS | 7.6 (HIGH) โ CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N |
| CWE | CWE-266 (CWE-266: Incorrect Privilege Assignment) |
| Affected | < 2026.4.14 |
| Vendor/Product | OpenClaw / OpenClaw |
| Advisory | GHSA-jwrq-8g5x-5fhm |
OpenClaw before 2026.4.14 contains an authorization context reuse vulnerability in collect-mode queue batches that allows messages from different senders to inherit the final sender's authorization context. Attackers can exploit this by sending multiple queued messages to drain batches using a more privileged sender's context, causing earlier messages to execute with elevated permissions.
References:
- Patch Commit
- VulnCheck Advisory: OpenClaw < 2026.4.14 - Authorization Context Reuse in Collect-Mode Queue Batches
CVE-2026-26316 โ OpenClaw has BlueBubbles webhook auth bypass via loopback proxy trust
| Field | Detail |
|---|---|
| CVSS | 7.5 (HIGH) โ CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
| CWE | CWE-863 (CWE-863: Incorrect Authorization) |
| Affected | < 2026.2.13 |
| Vendor/Product | openclaw / @openclaw/bluebubbles |
| Advisory | GHSA-pchc-86f6-8758 |
OpenClaw is a personal AI assistant. Prior to 2026.2.13, the optional BlueBubbles iMessage channel plugin could accept webhook requests as authenticated based only on the TCP peer address being loopback (127.0.0.1, ::1, ::ffff:127.0.0.1) even when the configured webhook secret was missing or incorrect. This does not affect the default iMessage integration unless BlueBubbles is installed and enabled. Version 2026.2.13 contains a patch. Other mitigations include setting a non-empty BlueBubbles webhook password and avoiding deployments where a public-facing reverse proxy forwards to a loopback-bound Gateway without strong upstream authentication.
References:
- https://github.com/openclaw/openclaw/commit/743f4b28495cdeb0d5bf76f6ebf4af01f6a02e5a
- https://github.com/openclaw/openclaw/commit/f836c385ffc746cb954e8ee409f99d079bfdcd2f
- https://github.com/openclaw/openclaw/releases/tag/v2026.2.13
CVE-2026-26324 โ OpenClaw has a SSRF guard bypass via full-form IPv4-mapped IPv6 (loopback / metadata reachable)
| Field | Detail |
|---|---|
| CVSS | 7.5 (HIGH) โ CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
| CWE | CWE-918 (CWE-918: Server-Side Request Forgery (SSRF)) |
| Affected | < 2026.2.14 |
| Vendor/Product | openclaw / openclaw |
| Advisory | GHSA-jrvc-8ff5-2f9f |
OpenClaw is a personal AI assistant. Prior to version 2026.2.14, OpenClaw's SSRF protection could be bypassed using full-form IPv4-mapped IPv6 literals such as 0:0:0:0:0:ffff:7f00:1 (which is 127.0.0.1). This could allow requests that should be blocked (loopback / private network / link-local metadata) to pass the SSRF guard. Version 2026.2.14 patches the issue.
References:
- https://github.com/openclaw/openclaw/commit/c0c0e0f9aecb913e738742f73e091f2f72d39a19
- https://github.com/openclaw/openclaw/releases/tag/v2026.2.14
CVE-2026-22179 โ OpenClaw < 2026.2.22 - Allowlist Bypass via Command Substitution in system.run
| Field | Detail |
|---|---|
| CVSS | 7.5 (HIGH) โ CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
| CWE | CWE-78 (Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78)) |
| Affected | < 2026.2.22 |
| Vendor/Product | OpenClaw / OpenClaw |
| Advisory | GHSA-9p38-94jf-hgjj |
OpenClaw versions prior to 2026.2.22 in macOS node-host system.run contain an allowlist bypass vulnerability that allows remote attackers to execute non-allowlisted commands by exploiting improper parsing of command substitution tokens. Attackers can craft shell payloads with command substitution syntax within double-quoted text to bypass security restrictions and execute arbitrary commands on the system.
References:
- Patch Commit
- VulnCheck Advisory: OpenClaw < 2026.2.22 - Allowlist Bypass via Command Substitution in system.run
CVE-2026-32025 โ OpenClaw < 2026.2.25 - Password Brute-Force via Browser-Origin WebSocket Authentication Bypass
| Field | Detail |
|---|---|
| CVSS | 7.5 (HIGH) โ CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
| CWE | CWE-307 (CWE-307 Improper Restriction of Excessive Authentication Attempts) |
| Affected | < 2026.2.25 |
| Vendor/Product | OpenClaw / OpenClaw |
| Advisory | GHSA-jmmg-jqc7-5qf4 |
OpenClaw versions prior to 2026.2.25 contain an authentication hardening gap in browser-origin WebSocket clients that allows attackers to bypass origin checks and auth throttling on loopback deployments. An attacker can trick a user into opening a malicious webpage and perform password brute-force attacks against the gateway to establish an authenticated operator session and invoke control-plane methods.
References:
- Patch Commit
- VulnCheck Advisory: OpenClaw < 2026.2.25 - Password Brute-Force via Browser-Origin WebSocket Authentication Bypass
CVE-2026-28458 โ OpenClaw's Browser Relay /cdp websocket is missing auth which could allow cross-tab cookie access
| Field | Detail |
|---|---|
| CVSS | 7.4 (HIGH) โ CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N |
| CWE | CWE-306 (Missing Authentication for Critical Function) |
| Affected | < 2026.2.1 |
| Vendor/Product | OpenClaw / OpenClaw |
| Advisory | GHSA-mr32-vwc2-5j6h |
OpenClaw version 2026.1.20 prior to 2026.2.1 contains a vulnerability in the Browser Relay (extension must be installed and enabled) /cdp WebSocket endpoint in which it does not require authentication tokens, allowing websites to connect via loopback and access sensitive data. Attackers can exploit this by connecting to ws://127.0.0.1:18792/cdp to steal session cookies and execute JavaScript in other browser tabs.
References:
- Patch Commit
- VulnCheck Advisory: OpenClaw 2026.1.20 < 2026.2.1 - Missing Authentication in Browser Relay /cdp WebSocket Endpoint
CVE-2026-34512 โ OpenClaw < 2026.3.25 - Improper Access Control in /sessions/:sessionKey/kill Endpoint
| Field | Detail |
|---|---|
| CVSS | 7.2 (HIGH) โ CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N |
| CWE | CWE-863 (CWE-863: Incorrect Authorization) |
| Affected | < 2026.3.25 |
| Vendor/Product | OpenClaw / OpenClaw |
| Advisory | GHSA-9p93-7j67-5pc2 |
OpenClaw before 2026.3.25 contains an improper access control vulnerability in the HTTP /sessions/:sessionKey/kill route that allows any bearer-authenticated user to invoke admin-level session termination functions without proper scope validation. Attackers can exploit this by sending authenticated requests to kill arbitrary subagent sessions via the killSubagentRunAdmin function, bypassing ownership and operator scope restrictions.
References:
- Patch Commit
- VulnCheck Advisory: OpenClaw < 2026.3.25 - Improper Access Control in /sessions/:sessionKey/kill Endpoint
CVE-2026-26317 โ OpenClaw affected by cross-site request forgery (CSRF) through loopback browser mutation endpoints
| Field | Detail |
|---|---|
| CVSS | 7.1 (HIGH) โ CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L |
| CWE | CWE-352 (CWE-352: Cross-Site Request Forgery (CSRF)) |
| Affected | <= 2026.1.24-3 |
| Vendor/Product | openclaw / clawdbot |
| Advisory | GHSA-3fqr-4cg8-h96q |
OpenClaw is a personal AI assistant. Prior to 2026.2.14, browser-facing localhost mutation routes accepted cross-origin browser requests without explicit Origin/Referer validation. Loopback binding reduces remote exposure but does not prevent browser-initiated requests from malicious origins. A malicious website can trigger unauthorized state changes against a victim's local OpenClaw browser control plane (for example opening tabs, starting/stopping the browser, mutating storage/cookies) if the browser control service is reachable on loopback in the victim's browser context. Starting in version 2026.2.14, mutating HTTP methods (POST/PUT/PATCH/DELETE) are rejected when the request indicates a non-loopback Origin/Referer (or Sec-Fetch-Site: cross-site). Other mitigations include enabling browser control auth (token/password) and avoid running with auth disabled.
Naming note: Uses old name
openclaw/clawdbotas vendor/product. References:
- https://github.com/openclaw/openclaw/commit/b566b09f81e2b704bf9398d8d97d5f7a90aa94c3
- https://github.com/openclaw/openclaw/releases/tag/v2026.2.14
CVE-2026-26327 โ OpenClaw allows unauthenticated discovery TXT records to steer routing and TLS pinning
| Field | Detail |
|---|---|
| CVSS | 7.1 (HIGH) โ CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
| CWE | CWE-345 (CWE-345: Insufficient Verification of Data Authenticity) |
| Affected | < 2026.2.14 |
| Vendor/Product | openclaw / openclaw |
| Advisory | GHSA-pv58-549p-qh99 |
OpenClaw is a personal AI assistant. Discovery beacons (Bonjour/mDNS and DNS-SD) include TXT records such as lanHost, tailnetDns, gatewayPort, and gatewayTlsSha256. TXT records are unauthenticated. Prior to version 2026.2.14, some clients treated TXT values as authoritative routing/pinning inputs. iOS and macOS used TXT-provided host hints (lanHost/tailnetDns) and ports (gatewayPort) to build the connection URL. iOS and Android allowed the discovery-provided TLS fingerprint (gatewayTlsSha256) to override a previously stored TLS pin. On a shared/untrusted LAN, an attacker could advertise a rogue _openclaw-gw._tcp service. This could cause a client to connect to an attacker-controlled endpoint and/or accept an attacker certificate, potentially exfiltrating Gateway credentials (auth.token / auth.password) during connection. As of time of publication, the iOS and Android apps are alpha/not broadly shipped (no public App Store / Play Store release). Practical impact is primarily limited to developers/testers running those builds, plus any other shipped clients relying on discovery on a shared/untrusted LAN. Version 2026.2.14 fixes the issue. Clients now prefer the resolved service endpoint (SRV + A/AAAA) over TXT-provided routing hints. Discovery-provided fingerprints no longer override stored TLS pins. In iOS/Android, first-time TLS pins require explicit user confirmation (fingerprint shown; no silent TOFU) and discovery-based direct connects are TLS-only. In Android, hostname verification is no longer globally disabled (only bypassed when pinning).
References:
- https://github.com/openclaw/openclaw/commit/d583782ee322a6faa1fe87ae52455e0d349de586
- https://github.com/openclaw/openclaw/releases/tag/v2026.2.14
CVE-2026-32008 โ OpenClaw < 2026.2.21 - Arbitrary Local File Read via Browser Navigation Guard
| Field | Detail |
|---|---|
| CVSS | 7.1 (HIGH) โ CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
| CWE | CWE-610 (CWE-610: Externally Controlled Reference to a Resource in Another Sphere) |
| Affected | < 2026.2.21 |
| Vendor/Product | OpenClaw / OpenClaw |
| Advisory | GHSA-45cg-2683-gfmq |
OpenClaw versions prior to 2026.2.21 contain an improper URL scheme validation vulnerability in the assertBrowserNavigationAllowed() function that allows authenticated users with browser-tool access to navigate to file:// URLs. Attackers can exploit this by accessing local files readable by the OpenClaw process user through browser snapshot and extraction actions to exfiltrate sensitive data.
References:
- Patch Commit
- VulnCheck Advisory: OpenClaw < 2026.2.21 - Arbitrary Local File Read via Browser Navigation Guard
CVE-2026-32976 โ OpenClaw < 2026.3.11 - Account-Scoped configWrites Policy Bypass via Channel Commands
| Field | Detail |
|---|---|
| CVSS | 7.1 (HIGH) โ CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N |
| CWE | CWE-639 (Authorization Bypass Through User-Controlled Key) |
| Affected | < 2026.3.11 |
| Vendor/Product | OpenClaw / OpenClaw |
| Advisory | GHSA-8jhh-jcqg-mj5p |
OpenClaw before 2026.3.11 contains an authorization bypass vulnerability allowing channel commands to mutate protected sibling-account configuration despite configWrites restrictions. Attackers with authorized access on one account can execute channel commands like /config set channels.
References:
CVE-2026-35644 โ OpenClaw < 2026.3.22 - Credential Exposure via baseUrl Fields in Gateway Snapshots
| Field | Detail |
|---|---|
| CVSS | 7.1 (HIGH) โ CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
| CWE | CWE-312 (CWE-312: Cleartext Storage of Sensitive Information) |
| Affected | < 2026.3.22 |
| Vendor/Product | OpenClaw / OpenClaw |
| Advisory | GHSA-ppwq-6v66-5m6j |
OpenClaw before 2026.3.22 contains an information disclosure vulnerability that allows attackers with operator.read scope to expose credentials embedded in channel baseUrl and httpUrl fields. Attackers can access gateway snapshots via config.get and channels.status endpoints to retrieve sensitive authentication information from URL userinfo components.
References:
- Patch Commit #1
- Patch Commit #2
- VulnCheck Advisory: OpenClaw < 2026.3.22 - Credential Exposure via baseUrl Fields in Gateway Snapshots
CVE-2026-35636 โ OpenClaw 2026.3.11 < 2026.3.25 - Session Isolation Bypass via sessionId Resolution
| Field | Detail |
|---|---|
| CVSS | 7.1 (HIGH) โ CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
| CWE | CWE-696 (CWE-696: Incorrect Behavior Order) |
| Affected | < * |
| Vendor/Product | OpenClaw / OpenClaw |
| Advisory | GHSA-q2qc-744p-66r2 |
OpenClaw versions 2026.3.11 through 2026.3.24 contain a session isolation bypass vulnerability where session_status resolves sessionId to canonical session keys before enforcing visibility checks. Sandboxed child sessions can exploit this to access parent or sibling sessions that should be blocked by explicit sessionKey restrictions.
References:
- Patch Commit
- VulnCheck Advisory: OpenClaw 2026.3.11 < 2026.3.25 - Session Isolation Bypass via sessionId Resolution
CVE-2026-41368 โ OpenClaw < 2026.3.28 - Environment Variable Disclosure via jq $ENV Filter Bypass
| Field | Detail |
|---|---|
| CVSS | 7.1 (HIGH) โ CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
| CWE | CWE-668 (CWE-668: Exposure of Resource to Wrong Sphere) |
| Affected | < 2026.3.28 |
| Vendor/Product | OpenClaw / OpenClaw |
| Advisory | GHSA-jccr-rrw2-vc8h |
OpenClaw before 2026.3.28 contains an environment variable disclosure vulnerability in the jq safe-bin policy that fails to block the ENV in jq programs to access sensitive environment variables that should be restricted.
References:
- VulnCheck Advisory: OpenClaw < 2026.3.28 - Environment Variable Disclosure via jq $ENV Filter Bypass
CVE-2026-41385 โ OpenClaw < 2026.3.31 - Nostr Private Key Exposure via config.get Redaction Bypass
| Field | Detail |
|---|---|
| CVSS | 7.1 (HIGH) โ CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
| CWE | CWE-312 (CWE-312: Cleartext Storage of Sensitive Information) |
| Affected | < 2026.3.31 |
| Vendor/Product | OpenClaw / OpenClaw |
| Advisory | GHSA-jjw7-3vjf-fg5j |
OpenClaw before 2026.3.31 stores Nostr privateKey as plaintext in configuration, allowing exposure through config.get method calls that bypass redaction mechanisms. Attackers can retrieve unredacted configuration data to obtain plaintext signing keys used for Nostr protocol operations.
References:
- Patch Commit
- VulnCheck Advisory: OpenClaw < 2026.3.31 - Nostr Private Key Exposure via config.get Redaction Bypass
CVE-2026-42433 โ OpenClaw: Matrix profile config persistence was reachable from operator.write message tools
| Field | Detail |
|---|---|
| CVSS | 7.1 (HIGH) โ CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N |
| CWE | CWE-862 (CWE-862 Missing Authorization) |
| Affected | < 2026.4.10 |
| Vendor/Product | OpenClaw / OpenClaw |
| Advisory | GHSA-7jp6-r74r-995q |
OpenClaw before 2026.4.10 contains an authorization bypass vulnerability allowing operator.write message-tool paths to access Matrix profile persistence requiring admin-level authority. Attackers can exploit insufficient access controls to mutate persistent profile configuration through non-owner message-tool runs.
References:
- Patch Commit
- VulnCheck Advisory: OpenClaw < 2026.4.10 - Unauthorized Matrix Profile Config Persistence Access via operator.write Message Tools
CVE-2026-43567 โ OpenClaw < 2026.4.10 - Path Traversal in screen_record outPath Parameter
| Field | Detail |
|---|---|
| CVSS | 7.1 (HIGH) โ CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N |
| CWE | CWE-862 (CWE-862 Missing Authorization) |
| Affected | < 2026.4.10 |
| Vendor/Product | OpenClaw / OpenClaw |
| Advisory | GHSA-jf25-7968-h2h5 |
OpenClaw before 2026.4.10 contains a path traversal vulnerability in the screen_record tool's outPath parameter that bypasses workspace-only filesystem guards. Attackers can exploit this by specifying an outPath outside the workspace boundary to write files to unintended locations on the system.
References:
- Patch Commit
- VulnCheck Advisory: OpenClaw < 2026.4.10 - Path Traversal in screen_record outPath Parameter
CVE-2026-43568 โ OpenClaw 2026.4.5 < 2026.4.10 - Privilege Escalation via Memory Dreaming Configuration in /dreaming Endpoint
| Field | Detail |
|---|---|
| CVSS | 7.1 (HIGH) โ CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N |
| CWE | CWE-862 (CWE-862 Missing Authorization) |
| Affected | < 2026.4.10 |
| Vendor/Product | OpenClaw / OpenClaw |
| Advisory | GHSA-5gjc-grvm-m88j |
OpenClaw versions 2026.4.5 before 2026.4.10 contain a privilege escalation vulnerability allowing write-scoped operators to modify persistent memory dreaming settings. Attackers with write-scoped gateway access can toggle admin-class configuration mutations through the /dreaming endpoint to escalate privileges.
References:
- Patch Commit
- VulnCheck Advisory: OpenClaw 2026.4.5 < 2026.4.10 - Privilege Escalation via Memory Dreaming Configuration in /dreaming Endpoint
CVE-2026-41380 โ OpenClaw < 2026.3.28 - Arbitrary Execution Allowlist via Wrapper Carrier Executables
| Field | Detail |
|---|---|
| CVSS | 7 (HIGH) โ CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
| CWE | CWE-807 (CWE-807 Reliance on Untrusted Inputs in a Security Decision) |
| Affected | < 2026.3.28 |
| Vendor/Product | OpenClaw / OpenClaw |
| Advisory | GHSA-p4x4-2r7f-wjxg |
OpenClaw before 2026.3.28 contains an execution approval vulnerability in exec-approvals-allowlist.ts that allows allow-always persistence to trust wrapper carrier executables instead of invoked targets. Attackers can exploit positional carrier executable routing through dispatch wrappers to establish broader allowlist entries than intended, weakening execution approval boundaries.
References:
CVE-2026-43531 โ OpenClaw < 2026.4.9 - Environment Variable Injection via Workspace .env File
| Field | Detail |
|---|---|
| CVSS | 7 (HIGH) โ CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
| CWE | CWE-15 (CWE-15: External Control of System or Configuration Setting) |
| Affected | < 2026.4.9 |
| Vendor/Product | OpenClaw / OpenClaw |
| Advisory | GHSA-7wv4-cc7p-jhxc |
OpenClaw before 2026.4.9 contains an environment variable injection vulnerability allowing malicious workspace .env files to set runtime-control variables. Attackers can inject variables affecting update sources, gateway URLs, ClawHub resolution, and browser executable paths to compromise application behavior.
References:
- Patch Commit
- VulnCheck Advisory: OpenClaw < 2026.4.9 - Environment Variable Injection via Workspace .env File
CVE-2026-22178 โ OpenClaw < 2026.2.19 - ReDoS and Regex Injection via Unescaped Feishu Mention Metadata
| Field | Detail |
|---|---|
| CVSS | 6.9 (MEDIUM) โ CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N |
| CWE | CWE-1333 (CWE-1333) |
| Affected | < 2026.2.19 |
| Vendor/Product | OpenClaw / OpenClaw |
| Advisory | GHSA-c6hr-w26q-c636 |
OpenClaw versions prior to 2026.2.19 construct RegExp objects directly from unescaped Feishu mention metadata in the stripBotMention function, allowing regex injection and denial of service. Attackers can craft nested-quantifier patterns or metacharacters in mention metadata to trigger catastrophic backtracking, block message processing, or remove unintended content before model processing.
References:
- Patch Commit #1
- Patch Commit #2
- VulnCheck Advisory: OpenClaw < 2026.2.19 - ReDoS and Regex Injection via Unescaped Feishu Mention Metadata
CVE-2026-28480 โ OpenClaw Telegram allowlist authorization accepted mutable usernames
| Field | Detail |
|---|---|
| CVSS | 6.9 (MEDIUM) โ CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N |
| CWE | CWE-290 (Authentication Bypass by Spoofing) |
| Affected | < 2026.2.14 |
| Vendor/Product | OpenClaw / OpenClaw |
| Advisory | GHSA-mj5r-hh7j-4gxf |
OpenClaw versions prior to 2026.2.14 contain an authorization bypass vulnerability where Telegram allowlist matching accepts mutable usernames instead of immutable numeric sender IDs. Attackers can spoof identity by obtaining recycled usernames to bypass allowlist restrictions and interact with bots as unauthorized senders.
References:
- Patch Commit #1
- Patch Commit #2
- VulnCheck Advisory: OpenClaw < 2026.2.14 - Identity Spoofing via Mutable Username in Telegram Allowlist Authorization
CVE-2026-32975 โ OpenClaw < 2026.3.12 - Weak Authorization via Mutable Group Names in Zalouser Allowlist
| Field | Detail |
|---|---|
| CVSS | 6.9 (MEDIUM) โ CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N |
| CWE | CWE-807 (Reliance on Untrusted Inputs in a Security Decision) |
| Affected | < 2026.3.12 |
| Vendor/Product | OpenClaw / OpenClaw |
| Advisory | GHSA-f5mf-3r52-r83w |
OpenClaw before 2026.3.12 contains a weak authorization vulnerability in Zalouser allowlist mode that matches mutable group display names instead of stable group identifiers. Attackers can create groups with identical names to allowlisted groups to bypass channel authorization and route messages from unintended groups to the agent.
References:
CVE-2026-35626 โ OpenClaw < 2026.3.22 - Unauthenticated Resource Exhaustion via Voice Call Webhook
| Field | Detail |
|---|---|
| CVSS | 6.9 (MEDIUM) โ CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N |
| CWE | CWE-405 (CWE-405 Asymmetric Resource Consumption (Amplification)) |
| Affected | < 2026.3.22 |
| Vendor/Product | OpenClaw / OpenClaw |
| Advisory | GHSA-rm59-992w-x2mv |
OpenClaw before 2026.3.22 contains an unauthenticated resource exhaustion vulnerability in voice call webhook handling that buffers request bodies before provider signature checks. Attackers can send large or malicious webhook requests to exhaust server resources without authentication by bypassing signature validation.
References:
- Patch Commit #1
- Patch Commit #2
- VulnCheck Advisory: OpenClaw < 2026.3.22 - Unauthenticated Resource Exhaustion via Voice Call Webhook
CVE-2026-34426 โ OpenClaw - Approval Bypass via Environment Variable Normalization
| Field | Detail |
|---|---|
| CVSS | 6.9 (MEDIUM) โ CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N |
| CWE | CWE-184 (CWE-184 Incomplete List of Disallowed Inputs) |
| Affected | < b57b680c0c34de907d57f60c38fb358e82aef8f7 |
| Vendor/Product | OpenClaw / OpenClaw |
| Advisory | GHSA-98ch-45wp-ch47 |
OpenClaw versions prior to commit b57b680ย contain an approval bypass vulnerability due to inconsistent environment variable normalization between approval and execution paths, allowing attackers to inject attacker-controlled environment variables into execution without approval system validation. Attackers can exploit differing normalization logic to discard non-portable keys during approval processing while accepting them at execution time, bypassing operator review and potentially influencing runtime behavior including execution of attacker-controlled binaries.
References:
- Patch Commit #1
- b57b680c0c34de907d57f60c38fb358e82aef8f7
- openclaw-approval-bypass-via-environment-variable-normalization
CVE-2026-35647 โ OpenClaw < 2026.3.25 - Direct Message Policy Bypass via Verification Notices
| Field | Detail |
|---|---|
| CVSS | 6.9 (MEDIUM) โ CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N |
| CWE | CWE-288 (CWE-288: Authentication Bypass Using an Alternate Path or Channel) |
| Affected | < 2026.3.25 |
| Vendor/Product | OpenClaw / OpenClaw |
| Advisory | GHSA-9wqx-g2cw-vc7r |
OpenClaw before 2026.3.25 contains an access control vulnerability where verification notices bypass DM policy checks and reply to unpaired peers. Attackers can send verification notices to users outside allowed direct message policies by exploiting insufficient access validation before message transmission.
References:
- Patch Commit
- VulnCheck Advisory: OpenClaw < 2026.3.25 - Direct Message Policy Bypass via Verification Notices
CVE-2026-41300 โ OpenClaw < 2026.3.31 - Attacker-Discovered Endpoint Preservation in Remote Onboarding
| Field | Detail |
|---|---|
| CVSS | 6.9 (MEDIUM) โ CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
| CWE | CWE-372 (CWE-372: Incomplete Internal State Distinction) |
| Affected | < 2026.3.31 |
| Vendor/Product | OpenClaw / OpenClaw |
| Advisory | GHSA-9f4w-67g7-mqwv |
OpenClaw before 2026.3.31 contains a trust-decline vulnerability that preserves attacker-discovered endpoints in remote onboarding flows. Attackers can route gateway credentials to malicious endpoints by having their discovered URL survive the trust decline process into manual prompts requiring operator acceptance.
References:
- Patch Commit
- VulnCheck Advisory: OpenClaw < 2026.3.31 - Attacker-Discovered Endpoint Preservation in Remote Onboarding
CVE-2026-41331 โ OpenClaw < 2026.3.31 - Resource Consumption via Unauthorized Telegram Audio Preflight Transcription
| Field | Detail |
|---|---|
| CVSS | 6.9 (MEDIUM) โ CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N |
| CWE | CWE-408 (CWE-408: Incorrect Behavior Order: Early Amplification) |
| Affected | < 2026.3.31 |
| Vendor/Product | OpenClaw / OpenClaw |
| Advisory | GHSA-m6fx-m8hc-572m |
OpenClaw before 2026.3.31 contains a resource consumption vulnerability in Telegram audio preflight transcription that allows unauthorized group senders to trigger transcription processing. Attackers can exploit insufficient allowlist enforcement to cause resource or billing consumption by initiating audio preflight operations before authorization checks are applied.
References:
- Patch Commit
- VulnCheck Advisory: OpenClaw < 2026.3.31 - Resource Consumption via Unauthorized Telegram Audio Preflight Transcription
CVE-2026-35664 โ OpenClaw < 2026.3.25 - DM Pairing Bypass via Legacy Card Callbacks
| Field | Detail |
|---|---|
| CVSS | 6.9 (MEDIUM) โ CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N |
| CWE | CWE-288 (CWE-288: Authentication Bypass Using an Alternate Path or Channel) |
| Affected | < 2026.3.25 |
| Vendor/Product | OpenClaw / OpenClaw |
| Advisory | GHSA-77w2-crqv-cmv3 |
OpenClaw before 2026.3.25 contains an authentication bypass vulnerability in raw card send surface that allows unpaired recipients to mint legacy callback payloads. Attackers can send raw card commands to bypass DM pairing restrictions and reach callback handling without proper authorization.
References:
CVE-2026-41374 โ OpenClaw < 2026.3.31 - Resource Consumption via Discord Audio Preflight Before Member Authorization
| Field | Detail |
|---|---|
| CVSS | 6.9 (MEDIUM) โ CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N |
| CWE | CWE-408 (CWE-408: Incorrect Behavior Order: Early Amplification) |
| Affected | < 2026.3.31 |
| Vendor/Product | OpenClaw / OpenClaw |
| Advisory | GHSA-hhff-fj5f-qg48 |
OpenClaw before 2026.3.31 performs Discord audio preflight transcription before validating member authorization, allowing unauthenticated attackers to consume resources. Remote attackers can trigger audio preflight processing without member allowlist validation to cause resource exhaustion.
References:
- Patch Commit
- VulnCheck Advisory: OpenClaw < 2026.3.31 - Resource Consumption via Discord Audio Preflight Before Member Authorization
CVE-2026-41400 โ OpenClaw < 2026.3.31 - Resource Consumption via Oversized WebSocket Frames in voice-call
| Field | Detail |
|---|---|
| CVSS | 6.9 (MEDIUM) โ CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N |
| CWE | CWE-770 (CWE-770: Allocation of Resources Without Limits or Throttling) |
| Affected | < 2026.3.31 |
| Vendor/Product | OpenClaw / OpenClaw |
| Advisory | GHSA-2w79-r9g8-wmcr |
OpenClaw before 2026.3.31 contains an incomplete fix for CVE-2026-32062 where the voice-call component parses large WebSocket frames before start validation. Remote attackers can send oversized pre-start WebSocket frames to cause resource consumption and denial of service.
References:
- Patch Commit
- VulnCheck Advisory: OpenClaw < 2026.3.31 - Resource Consumption via Oversized WebSocket Frames in voice-call
CVE-2026-44116 โ OpenClaw < 2026.4.22 - Server-Side Request Forgery in Zalo Photo URL Validation
| Field | Detail |
|---|---|
| CVSS | 6.9 (MEDIUM) โ CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:H/SI:N/SA:N |
| CWE | CWE-918 (CWE-918 Server-Side Request Forgery (SSRF)) |
| Affected | < 2026.4.22 |
| Vendor/Product | OpenClaw / OpenClaw |
| Advisory | GHSA-2hh7-c75g-qj2r |
OpenClaw before 2026.4.22 contains a server-side request forgery vulnerability in the Zalo plugin's sendPhoto function that fails to validate outbound photo URLs through the SSRF guard. Attackers can bypass SSRF protection by providing malicious photo URLs to the Zalo Bot API, enabling unauthorized access to internal resources.
References:
- Patch Commit
- VulnCheck Advisory: OpenClaw < 2026.4.22 - Server-Side Request Forgery in Zalo Photo URL Validation
CVE-2026-53818 โ OpenClaw < 2026.4.24 - Owner-Only Tool Policy Bypass via MCP Loopback
| Field | Detail |
|---|---|
| CVSS | 6.9 (MEDIUM) โ CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N |
| CWE | CWE-862 (Missing Authorization) |
| Affected | < 2026.4.24 |
| Vendor/Product | OpenClaw / OpenClaw |
| Advisory | GHSA-rj6p-xmxr-qj4h |
OpenClaw before 2026.4.24 contains an authorization bypass vulnerability in the MCP loopback feature that allows non-owner callers to skip owner-only tool policies and before-tool-call hooks. Attackers can invoke owner-only behavior through the affected loopback path to execute restricted tools when the feature is enabled and reachable.
References:
CVE-2026-29612 โ OpenClaw < 2026.2.14 - Denial of Service via Large Base64 Media File Decoding
| Field | Detail |
|---|---|
| CVSS | 6.8 (MEDIUM) โ CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
| CWE | CWE-770 (Allocation of Resources Without Limits or Throttling) |
| Affected | < 2026.2.14 |
| Vendor/Product | OpenClaw / OpenClaw |
| Advisory | GHSA-w2cg-vxx6-5xjg |
OpenClaw versions prior to 2026.2.14 decode base64-backed media inputs into buffers before enforcing decoded-size budget limits, allowing attackers to trigger large memory allocations. Remote attackers can supply oversized base64 payloads to cause memory pressure and denial of service.
References:
- Patch Commit
- VulnCheck Advisory: OpenClaw < 2026.2.14 - Denial of Service via Large Base64 Media File Decoding
CVE-2026-26972 โ OpenClaw has a Path Traversal in Browser Download Functionality
| Field | Detail |
|---|---|
| CVSS | 6.7 (MEDIUM) โ CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
| CWE | CWE-22 (CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')) |
| Affected | < >= 2026.1.12, < 2026.2.13 |
| Vendor/Product | openclaw / openclaw |
| Advisory | GHSA-xwjm-j929-xq7c |
OpenClaw is a personal AI assistant. In versions 2026.1.12 through 2026.2.12, OpenClaw browser download helpers accepted an unsanitized output path. When invoked via the browser control gateway routes, this allowed path traversal to write downloads outside the intended OpenClaw temp downloads directory. This issue is not exposed via the AI agent tool schema (no download action). Exploitation requires authenticated CLI access or an authenticated gateway RPC token. Version 2026.2.13 fixes the issue.
References:
- https://github.com/openclaw/openclaw/commit/7f0489e4731c8d965d78d6eac4a60312e46a9426
- https://github.com/openclaw/openclaw/releases/tag/v2026.2.13
CVE-2026-28452 โ OpenClaw affected by denial of service through unguarded archive extraction allowing high expansion/resource abuse (ZIP/TAR)
| Field | Detail |
|---|---|
| CVSS | 6.7 (MEDIUM) โ CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
| CWE | CWE-770 (Allocation of Resources Without Limits or Throttling) |
| Affected | < 2026.2.14 |
| Vendor/Product | OpenClaw / OpenClaw |
| Advisory | GHSA-h89v-j3x9-8wqj |
OpenClaw versions prior to 2026.2.14 contain a denial of service vulnerability in the extractArchive function within src/infra/archive.ts that allows attackers to consume excessive CPU, memory, and disk resources through high-expansion ZIP and TAR archives. Remote attackers can trigger resource exhaustion by providing maliciously crafted archive files during install or update operations, causing service degradation or system unavailability.
References:
- Patch Commit #1
- Patch Commit #2
- VulnCheck Advisory: OpenClaw < 2026.2.14 - Denial of Service via Unguarded Archive Extraction in extractArchive
CVE-2026-26328 โ OpenClaw iMessage group allowlist authorization inherited DM pairing-store identities
| Field | Detail |
|---|---|
| CVSS | 6.5 (MEDIUM) โ CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N |
| CWE | CWE-284 (CWE-284: Improper Access Control), CWE-863 (CWE-863: Incorrect Authorization) |
| Affected | <= 2026.1.24-3 |
| Vendor/Product | openclaw / clawdbot |
| Advisory | GHSA-g34w-4xqq-h79m |
OpenClaw is a personal AI assistant. Prior to version 2026.2.14, under iMessage groupPolicy=allowlist, group authorization could be satisfied by sender identities coming from the DM pairing store, broadening DM trust into group contexts. Version 2026.2.14 fixes the issue.
Naming note: Uses old name
openclaw/clawdbotas vendor/product. References:
- https://github.com/openclaw/openclaw/commit/872079d42fe105ece2900a1dd6ab321b92da2d59
- https://github.com/openclaw/openclaw/releases/tag/v2026.2.14
CVE-2026-28449 โ OpenClaw < 2026.2.25 - Webhook Replay Attack via Missing Durable Replay Suppression
| Field | Detail |
|---|---|
| CVSS | 6.3 (MEDIUM) โ CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N |
| CWE | CWE-294 (CWE-294 Authentication Bypass by Capture-replay) |
| Affected | < 2026.2.25 |
| Vendor/Product | OpenClaw / OpenClaw |
| Advisory | GHSA-r9q5-c7qc-p26w |
OpenClaw versions prior to 2026.2.25 lack durable replay state for Nextcloud Talk webhook events, allowing valid signed webhook requests to be replayed without suppression. Attackers can capture and replay previously valid signed webhook requests to trigger duplicate inbound message processing and cause integrity or availability issues.
References:
- Patch Commit
- VulnCheck Advisory: OpenClaw < 2026.2.25 - Webhook Replay Attack via Missing Durable Replay Suppression
CVE-2026-35628 โ OpenClaw < 2026.3.25 - Brute-Force Attack via Missing Telegram Webhook Rate Limiting
| Field | Detail |
|---|---|
| CVSS | 6.3 (MEDIUM) โ CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N |
| CWE | CWE-307 (CWE-307 Improper Restriction of Excessive Authentication Attempts) |
| Affected | < 2026.3.25 |
| Vendor/Product | OpenClaw / OpenClaw |
| Advisory | GHSA-vcx4-4qxg-mfp4 |
OpenClaw before 2026.3.25 contains a missing rate limiting vulnerability in Telegram webhook authentication that allows attackers to brute-force weak webhook secrets. The vulnerability enables repeated authentication guesses without throttling, permitting attackers to systematically guess webhook secrets through brute-force attacks.
References:
- Patch Commit
- VulnCheck Advisory: OpenClaw < 2026.3.25 - Brute-Force Attack via Missing Telegram Webhook Rate Limiting
CVE-2026-35646 โ OpenClaw < 2026.3.25 - Pre-Authentication Rate-Limit Bypass in Webhook Token Validation
| Field | Detail |
|---|---|
| CVSS | 6.3 (MEDIUM) โ CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N |
| CWE | CWE-307 (CWE-307 Improper Restriction of Excessive Authentication Attempts) |
| Affected | < 2026.3.25 |
| Vendor/Product | OpenClaw / OpenClaw |
| Advisory | GHSA-mf5g-6r6f-ghhm |
OpenClaw before 2026.3.25 contains a pre-authentication rate-limit bypass vulnerability in webhook token validation that allows attackers to brute-force weak webhook secrets. The vulnerability exists because invalid webhook tokens are rejected without throttling repeated authentication attempts, enabling attackers to guess weak tokens through rapid successive requests.
References:
- Patch Commit
- VulnCheck Advisory: OpenClaw < 2026.3.25 - Pre-Authentication Rate-Limit Bypass in Webhook Token Validation
CVE-2026-35649 โ OpenClaw < 2026.3.22 - Settings Reconciliation Bypass via Empty Allowlist
| Field | Detail |
|---|---|
| CVSS | 6.3 (MEDIUM) โ CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N |
| CWE | CWE-183 (CWE-183: Permissive List of Allowed Inputs) |
| Affected | < 2026.3.22 |
| Vendor/Product | OpenClaw / OpenClaw |
| Advisory | GHSA-pw7h-9g6p-c378 |
OpenClaw before 2026.3.22 contains a settings reconciliation vulnerability that allows attackers to bypass intended deny-all revocations by exploiting empty allowlist handling. The vulnerability treats explicit empty allowlists as unset during reconciliation, silently undoing intended access control denials and restoring previously revoked permissions.
References:
- Patch Commit #1
- Patch Commit #2
- VulnCheck Advisory: OpenClaw < 2026.3.22 - Settings Reconciliation Bypass via Empty Allowlist
CVE-2026-35635 โ OpenClaw < 2026.3.22 - Webhook Path Route Replacement Vulnerability in Synology Chat
| Field | Detail |
|---|---|
| CVSS | 6.3 (MEDIUM) โ CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N |
| CWE | CWE-706 (CWE-706: Use of Incorrectly-Resolved Name or Reference) |
| Affected | < 2026.3.22 |
| Vendor/Product | OpenClaw / OpenClaw |
| Advisory | GHSA-rqp8-q22p-5j9q |
OpenClaw before 2026.3.22 contains a webhook path route replacement vulnerability in the Synology Chat extension that allows attackers to collapse multi-account configurations onto shared webhook paths. Attackers can exploit inherited or duplicate webhook paths to bypass per-account DM access control policies and replace route ownership across accounts.
References:
- Patch Commit #1
- Patch Commit #2
- VulnCheck Advisory: OpenClaw < 2026.3.22 - Webhook Path Route Replacement Vulnerability in Synology Chat
CVE-2026-41333 โ OpenClaw < 2026.3.31 - Authentication Rate Limiting Bypass via Fake DeviceToken
| Field | Detail |
|---|---|
| CVSS | 6.3 (MEDIUM) โ CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N |
| CWE | CWE-799 (Improper Control of Interaction Frequency) |
| Affected | < 2026.3.31 |
| Vendor/Product | OpenClaw / OpenClaw |
| Advisory | GHSA-6p8r-6m93-557f |
OpenClaw before 2026.3.31 contains an authentication rate limiting bypass vulnerability that allows attackers to circumvent shared authentication protections using fake device tokens. Attackers can exploit the mixed WebSocket authentication flow to bypass rate limiting controls and conduct brute force attacks against weak shared passwords.
References:
- Patch Commit
- VulnCheck Advisory: OpenClaw < 2026.3.31 - Authentication Rate Limiting Bypass via Fake DeviceToken
CVE-2026-41389 โ OpenClaw: Webchat media embedding enforces local-root containment for tool-result files
| Field | Detail |
|---|---|
| CVSS | 6.3 (MEDIUM) โ CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N |
| CWE | CWE-73 (CWE-73: External Control of File Name or Path) |
| Affected | < 2026.4.15 |
| Vendor/Product | OpenClaw / OpenClaw |
| Advisory | GHSA-mr34-9552-qr95 |
OpenClaw versions 2026.4.7 before 2026.4.15 fail to enforce local-root containment on tool-result media paths, allowing arbitrary local and UNC file access. Attackers can craft malicious tool-result media references to trigger host-side file reads or Windows network path access, potentially disclosing sensitive files or exposing credentials.
References:
- Patch Commit
- Patch Commit
- Patch Commit
- openclaw-arbitrary-file-read-via-unvalidated-tool-result-media-paths
CVE-2026-41913 โ OpenClaw < 2026.4.4 - Rate-Limit Bypass via Concurrent Async Authentication Attempts
| Field | Detail |
|---|---|
| CVSS | 6.3 (MEDIUM) โ CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N |
| CWE | CWE-362 (CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')) |
| Affected | < 2026.4.4 |
| Vendor/Product | OpenClaw / OpenClaw |
| Advisory | GHSA-25wv-8phj-8p7r |
OpenClaw before 2026.4.4 contains a race condition vulnerability in shared-secret authentication that allows concurrent asynchronous requests to bypass the per-key rate-limit budget. Attackers can exploit this by sending multiple simultaneous authentication attempts to circumvent intended rate-limiting protections on Tailscale-capable paths.
References:
- Patch Commit
- VulnCheck Advisory: OpenClaw < 2026.4.4 - Rate-Limit Bypass via Concurrent Async Authentication Attempts
CVE-2026-43527 โ OpenClaw: Browser SSRF policy default allowed private-network navigation
| Field | Detail |
|---|---|
| CVSS | 6.3 (MEDIUM) โ CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N |
| CWE | CWE-918 (CWE-918 Server-Side Request Forgery (SSRF)), CWE-1188 (CWE-1188 Initialization of a Resource with an Insecure Default) |
| Affected | < 2026.4.14 |
| Vendor/Product | OpenClaw / OpenClaw |
| Advisory | GHSA-53vx-pmqw-863c |
OpenClaw before 2026.4.14 contains a server-side request forgery vulnerability in browser SSRF policy that allows private-network navigation by default. Attackers can exploit this misconfiguration to access internal services or metadata endpoints through browser-driven requests.
References:
- Patch Commit (1)
- Patch Commit (2)
- Patch Commit (3)
- Patch Commit (4)
- VulnCheck Advisory: OpenClaw < 2026.4.14 - Server-Side Request Forgery via Private Network Navigation
CVE-2026-44117 โ OpenClaw < 2026.4.20 - Server-Side Request Forgery in QQBot Direct Media Upload
| Field | Detail |
|---|---|
| CVSS | 6.3 (MEDIUM) โ CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N |
| CWE | CWE-918 (CWE-918 Server-Side Request Forgery (SSRF)) |
| Affected | < 2026.4.20 |
| Vendor/Product | OpenClaw / OpenClaw |
| Advisory | GHSA-c4qg-j8jg-42q5 |
OpenClaw before 2026.4.20 contains a server-side request forgery vulnerability in QQBot direct media upload that skips URL validation. Attackers can bypass SSRF protections by sending crafted image URLs to uploadC2CMedia and uploadGroupMedia endpoints to relay unintended requests.
References:
- Patch Commit
- VulnCheck Advisory: OpenClaw < 2026.4.20 - Server-Side Request Forgery in QQBot Direct Media Upload
CVE-2026-44999 โ OpenClaw < 2026.4.20 - Improper Trust Labeling in Isolated Cron Awareness Events
| Field | Detail |
|---|---|
| CVSS | 6.3 (MEDIUM) โ CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N |
| CWE | CWE-345 (Insufficient Verification of Data Authenticity) |
| Affected | < 2026.4.20 |
| Vendor/Product | OpenClaw / OpenClaw |
| Advisory | GHSA-57r2-h2wj-g887 |
OpenClaw before 2026.4.20 fails to properly preserve untrusted labels for isolated cron awareness events, allowing webhook-triggered cron agent output to be recorded as trusted system events. Attackers can exploit this trust-labeling issue to strengthen prompt-injection attacks by rendering untrusted events as trusted System events.
References:
- Patch Commit
- VulnCheck Advisory: OpenClaw < 2026.4.20 - Improper Trust Labeling in Isolated Cron Awareness Events
CVE-2026-45002 โ OpenClaw < 2026.4.20 - Hook Session-Key Bypass via Template Mapping
| Field | Detail |
|---|---|
| CVSS | 6.3 (MEDIUM) โ CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N |
| CWE | CWE-863 (Incorrect Authorization) |
| Affected | < 2026.4.20 |
| Vendor/Product | OpenClaw / OpenClaw |
| Advisory | GHSA-2xcp-x87w-q377 |
OpenClaw before 2026.4.20 contains a hook session-key bypass vulnerability that allows attackers to circumvent the hooks.allowRequestSessionKey opt-in restriction. Attackers can render externally influenced session keys through templated hook mappings to bypass webhook routing isolation controls.
References:
- Patch Commit
- VulnCheck Advisory: OpenClaw < 2026.4.20 - Hook Session-Key Bypass via Template Mapping
CVE-2026-35645 โ OpenClaw < 2026.3.25 - Privilege Escalation via Synthetic operator.admin in deleteSession
| Field | Detail |
|---|---|
| CVSS | 6.1 (MEDIUM) โ CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N |
| CWE | CWE-648 (CWE-648: Incorrect Use of Privileged APIs) |
| Affected | < 2026.3.25 |
| Vendor/Product | OpenClaw / OpenClaw |
| Advisory | GHSA-h4jx-hjr3-fhgc |
OpenClaw before 2026.3.25 contains a privilege escalation vulnerability in the gateway plugin subagent fallback deleteSession function that uses a synthetic operator.admin runtime scope. Attackers can exploit this by triggering session deletion without a request-scoped client to execute privileged operations with unintended administrative scope.
References:
- Patch Commit
- VulnCheck Advisory: OpenClaw < 2026.3.25 - Privilege Escalation via Synthetic operator.admin in deleteSession
CVE-2026-32039 โ OpenClaw < 2026.2.22 - Sender Authorization Bypass via Identity Collision in toolsBySender
| Field | Detail |
|---|---|
| CVSS | 6 (MEDIUM) โ CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N |
| CWE | CWE-639 (CWE-639 Authorization Bypass Through User-Controlled Key) |
| Affected | < 2026.2.22 |
| Vendor/Product | OpenClaw / OpenClaw |
| Advisory | GHSA-wpph-cjgr-7c39 |
OpenClaw versions prior to 2026.2.22 contain an authorization bypass vulnerability in the toolsBySender group policy matching that allows attackers to inherit elevated tool permissions through identifier collision attacks. Attackers can exploit untyped sender keys by forcing collisions with mutable identity values such as senderName or senderUsername to bypass sender-authorization policies and gain unauthorized access to privileged tools.
References:
- Patch Commit
- VulnCheck Advisory: OpenClaw < 2026.2.22 - Sender Authorization Bypass via Identity Collision in toolsBySender
CVE-2026-35622 โ OpenClaw < 2026.3.22 - Improper Authentication Verification in Google Chat Webhook
| Field | Detail |
|---|---|
| CVSS | 6 (MEDIUM) โ CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N |
| CWE | CWE-290 (CWE-290: Authentication Bypass by Spoofing) |
| Affected | < 2026.3.22 |
| Vendor/Product | OpenClaw / OpenClaw |
| Advisory | GHSA-mp66-rf4f-mhh8 |
OpenClaw before 2026.3.22 contains an improper authentication verification vulnerability in Google Chat app-url webhook handling that accepts add-on principals outside intended deployment bindings. Attackers can bypass webhook authentication by providing non-deployment add-on principals to execute unauthorized actions through the Google Chat integration.
References:
- Patch Commit #1
- Patch Commit #2
- VulnCheck Advisory: OpenClaw < 2026.3.22 - Improper Authentication Verification in Google Chat Webhook
CVE-2026-42429 โ OpenClaw < 2026.4.8 - Privilege Escalation via Gateway Plugin HTTP Authentication
| Field | Detail |
|---|---|
| CVSS | 6 (MEDIUM) โ CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N |
| CWE | CWE-863 (CWE-863: Incorrect Authorization) |
| Affected | < 2026.4.8 |
| Vendor/Product | OpenClaw / OpenClaw |
| Advisory | GHSA-4f8g-77mw-3rxc |
OpenClaw before 2026.4.8 contains a privilege escalation vulnerability in the gateway plugin HTTP authentication mechanism that widens identity-bearing operator.read requests into runtime operator.write permissions. Attackers can exploit this by sending read-scoped requests through the gateway auth route to gain unauthorized write access to runtime operations.
References:
- Patch Commit
- VulnCheck Advisory: OpenClaw < 2026.4.8 - Privilege Escalation via Gateway Plugin HTTP Authentication
CVE-2026-43570 โ OpenClaw contains a symlink traversal vulnerability
| Field | Detail |
|---|---|
| CVSS | 6 (MEDIUM) โ CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
| CWE | CWE-61 (CWE-61 UNIX Symbolic Link (Symlink) Following) |
| Affected | < 2026.4.5 |
| Vendor/Product | OpenClaw / OpenClaw |
| Advisory | GHSA-cr8r-7g2h-6wr6 |
OpenClaw versions 2026.3.22 before 2026.4.5 contain a symlink traversal vulnerability in remote marketplace repository path handling that allows attackers to escape the expected repository root. Attackers can exploit this by providing crafted symlink paths to access files outside the intended repository directory.
References:
- Patch Commit (1)
- Patch Commit (2)
- VulnCheck Advisory: OpenClaw 2026.3.22 < 2026.4.5 - Symlink Traversal in Remote Marketplace Repository Path Handling
CVE-2026-44112 โ OpenClaw < 2026.4.22 - Symlink Swap Race Condition in OpenShell FS Bridge Writes
| Field | Detail |
|---|---|
| CVSS | 6 (MEDIUM) โ CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N |
| CWE | CWE-367 (CWE-367: Time-of-check Time-of-use (TOCTOU) Race Condition) |
| Affected | < 2026.4.22 |
| Vendor/Product | OpenClaw / OpenClaw |
| Advisory | GHSA-wppj-c6mr-83jj |
OpenClaw before 2026.4.22 contains a time-of-check/time-of-use race condition in OpenShell sandbox filesystem writes that allows attackers to redirect writes outside the intended mount root. Attackers can exploit symlink swaps during filesystem operations to bypass sandbox restrictions and write files outside the local mount root.
References:
- Patch Commit
- VulnCheck Advisory: OpenClaw < 2026.4.22 - Symlink Swap Race Condition in OpenShell FS Bridge Writes
CVE-2026-44113 โ OpenClaw: OpenShell FS bridge reads pin and verify the opened file before returning bytes
| Field | Detail |
|---|---|
| CVSS | 6 (MEDIUM) โ CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
| CWE | CWE-367 (CWE-367: Time-of-check Time-of-use (TOCTOU) Race Condition) |
| Affected | < 2026.4.22 |
| Vendor/Product | OpenClaw / OpenClaw |
| Advisory | GHSA-5h3g-6xhh-rg6p |
OpenClaw before 2026.4.22 contains a time-of-check/time-of-use race condition in the OpenShell filesystem bridge that allows attackers to read files outside the intended mount root. Attackers can exploit symlink swaps during filesystem operations to bypass sandbox restrictions and access unauthorized file contents.
References:
- Patch Commit
- VulnCheck Advisory: OpenClaw < 2026.4.22 - Time-of-Check/Time-of-Use Race Condition in OpenShell FS Bridge
CVE-2026-53830 โ OpenClaw < 2026.4.22 - Webhook Secret Revocation Bypass via secrets.reload
| Field | Detail |
|---|---|
| CVSS | 6 (MEDIUM) โ CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N |
| CWE | CWE-613 (Insufficient Session Expiration) |
| Affected | < 2026.4.22 |
| Vendor/Product | OpenClaw / OpenClaw |
| Advisory | GHSA-275c-xpvc-jgfw |
OpenClaw before 2026.4.22 contains a webhook secret revocation bypass vulnerability allowing callers with old Slack and Zalo webhook secrets to remain active after secrets.reload. Attackers can exploit the stale-secret window to deliver webhook events after operator-expected secret revocation, potentially accepting previous credentials.
References:
CVE-2026-53838 โ OpenClaw < 2026.5.27 - Node Pairing State Mutation via Reconnection
| Field | Detail |
|---|---|
| CVSS | 6 (MEDIUM) โ CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N |
| CWE | CWE-367 (Time-of-check Time-of-use (TOCTOU) Race Condition) |
| Affected | < 2026.5.27 |
| Vendor/Product | OpenClaw / OpenClaw |
| Advisory | GHSA-83w9-h5wv-j9xm |
OpenClaw before 2026.5.27 contains a state mutation vulnerability in node pairing reconnection that allows paired nodes to confuse approval scope decisions. Attackers can exploit reconnection logic to restore or present broader node authority than intended, potentially bypassing approval restrictions.
References:
CVE-2026-28481 โ OpenClaw < 2026.2.1 - Bearer Token Leakage via MS Teams Attachment Downloader Suffix Matching
| Field | Detail |
|---|---|
| CVSS | 5.9 (MEDIUM) โ CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
| CWE | CWE-201 (Insertion of Sensitive Information Into Sent Data) |
| Affected | < 0 |
| Vendor/Product | OpenClaw / OpenClaw |
| Advisory | GHSA-7vwx-582j-j332 |
OpenClaw versions 2026.1.30 and earlier, contain an information disclosure vulnerability, patched in 2026.2.1, in the MS Teams attachment downloader (optional extension must be enabled) that leaks bearer tokens to allowlisted suffix domains. When retrying downloads after receiving 401 or 403 responses, the application sends Authorization bearer tokens to untrusted hosts matching the permissive suffix-based allowlist, enabling token theft.
References:
- Patch Commit
- VulnCheck Advisory: OpenClaw < 2026.2.1 - Bearer Token Leakage via MS Teams Attachment Downloader Suffix Matching
CVE-2026-32054 โ OpenClaw < 2026.2.25 - Symlink Traversal in Browser Trace/Download Path Handling
| Field | Detail |
|---|---|
| CVSS | 5.9 (MEDIUM) โ CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N |
| CWE | CWE-59 (CWE-59: Improper Link Resolution Before File Access ('Link Following')) |
| Affected | < 2026.2.25 |
| Vendor/Product | OpenClaw / OpenClaw |
| Advisory | GHSA-36h3-7c54-j27r |
OpenClaw versions prior to 2026.2.25 contain a symlink traversal vulnerability in browser trace and download output path handling that allows local attackers to escape the managed temp root directory. An attacker with local access can create symlinks to route file writes outside the intended temp directory, enabling arbitrary file overwrite on the affected system.
References:
- Patch Commit
- VulnCheck Advisory: OpenClaw < 2026.2.25 - Symlink Traversal in Browser Trace/Download Path Handling
CVE-2026-45005 โ OpenClaw < 2026.4.23 - Webhook Route Secret Cache Not Invalidated After Rotation
| Field | Detail |
|---|---|
| CVSS | 5.9 (MEDIUM) โ CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N |
| CWE | CWE-672 (Operation on a Resource after Expiration or Release) |
| Affected | < 2026.4.23 |
| Vendor/Product | OpenClaw / OpenClaw |
| Advisory | GHSA-q8ff-7ffm-m3r9 |
OpenClaw before 2026.4.23 caches resolved webhook route secrets backed by SecretRef values, allowing stale secrets to remain valid after rotation and reload. Attackers with previously valid webhook route secrets can continue authenticating requests and invoking configured webhook task flows until gateway or plugin restart.
References:
- Patch Commit
- VulnCheck Advisory: OpenClaw < 2026.4.23 - Webhook Route Secret Cache Not Invalidated After Rotation
CVE-2026-31999 โ OpenClaw 2026.2.26 < 2026.3.1 - Current Working Directory Injection via Windows Wrapper Resolution Fallback
| Field | Detail |
|---|---|
| CVSS | 5.8 (MEDIUM) โ CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N |
| CWE | CWE-78 (Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78)) |
| Affected | < 2026.3.1 |
| Vendor/Product | OpenClaw / OpenClaw |
| Advisory | GHSA-6f6j-wx9w-ff4j |
OpenClaw versions 2026.2.26 prior to 2026.3.1 on Windows contain a current working directory injection vulnerability in wrapper resolution for .cmd/.bat files that allows attackers to influence execution behavior through cwd manipulation. Remote attackers can exploit improper shell execution fallback mechanisms to achieve command execution integrity loss by controlling the current working directory during wrapper resolution.
References:
CVE-2026-32000 โ OpenClaw < 2026.2.19 - Command Injection via Windows Shell Fallback in Lobster Tool Execution
| Field | Detail |
|---|---|
| CVSS | 5.8 (MEDIUM) โ CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N |
| CWE | CWE-78 (Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78)) |
| Affected | < 2026.2.19 |
| Vendor/Product | OpenClaw / OpenClaw |
| Advisory | GHSA-7fcc-cw49-xm78 |
OpenClaw versions prior to 2026.2.19 contain a command injection vulnerability in the Lobster extension tool execution that uses Windows shell fallback with shell: true after spawn failures. Attackers can inject shell metacharacters in command arguments to execute arbitrary commands when subprocess launch fails with EINVAL or ENOENT errors.
References:
- Patch Commit
- VulnCheck Advisory: OpenClaw < 2026.2.19 - Command Injection via Windows Shell Fallback in Lobster Tool Execution
CVE-2026-31995 โ OpenClaw 2026.1.21 < 2026.2.19 - Command Injection via Windows Shell Fallback in Lobster Extension
| Field | Detail |
|---|---|
| CVSS | 5.8 (MEDIUM) โ CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N |
| CWE | CWE-78 (Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78)) |
| Affected | < 2026.2.19 |
| Vendor/Product | OpenClaw / OpenClaw |
| Advisory | GHSA-fg3m-vhrr-8gj6 |
OpenClaw versions 2026.1.21 prior to 2026.2.19 contain a command injection vulnerability in the Lobster extension's Windows shell fallback mechanism that allows attackers to inject arbitrary commands through tool-provided arguments. When spawn failures trigger shell fallback with shell: true, attackers can exploit cmd.exe command interpretation to execute malicious commands by controlling workflow arguments.
References:
- Patch Commit
- VulnCheck Advisory: OpenClaw 2026.1.21 < 2026.2.19 - Command Injection via Windows Shell Fallback in Lobster Extension
CVE-2026-32988 โ OpenClaw < 2026.3.11 - Sandbox Boundary Bypass via Unvalidated Temporary File Creation
| Field | Detail |
|---|---|
| CVSS | 5.8 (MEDIUM) โ CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N |
| CWE | CWE-367 (Time-of-check Time-of-use (TOCTOU) Race Condition) |
| Affected | < 2026.3.11 |
| Vendor/Product | OpenClaw / OpenClaw |
| Advisory | GHSA-mj4p-rc52-m843 |
OpenClaw before 2026.3.11 contains a sandbox boundary bypass vulnerability in fs-bridge staged writes where temporary file creation and population are not pinned to a verified parent directory. Attackers can exploit a race condition in parent-path alias changes to write attacker-controlled bytes outside the intended validated path before the final guarded replace step executes.
References:
CVE-2026-41332 โ OpenClaw < 2026.3.28 - Code Execution via Missing Environment Variable Blocklist
| Field | Detail |
|---|---|
| CVSS | 5.8 (MEDIUM) โ CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N |
| CWE | CWE-184 (CWE-184: Incomplete List of Disallowed Inputs) |
| Affected | < 2026.3.28 |
| Vendor/Product | OpenClaw / OpenClaw |
| Advisory | GHSA-m866-6qv5-p2fg |
OpenClaw before 2026.3.28 contains an environment variable sanitization vulnerability where GIT_TEMPLATE_DIR and AWS_CONFIG_FILE are not blocked in the host-env blocklist. Attackers can exploit approved exec requests to redirect git or AWS CLI behavior through attacker-controlled configuration files to execute untrusted code or load malicious credentials.
References:
- VulnCheck Advisory: OpenClaw < 2026.3.28 - Code Execution via Missing Environment Variable Blocklist
CVE-2026-41360 โ OpenClaw < 2026.4.2 - Approval Integrity Bypass in pnpm dlx Local Script Binding
| Field | Detail |
|---|---|
| CVSS | 5.4 (MEDIUM) โ CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
| CWE | CWE-367 (CWE-367: Time-of-check Time-of-use (TOCTOU) Race Condition) |
| Affected | < 2026.4.2 |
| Vendor/Product | OpenClaw / OpenClaw |
| Advisory | GHSA-w6wx-jq6j-6mcj |
OpenClaw before 2026.4.2 contains an approval integrity vulnerability in pnpm dlx that fails to bind local script operands consistently with pnpm exec flows. Attackers can replace approved local scripts before execution without invalidating the approval plan, allowing execution of modified script contents.
References:
- Patch Commit
- VulnCheck Advisory: OpenClaw < 2026.4.2 - Approval Integrity Bypass in pnpm dlx Local Script Binding
CVE-2026-44995 โ OpenClaw: MCP stdio server env could load dangerous startup variables from workspace config
| Field | Detail |
|---|---|
| CVSS | 5.4 (MEDIUM) โ CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
| CWE | CWE-829 (Inclusion of Functionality from Untrusted Control Sphere) |
| Affected | < 2026.4.20 |
| Vendor/Product | OpenClaw / OpenClaw |
| Advisory | GHSA-mj59-h3q9-ghfh |
OpenClaw before 2026.4.20 contains an improper environment variable validation vulnerability in MCP stdio server configuration that allows attackers to execute arbitrary code. Malicious workspace configurations can pass dangerous startup variables like NODE_OPTIONS, LD_PRELOAD, or BASH_ENV to spawned MCP server processes, enabling code injection when operators start sessions using those servers.
References:
- Patch Commit (1)
- Patch Commit (2)
- VulnCheck Advisory: OpenClaw < 2026.4.20 - Arbitrary Code Execution via MCP stdio Environment Variables
CVE-2026-26326 โ OpenClaw skills.status could leak secrets to operator.read clients
| Field | Detail |
|---|---|
| CVSS | 5.3 (MEDIUM) โ CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N |
| CWE | CWE-200 (CWE-200: Exposure of Sensitive Information to an Unauthorized Actor) |
| Affected | < 2026.2.14 |
| Vendor/Product | openclaw / openclaw |
| Advisory | GHSA-8mh7-phf8-xgfm |
OpenClaw is a personal AI assistant. Prior to version 2026.2.14, skills.status could disclose secrets to operator.read clients by returning raw resolved config values in configChecks for skill requires.config paths. Version 2026.2.14 stops including raw resolved config values in requirement checks (return only { path, satisfied }) and narrows the Discord skill requirement to the token key. In addition to upgrading, users should rotate any Discord tokens that may have been exposed to read-scoped clients.
References:
- https://github.com/openclaw/openclaw/commit/d3428053d95eefbe10ecf04f92218ffcba55ae5a
- https://github.com/openclaw/openclaw/commit/ebc68861a61067fc37f9298bded3eec9de0ba783
- https://github.com/openclaw/openclaw/releases/tag/v2026.2.14
CVE-2026-32899 โ OpenClaw < 2026.2.25 - Sender Policy Bypass in Slack Reaction and Pin Event Handlers
| Field | Detail |
|---|---|
| CVSS | 5.3 (MEDIUM) โ CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N |
| CWE | CWE-863 (CWE-863: Incorrect Authorization) |
| Affected | < 2026.2.25 |
| Vendor/Product | OpenClaw / OpenClaw |
| Advisory | GHSA-rm2p-j3r7-4x4j |
OpenClaw versions prior to 2026.2.25 fail to consistently apply sender-policy checks to reaction_* and pin_* non-message events before adding them to system-event context. Attackers can bypass configured DM policies and channel user allowlists to inject unauthorized reaction and pin events from restricted senders.
References:
- Patch Commit #1
- Patch Commit #2
- VulnCheck Advisory: OpenClaw < 2026.2.25 - Sender Policy Bypass in Slack Reaction and Pin Event Handlers
CVE-2026-41909 โ OpenClaw < 2026.4.20 - Improper Authorization in Paired-Device Pairing Actions
| Field | Detail |
|---|---|
| CVSS | 5.3 (MEDIUM) โ CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N |
| CWE | CWE-863 (CWE-863 Incorrect Authorization) |
| Affected | < 2026.4.20 |
| Vendor/Product | OpenClaw / OpenClaw |
| Advisory | GHSA-xrq9-jm7v-g9h7 |
OpenClaw before 2026.4.20 contains an improper authorization vulnerability in paired-device pairing management that allows limited-scope sessions to enumerate and act on pairing requests. Attackers with paired-device access can approve or operate on unrelated pending device requests within the same gateway scope.
References:
CVE-2026-35634 โ OpenClaw < 2026.3.23 - Authentication Bypass via Local-Direct Requests in Canvas Gateway
| Field | Detail |
|---|---|
| CVSS | 5.1 (MEDIUM) โ CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N |
| CWE | CWE-288 (CWE-288: Authentication Bypass Using an Alternate Path or Channel) |
| Affected | < 2026.3.23 |
| Vendor/Product | OpenClaw / OpenClaw |
| Advisory | GHSA-6mqc-jqh6-x8fc |
OpenClaw before 2026.3.23 contains an authentication bypass vulnerability in the Canvas gateway where authorizeCanvasRequest() unconditionally allows local-direct requests without validating bearer tokens or canvas capabilities. Attackers can send unauthenticated loopback HTTP and WebSocket requests to Canvas routes to bypass authentication and gain unauthorized access.
References:
- Patch Commit #1
- Patch Commit #2
- VulnCheck Advisory: OpenClaw < 2026.3.23 - Authentication Bypass via Local-Direct Requests in Canvas Gateway
CVE-2026-42436 โ OpenClaw < 2026.4.14 - Internal Page Content Exposure via Browser Snapshot and Screenshot Routes
| Field | Detail |
|---|---|
| CVSS | 4.9 (MEDIUM) โ CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N |
| CWE | CWE-862 (CWE-862 Missing Authorization) |
| Affected | < 2026.4.14 |
| Vendor/Product | OpenClaw / OpenClaw |
| Advisory | GHSA-c4qm-58hj-j6pj |
OpenClaw before 2026.4.14 contains an improper access control vulnerability in browser snapshot, screenshot, and tab routes that fail to consistently validate the final browser target after navigation. Authenticated callers can bypass SSRF restrictions to expose internal or disallowed page content by exploiting route-driven navigation without proper policy re-validation.
References:
- Patch Commit
- VulnCheck Advisory: OpenClaw < 2026.4.14 - Internal Page Content Exposure via Browser Snapshot and Screenshot Routes
CVE-2026-42439 โ OpenClaw < 2026.4.10 - SSRF Policy Bypass in Browser Tabs Action Routes
| Field | Detail |
|---|---|
| CVSS | 4.9 (MEDIUM) โ CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:H/SI:N/SA:N |
| CWE | CWE-862 (CWE-862 Missing Authorization) |
| Affected | < 2026.4.10 |
| Vendor/Product | OpenClaw / OpenClaw |
| Advisory | GHSA-rj2p-j66c-mgqh |
OpenClaw before 2026.4.10 contains a server-side request forgery policy bypass vulnerability in the browser tabs action select and close routes. Attackers can bypass configured browser SSRF policy protections by exploiting the /tabs/action endpoint to perform unauthorized tab navigation operations.
References:
- Patch Commit
- VulnCheck Advisory: OpenClaw < 2026.4.10 - SSRF Policy Bypass in Browser Tabs Action Routes
CVE-2026-43532 โ OpenClaw 2026.4.7 < 2026.4.10 - Sandbox Media Normalization Bypass via Discord Event Cover Image
| Field | Detail |
|---|---|
| CVSS | 4.9 (MEDIUM) โ CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N |
| CWE | CWE-184 (CWE-184: Incomplete List of Disallowed Inputs) |
| Affected | < 2026.4.10 |
| Vendor/Product | OpenClaw / OpenClaw |
| Advisory | GHSA-c9h3-5p7r-mrjh |
OpenClaw versions 2026.4.7 before 2026.4.10 fail to normalize Discord event cover image parameters in sandbox media processing. Attackers can bypass media normalization to inject host-local media references into channel action paths expecting normalized media.
References:
- Patch Commit
- VulnCheck Advisory: OpenClaw 2026.4.7 < 2026.4.10 - Sandbox Media Normalization Bypass via Discord Event Cover Image
CVE-2026-42438 โ OpenClaw: Sender policy bypass in host media attachment reads allows unauthorized local file disclosure
| Field | Detail |
|---|---|
| CVSS | 4.9 (MEDIUM) โ CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:H/SI:N/SA:N |
| CWE | CWE-863 (CWE-863: Incorrect Authorization) |
| Affected | < 2026.4.10 |
| Vendor/Product | OpenClaw / OpenClaw |
| Advisory | GHSA-jhpv-5j76-m56h |
OpenClaw versions 2026.4.9 before 2026.4.10 contain a sender policy bypass vulnerability in the outbound host-media attachment read helper that allows unauthorized local file disclosure. Attackers with denied read access via toolsBySender or group policy can trigger host-media attachment loading to bypass sender and group-scoped authorization boundaries and retrieve readable local files through the outbound media path.
References:
- Patch Commit
- VulnCheck Advisory: OpenClaw 2026.4.9 < 2026.4.10 - Sender Policy Bypass in Host Media Attachment Reads
CVE-2026-43573 โ OpenClaw: Existing-session browser interaction routes bypassed SSRF policy enforcement
| Field | Detail |
|---|---|
| CVSS | 4.9 (MEDIUM) โ CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N |
| CWE | CWE-862 (CWE-862 Missing Authorization), CWE-918 (CWE-918 Server-Side Request Forgery (SSRF)) |
| Affected | < 2026.4.10 |
| Vendor/Product | OpenClaw / OpenClaw |
| Advisory | GHSA-527m-976r-jf79 |
OpenClaw before 2026.4.10 contains a server-side request forgery policy bypass vulnerability in existing-session browser interaction routes. Attackers can bypass SSRF navigation guards to interact with or navigate to unauthorized targets without policy enforcement.
References:
- Patch Commit
- VulnCheck Advisory: OpenClaw < 2026.4.10 - SSRF Policy Bypass in Existing-Session Browser Interaction Routes
CVE-2026-43576 โ OpenClaw < 2026.4.5 - Second-hop SSRF via CDP /json/version WebSocket URL
| Field | Detail |
|---|---|
| CVSS | 4.9 (MEDIUM) โ CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N |
| CWE | CWE-601 (CWE-601 URL Redirection to Untrusted Site ('Open Redirect')), CWE-918 (CWE-918 Server-Side Request Forgery (SSRF)) |
| Affected | < 2026.4.5 |
| Vendor/Product | OpenClaw / OpenClaw |
| Advisory | GHSA-f7fh-qg34-x2xh |
OpenClaw before 2026.4.5 contains a server-side request forgery vulnerability in the CDP /json/version WebSocket endpoint that allows attackers to pivot to untrusted second-hop targets. The webSocketDebuggerUrl response field is not properly validated, enabling attackers to redirect connections to arbitrary hosts and perform SSRF-style attacks.
References:
- Patch Commit
- VulnCheck Advisory: OpenClaw < 2026.4.5 - Second-hop SSRF via CDP /json/version WebSocket URL
CVE-2026-43580 โ OpenClaw: Browser press/type interaction routes missed complete navigation guard coverage
| Field | Detail |
|---|---|
| CVSS | 4.9 (MEDIUM) โ CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N |
| CWE | CWE-862 (CWE-862 Missing Authorization) |
| Affected | < 2026.4.10 |
| Vendor/Product | OpenClaw / OpenClaw |
| Advisory | GHSA-536q-mj95-h29h |
OpenClaw before 2026.4.10 contains an incomplete navigation guard vulnerability that allows attackers to trigger navigation without complete SSRF policy enforcement. Browser press/type style interactions, including pressKey and type submit flows, can bypass post-action security checks to execute unauthorized navigation.
References:
- Patch Commit (1)
- Patch Commit (2)
- Patch Commit (3)
- VulnCheck Advisory: OpenClaw < 2026.4.10 - Incomplete Navigation Guard Coverage in Browser Interactions
CVE-2026-43582 โ OpenClaw < 2026.4.10 - DNS Rebinding SSRF via Hostname Validation Bypass
| Field | Detail |
|---|---|
| CVSS | 4.9 (MEDIUM) โ CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N |
| CWE | CWE-367 (CWE-367: Time-of-check Time-of-use (TOCTOU) Race Condition) |
| Affected | < 2026.4.10 |
| Vendor/Product | OpenClaw / OpenClaw |
| Advisory | GHSA-xq94-r468-qwgj |
OpenClaw before 2026.4.10 contains a server-side request forgery vulnerability in browser navigation policy that allows attackers to bypass hostname validation through DNS rebinding attacks. Attackers can exploit inconsistent hostname resolution between validation and actual network requests to pivot to internal resources via unallowlisted hostname URLs.
References:
- Patch Commit
- VulnCheck Advisory: OpenClaw < 2026.4.10 - DNS Rebinding SSRF via Hostname Validation Bypass
CVE-2026-27007 โ OpenClaw's sandbox config hash sorted primitive arrays and suppressed needed container recreation
| Field | Detail |
|---|---|
| CVSS | 4.8 (MEDIUM) โ CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N |
| CWE | CWE-1254 (CWE-1254: Incorrect Comparison Logic Granularity) |
| Affected | < 2026.2.15 |
| Vendor/Product | openclaw / openclaw |
| Advisory | GHSA-xxvh-5hwj-42pp |
OpenClaw is a personal AI assistant. Prior to version 2026.2.15, normalizeForHash in src/agents/sandbox/config-hash.ts recursively sorted arrays that contained only primitive values. This made order-sensitive sandbox configuration arrays hash to the same value even when order changed. In OpenClaw sandbox flows, this hash is used to decide whether existing sandbox containers should be recreated. As a result, order-only config changes (for example Docker dns and binds array order) could be treated as unchanged and stale containers could be reused. This is a configuration integrity issue affecting sandbox recreation behavior. Starting in version 2026.2.15, array ordering is preserved during hash normalization; only object key ordering remains normalized for deterministic hashing.
References:
- https://github.com/openclaw/openclaw/commit/41ded303b4f6dae5afa854531ff837c3276ad60b
- https://github.com/openclaw/openclaw/releases/tag/v2026.2.15
CVE-2026-44992 โ OpenClaw 2026.4.5 < 2026.4.20 - MiniMax API Host Override via Workspace dotenv
| Field | Detail |
|---|---|
| CVSS | 4.1 (MEDIUM) โ CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
| CWE | CWE-441 (Unintended Proxy or Intermediary ('Confused Deputy')) |
| Affected | < 2026.4.20 |
| Vendor/Product | OpenClaw / OpenClaw |
| Advisory | GHSA-h2vw-ph2c-jvwf |
OpenClaw versions 2026.4.5 before 2026.4.20 contain an environment variable injection vulnerability allowing workspace dotenv to override MINIMAX_API_HOST. Attackers can redirect credentialed MiniMax API requests to attacker-controlled origins, exposing the MiniMax API key in Authorization headers.
References:
- Patch Commit
- VulnCheck Advisory: OpenClaw 2026.4.5 < 2026.4.20 - MiniMax API Host Override via Workspace dotenv
CVE-2026-45003 โ OpenClaw: Workspace dotenv files cannot override connector endpoint hosts
| Field | Detail |
|---|---|
| CVSS | 4.1 (MEDIUM) โ CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
| CWE | CWE-441 (Unintended Proxy or Intermediary ('Confused Deputy')) |
| Affected | < 2026.4.22 |
| Vendor/Product | OpenClaw / OpenClaw |
| Advisory | GHSA-55cf-xx38-4p9p |
OpenClaw before 2026.4.22 allows workspace dotenv files to override connector endpoint hosts for Matrix, Mattermost, IRC, and Synology connectors. Attackers with workspace access can redirect runtime traffic to malicious endpoints by setting endpoint variables in dotenv files.
References:
- Patch Commit
- VulnCheck Advisory: OpenClaw < 2026.4.22 - Connector Endpoint Host Override via Workspace dotenv Files
CVE-2026-32006 โ OpenClaw < 2026.2.26 - Authorization Bypass via DM Pairing-Store Fallback in Group Allowlist
| Field | Detail |
|---|---|
| CVSS | 2.3 (LOW) โ CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N |
| CWE | CWE-863 (CWE-863: Incorrect Authorization) |
| Affected | < 2026.2.26 |
| Vendor/Product | OpenClaw / OpenClaw |
| Advisory | GHSA-25pw-4h6w-qwvm |
OpenClaw versions prior to 2026.2.26 contain an authorization bypass vulnerability where DM pairing-store identities are incorrectly treated as group allowlist identities when dmPolicy=pairing and groupPolicy=allowlist. Remote attackers can send messages and reactions as DM-paired identities without explicit groupAllowFrom membership to bypass group sender authorization checks.
References:
- Patch Commit
- VulnCheck Advisory: OpenClaw < 2026.2.26 - Authorization Bypass via DM Pairing-Store Fallback in Group Allowlist
CVE-2026-34507 โ OpenClaw < 2026.4.29 - Policy Bypass in QQBot Admin Commands via DM-only and allowFrom Checks
| Field | Detail |
|---|---|
| CVSS | 2.3 (LOW) โ CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N |
| CWE | CWE-863 (Incorrect Authorization) |
| Affected | < 2026.4.29 |
| Vendor/Product | OpenClaw / OpenClaw |
| Advisory | GHSA-w4v6-g3wm-w36c |
OpenClaw before 2026.4.29 contains a policy bypass vulnerability in QQBot admin commands that allows authenticated senders to skip DM-only and allowFrom policy checks. Attackers can route admin commands from unauthorized senders or contexts to execute restricted behavior that policy should have blocked.
References:
CVE-2026-35617 โ OpenClaw < 2026.3.25 - Authorization Bypass via Group Policy Rebinding with Mutable Space displayName
| Field | Detail |
|---|---|
| CVSS | 2.3 (LOW) โ CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N |
| CWE | CWE-807 (CWE-807 Reliance on Untrusted Inputs in a Security Decision) |
| Affected | < 2026.3.25 |
| Vendor/Product | OpenClaw / OpenClaw |
| Advisory | GHSA-52q4-3xjc-6778 |
OpenClaw before 2026.3.25 contains an authorization bypass vulnerability in Google Chat group policy enforcement that relies on mutable space display names. Attackers can rebind group policies by changing or colliding space display names to gain unauthorized access to protected resources.
References:
- Patch Commit
- VulnCheck Advisory: OpenClaw < 2026.3.25 - Authorization Bypass via Group Policy Rebinding with Mutable Space displayName
CVE-2026-35648 โ OpenClaw < 2026.3.22 - Policy Bypass via Unvalidated Queued Node Actions
| Field | Detail |
|---|---|
| CVSS | 2.3 (LOW) โ CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N |
| CWE | CWE-367 (CWE-367: Time-of-check Time-of-use (TOCTOU) Race Condition) |
| Affected | < 2026.3.22 |
| Vendor/Product | OpenClaw / OpenClaw |
| Advisory | GHSA-wj55-88gf-x564 |
OpenClaw before 2026.3.22 contains a policy bypass vulnerability where queued node actions are not revalidated against current command policy when delivered. Attackers can exploit stale allowlists or declarations that survive policy tightening to execute unauthorized commands.
References:
- Patch Commit #1
- Patch Commit #2
- VulnCheck Advisory: OpenClaw < 2026.3.22 - Policy Bypass via Unvalidated Queued Node Actions
CVE-2026-41347 โ OpenClaw < 2026.3.31 - Cross-Site Request Forgery via Missing Browser-Origin Validation in HTTP Operator Endpoints
| Field | Detail |
|---|---|
| CVSS | 2.3 (LOW) โ CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:L |
| CWE | CWE-352 (CWE-352 Cross-Site Request Forgery (CSRF)) |
| Affected | < 2026.3.31 |
| Vendor/Product | OpenClaw / OpenClaw |
| Advisory | GHSA-mhr7-2xmv-4c4q |
OpenClaw before 2026.3.31 lacks browser-origin validation in HTTP operator endpoints when operating in trusted-proxy mode, allowing cross-site request forgery attacks. Attackers can exploit this by sending malicious requests from a browser in trusted-proxy deployments to perform unauthorized actions on HTTP operator endpoints.
References:
- Patch Commit
- VulnCheck Advisory: OpenClaw < 2026.3.31 - Cross-Site Request Forgery via Missing Browser-Origin Validation in HTTP Operator Endpoints
CVE-2026-41358 โ OpenClaw < 2026.4.2 - Sender Allowlist Bypass via Slack Thread Context
| Field | Detail |
|---|---|
| CVSS | 2.3 (LOW) โ CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N |
| CWE | CWE-346 (CWE-346: Origin Validation Error) |
| Affected | < 2026.4.2 |
| Vendor/Product | OpenClaw / OpenClaw |
| Advisory | GHSA-qm77-8qjp-4vcm |
OpenClaw before 2026.4.2 fails to filter Slack thread context by sender allowlist, allowing non-allowlisted messages to enter agent context. Attackers can inject unauthorized thread messages through allowlisted user replies to bypass sender access controls and manipulate model context.
References:
- Patch Commit
- VulnCheck Advisory: OpenClaw < 2026.4.2 - Sender Allowlist Bypass via Slack Thread Context
CVE-2026-41916 โ OpenClaw < 2026.4.8 - Stale Authentication State via Config Reload
| Field | Detail |
|---|---|
| CVSS | 2.3 (LOW) โ CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N |
| CWE | CWE-613 (CWE-613: Insufficient Session Expiration) |
| Affected | < 2026.4.8 |
| Vendor/Product | OpenClaw / OpenClaw |
| Advisory | GHSA-68x5-xx89-w9mm |
OpenClaw before 2026.4.8 contains an authentication state management vulnerability where the resolvedAuth closure becomes stale after configuration reload. Newly accepted gateway connections continue using outdated resolved auth state, allowing attackers to bypass authentication controls through config reload operations.
References:
CVE-2026-41908 โ OpenClaw < 2026.4.20 - Scope Enforcement Bypass in Assistant-Media Route
| Field | Detail |
|---|---|
| CVSS | 2.3 (LOW) โ CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N |
| CWE | CWE-863 (CWE-863 Incorrect Authorization) |
| Affected | < 2026.4.20 |
| Vendor/Product | OpenClaw / OpenClaw |
| Advisory | GHSA-v8qf-fr4g-28p2 |
OpenClaw before 2026.4.20 contains a scope enforcement bypass vulnerability in the assistant-media route that allows trusted-proxy callers without operator.read scope to access protected assistant-media files and metadata. Attackers can bypass identity-bearing HTTP auth path scope validation to retrieve sensitive media content within allowed media roots.
References:
CVE-2026-44111 โ OpenClaw < 2026.4.15 - Arbitrary Markdown File Read via QMD memory_get
| Field | Detail |
|---|---|
| CVSS | 2.3 (LOW) โ CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N |
| CWE | CWE-183 (CWE-183: Permissive List of Allowed Inputs) |
| Affected | < 2026.4.15 |
| Vendor/Product | OpenClaw / OpenClaw |
| Advisory | GHSA-f934-5rqf-xx47 |
OpenClaw before 2026.4.15 contains an arbitrary file read vulnerability in the QMD backend memory_get function that allows callers to read any Markdown files within the workspace root. Attackers with access to the memory tool can bypass path restrictions by providing arbitrary workspace Markdown paths to read files outside canonical memory locations or indexed QMD result sets.
References:
- Patch Commit
- VulnCheck Advisory: OpenClaw < 2026.4.15 - Arbitrary Markdown File Read via QMD memory_get
CVE-2026-44993 โ OpenClaw < 2026.4.20 - Direct Message Misclassification in Feishu Card Actions
| Field | Detail |
|---|---|
| CVSS | 2.3 (LOW) โ CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N |
| CWE | CWE-184 (Incomplete List of Disallowed Inputs) |
| Affected | < 2026.4.20 |
| Vendor/Product | OpenClaw / OpenClaw |
| Advisory | GHSA-72q8-jcmc-97wx |
OpenClaw before 2026.4.20 contains a message classification vulnerability in Feishu card-action callbacks that misclassifies direct messages as group conversations. Attackers can bypass dmPolicy enforcement by triggering card-action flows in direct message conversations that should have been blocked by restrictive policies.
References:
- Patch Commit
- VulnCheck Advisory: OpenClaw < 2026.4.20 - Direct Message Misclassification in Feishu Card Actions
CVE-2026-44997 โ OpenClaw < 2026.4.22 - Security Envelope Constraint Bypass in ACP Child Sessions
| Field | Detail |
|---|---|
| CVSS | 2.3 (LOW) โ CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N |
| CWE | CWE-266 (Incorrect Privilege Assignment) |
| Affected | < 2026.4.22 |
| Vendor/Product | OpenClaw / OpenClaw |
| Advisory | GHSA-q3jj-46pq-826r |
OpenClaw before 2026.4.22 contains a security envelope constraint bypass vulnerability allowing restricted subagents to spawn ACP child sessions that fail to inherit depth, child-count limits, control scope, or target-agent restrictions. Attackers can exploit this by spawning child sessions that bypass subagent-only constraints, potentially escalating privileges or accessing restricted resources.
References:
- Patch Commit
- VulnCheck Advisory: OpenClaw < 2026.4.22 - Security Envelope Constraint Bypass in ACP Child Sessions
CVE-2026-44991 โ OpenClaw: Owner-enforced commands could accept wildcard channel senders as command owners
| Field | Detail |
|---|---|
| CVSS | 2.3 (LOW) โ CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N |
| CWE | CWE-863 (Incorrect Authorization) |
| Affected | < 2026.4.21 |
| Vendor/Product | OpenClaw / OpenClaw |
| Advisory | GHSA-c28g-vh7m-fm7v |
OpenClaw before 2026.4.21 contains an authorization bypass vulnerability in command-auth.ts that allows non-owner senders to execute owner-enforced slash commands when wildcard inbound senders are configured without explicit owner allowFrom settings. Attackers can exploit this by sending commands like /send, /config, or /debug on affected channels to bypass owner-only command authorization checks.
References:
- Patch Commit (1)
- Patch Commit (2)
- VulnCheck Advisory: OpenClaw < 2026.4.21 - Authorization Bypass in Owner-Enforced Commands via Wildcard Channel Senders
CVE-2026-53826 โ OpenClaw < 2026.4.26 - Information Disclosure via Sandboxed Session Spawn
| Field | Detail |
|---|---|
| CVSS | 2.3 (LOW) โ CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N |
| CWE | CWE-668 (Exposure of Resource to Wrong Sphere) |
| Affected | < 2026.4.26 |
| Vendor/Product | OpenClaw / OpenClaw |
| Advisory | GHSA-6c4r-g249-wv3c |
OpenClaw before 2026.4.26 contains an information disclosure vulnerability in sandboxed session spawning that exposes the real workspace path to child prompts. Attackers can exploit this by spawning child sessions from sandboxed parents to reveal host workspace location or related memory context to child models.
References:
CVE-2026-31991 โ OpenClaw < 2026.2.26 - Authorization Bypass via DM Pairing-Store Leakage in Signal Group Allowlist
| Field | Detail |
|---|---|
| CVSS | 2 (LOW) โ CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N |
| CWE | CWE-863 (CWE-863: Incorrect Authorization) |
| Affected | < 2026.2.26 |
| Vendor/Product | OpenClaw / OpenClaw |
| Advisory | GHSA-wm8r-w8pf-2v6w |
OpenClaw versions prior to 2026.2.26 contain an authorization bypass vulnerability where Signal group allowlist policy incorrectly accepts sender identities from DM pairing-store approvals. Attackers can exploit this boundary weakness by obtaining DM pairing approval to bypass group allowlist checks and gain unauthorized group access.
References:
- Patch Commit
- Patch Commit
- VulnCheck Advisory: OpenClaw < 2026.2.26 - Authorization Bypass via DM Pairing-Store Leakage in Signal Group Allowlist
CVE-2026-32058 โ OpenClaw < 2026.2.26 - Approval Context-Binding Weakness in system.run via host=node
| Field | Detail |
|---|---|
| CVSS | 2 (LOW) โ CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N |
| CWE | CWE-863 (CWE-863: Incorrect Authorization) |
| Affected | < 2026.2.26 |
| Vendor/Product | OpenClaw / OpenClaw |
| Advisory | GHSA-hjvp-qhm6-wrh2 |
OpenClaw versions prior to 2026.2.26 contain an approval context-binding weakness in system.run execution flows with host=node that allows reuse of previously approved requests with modified environment variables. Attackers with access to an approval id can exploit this by reusing an approval with changed env input, bypassing execution-integrity controls in approval-enabled workflows.
References:
- Patch Commit
- VulnCheck Advisory: OpenClaw < 2026.2.26 - Approval Context-Binding Weakness in system.run via host=node
โณ CVE Publication Pipeline
Of 48 GHSAs with CVE IDs, 48 are fully published and 0 remain RESERVED.
graph LR
A["1๏ธโฃ GitHub Reserves<br/>CVE ID<br/><b>RESERVED</b>"] --> B["2๏ธโฃ GHSA Goes Public<br/>with CVE ID Shown"]
B --> C["3๏ธโฃ CNA Submits<br/>CVE Record via<br/>CVE Services<br/><b>PUBLISHED</b>"]
C --> D["4๏ธโฃ cvelistV5 Bot<br/>Commits JSON File"]
style A fill:#fee,stroke:#c33,color:#333
style B fill:#fff3cd,stroke:#856404,color:#333
style C fill:#d4edda,stroke:#155724,color:#333
style D fill:#cce5ff,stroke:#004085,color:#333
| CVE ID | State | cvelistV5 | GHSA Published | CNA |
|---|---|---|---|---|
| CVE-2026-24763 | โ PUBLISHED | โ | 2026-02-02 | GitHub_M |
| CVE-2026-25157 | โ PUBLISHED | โ | 2026-02-02 | GitHub_M |
| CVE-2026-25253 | โ PUBLISHED | โ | 2026-02-02 | mitre |
| CVE-2026-26317 | โ PUBLISHED | โ | 2026-02-18 | GitHub_M |
| CVE-2026-26328 | โ PUBLISHED | โ | 2026-02-18 | GitHub_M |
| CVE-2026-28452 | โ PUBLISHED | โ | 2026-02-18 | VulnCheck |
| CVE-2026-28458 | โ PUBLISHED | โ | 2026-02-17 | VulnCheck |
| CVE-2026-28469 | โ PUBLISHED | โ | 2026-02-18 | VulnCheck |
| CVE-2026-28478 | โ PUBLISHED | โ | 2026-02-18 | VulnCheck |
| CVE-2026-28480 | โ PUBLISHED | โ | 2026-02-18 | VulnCheck |
| CVE-2026-29612 | โ PUBLISHED | โ | 2026-02-18 | VulnCheck |
| CVE-2026-41358 | โ PUBLISHED | โ | 2026-05-04 | VulnCheck |
| CVE-2026-41389 | โ PUBLISHED | โ | 2026-04-17 | VulnCheck |
| CVE-2026-41908 | โ PUBLISHED | โ | 2026-04-25 | VulnCheck |
| CVE-2026-42433 | โ PUBLISHED | โ | 2026-04-17 | VulnCheck |
| CVE-2026-42434 | โ PUBLISHED | โ | 2026-04-17 | VulnCheck |
| CVE-2026-42438 | โ PUBLISHED | โ | 2026-04-17 | VulnCheck |
| CVE-2026-42439 | โ PUBLISHED | โ | 2026-04-17 | VulnCheck |
| CVE-2026-43526 | โ PUBLISHED | โ | 2026-04-17 | VulnCheck |
| CVE-2026-43527 | โ PUBLISHED | โ | 2026-04-17 | VulnCheck |
| CVE-2026-43530 | โ PUBLISHED | โ | 2026-04-17 | VulnCheck |
| CVE-2026-43533 | โ PUBLISHED | โ | 2026-04-17 | VulnCheck |
| CVE-2026-43567 | โ PUBLISHED | โ | 2026-04-17 | VulnCheck |
| CVE-2026-43569 | โ PUBLISHED | โ | 2026-04-17 | VulnCheck |
| CVE-2026-43570 | โ PUBLISHED | โ | 2026-05-05 | VulnCheck |
| CVE-2026-43571 | โ PUBLISHED | โ | 2026-04-17 | VulnCheck |
| CVE-2026-43573 | โ PUBLISHED | โ | 2026-04-17 | VulnCheck |
| CVE-2026-43576 | โ PUBLISHED | โ | 2026-04-17 | VulnCheck |
| CVE-2026-43580 | โ PUBLISHED | โ | 2026-04-17 | VulnCheck |
| CVE-2026-43582 | โ PUBLISHED | โ | 2026-04-17 | VulnCheck |
| CVE-2026-43585 | โ PUBLISHED | โ | 2026-04-17 | VulnCheck |
| CVE-2026-44109 | โ PUBLISHED | โ | 2026-04-17 | VulnCheck |
| CVE-2026-44110 | โ PUBLISHED | โ | 2026-04-17 | VulnCheck |
| CVE-2026-44112 | โ PUBLISHED | โ | 2026-05-04 | VulnCheck |
| CVE-2026-44113 | โ PUBLISHED | โ | 2026-05-04 | VulnCheck |
| CVE-2026-44114 | โ PUBLISHED | โ | 2026-04-25 | VulnCheck |
| CVE-2026-44116 | โ PUBLISHED | โ | 2026-05-04 | VulnCheck |
| CVE-2026-44117 | โ PUBLISHED | โ | 2026-04-25 | VulnCheck |
| CVE-2026-44118 | โ PUBLISHED | โ | 2026-05-04 | VulnCheck |
| CVE-2026-44991 | โ PUBLISHED | โ | 2026-04-29 | VulnCheck |
| CVE-2026-44992 | โ PUBLISHED | โ | 2026-04-25 | VulnCheck |
| CVE-2026-44995 | โ PUBLISHED | โ | 2026-04-25 | VulnCheck |
| CVE-2026-44997 | โ PUBLISHED | โ | 2026-05-04 | VulnCheck |
| CVE-2026-44999 | โ PUBLISHED | โ | 2026-04-25 | VulnCheck |
| CVE-2026-45002 | โ PUBLISHED | โ | 2026-04-25 | VulnCheck |
| CVE-2026-45003 | โ PUBLISHED | โ | 2026-05-04 | VulnCheck |
| CVE-2026-45004 | โ PUBLISHED | โ | 2026-05-05 | VulnCheck |
| CVE-2026-45005 | โ PUBLISHED | โ | 2026-05-05 | VulnCheck |
๐ Key Insights
| Insight | Detail |
|---|---|
| Dominant Weakness | 43% of categorized issues relate to Allowlist Bypass (40/93) |
| V5 Sync Rate | 48/48 CVE IDs (100%) have full cvelistV5 records |
| Advisory Velocity | 186 security advisories across 2026-02-02 โ 2026-05-11 |
| Top Severity | 4 Critical + 45 High = 49 high-impact issues (26%) |
Vulnerability Categories
| Category | Count | Examples |
|---|---|---|
| OS Command Injection (CWE-78) | 22 | PATH injection, SSH command injection, Docker exec, keychain writes |
| Path Traversal (CWE-22) | 7 | MEDIA: paths, plugin install, browser downloads, Zip Slip, transcript paths |
| SSRF | 11 | Image tool fetch, Feishu extension, attachment/media URLs, IPv6 bypass |
| Auth Bypass / Missing Auth | 4 | WebSocket config.apply, webhook verification, browser relay, sandbox bridge |
| Allowlist Bypass | 40 | Telegram usernames, Matrix displayName, Slack DM, Twitch, voice-call |
| Injection (XSS/CSRF/Prompt) | 6 | XSS in Control UI, prompt injection via Slack/CWD/logs, CSRF |
| Denial of Service | 3 | Unbounded media fetch, webhook body buffering, archive expansion |
๐ All Security Advisories (186)
Critical & High Severity
| GHSA | CVE | Severity | Title | Published |
|---|---|---|---|---|
| GHSA-xpr6-2hgm-4wwp | โ | Duplicate Advisory: OpenClaw vulnerable to arbitrary code execution via attacker-controlled setup-api.js loaded from cwd during env-key resolution | 2026-05-11 | |
| GHSA-9r9j-3r2w-fg3v | โ | Duplicate Advisory: OpenClaw: Workspace dotenv could override runtime-control environment variables | 2026-05-06 | |
| GHSA-35vf-vw9f-q3cr | โ | Duplicate Advisory: OpenClaw: MCP loopback owner context is derived from server-issued bearer tokens | 2026-05-06 | |
| GHSA-m8wm-r5vq-qjpg | โ | Duplicate Advisory: OpenClaw: Gateway HTTP endpoints re-resolve bearer auth after SecretRef rotation | 2026-05-06 | |
| GHSA-xrgf-r9gr-jjjf | โ | Duplicate Advisory: OpenClaw: Exec environment denylist missed high-risk interpreter startup variables | 2026-05-06 | |
| GHSA-cjg8-85gj-v9q2 | โ | Duplicate Advisory: OpenClaw: Feishu webhook and card-action validation now fail closed | 2026-05-06 | |
| GHSA-79rr-5c85-xvw3 | โ | Duplicate Advisory: OpenClaw: Matrix room control-command authorization no longer trusts DM pairing-store entries | 2026-05-06 | |
| GHSA-r39h-4c2p-3jxp | CVE-2026-45004 | OpenClaw vulnerable to arbitrary code execution via attacker-controlled setup-api.js loaded from cwd during env-key resolution | 2026-05-05 | |
| GHSA-cwj3-vqpp-pmxr | โ | OpenClaw's gateway config mutation guard allowed unsafe model-driven config writes | 2026-05-05 | |
| GHSA-r6xh-pqhr-v4xh | CVE-2026-44118 | OpenClaw: MCP loopback owner context is derived from server-issued bearer tokens | 2026-05-04 | |
| GHSA-5mh4-3rv3-fpcf | โ | Duplicate Advisory: OpenClaw: Host exec environment sanitization misses package, registry, Docker, compiler, and TLS override variables | 2026-04-28 | |
| GHSA-5799-3xg7-rfrv | โ | Duplicate Advisory: OpenClaw: SSH sandbox tar upload follows symlinks, enabling arbitrary file write on remote host | 2026-04-28 | |
| GHSA-hxvm-xjvf-93f3 | CVE-2026-44114 | OpenClaw: Workspace dotenv could override runtime-control environment variables | 2026-04-25 | |
| GHSA-394x-274p-mqc6 | โ | Duplicate Advisory: OpenClaw: Gateway operator.write Can Reach Admin-Class Telegram Config and Cron Persistence via send | 2026-04-24 | |
| GHSA-7vq9-42cc-33j4 | โ | Duplicate Advisory: OpenClaw: Device-Paired Node Skips Node Scope Gate โ Host RCE.md | 2026-04-24 | |
| GHSA-gv2f-q4wp-fvh5 | โ | Duplicate Advisory: OpenClaw: CLI Remote Onboarding Persists Unauthenticated Discovery Endpoint and Exfiltrates Gateway Credentials | 2026-04-24 | |
| GHSA-jx3c-247h-cxwp | โ | Duplicate Advisory: OpenClaw: Workspace .env can override the bundled hooks root and load attacker hook code | 2026-04-24 | |
| GHSA-xh72-v6v9-mwhc | CVE-2026-44109 | OpenClaw: Feishu webhook and card-action validation now fail closed | 2026-04-17 | |
| GHSA-2gvc-4f3c-2855 | CVE-2026-44110 | OpenClaw: Matrix room control-command authorization no longer trusts DM pairing-store entries | 2026-04-17 | |
| GHSA-xmxx-7p24-h892 | CVE-2026-43585 | OpenClaw: Gateway HTTP endpoints re-resolve bearer auth after SecretRef rotation | 2026-04-17 | |
| GHSA-66r7-m7xm-v49h | CVE-2026-43533 | OpenClaw: QQBot media tags could read arbitrary local files through reply text | 2026-04-17 | |
| GHSA-2cq5-mf3v-mx44 | CVE-2026-43530 | OpenClaw: busybox and toybox applet execution weakened exec approval binding | 2026-04-17 | |
| GHSA-7jp6-r74r-995q | CVE-2026-42433 | OpenClaw: Matrix profile config persistence was reachable from operator.write message tools | 2026-04-17 | |
| GHSA-736r-jwj6-4w23 | CVE-2026-42434 | OpenClaw: Sandboxed agents could escape exec routing via host=node override | 2026-04-17 | |
| GHSA-939r-rj45-g2rj | CVE-2026-43569 | OpenClaw: Workspace provider auth choices could auto-enable untrusted provider plugins | 2026-04-17 | |
| GHSA-82qx-6vj7-p8m2 | CVE-2026-43571 | OpenClaw: Channel setup catalog lookups could include untrusted workspace plugin shadows | 2026-04-17 | |
| GHSA-525j-hqq2-66r4 | โ | OpenClaw: Sandbox browser CDP relay could expose DevTools protocol on 0.0.0.0 | 2026-04-17 | |
| GHSA-rq6g-px6m-c248 | CVE-2026-28469 | OpenClaw Google Chat shared-path webhook target ambiguity allowed cross-account policy-context misrouting | 2026-02-18 | |
| GHSA-3fqr-4cg8-h96q | CVE-2026-26317 | OpenClaw affected by cross-site request forgery (CSRF) through loopback browser mutation endpoints | 2026-02-18 | |
| GHSA-q447-rj3r-2cgh | CVE-2026-28478 | OpenClaw affected by denial of service via unbounded webhook request body buffering | 2026-02-18 | |
| GHSA-mr32-vwc2-5j6h | CVE-2026-28458 | OpenClaw's Browser Relay /cdp websocket is missing auth which could allow cross-tab cookie access | 2026-02-17 | |
| GHSA-q284-4pvr-m585 | CVE-2026-25157 | OpenClaw/Clawdbot has OS Command Injection via Project Root Path in sshNodeCommand | 2026-02-02 | |
| GHSA-g8p2-7wf7-98mq | CVE-2026-25253 | OpenClaw/Clawdbot has 1-Click RCE via Authentication Token Exfiltration From gatewayUrl | 2026-02-02 | |
| GHSA-mc68-q9jw-2h3v | CVE-2026-24763 | OpenClaw/Clawdbot Docker Execution has Authenticated Command Injection via PATH Environment Variable | 2026-02-02 | |
| GHSA-r2c6-8jc8-g32w | โ | Duplicate Advisory: 1-Click RCE via Authentication Token Exfiltration From gatewayUrl | 2026-02-02 |
Medium Severity
| GHSA | CVE | Severity | Title | Published |
|---|---|---|---|---|
| GHSA-v8j2-5f9p-fmh4 | โ | Duplicate Advisory: OpenClaw's Webhooks SecretRef route secret remains valid after rotation/reload | 2026-05-11 | |
| GHSA-5jgm-f9wr-9qm7 | โ | Duplicate Advisory: OpenClaw: Workspace dotenv files cannot override connector endpoint hosts | 2026-05-11 | |
| GHSA-9j32-3m66-mc4m | โ | Duplicate Advisory: OpenClaw: Hook mapping templates could bypass hook session-key opt-in | 2026-05-11 | |
| GHSA-m5j2-r859-r5cv | โ | Duplicate Advisory: OpenClaw: Isolated cron awareness events were recorded as trusted system events | 2026-05-11 | |
| GHSA-4mhr-cxr4-2prm | โ | Duplicate Advisory: OpenClaw: Workspace dotenv MiniMax host override could redirect credentialed requests | 2026-05-11 | |
| GHSA-p3m6-jr2h-hhxj | โ | Duplicate Advisory: OpenClaw: MCP stdio server env could load dangerous startup variables from workspace config | 2026-05-11 | |
| GHSA-6f72-9gxx-98mj | โ | Duplicate Advisory: OpenClaw: OpenShell FS bridge writes stay pinned to the sandbox mount root | 2026-05-06 | |
| GHSA-frr5-j3mh-h9ch | โ | Duplicate Advisory: OpenClaw: OpenShell FS bridge reads pin and verify the opened file before returning bytes | 2026-05-06 | |
| GHSA-qvmw-h675-h7qg | โ | Duplicate Advisory: OpenClaw validates Zalo outbound photo URLs through the SSRF guard | 2026-05-06 | |
| GHSA-r747-33r4-rmjw | โ | Duplicate Advisory: OpenClaw: QQBot direct media upload skipped URL SSRF validation | 2026-05-06 | |
| GHSA-82rm-qcfx-2v78 | โ | Duplicate Advisory: OpenClaw: Delivery queue recovery could lose group tool-policy context for media replay | 2026-05-06 | |
| GHSA-w7rc-vvgx-pj45 | โ | Duplicate Advisory: OpenClaw: Browser SSRF hostname validation could be bypassed by DNS rebinding | 2026-05-06 | |
| GHSA-3r56-7hhr-vfg9 | โ | Duplicate Advisory: OpenClaw: CDP /json/version WebSocket URL could pivot to untrusted second-hop targets | 2026-05-06 | |
| GHSA-wwwc-f646-vj2j | โ | Duplicate Advisory: OpenClaw: Browser press/type interaction routes missed complete navigation guard coverage | 2026-05-06 | |
| GHSA-q8ff-7ffm-m3r9 | CVE-2026-45005 | OpenClaw's Webhooks SecretRef route secret remains valid after rotation/reload | 2026-05-05 | |
| GHSA-35mw-5vvr-vrxc | CVE-2026-43570 | OpenClaw contains a symlink traversal vulnerability | 2026-05-05 | |
| GHSA-5h3g-6xhh-rg6p | CVE-2026-44113 | OpenClaw: OpenShell FS bridge reads pin and verify the opened file before returning bytes | 2026-05-04 | |
| GHSA-wppj-c6mr-83jj | CVE-2026-44112 | OpenClaw: OpenShell FS bridge writes stay pinned to the sandbox mount root | 2026-05-04 | |
| GHSA-55cf-xx38-4p9p | CVE-2026-45003 | OpenClaw: Workspace dotenv files cannot override connector endpoint hosts | 2026-05-04 | |
| GHSA-q3jj-46pq-826r | CVE-2026-44997 | OpenClaw's ACP child sessions inherit subagent security envelope constraints | 2026-05-04 | |
| GHSA-2hh7-c75g-qj2r | CVE-2026-44116 | OpenClaw validates Zalo outbound photo URLs through the SSRF guard | 2026-05-04 | |
| GHSA-93rg-2xm5-2p9v | โ | OpenClaw's Gateway Control UI bootstrap config required Gateway auth | 2026-05-04 | |
| GHSA-x3h8-jrgh-p8jx | โ | OpenClaw's exec allowlist analysis rejects shell expansion in unquoted heredocs | 2026-05-04 | |
| GHSA-c28g-vh7m-fm7v | CVE-2026-44991 | OpenClaw: Owner-enforced commands could accept wildcard channel senders as command owners | 2026-04-29 | |
| GHSA-gfg9-5357-hv4c | โ | OpenClaw: Webchat audio embedding could read local files without local-root containment | 2026-04-29 | |
| GHSA-f5fm-9jmp-c88r | โ | Duplicate Advisory: OpenClaw: Trailing-dot localhost CDP hosts could bypass remote loopback protections | 2026-04-28 | |
| GHSA-8pf2-vj79-4wxg | โ | Duplicate Advisory: OpenClaw: MSTeams thread history bypasses sender allowlist via Graph API | 2026-04-28 | |
| GHSA-qp56-gp47-jwj3 | โ | Duplicate Advisory: OpenClaw: Feishu extension resolveUploadInput bypasses file-system sandbox and allows arbitrary file reads via upload_image | 2026-04-28 | |
| GHSA-h2vw-ph2c-jvwf | CVE-2026-44992 | OpenClaw: Workspace dotenv MiniMax host override could redirect credentialed requests | 2026-04-25 | |
| GHSA-c4qg-j8jg-42q5 | CVE-2026-44117 | OpenClaw: QQBot direct media upload skipped URL SSRF validation | 2026-04-25 | |
| GHSA-mj59-h3q9-ghfh | CVE-2026-44995 | OpenClaw: MCP stdio server env could load dangerous startup variables from workspace config | 2026-04-25 | |
| GHSA-2xcp-x87w-q377 | CVE-2026-45002 | OpenClaw: Hook mapping templates could bypass hook session-key opt-in | 2026-04-25 | |
| GHSA-7jm2-g593-4qrc | โ | OpenClaw: Agent gateway config mutations could change protected operator settings | 2026-04-25 | |
| GHSA-qrp5-gfw2-gxv4 | โ | OpenClaw: Bundled MCP/LSP tools could bypass configured tool policy | 2026-04-25 | |
| GHSA-72q8-jcmc-97wx | โ | OpenClaw: Feishu card actions could misclassify DMs and skip dmPolicy | 2026-04-25 | |
| GHSA-m563-373q-885c | โ | Duplicate Advisory: OpenClaw: OpenShell mirror mode can convert untrusted sandbox files into explicitly enabled workspace hooks and execute them on the host during gateway startup | 2026-04-24 | |
| GHSA-6477-wvjj-47v6 | โ | Duplicate Advisory: OpenClaw: Zalo replay dedupe keys could suppress messages across chats or senders | 2026-04-24 | |
| GHSA-m958-864j-xq5w | โ | Duplicate Advisory: OpenClaw: Telnyx Webhook Replay Detection Bypass via Base64 Signature Re-encoding | 2026-04-24 | |
| GHSA-mf69-r24q-ghhr | โ | Duplicate Advisory: OpenClaw: Pairing pending-request caps were enforced per channel instead of per account | 2026-04-24 | |
| GHSA-v3c2-39fm-jq4h | โ | Duplicate Advisory: OpenClaw: Gateway operator.write can reach admin-only persisted verboseLevel via chat.send /verbose | 2026-04-24 | |
| GHSA-2hv5-4h3g-4hjv | โ | Duplicate Advisory: OpenClaw: LINE webhook handler lacks shared pre-auth concurrency budget before signature verification | 2026-04-24 | |
| GHSA-cw28-63x4-37c3 | โ | Duplicate Advisory: OpenClaw: Voice-call Plivo replay mutates in-process callback origin before replay rejection | 2026-04-24 | |
| GHSA-fjm8-mgc9-mf65 | โ | Duplicate Advisory: OpenClaw Has a Gateway Control Interface Information Disclosure Vulnerability | 2026-04-24 | |
| GHSA-r7p2-r9g4-4xph | โ | Duplicate Advisory: OpenClaw: Gateway hello snapshots exposed host config and state paths to non-admin clients | 2026-04-24 | |
| GHSA-w9f5-8q83-qwpx | โ | Duplicate Advisory: OpenClaw: Fake DeviceToken Bypasses Shared Auth Rate Limiting | 2026-04-24 | |
| GHSA-wcm7-94wg-h74h | โ | Duplicate Advisory: OpenClaw host-env blocklist missing GIT_TEMPLATE_DIR and AWS_CONFIG_FILE allows code execution via env override | 2026-04-24 | |
| GHSA-qc5j-2mqx-x83q | โ | Duplicate Advisory: OpenClaw: Webchat media embedding enforces local-root containment for tool-result files | 2026-04-20 | |
| GHSA-mr34-9552-qr95 | CVE-2026-41389 | OpenClaw: Webchat media embedding enforces local-root containment for tool-result files | 2026-04-17 | |
| GHSA-f7fh-qg34-x2xh | CVE-2026-43576 | OpenClaw: CDP /json/version WebSocket URL could pivot to untrusted second-hop targets | 2026-04-17 | |
| GHSA-jhpv-5j76-m56h | CVE-2026-42438 | OpenClaw: Sender policy bypass in host media attachment reads allows unauthorized local file disclosure | 2026-04-17 | |
| GHSA-536q-mj95-h29h | CVE-2026-43580 | OpenClaw: Browser press/type interaction routes missed complete navigation guard coverage | 2026-04-17 | |
| GHSA-527m-976r-jf79 | CVE-2026-43573 | OpenClaw: Existing-session browser interaction routes bypassed SSRF policy enforcement | 2026-04-17 | |
| GHSA-rj2p-j66c-mgqh | CVE-2026-42439 | OpenClaw: Browser tabs action select and close routes bypassed SSRF policy | 2026-04-17 | |
| GHSA-jf25-7968-h2h5 | CVE-2026-43567 | OpenClaw: screen_record outPath bypassed workspace-only filesystem guard | 2026-04-17 | |
| GHSA-53vx-pmqw-863c | CVE-2026-43527 | OpenClaw: Browser SSRF policy default allowed private-network navigation | 2026-04-17 | |
| GHSA-xq94-r468-qwgj | CVE-2026-43582 | OpenClaw: Browser SSRF hostname validation could be bypassed by DNS rebinding | 2026-04-17 | |
| GHSA-2767-2q9v-9326 | CVE-2026-43526 | OpenClaw: QQBot reply media URL handling could trigger SSRF and re-upload fetched bytes | 2026-04-17 | |
| GHSA-f934-5rqf-xx47 | โ | OpenClaw: QMD memory_get restricts reads to canonical or indexed memory paths | 2026-04-17 | |
| GHSA-qmwg-qprg-3j38 | โ | OpenClaw: Browser interaction routes could pivot into local CDP and regain file reads | 2026-04-17 | |
| GHSA-f3h5-h452-vp3j | โ | OpenClaw: Nostr profile mutation routes allowed operator.write config persistence | 2026-04-17 | |
| GHSA-mj5r-hh7j-4gxf | CVE-2026-28480 | OpenClaw Telegram allowlist authorization accepted mutable usernames | 2026-02-18 | |
| GHSA-h89v-j3x9-8wqj | CVE-2026-28452 | OpenClaw affected by denial of service through unguarded archive extraction allowing high expansion/resource abuse (ZIP/TAR) | 2026-02-18 | |
| GHSA-w2cg-vxx6-5xjg | CVE-2026-29612 | OpenClaw: denial of service through large base64 media files allocating large buffers before limit checks | 2026-02-18 | |
| GHSA-g34w-4xqq-h79m | CVE-2026-26328 | OpenClaw iMessage group allowlist authorization inherited DM pairing-store identities | 2026-02-18 |
Low Severity
| GHSA | CVE | Severity | Title | Published |
|---|---|---|---|---|
| GHSA-p3pv-c954-9m6f | โ | Duplicate Advisory: OpenClaw: Owner-enforced commands could accept wildcard channel senders as command owners | 2026-05-11 | |
| GHSA-w626-296m-8f85 | โ | Duplicate Advisory: OpenClaw's ACP child sessions inherit subagent security envelope constraints | 2026-05-11 | |
| GHSA-qm77-8qjp-4vcm | CVE-2026-41358 | OpenClaw: Slack thread context could include messages from non-allowlisted senders | 2026-05-04 | |
| GHSA-57r2-h2wj-g887 | CVE-2026-44999 | OpenClaw: Isolated cron awareness events were recorded as trusted system events | 2026-04-25 | |
| GHSA-v8qf-fr4g-28p2 | CVE-2026-41908 | OpenClaw: Assistant media route missed scope enforcement for trusted-proxy authorization | 2026-04-25 | |
| GHSA-j4c5-89f5-f3pm | โ | OpenClaw: Browser CDP profile creation skipped strict-mode SSRF checks | 2026-04-25 | |
| GHSA-xrq9-jm7v-g9h7 | โ | OpenClaw: Paired-device pairing actions were not limited to the caller device | 2026-04-25 | |
| GHSA-7hrg-5w46-5r2x | โ | Duplicate Advisory: OpenClaw: Slack thread context could include messages from non-allowlisted senders | 2026-04-24 | |
| GHSA-wwc3-c577-533m | โ | Duplicate Advisory: OpenClaw: Gateway device.token.rotate does not terminate active WebSocket sessions after credential rotation | 2026-04-24 | |
| GHSA-qgp3-3rj7-qqq4 | โ | Duplicate Advisory: OpenClaw: Discord Slash Commands Bypass Group DM Channel Allowlist | 2026-04-24 | |
| GHSA-2xp4-qhr4-xqm2 | โ | Duplicate Advisory: OpenClaw: HTTP operator endpoints lack browser-origin validation in trusted-proxy mode | 2026-04-24 | |
| GHSA-pr66-whqj-rq5p | โ | Duplicate Advisory: OpenClaw: Discord Component Interaction Misclassifies Group DM as Direct Message | 2026-04-24 | |
| GHSA-qgx9-6px9-7p75 | โ | Duplicate Advisory: OpenClaw: Assistant media route missed scope enforcement for trusted-proxy authorization | 2026-04-23 | |
| GHSA-chm2-m3w2-wcxm | โ | OpenClaw Google Chat spoofing access with allowlist authorized mutable email principal despite sender-ID mismatch | 2026-02-17 |
Repo-Only Advisories (~73 more)
These advisories are listed on the repo security page but not yet indexed in the GitHub Advisory Database. See the full advisory list for details.
Show 73 repo-only advisories
| GHSA | Severity | Title | Published |
|---|---|---|---|
| GHSA-2hfg-4fh4-qp7f | Browser act interactions could bypass private-network navigation checks | 2026-05-28 | |
| GHSA-3c6j-hq33-3jv4 | Paired nodes could forge exec lifecycle events without system.run provenance | 2026-05-28 | |
| GHSA-6fvr-66p3-3qj4 | Hook-triggered CLI runs could receive owner MCP tool authority | 2026-05-28 | |
| GHSA-8372-7vhw-cm6q | config.get redaction bypass through sourceConfig and runtimeConfig aliases | 2026-04-16 | |
| GHSA-chr9-m4q2-76hw | Control UI locality spoofing could mint a durable admin device token | 2026-05-28 | |
| GHSA-hw9r-h9mr-4jff | Scoped chat.send route inheritance could bypass admin command scope gates | 2026-05-28 | |
| GHSA-mgq6-vr84-7m2j | QQBot native approval buttons did not enforce configured approver identity | 2026-05-28 | |
| GHSA-mhq8-78pj-5j79 | POSIX node system.run safe-bin allowlist could be widened by shell expansion | 2026-05-28 | |
| GHSA-q99w-vh6v-q3v7 | Pairing-scoped device session could restore revoked node token authority | 2026-05-28 | |
| GHSA-qjpc-qf9m-xwmr | Trusted-proxy Control UI WebSocket accepted client-declared scopes before pairing | 2026-05-28 | |
| GHSA-rjxq-qqhf-8hwh | MCP Streamable HTTP redirects could forward configured custom headers to another origin | 2026-05-28 | |
| GHSA-v2ww-5rh7-2h5v | Linux and macOS exec allowlists skipped configured argument patterns | 2026-05-28 | |
| GHSA-xr4f-mjxj-w6w5 | Non-owner chat senders could issue device-pairing bootstrap codes | 2026-05-28 | |
| GHSA-xww8-gqvh-92x9 | Exec approval display truncation could hide the command being approved | 2026-05-28 | |
| GHSA-24vr-rprv-67rf | Workspace .env npm_execpath could influence bundled runtime dependency install | 2026-05-28 | |
| GHSA-275c-xpvc-jgfw | Slack and Zalo webhook secrets could remain active after secrets.reload | 2026-05-28 | |
| GHSA-2j8v-hwgc-x698 | Shell wrapper argv could change between approval and execution | 2026-05-28 | |
| GHSA-4hpg-mp64-x7xq | Internal/webchat command auth could inherit ownerAllowFrom wildcard state | 2026-05-28 | |
| GHSA-4m3v-q747-pc6h | Mattermost slash token revocation could lag until monitor refresh | 2026-05-28 | |
| GHSA-5cj2-3jr2-5h77 | Shell positional parameters could weaken strict inline-eval checks | 2026-05-28 | |
| GHSA-6c4r-g249-wv3c | Sandboxed session spawn could expose the real workspace path to child prompts | 2026-05-28 | |
| GHSA-72fw-cqh5-f324 | memory-wiki shared search could miss session visibility checks | 2026-05-28 | |
| GHSA-77pv-3w4q-vrj5 | QQBot pre-dispatch slash commands could skip allowFrom checks | 2026-05-28 | |
| GHSA-77q5-rr5v-x43q | Trusted retry endpoint checks could match hostname prefixes | 2026-05-28 | |
| GHSA-7hxm-f538-3xp6 | Matrix allowFrom could bind to mutable display names | 2026-05-28 | |
| GHSA-83w9-h5wv-j9xm | Node pairing reconnection could confuse approval scope state | 2026-05-28 | |
| GHSA-8c59-hr4w-qg69 | Zalo allowFrom could bind to mutable display names | 2026-05-28 | |
| GHSA-8mg9-j9cf-54cj | Empty-scope device re-pairing could confuse caller scope containment | 2026-05-28 | |
| GHSA-8wg3-5mcm-fjq8 | Workspace .env could override Homebrew executable selection for skill install flows | 2026-05-28 | |
| GHSA-985f-72mj-8gf7 | Tool group policy callers could accept unvalidated group IDs | 2026-05-28 | |
| GHSA-9v8j-9c9g-w66c | Bootstrap token replay could widen pending pairing scopes | 2026-05-28 | |
| GHSA-c226-q6fx-6j6c | macOS Swift exec allowlist missed combined POSIX inline flags | 2026-05-28 | |
| GHSA-c29c-2q9c-pc86 | Slack allowFrom could bind to mutable display names | 2026-05-28 | |
| GHSA-c4qm-58hj-j6pj | Browser snapshot and screenshot routes could expose internal page content after navigation | 2026-04-16 | |
| GHSA-ccwh-wwpp-6wg5 | Host environment sanitizer missed two Node.js control variables | 2026-05-28 | |
| GHSA-cqwv-9qjx-vxw2 | Skill Workshop apply flow could override pending approval | 2026-05-28 | |
| GHSA-cw4q-gqg5-g38h | Discord allowFrom could bind to mutable display names | 2026-05-28 | |
| GHSA-cwpp-5962-q4f6 | Exec allowlist could miss side effects from transparent command wrappers | 2026-05-28 | |
| GHSA-f397-5vjw-v2c2 | Shell inline-command parsing could miss an allowlist check | 2026-05-28 | |
| GHSA-fq9j-vw4w-fr6v | Workspace .env CLOUDSDK_PYTHON could influence Gmail setup gcloud execution | 2026-05-28 | |
| GHSA-g2hm-779g-vm32 | Heartbeat owner downgrade missed untrusted webhook wake events | 2026-04-16 | |
| GHSA-gp79-m99v-gjmh | Mattermost handlers could fall open when channel type was missing | 2026-05-28 | |
| GHSA-grc3-2j34-p6gm | message.action forwarding could send Gateway credentials to model-supplied loopback URLs | 2026-05-28 | |
| GHSA-gxg4-2rrr-jhc7 | Hostname checks could treat trailing-dot hosts inconsistently | 2026-05-28 | |
| GHSA-hcm3-8f6r-6xwg | Browser debug/export routes could reuse already-open blocked tabs | 2026-05-28 | |
| GHSA-j472-gf56-x589 | PowerShell encoded-command aliases could miss exec allowlist checks | 2026-05-28 | |
| GHSA-jvm4-4j77-39p6 | QQBot streaming command could mutate config without explicit allowFrom | 2026-05-28 | |
| GHSA-jwrq-8g5x-5fhm | Collect-mode queue batches could reuse the last sender authorization context | 2026-04-16 | |
| GHSA-mpc8-jxjh-qpgh | Focus command could miss controlScope enforcement | 2026-05-28 | |
| GHSA-p2fh-f5fc-44hr | memory-wiki ingest could read local files with operator.write scope | 2026-05-28 | |
| GHSA-p39j-x9h5-q66m | Embedded runner policy could be confused by provider aliases | 2026-05-28 | |
| GHSA-p73f-w79w-jqr5 | Native command authorization could skip owner-command enforcement | 2026-05-28 | |
| GHSA-q7q8-3mgw-q67r | Message read actions could skip channel allowlist checks | 2026-05-28 | |
| GHSA-qh2f-99mv-mrcf | Bundle MCP loopback could miss its exec denylist on session spawn | 2026-05-28 | |
| GHSA-r77c-2cmr-7p47 | Delivery queue recovery could lose group tool-policy context for media replay | 2026-04-16 | |
| GHSA-rggc-m335-3wvj | Same-host trusted-proxy deployments could accept local forged identity headers | 2026-05-28 | |
| GHSA-rj6p-xmxr-qj4h | MCP loopback could skip owner-only tool policy for non-owner callers | 2026-05-28 | |
| GHSA-rwp6-7w3q-75fq | Config recovery could restore openclaw.json with broad file permissions | 2026-05-28 | |
| GHSA-rx78-29qr-5hq8 | Workspace-derived service PATH could influence trash command selection | 2026-05-28 | |
| GHSA-v6r2-jh58-xx6w | Marketplace runtime extension metadata could point at unscanned payloads | 2026-05-28 | |
| GHSA-v8cx-933x-r976 | Fake package roots could influence memory-core artifact loading | 2026-05-28 | |
| GHSA-vxx3-6hc9-7cc3 | Combined POSIX shell options could confuse exec revalidation | 2026-05-28 | |
| GHSA-w4v6-g3wm-w36c | QQBot admin commands could skip DM-only and allowFrom policy | 2026-05-28 | |
| GHSA-w5ww-7chg-mxcq | Telegram interactive callbacks could skip commands.allowFrom | 2026-05-28 | |
| GHSA-w9hf-3pp7-pvxv | Exported session HTML could keep unsafe markdown links | 2026-05-28 | |
| GHSA-wc84-j36w-pw4x | Workspace .env STATE_DIRECTORY could influence bundled runtime dependency roots | 2026-05-28 | |
| GHSA-wv26-j37q-2g7p | Slack plugin approvals used the exec approver gate for plugin actions | 2026-05-28 | |
| GHSA-x629-46cc-7xgw | Active Memory write scope could mutate global config | 2026-05-28 | |
| GHSA-3wqp-prf6-2m72 | Feishu dynamic-agent bindings could miss configWrites enforcement | 2026-05-28 | |
| GHSA-68xw-r643-9p5w | Skill-command dispatch could skip before-tool-call hooks | 2026-05-28 | |
| GHSA-8j37-5w68-wj2g | BlueBubbles sender policy could match mutable conversation identifiers | 2026-05-28 | |
| GHSA-fcvx-5cxc-v5p8 | Slack reaction events could ignore reaction notification settings | 2026-05-28 | |
| GHSA-gc9r-867r-j85f | Microsoft Teams SSO invoke handler missed sender authorization checks | 2026-04-16 |
Naming Inconsistencies
The OpenClaw project has been renamed multiple times, causing inconsistencies across CVE records:
| CVE | vendor | product | packageURL | Description Names |
|---|---|---|---|---|
| CVE-2026-28466 | OpenClaw | OpenClaw | pkg:npm/openclaw | OpenClaw |
| CVE-2026-43534 | OpenClaw | OpenClaw | pkg:npm/openclaw | OpenClaw |
| CVE-2026-32918 | OpenClaw | OpenClaw | pkg:npm/openclaw | OpenClaw |
| CVE-2026-32917 | OpenClaw | OpenClaw | pkg:npm/openclaw | OpenClaw |
| CVE-2026-43585 | OpenClaw | OpenClaw | pkg:npm/openclaw | OpenClaw |
| CVE-2026-44109 | OpenClaw | OpenClaw | pkg:npm/openclaw | OpenClaw |
| CVE-2026-41386 | OpenClaw | OpenClaw | pkg:npm/openclaw | OpenClaw |
| CVE-2026-43533 | OpenClaw | OpenClaw | pkg:npm/openclaw | OpenClaw |
| CVE-2026-25253 | OpenClaw | OpenClaw | pkg:npm/clawdbot | OpenClaw / clawdbot / Moltbot |
| CVE-2026-24763 | clawdbot | clawdbot | โ | OpenClaw (formerly Clawdbot) |
| CVE-2026-32913 | OpenClaw | OpenClaw | pkg:npm/openclaw | OpenClaw |
| CVE-2026-41296 | OpenClaw | OpenClaw | pkg:npm/openclaw | OpenClaw |
| CVE-2026-28478 | OpenClaw | OpenClaw | pkg:npm/openclaw | OpenClaw |
| CVE-2026-32042 | OpenClaw | OpenClaw | pkg:npm/openclaw | OpenClaw |
| CVE-2026-32051 | OpenClaw | OpenClaw | pkg:npm/openclaw | OpenClaw |
| CVE-2026-33573 | OpenClaw | OpenClaw | pkg:npm/openclaw | OpenClaw |
| CVE-2026-41405 | OpenClaw | OpenClaw | pkg:npm/openclaw | OpenClaw |
| CVE-2026-42434 | OpenClaw | OpenClaw | pkg:npm/openclaw | OpenClaw |
| CVE-2026-43530 | OpenClaw | OpenClaw | pkg:npm/openclaw | OpenClaw |
| CVE-2026-44115 | OpenClaw | OpenClaw | pkg:npm/openclaw | OpenClaw |
| CVE-2026-53814 | OpenClaw | OpenClaw | pkg:npm/openclaw | OpenClaw |
| CVE-2026-32920 | OpenClaw | OpenClaw | pkg:npm/openclaw | OpenClaw |
| CVE-2026-33579 | OpenClaw | OpenClaw | pkg:npm/openclaw | OpenClaw |
| CVE-2026-53823 | OpenClaw | OpenClaw | pkg:npm/openclaw | OpenClaw |
| CVE-2026-44118 | OpenClaw | OpenClaw | pkg:npm/openclaw | OpenClaw |
| CVE-2026-44114 | OpenClaw | OpenClaw | pkg:npm/openclaw | OpenClaw |
| CVE-2026-45004 | OpenClaw | OpenClaw | pkg:npm/openclaw | OpenClaw |
| CVE-2026-31998 | OpenClaw | OpenClaw | pkg:npm/openclaw | OpenClaw |
| CVE-2026-35618 | OpenClaw | OpenClaw | pkg:npm/openclaw | OpenClaw |
| CVE-2026-43526 | OpenClaw | OpenClaw | pkg:npm/openclaw | OpenClaw |
| CVE-2026-28469 | OpenClaw | OpenClaw | pkg:npm/openclaw | OpenClaw |
| CVE-2026-29611 | OpenClaw | OpenClaw | pkg:npm/openclaw | OpenClaw |
| CVE-2026-25157 | openclaw | openclaw | โ | OpenClaw |
| CVE-2026-27002 | openclaw | openclaw | โ | OpenClaw |
| CVE-2026-32048 | OpenClaw | OpenClaw | pkg:npm/openclaw | OpenClaw |
| CVE-2026-43569 | OpenClaw | OpenClaw | pkg:npm/openclaw | OpenClaw |
| CVE-2026-43571 | OpenClaw | OpenClaw | pkg:npm/openclaw | OpenClaw |
| CVE-2026-44110 | OpenClaw | OpenClaw | pkg:npm/openclaw | OpenClaw |
| CVE-2026-53807 | OpenClaw | OpenClaw | pkg:npm/openclaw | OpenClaw |
| CVE-2026-41353 | OpenClaw | OpenClaw | pkg:npm/openclaw | OpenClaw |
| CVE-2026-43535 | OpenClaw | OpenClaw | pkg:npm/openclaw | OpenClaw |
| CVE-2026-26316 | openclaw | @openclaw/bluebubbles | โ | OpenClaw |
| CVE-2026-26324 | openclaw | openclaw | โ | OpenClaw |
| CVE-2026-22179 | OpenClaw | OpenClaw | pkg:npm/openclaw | OpenClaw |
| CVE-2026-32025 | OpenClaw | OpenClaw | pkg:npm/openclaw | OpenClaw |
| CVE-2026-28458 | OpenClaw | OpenClaw | pkg:npm/openclaw | OpenClaw |
| CVE-2026-34512 | OpenClaw | OpenClaw | pkg:npm/openclaw | OpenClaw |
| CVE-2026-26317 | openclaw | clawdbot | โ | OpenClaw (formerly Clawdbot) |
| CVE-2026-26327 | openclaw | openclaw | โ | OpenClaw |
| CVE-2026-32008 | OpenClaw | OpenClaw | pkg:npm/openclaw | OpenClaw |
| CVE-2026-32976 | OpenClaw | OpenClaw | pkg:npm/openclaw | OpenClaw |
| CVE-2026-35644 | OpenClaw | OpenClaw | pkg:npm/openclaw | OpenClaw |
| CVE-2026-35636 | OpenClaw | OpenClaw | pkg:npm/openclaw | OpenClaw |
| CVE-2026-41368 | OpenClaw | OpenClaw | pkg:npm/openclaw | OpenClaw |
| CVE-2026-41385 | OpenClaw | OpenClaw | pkg:npm/openclaw | OpenClaw |
| CVE-2026-42433 | OpenClaw | OpenClaw | pkg:npm/openclaw | OpenClaw |
| CVE-2026-43567 | OpenClaw | OpenClaw | pkg:npm/openclaw | OpenClaw |
| CVE-2026-43568 | OpenClaw | OpenClaw | pkg:npm/openclaw | OpenClaw |
| CVE-2026-41380 | OpenClaw | OpenClaw | pkg:npm/openclaw | OpenClaw |
| CVE-2026-43531 | OpenClaw | OpenClaw | pkg:npm/openclaw | OpenClaw |
| CVE-2026-22178 | OpenClaw | OpenClaw | pkg:npm/openclaw | OpenClaw |
| CVE-2026-28480 | OpenClaw | OpenClaw | pkg:npm/openclaw | OpenClaw |
| CVE-2026-32975 | OpenClaw | OpenClaw | pkg:npm/openclaw | OpenClaw |
| CVE-2026-35626 | OpenClaw | OpenClaw | pkg:npm/openclaw | OpenClaw |
| CVE-2026-34426 | OpenClaw | OpenClaw | pkg:npm/openclaw | OpenClaw |
| CVE-2026-35647 | OpenClaw | OpenClaw | pkg:npm/openclaw | OpenClaw |
| CVE-2026-41300 | OpenClaw | OpenClaw | pkg:npm/openclaw | OpenClaw |
| CVE-2026-41331 | OpenClaw | OpenClaw | pkg:npm/openclaw | OpenClaw |
| CVE-2026-35664 | OpenClaw | OpenClaw | pkg:npm/openclaw | OpenClaw |
| CVE-2026-41374 | OpenClaw | OpenClaw | pkg:npm/openclaw | OpenClaw |
| CVE-2026-41400 | OpenClaw | OpenClaw | pkg:npm/openclaw | OpenClaw |
| CVE-2026-44116 | OpenClaw | OpenClaw | pkg:npm/openclaw | OpenClaw |
| CVE-2026-53818 | OpenClaw | OpenClaw | pkg:npm/openclaw | OpenClaw |
| CVE-2026-29612 | OpenClaw | OpenClaw | pkg:npm/openclaw | OpenClaw |
| CVE-2026-26972 | openclaw | openclaw | โ | OpenClaw |
| CVE-2026-28452 | OpenClaw | OpenClaw | pkg:npm/openclaw | OpenClaw |
| CVE-2026-26328 | openclaw | clawdbot | โ | OpenClaw (formerly Clawdbot) |
| CVE-2026-28449 | OpenClaw | OpenClaw | pkg:npm/openclaw | OpenClaw |
| CVE-2026-35628 | OpenClaw | OpenClaw | pkg:npm/openclaw | OpenClaw |
| CVE-2026-35646 | OpenClaw | OpenClaw | pkg:npm/openclaw | OpenClaw |
| CVE-2026-35649 | OpenClaw | OpenClaw | pkg:npm/openclaw | OpenClaw |
| CVE-2026-35635 | OpenClaw | OpenClaw | pkg:npm/openclaw | OpenClaw |
| CVE-2026-41333 | OpenClaw | OpenClaw | pkg:npm/openclaw | OpenClaw |
| CVE-2026-41389 | OpenClaw | OpenClaw | pkg:npm/openclaw | OpenClaw |
| CVE-2026-41913 | OpenClaw | OpenClaw | pkg:npm/openclaw | OpenClaw |
| CVE-2026-43527 | OpenClaw | OpenClaw | pkg:npm/openclaw | OpenClaw |
| CVE-2026-44117 | OpenClaw | OpenClaw | pkg:npm/openclaw | OpenClaw |
| CVE-2026-44999 | OpenClaw | OpenClaw | pkg:npm/openclaw | OpenClaw |
| CVE-2026-45002 | OpenClaw | OpenClaw | pkg:npm/openclaw | OpenClaw |
| CVE-2026-35645 | OpenClaw | OpenClaw | pkg:npm/openclaw | OpenClaw |
| CVE-2026-32039 | OpenClaw | OpenClaw | pkg:npm/openclaw | OpenClaw |
| CVE-2026-35622 | OpenClaw | OpenClaw | pkg:npm/openclaw | OpenClaw |
| CVE-2026-42429 | OpenClaw | OpenClaw | pkg:npm/openclaw | OpenClaw |
| CVE-2026-43570 | OpenClaw | OpenClaw | pkg:npm/openclaw | OpenClaw |
| CVE-2026-44112 | OpenClaw | OpenClaw | pkg:npm/openclaw | OpenClaw |
| CVE-2026-44113 | OpenClaw | OpenClaw | pkg:npm/openclaw | OpenClaw |
| CVE-2026-53830 | OpenClaw | OpenClaw | pkg:npm/openclaw | OpenClaw |
| CVE-2026-53838 | OpenClaw | OpenClaw | pkg:npm/openclaw | OpenClaw |
| CVE-2026-28481 | OpenClaw | OpenClaw | pkg:npm/openclaw | OpenClaw |
| CVE-2026-32054 | OpenClaw | OpenClaw | pkg:npm/openclaw | OpenClaw |
| CVE-2026-45005 | OpenClaw | OpenClaw | pkg:npm/openclaw | OpenClaw |
| CVE-2026-31999 | OpenClaw | OpenClaw | pkg:npm/openclaw | OpenClaw |
| CVE-2026-32000 | OpenClaw | OpenClaw | pkg:npm/openclaw | OpenClaw |
| CVE-2026-31995 | OpenClaw | OpenClaw | pkg:npm/openclaw | OpenClaw |
| CVE-2026-32988 | OpenClaw | OpenClaw | pkg:npm/openclaw | OpenClaw |
| CVE-2026-41332 | OpenClaw | OpenClaw | pkg:npm/openclaw | OpenClaw |
| CVE-2026-41360 | OpenClaw | OpenClaw | pkg:npm/openclaw | OpenClaw |
| CVE-2026-44995 | OpenClaw | OpenClaw | pkg:npm/openclaw | OpenClaw |
| CVE-2026-26326 | openclaw | openclaw | โ | OpenClaw |
| CVE-2026-32899 | OpenClaw | OpenClaw | pkg:npm/openclaw | OpenClaw |
| CVE-2026-41909 | OpenClaw | OpenClaw | pkg:npm/openclaw | OpenClaw |
| CVE-2026-35634 | OpenClaw | OpenClaw | pkg:npm/openclaw | OpenClaw |
| CVE-2026-42436 | OpenClaw | OpenClaw | pkg:npm/openclaw | OpenClaw |
| CVE-2026-42439 | OpenClaw | OpenClaw | pkg:npm/openclaw | OpenClaw |
| CVE-2026-43532 | OpenClaw | OpenClaw | pkg:npm/openclaw | OpenClaw |
| CVE-2026-42438 | OpenClaw | OpenClaw | pkg:npm/openclaw | OpenClaw |
| CVE-2026-43573 | OpenClaw | OpenClaw | pkg:npm/openclaw | OpenClaw |
| CVE-2026-43576 | OpenClaw | OpenClaw | pkg:npm/openclaw | OpenClaw |
| CVE-2026-43580 | OpenClaw | OpenClaw | pkg:npm/openclaw | OpenClaw |
| CVE-2026-43582 | OpenClaw | OpenClaw | pkg:npm/openclaw | OpenClaw |
| CVE-2026-27007 | openclaw | openclaw | โ | OpenClaw |
| CVE-2026-44992 | OpenClaw | OpenClaw | pkg:npm/openclaw | OpenClaw |
| CVE-2026-45003 | OpenClaw | OpenClaw | pkg:npm/openclaw | OpenClaw |
| CVE-2026-32006 | OpenClaw | OpenClaw | pkg:npm/openclaw | OpenClaw |
| CVE-2026-34507 | OpenClaw | OpenClaw | pkg:npm/openclaw | OpenClaw |
| CVE-2026-35617 | OpenClaw | OpenClaw | pkg:npm/openclaw | OpenClaw |
| CVE-2026-35648 | OpenClaw | OpenClaw | pkg:npm/openclaw | OpenClaw |
| CVE-2026-41347 | OpenClaw | OpenClaw | pkg:npm/openclaw | OpenClaw |
| CVE-2026-41358 | OpenClaw | OpenClaw | pkg:npm/openclaw | OpenClaw |
| CVE-2026-41916 | OpenClaw | OpenClaw | pkg:npm/openclaw | OpenClaw |
| CVE-2026-41908 | OpenClaw | OpenClaw | pkg:npm/openclaw | OpenClaw |
| CVE-2026-44111 | OpenClaw | OpenClaw | pkg:npm/openclaw | OpenClaw |
| CVE-2026-44993 | OpenClaw | OpenClaw | pkg:npm/openclaw | OpenClaw |
| CVE-2026-44997 | OpenClaw | OpenClaw | pkg:npm/openclaw | OpenClaw |
| CVE-2026-44991 | OpenClaw | OpenClaw | pkg:npm/openclaw | OpenClaw |
| CVE-2026-53826 | OpenClaw | OpenClaw | pkg:npm/openclaw | OpenClaw |
| CVE-2026-31991 | OpenClaw | OpenClaw | pkg:npm/openclaw | OpenClaw |
| CVE-2026-32058 | OpenClaw | OpenClaw | pkg:npm/openclaw | OpenClaw |
Data Sources
| Source | URL |
|---|---|
| CVE List v5 | CVEProject/cvelistV5 |
| GitHub Advisory DB | github.com/advisories |
| Repo Security Tab | openclaw/openclaw/security |
| CVE Services API | https://cveawg.mitre.org/api/cve-id/{CVE-ID} |
Auto-generated by update_readme.py ยท Updated hourly via GitHub Actions
Data: ghsa-advisories.json ยท cves.json ยท cve-pipeline-status.json
Maintained by Jerry Gamblin ยท OpenClawCVEs