robinfehr/OpenClawCVEs

Tracking OpenClaw CVEs

โ˜… 0Forks 0GitHub โ†—Compare

README

๐Ÿ›ก๏ธ OpenClaw CVE & Security Advisory Tracker

Total Advisories CVEs Assigned CVEs Published Reserved
Critical High Medium Low Awaiting CVE

An automated tracker that continuously monitors OpenClaw security advisories across the GitHub Advisory Database, repo-level security advisories, and the CVE V5 (cvelistV5) registry. Every hour it pulls the latest data, reconciles GHSA โ†’ CVE publication state, and regenerates this dashboard so you always have an up-to-date picture of the project's vulnerability landscape.

Last updated: 2026-04-16 12:32 UTC ยท MIT License ยท Full Advisory List ยท Security Policy ยท Data: cvelistV5 + Advisory DB ยท Updates hourly


Published CVEs ยท Pipeline ยท Advisories ยท Categories ยท Insights ยท Identity


๐Ÿ—๏ธ Project Identity

Field Value
Current Name OpenClaw
Previous Names Moltbot (second name), Clawdbot (original name)
Repository openclaw/openclaw
npm Package openclaw (formerly clawdbot)
Author Peter Steinberger (steipete)
Search terms for CVE discovery

To find all CVEs, search for: openclaw, clawdbot, moltbot, clawhub, pkg:npm/clawdbot, pkg:npm/openclaw


๐Ÿš€ CVEs Published in cvelistV5 (15)

These CVEs have full records in the CVEProject/cvelistV5 repository:

CVE ID Severity CVSS Title CWE Published
CVE-2026-32922 Critical 9.4 OpenClaw < 2026.3.11 - Privilege Escalation via Unvalidated Scope in device.token.rotate CWE-266 2026-03-29
CVE-2026-28474 Critical 9.3 OpenClaw Nextcloud Talk < 2026.2.6 - Allowlist Bypass via actor.name Display Name Spoofing CWE-863 2026-03-05
CVE-2026-32987 Critical 9.3 OpenClaw < 2026.3.13 - Bootstrap Setup Code Replay via Device Pairing CWE-294 2026-03-29
CVE-2026-28391 Critical 9.2 OpenClaw < 2026.2.2 - Command Injection via cmd.exe Parsing Bypass in Allowlist Enforcement CWE-184 2026-03-05
CVE-2026-28446 Critical 9.2 OpenClaw < 2026.2.1 - Inbound Allowlist Policy Bypass in voice-call Extension via Empty Caller ID and Suffix Matching CWE-303 2026-03-05
CVE-2026-32917 Critical 9.2 OpenClaw < 2026.3.13 - Remote Command Injection via Unsanitized iMessage Attachment Paths in SCP CWE-78 2026-03-31
CVE-2026-25253 High 8.8 OpenClaw/Clawdbot has 1-Click RCE via Authentication Token Exfiltration From gatewayUrl CWE-669 2026-02-01
CVE-2026-24763 High 8.8 OpenClaw/Clawdbot Docker Execution has Authenticated Command Injection via PATH Environment Variable CWE-78 2026-02-02
CVE-2026-22171 High 8.8 OpenClaw < 2026.2.19 - Path Traversal in Feishu Media Temporary File Naming CWE-22 2026-03-18
CVE-2026-32973 High 8.8 OpenClaw < 2026.3.11 - Exec Allowlist Pattern Overmatch via POSIX Path Normalization CWE-625 2026-03-29
CVE-2026-28461 High 8.7 OpenClaw < 2026.3.1 - Unbounded Memory Growth in Zalo Webhook via Query String Key Churn CWE-770 2026-03-19
CVE-2026-28478 High 8.7 OpenClaw affected by denial of service via unbounded webhook request body buffering CWE-770 2026-03-05
CVE-2026-32049 High 8.7 OpenClaw < 2026.2.22 - Denial of Service via Inbound Media Download Byte Limit Bypass CWE-770 2026-03-21
CVE-2026-32980 High 8.7 OpenClaw < 2026.3.13 - Resource Exhaustion via Unauthenticated Telegram Webhook Request CWE-770 2026-03-29
CVE-2026-32982 High 8.7 OpenClaw < 2026.3.13 - Telegram Bot Token Exposure in Media Fetch Error Logs CWE-532 2026-03-31
CVE-2026-33573 High 8.7 OpenClaw < 2026.3.11 - Workspace Boundary Bypass via Agent RPC Parameters CWE-668 2026-03-29
CVE-2026-35639 High 8.7 OpenClaw < 2026.3.22 - Privilege Escalation via device.pair.approve Scope Validation CWE-648 2026-04-09
CVE-2026-35638 High 8.7 OpenClaw < 2026.3.22 - Privilege Escalation via Self-Declared Scopes in Trusted-Proxy Control UI CWE-286 2026-04-09
CVE-2026-27001 High 8.6 OpenClaw: Unsanitized CWD path injection into LLM prompts CWE-77 2026-02-19
CVE-2026-33579 High 8.6 OpenClaw < 2026.3.28 - Privilege Escalation via Missing Caller Scope Validation in Device Pair Approval CWE-863 2026-03-31
CVE-2026-34503 High 8.6 OpenClaw < 2026.3.28 - Incomplete WebSocket Session Termination on Device Removal and Token Revocation CWE-613 2026-03-31
CVE-2026-33577 High 8.6 OpenClaw < 2026.3.28 - Insufficient Scope Validation in node.pair.approve CWE-863 2026-03-31
CVE-2026-28450 High 8.3 OpenClaw < 2026.2.12 - Unauthenticated Profile Tampering via Nostr Plugin HTTP Endpoints CWE-306 2026-03-05
CVE-2026-28393 High 8.3 OpenClaw 2.0.0-beta3 < 2026.2.14 - Arbitrary JavaScript Module Loading via Hook Transform Path Traversal CWE-427 2026-03-05
CVE-2026-28453 High 8.3 OpenClaw < 2026.2.14 - Zip Slip Path Traversal in TAR Archive Extraction CWE-22 2026-03-05
CVE-2026-32036 High 8.3 OpenClaw < 2026.2.26- Authentication Bypass via Encoded Dot-Segment Traversal in /api/channels CWE-289 2026-03-19
CVE-2026-35618 High 8.3 OpenClaw < 2026.3.23 - Replay Identity Drift via Query-Only Variants in Plivo V2 Verification CWE-294 2026-04-09
CVE-2026-28469 High 8.2 OpenClaw Google Chat shared-path webhook target ambiguity allowed cross-account policy-context misrouting CWE-639 2026-03-05
CVE-2026-32045 High 8.2 OpenClaw < 2026.2.21 - Authentication Bypass in HTTP Gateway Routes via Tokenless Tailscale Auth CWE-290 2026-03-21
CVE-2026-25157 High 7.8 OpenClaw/Clawdbot has OS Command Injection via Project Root Path in sshNodeCommand CWE-78 2026-02-04
CVE-2026-35650 High 7.7 OpenClaw < 2026.3.22 - Environment Variable Override Bypass via Inconsistent Sanitization CWE-15 2026-04-10
CVE-2026-35666 High 7.7 OpenClaw < 2026.3.22 - Allowlist Bypass via Unregistered Time Dispatch Wrapper CWE-706 2026-04-10
CVE-2026-27487 High 7.6 OpenClaw: Prevent shell injection in macOS keychain credential write CWE-78 2026-02-21
CVE-2026-32007 High 7.6 OpenClaw < 2026.2.23 - Sandbox Bypass in apply_patch Tool via Workspace-Only Check Bypass CWE-22 2026-03-19
CVE-2026-26319 High 7.5 OpenClaw has Missing Webhook Authentication in Telnyx Provider Allowing Unauthenticated Requests CWE-306 2026-02-19
CVE-2026-25474 High 7.5 OpenClaw has a Telegram webhook request forgery (missing channels.telegram.webhookSecret) โ†’ auth bypass CWE-345 2026-02-19
CVE-2026-26321 High 7.5 OpenClaw has a local file disclosure via sendMediaFeishu in Feishu extension CWE-22 2026-02-19
CVE-2026-28458 High 7.4 OpenClaw's Browser Relay /cdp websocket is missing auth which could allow cross-tab cookie access CWE-306 2026-03-05
CVE-2026-28473 High 7.2 OpenClaw < 2026.2.2 - Authorization Bypass via /approve Chat Command CWE-863 2026-03-05
CVE-2026-35653 High 7.2 OpenClaw < 2026.3.24 - Incorrect Authorization in POST /reset-profile via browser.request CWE-863 2026-04-10
CVE-2026-26317 High 7.1 OpenClaw affected by cross-site request forgery (CSRF) through loopback browser mutation endpoints CWE-352 2026-02-19
CVE-2026-22169 High 7.1 OpenClaw < 2026.2.22 - Allowlist Bypass via sort Configuration in safeBins CWE-78 2026-03-18
CVE-2026-22175 High 7.1 OpenClaw < 2026.2.23 - Exec Approval Bypass via Unrecognized Multiplexer Shell Wrappers CWE-184 2026-03-18
CVE-2026-22168 High 7.1 OpenClaw < 2026.2.21 - Command Injection via cmd.exe /c Trailing Arguments in system.run CWE-88 2026-03-18
CVE-2026-29607 High 7.1 OpenClaw < 2026.2.22 - Authorization Bypass via allow-always Wrapper Persistence CWE-78 2026-03-19
CVE-2026-28459 High 7.1 OpenClaw < 2026.2.12 - Arbitrary File Write via Untrusted sessionFile Path CWE-73 2026-03-05
CVE-2026-32027 High 7.1 OpenClaw < 2026.2.26 - Improper Authorization via DM Pairing Store Identity Inheritance in Group Allowlist CWE-22 2026-03-19
CVE-2026-32976 High 7.1 OpenClaw < 2026.3.11 - Account-Scoped configWrites Policy Bypass via Channel Commands CWE-639 2026-03-31
CVE-2026-35631 High 7.1 OpenClaw < 2026.3.22 - Missing Authorization Enforcement in Internal ACP Chat Commands CWE-862 2026-04-09
CVE-2026-35644 High 7.1 OpenClaw < 2026.3.22 - Credential Exposure via baseUrl Fields in Gateway Snapshots CWE-312 2026-04-09
CVE-2026-35657 High 7.1 OpenClaw < 2026.3.25 - Authorization Bypass in HTTP Session History Route CWE-863 2026-04-10
CVE-2026-40037 High 7.1 OpenClaw: fetchWithSsrFGuard replays unsafe request bodies across cross-origin redirects CWE-601 2026-04-08
CVE-2026-22176 Medium 6.9 OpenClaw < 2026.2.19 - Command Injection via Unescaped Environment Variables in Windows Scheduled Task Script Generation CWE-78 2026-03-19
CVE-2026-22177 Medium 6.9 OpenClaw < 2026.2.21 - Environment Variable Injection via Config env.vars CWE-15 2026-03-18
CVE-2026-28480 Medium 6.9 OpenClaw Telegram allowlist authorization accepted mutable usernames CWE-290 2026-03-05
CVE-2026-32975 Medium 6.9 OpenClaw < 2026.3.12 - Weak Authorization via Mutable Group Names in Zalouser Allowlist CWE-807 2026-03-29
CVE-2026-32919 Medium 6.9 OpenClaw < 2026.3.11 - Unauthorized Session Reset via agent Slash Commands CWE-863 2026-03-29
CVE-2026-35627 Medium 6.9 OpenClaw < 2026.3.22 - Unauthenticated Cryptographic Work in Nostr Inbound DM Handling CWE-696 2026-04-09
CVE-2026-35633 Medium 6.9 OpenClaw < 2026.3.22 - Unbounded Memory Allocation via Remote Media Error Responses CWE-789 2026-04-09
CVE-2026-34510 Medium 6.9 OpenClaw < 2026.3.22 - Remote File URL Acceptance in Windows Media Loaders CWE-41 2026-04-01
CVE-2026-35652 Medium 6.9 OpenClaw < 2026.3.22 - Unauthorized Action Execution via Callback Dispatch CWE-696 2026-04-10
CVE-2026-35647 Medium 6.9 OpenClaw < 2026.3.25 - Direct Message Policy Bypass via Verification Notices CWE-288 2026-04-10
CVE-2026-35654 Medium 6.9 OpenClaw < 2026.3.25 - Authorization Bypass in Microsoft Teams Feedback Invoke CWE-288 2026-04-10
CVE-2026-35667 Medium 6.9 OpenClaw < 2026.3.24 - Improper Process Termination via Unpatched killProcessTree in shell-utils.ts CWE-404 2026-04-10
CVE-2026-32024 Medium 6.8 OpenClaw < 2026.2.22 - Symlink Traversal in Avatar Handling CWE-59 2026-03-19
CVE-2026-29612 Medium 6.8 OpenClaw < 2026.2.14 - Denial of Service via Large Base64 Media File Decoding CWE-770 2026-03-05
CVE-2026-28452 Medium 6.7 OpenClaw affected by denial of service through unguarded archive extraction allowing high expansion/resource abuse (ZIP/TAR) CWE-770 2026-03-05
CVE-2026-32044 Medium 6.7 OpenClaw < 2026.3.2 - Tar Archive Safety Bypass in Skills Installation CWE-409 2026-03-21
CVE-2026-26328 Medium 6.5 OpenClaw iMessage group allowlist authorization inherited DM pairing-store identities CWE-284, CWE-863 2026-02-19
CVE-2026-28449 Medium 6.3 OpenClaw < 2026.2.25 - Webhook Replay Attack via Missing Durable Replay Suppression CWE-294 2026-03-19
CVE-2026-28395 Medium 6.3 OpenClaw 2026.1.14-1 < 2026.2.12 - Unintended Public Binding of Chrome Extension Relay via Wildcard cdpUrl CWE-1327 2026-03-05
CVE-2026-28451 Medium 6.3 OpenClaw < 2026.2.14 - SSRF via Feishu Extension Media Fetching CWE-918 2026-03-05
CVE-2026-28471 Medium 6.3 OpenClaw 2026.1.14-1 < 2026.2.2 - Allowlist Bypass via displayName and Cross-Homeserver localpart Matching in Matrix Plugin CWE-287 2026-03-05
CVE-2026-32031 Medium 6.3 OpenClaw < 2026.2.26 - Authentication Bypass via Path Canonicalization Mismatch in /api/channels Gateway CWE-288 2026-03-19
CVE-2026-32050 Medium 6.3 OpenClaw < 2026.2.25 - Unauthorized Reaction Status Event Enqueue via Access Check Bypass CWE-863 2026-03-21
CVE-2026-33580 Medium 6.3 OpenClaw < 2026.3.28 - Brute Force Attack via Missing Rate Limiting on Webhook Shared Secret Authentication CWE-307 2026-03-31
CVE-2026-35628 Medium 6.3 OpenClaw < 2026.3.25 - Brute-Force Attack via Missing Telegram Webhook Rate Limiting CWE-307 2026-04-09
CVE-2026-35656 Medium 6.3 OpenClaw < 2026.3.22 - XFF Loopback Spoofing Bypass in Canvas Authentication and Rate Limiter CWE-290 2026-04-10
CVE-2026-32057 Medium 6 OpenClaw < 2026.2.25 - Authentication Bypass via Control UI client.id Parameter CWE-807 2026-03-21
CVE-2026-34511 Medium 6 OpenClaw < 2026.4.2 - PKCE Verifier Exposure via OAuth State Parameter CWE-330 2026-04-03
CVE-2026-28477 Medium 5.9 OpenClaw < 2026.2.14 - OAuth State Validation Bypass in Manual Chutes Login Flow CWE-352 2026-03-05
CVE-2026-27009 Medium 5.8 OpenClaw affected by Stored XSS in Control UI via unsanitized assistant name/avatar in inline script injection CWE-79 2026-02-19
CVE-2026-27670 Medium 5.8 OpenClaw < 2026.3.2 - Arbitrary File Write via ZIP Extraction Parent Symlink Race Condition CWE-367 2026-03-19
CVE-2026-31995 Medium 5.8 OpenClaw 2026.1.21 < 2026.2.19 - Command Injection via Windows Shell Fallback in Lobster Extension CWE-78 2026-03-19
CVE-2026-32000 Medium 5.8 OpenClaw < 2026.2.19 - Command Injection via Windows Shell Fallback in Lobster Tool Execution CWE-78 2026-03-19
CVE-2026-32052 Medium 5.8 OpenClaw < 2026.2.24 - Hidden Command Execution via Shell-Wrapper Positional argv Carriers CWE-436 2026-03-21
CVE-2026-32977 Medium 5.8 OpenClaw < 2026.3.11 - Sandbox Boundary Bypass via Unanchored writeFile Commit Path CWE-367 2026-03-31
CVE-2026-33574 Medium 5.8 OpenClaw < 2026.3.8 - Path Traversal via Tools Root Rebinding in Skills Download CWE-367 2026-03-29
CVE-2026-32988 Medium 5.8 OpenClaw < 2026.3.11 - Sandbox Boundary Bypass via Unvalidated Temporary File Creation CWE-367 2026-03-31
CVE-2026-28457 Medium 5.6 OpenClaw < 2026.2.14 - Path Traversal in Sandbox Skill Mirroring via Name Parameter CWE-22 2026-03-05
CVE-2026-31989 Medium 5.3 OpenClaw < 2026.3.1 - Server-Side Request Forgery via web_search Citation Redirect CWE-918 2026-03-19
CVE-2026-32001 Medium 5.3 OpenClaw < 2026.2.22 - Node Role Device-Identity Bypass via WebSocket Authentication CWE-863 2026-03-19
CVE-2026-32921 Medium 5.3 OpenClaw < 2026.3.8 - Script Content Modification via Mutable Operand Binding in system.run CWE-367 2026-03-31
CVE-2026-33578 Medium 5.3 OpenClaw < 2026.3.28 - Sender Policy Allowlist Bypass via Policy Downgrade in Google Chat and Zalouser Extensions CWE-863 2026-03-31
CVE-2026-35619 Medium 5.3 OpenClaw < 2026.3.24 - Authorization Bypass via HTTP /v1/models Endpoint CWE-863 2026-04-10
CVE-2026-34425 Medium 5.3 OpenClaw - Shell-Bleed Protection Preflight Validation Bypass CWE-184 2026-04-02
CVE-2026-35629 Medium 5.3 OpenClaw < 2026.3.25 - Server-Side Request Forgery via Unguarded Configured Base URLs in Channel Extensions CWE-918 2026-04-09
CVE-2026-35642 Medium 5.3 OpenClaw < 2026.3.25 - Authorization Bypass in Group Reactions via requireMention Bypass CWE-288 2026-04-09
CVE-2026-32020 Medium 4.8 OpenClaw < 2026.2.22 - Arbitrary File Read via Symlink Following in Static File Handler CWE-59 2026-03-19
CVE-2026-27486 Medium 4.3 OpenClaw: Process Safety - Unvalidated PID Kill via SIGKILL in Process Cleanup CWE-283 2026-02-21
CVE-2026-32040 Low 2.4 OpenClaw < 2026.2.23 - HTML Injection via Unvalidated Image MIME Type in Data-URL Interpolation CWE-79 2026-03-19
CVE-2026-34506 Low 2.3 OpenClaw < 2026.3.8 - Sender Allowlist Bypass in Microsoft Teams Plugin via Route Allowlist Configuration CWE-863 2026-03-31
CVE-2026-35648 Low 2.3 OpenClaw < 2026.3.22 - Policy Bypass via Unvalidated Queued Node Actions CWE-367 2026-04-10
CVE-2026-35624 Low 2.3 OpenClaw < 2026.3.22 - Policy Confusion via Room Name Collision in Nextcloud Talk CWE-807 2026-04-09
CVE-2026-32970 Low 2 OpenClaw < 2026.3.11 - Credential Fallback Logic Bypass via Unavailable Local Auth SecretRefs CWE-636 2026-03-31
๐Ÿ“– Detailed CVE Analysis (click to expand)

CVE-2026-32922 โ€” OpenClaw < 2026.3.11 - Privilege Escalation via Unvalidated Scope in device.token.rotate

Field Detail
CVSS 9.4 (CRITICAL) โ€” CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
CWE CWE-266 (Incorrect Privilege Assignment)
Affected < 2026.3.11
Vendor/Product OpenClaw / OpenClaw
Advisory GHSA-4jpw-hj22-2xmc

OpenClaw before 2026.3.11 contains a privilege escalation vulnerability in device.token.rotate that allows callers with operator.pairing scope to mint tokens with broader scopes by failing to constrain newly minted scopes to the caller's current scope set. Attackers can obtain operator.admin tokens for paired devices and achieve remote code execution on connected nodes via system.run or gain unauthorized gateway-admin access.

References:


CVE-2026-28474 โ€” OpenClaw Nextcloud Talk < 2026.2.6 - Allowlist Bypass via actor.name Display Name Spoofing

Field Detail
CVSS 9.3 (CRITICAL) โ€” CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CWE CWE-863 (Incorrect Authorization)
Affected < 2026.2.6
Vendor/Product OpenClaw / nextcloud-talk
Advisory GHSA-r5h9-vjqc-hq3r

OpenClaw's Nextcloud Talk plugin versions prior to 2026.2.6 accept equality matching on the mutable actor.name display name field for allowlist validation, allowing attackers to bypass DM and room allowlists. An attacker can change their Nextcloud display name to match an allowlisted user ID and gain unauthorized access to restricted conversations.

References:


CVE-2026-32987 โ€” OpenClaw < 2026.3.13 - Bootstrap Setup Code Replay via Device Pairing

Field Detail
CVSS 9.3 (CRITICAL) โ€” CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CWE CWE-294 (Authentication Bypass by Capture-replay)
Affected < 2026.3.13
Vendor/Product OpenClaw / OpenClaw
Advisory GHSA-63f5-hhc7-cx6p

OpenClaw before 2026.3.13 allows bootstrap setup codes to be replayed during device pairing verification in src/infra/device-bootstrap.ts. Attackers can verify a valid bootstrap code multiple times before approval to escalate pending pairing scopes, including privilege escalation to operator.admin.

References:


CVE-2026-28391 โ€” OpenClaw < 2026.2.2 - Command Injection via cmd.exe Parsing Bypass in Allowlist Enforcement

Field Detail
CVSS 9.2 (CRITICAL) โ€” CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CWE CWE-184 (Incomplete List of Disallowed Inputs)
Affected < 2026.2.2
Vendor/Product OpenClaw / OpenClaw
Advisory GHSA-qj77-c3c8-9c3q

OpenClaw versions prior to 2026.2.2 fail to properly validate Windows cmd.exe metacharacters in allowlist-gated exec requests, allowing attackers to bypass command approval restrictions. Remote attackers can craft command strings with shell metacharacters like & or %...% to execute unapproved commands beyond the allowlisted operations.

References:


CVE-2026-28446 โ€” OpenClaw < 2026.2.1 - Inbound Allowlist Policy Bypass in voice-call Extension via Empty Caller ID and Suffix Matching

Field Detail
CVSS 9.2 (CRITICAL) โ€” CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N
CWE CWE-303 (Incorrect Implementation of Authentication Algorithm)
Affected < 2026.2.1
Vendor/Product OpenClaw / OpenClaw
Advisory GHSA-4rj2-gpmh-qq5x

OpenClaw versions prior to 2026.2.1 with the voice-call extension installed and enabled contain an authentication bypass vulnerability in inbound allowlist policy validation that accepts empty caller IDs and uses suffix-based matching instead of strict equality. Remote attackers can bypass inbound access controls by placing calls with missing caller IDs or numbers ending with allowlisted digits to reach the voice-call agent and execute tools.

References:


CVE-2026-32917 โ€” OpenClaw < 2026.3.13 - Remote Command Injection via Unsanitized iMessage Attachment Paths in SCP

Field Detail
CVSS 9.2 (CRITICAL) โ€” CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CWE CWE-78 (Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'))
Affected < 2026.3.13
Vendor/Product OpenClaw / OpenClaw
Advisory GHSA-g2f6-pwvx-r275

OpenClaw before 2026.3.13 contains a remote command injection vulnerability in the iMessage attachment staging flow that allows attackers to execute arbitrary commands on configured remote hosts. The vulnerability exists because unsanitized remote attachment paths containing shell metacharacters are passed directly to the SCP remote operand without validation, enabling command execution when remote attachment staging is enabled.

References:


CVE-2026-25253 โ€” OpenClaw/Clawdbot has 1-Click RCE via Authentication Token Exfiltration From gatewayUrl

Field Detail
CVSS 8.8 (HIGH) โ€” CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CWE CWE-669 (CWE-669 Incorrect Resource Transfer Between Spheres)
Affected < 2026.1.29
Vendor/Product OpenClaw / OpenClaw
Advisory GHSA-g8p2-7wf7-98mq

OpenClaw (aka clawdbot or Moltbot) before 2026.1.29 obtains a gatewayUrl value from a query string and automatically makes a WebSocket connection without prompting, sending a token value.

Naming note: Uses all three names in description. packageURL still references pkg:npm/clawdbot. References:


CVE-2026-24763 โ€” OpenClaw/Clawdbot Docker Execution has Authenticated Command Injection via PATH Environment Variable

Field Detail
CVSS 8.8 (HIGH) โ€” CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE CWE-78 (CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'))
Affected < 2026.1.29
Vendor/Product clawdbot / clawdbot
Advisory GHSA-mc68-q9jw-2h3v

OpenClaw (formerly Clawdbot) is a personal AI assistant you run on your own devices. Prior to 2026.1.29, a command injection vulnerability existed in OpenClawโ€™s Docker sandbox execution mechanism due to unsafe handling of the PATH environment variable when constructing shell commands. An authenticated user able to control environment variables could influence command execution within the container context. This vulnerability is fixed in 2026.1.29.

Naming note: Uses old name clawdbot/clawdbot as vendor/product. References:


CVE-2026-22171 โ€” OpenClaw < 2026.2.19 - Path Traversal in Feishu Media Temporary File Naming

Field Detail
CVSS 8.8 (HIGH) โ€” CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N
CWE CWE-22 (CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'))
Affected < 2026.2.19
Vendor/Product OpenClaw / OpenClaw
Advisory GHSA-vj3g-5px3-gr46

OpenClaw versions prior to 2026.2.19 contain a path traversal vulnerability in the Feishu media download flow where untrusted media keys are interpolated directly into temporary file paths in extensions/feishu/src/media.ts. An attacker who can control Feishu media key values returned to the client can use traversal segments to escape os.tmpdir() and write arbitrary files within the OpenClaw process permissions.

References:


CVE-2026-32973 โ€” OpenClaw < 2026.3.11 - Exec Allowlist Pattern Overmatch via POSIX Path Normalization

Field Detail
CVSS 8.8 (HIGH) โ€” CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N
CWE CWE-625 (Permissive Regular Expression)
Affected < 2026.3.11
Vendor/Product OpenClaw / OpenClaw
Advisory GHSA-f8r2-vg7x-gh8m

OpenClaw before 2026.3.11 contains an exec allowlist bypass vulnerability where matchesExecAllowlistPattern improperly normalizes patterns with lowercasing and glob matching that overmatches on POSIX paths. Attackers can exploit the ? wildcard matching across path segments to execute commands or paths not intended by operators.

References:


CVE-2026-28461 โ€” OpenClaw < 2026.3.1 - Unbounded Memory Growth in Zalo Webhook via Query String Key Churn

Field Detail
CVSS 8.7 (HIGH) โ€” CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
CWE CWE-770 (CWE-770: Allocation of Resources Without Limits or Throttling)
Affected < 2026.3.1
Vendor/Product OpenClaw / OpenClaw
Advisory GHSA-wr6m-jg37-68xh

OpenClaw versions prior to 2026.3.1 contain an unbounded memory growth vulnerability in the Zalo webhook endpoint that allows unauthenticated attackers to trigger in-memory key accumulation by varying query strings. Remote attackers can exploit this by sending repeated requests with different query parameters to cause memory pressure, process instability, or out-of-memory conditions that degrade service availability.

References:


CVE-2026-28478 โ€” OpenClaw affected by denial of service via unbounded webhook request body buffering

Field Detail
CVSS 8.7 (HIGH) โ€” CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
CWE CWE-770 (Allocation of Resources Without Limits or Throttling)
Affected < 2026.2.13
Vendor/Product OpenClaw / OpenClaw
Advisory GHSA-q447-rj3r-2cgh

OpenClaw versions prior to 2026.2.13 contain a denial of service vulnerability in webhook handlers that buffer request bodies without strict byte or time limits. Remote unauthenticated attackers can send oversized JSON payloads or slow uploads to webhook endpoints causing memory pressure and availability degradation.

References:


CVE-2026-32049 โ€” OpenClaw < 2026.2.22 - Denial of Service via Inbound Media Download Byte Limit Bypass

Field Detail
CVSS 8.7 (HIGH) โ€” CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
CWE CWE-770 (CWE-770: Allocation of Resources Without Limits or Throttling)
Affected < 2026.2.22
Vendor/Product OpenClaw / OpenClaw
Advisory GHSA-rxxp-482v-7mrh

OpenClaw versions prior to 2026.2.22 fail to consistently enforce configured inbound media byte limits before buffering remote media across multiple channel ingestion paths. Remote attackers can send oversized media payloads to trigger elevated memory usage and potential process instability.

References:


CVE-2026-32980 โ€” OpenClaw < 2026.3.13 - Resource Exhaustion via Unauthenticated Telegram Webhook Request

Field Detail
CVSS 8.7 (HIGH) โ€” CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
CWE CWE-770 (Allocation of Resources Without Limits or Throttling)
Affected < 2026.3.13
Vendor/Product OpenClaw / OpenClaw
Advisory GHSA-jq3f-vjww-8rq7

OpenClaw before 2026.3.13 reads and buffers Telegram webhook request bodies before validating the x-telegram-bot-api-secret-token header, allowing unauthenticated attackers to exhaust server resources. Attackers can send POST requests to the webhook endpoint to force memory consumption, socket time, and JSON parsing work before authentication validation occurs.

References:


CVE-2026-32982 โ€” OpenClaw < 2026.3.13 - Telegram Bot Token Exposure in Media Fetch Error Logs

Field Detail
CVSS 8.7 (HIGH) โ€” CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
CWE CWE-532 (Insertion of Sensitive Information into Log File)
Affected < 2026.3.13
Vendor/Product OpenClaw / OpenClaw
Advisory GHSA-xwcj-hwhf-h378

OpenClaw before 2026.3.13 contains an information disclosure vulnerability in the fetchRemoteMedia function that exposes Telegram bot tokens in error messages. When media downloads fail, the original Telegram file URLs containing bot tokens are embedded in MediaFetchError strings and leaked to logs and error surfaces.

References:


CVE-2026-33573 โ€” OpenClaw < 2026.3.11 - Workspace Boundary Bypass via Agent RPC Parameters

Field Detail
CVSS 8.7 (HIGH) โ€” CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CWE CWE-668 (Exposure of Resource to Wrong Sphere)
Affected < 2026.3.11
Vendor/Product OpenClaw / OpenClaw
Advisory GHSA-2rqg-gjgv-84jm

OpenClaw before 2026.3.11 contains an authorization bypass vulnerability in the gateway agent RPC that allows authenticated operators with operator.write permission to override workspace boundaries by supplying attacker-controlled spawnedBy and workspaceDir values. Remote operators can escape the configured workspace boundary and execute arbitrary file and exec operations from any process-accessible directory.

References:


CVE-2026-35639 โ€” OpenClaw < 2026.3.22 - Privilege Escalation via device.pair.approve Scope Validation

Field Detail
CVSS 8.7 (HIGH) โ€” CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CWE CWE-648 (CWE-648: Incorrect Use of Privileged APIs)
Affected < 2026.3.22
Vendor/Product OpenClaw / OpenClaw
Advisory GHSA-hf68-49fm-59cq

OpenClaw before 2026.3.22 contains a privilege escalation vulnerability in the device.pair.approve method that allows an operator.pairing approver to approve pending device requests with broader operator scopes than the approver actually holds. Attackers can exploit insufficient scope validation to escalate privileges to operator.admin and achieve remote code execution on the Node infrastructure.

References:


CVE-2026-35638 โ€” OpenClaw < 2026.3.22 - Privilege Escalation via Self-Declared Scopes in Trusted-Proxy Control UI

Field Detail
CVSS 8.7 (HIGH) โ€” CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CWE CWE-286 (Execute unauthorized code or commands)
Affected < 2026.3.22
Vendor/Product OpenClaw / OpenClaw
Advisory GHSA-48vw-m3qc-wr99

OpenClaw before 2026.3.22 contains a privilege escalation vulnerability in the Control UI that allows unauthenticated sessions to retain self-declared privileged scopes without device identity verification. Attackers can exploit the device-less allow path in the trusted-proxy mechanism to maintain elevated permissions by declaring arbitrary scopes, bypassing device identity requirements.

References:


CVE-2026-27001 โ€” OpenClaw: Unsanitized CWD path injection into LLM prompts

Field Detail
CVSS 8.6 (HIGH) โ€” CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CWE CWE-77 (CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection'))
Affected < 2026.2.15
Vendor/Product openclaw / openclaw
Advisory GHSA-2qj5-gwg2-xwc4

OpenClaw is a personal AI assistant. Prior to version 2026.2.15, OpenClaw embedded the current working directory (workspace path) into the agent system prompt without sanitization. If an attacker can cause OpenClaw to run inside a directory whose name contains control/format characters (for example newlines or Unicode bidi/zero-width markers), those characters could break the prompt structure and inject attacker-controlled instructions. Starting in version 2026.2.15, the workspace path is sanitized before it is embedded into any LLM prompt output, stripping Unicode control/format characters and explicit line/paragraph separators. Workspace path resolution also applies the same sanitization as defense-in-depth.

References:


CVE-2026-33579 โ€” OpenClaw < 2026.3.28 - Privilege Escalation via Missing Caller Scope Validation in Device Pair Approval

Field Detail
CVSS 8.6 (HIGH) โ€” CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
CWE CWE-863 (CWE-863 Incorrect Authorization)
Affected < 2026.3.28
Vendor/Product OpenClaw / OpenClaw
Advisory GHSA-hc5h-pmr3-3497

OpenClaw before 2026.3.28 contains a privilege escalation vulnerability in the /pair approve command path that fails to forward caller scopes into the core approval check. A caller with pairing privileges but without admin privileges can approve pending device requests asking for broader scopes including admin access by exploiting the missing scope validation in extensions/device-pair/index.ts and src/infra/device-pairing.ts.

References:


CVE-2026-34503 โ€” OpenClaw < 2026.3.28 - Incomplete WebSocket Session Termination on Device Removal and Token Revocation

Field Detail
CVSS 8.6 (HIGH) โ€” CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
CWE CWE-613 (CWE-613 Insufficient Session Expiration)
Affected < 2026.3.28
Vendor/Product OpenClaw / OpenClaw
Advisory GHSA-2pr2-hcv6-7gwv

OpenClaw before 2026.3.28 fails to disconnect active WebSocket sessions when devices are removed or tokens are revoked. Attackers with revoked credentials can maintain unauthorized access through existing live sessions until forced reconnection.

References:


CVE-2026-33577 โ€” OpenClaw < 2026.3.28 - Insufficient Scope Validation in node.pair.approve

Field Detail
CVSS 8.6 (HIGH) โ€” CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
CWE CWE-863 (CWE-863 Incorrect Authorization)
Affected < 2026.3.28
Vendor/Product OpenClaw / OpenClaw
Advisory GHSA-2x4x-cc5g-qmmg

OpenClaw before 2026.3.28 contains an insufficient scope validation vulnerability in the node pairing approval path that allows low-privilege operators to approve nodes with broader scopes. Attackers can exploit missing callerScopes validation in node-pairing.ts to extend privileges onto paired nodes beyond their authorization level.

References:


CVE-2026-28450 โ€” OpenClaw < 2026.2.12 - Unauthenticated Profile Tampering via Nostr Plugin HTTP Endpoints

Field Detail
CVSS 8.3 (HIGH) โ€” CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N
CWE CWE-306 (Missing Authentication for Critical Function)
Affected < 2026.2.12
Vendor/Product OpenClaw / OpenClaw
Advisory GHSA-mv9j-6xhh-g383

OpenClaw versions prior to 2026.2.12 with the optional Nostr plugin enabled expose unauthenticated HTTP endpoints at /api/channels/nostr/:accountId/profile and /api/channels/nostr/:accountId/profile/import that allow reading and modifying Nostr profiles without gateway authentication. Remote attackers can exploit these endpoints to read sensitive profile data, modify Nostr profiles, persist malicious changes to gateway configuration, and publish signed Nostr events using the bot's private key when the gateway HTTP port is accessible beyond localhost.

References:


CVE-2026-28393 โ€” OpenClaw 2.0.0-beta3 < 2026.2.14 - Arbitrary JavaScript Module Loading via Hook Transform Path Traversal

Field Detail
CVSS 8.3 (HIGH) โ€” CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
CWE CWE-427 (Uncontrolled Search Path Element)
Affected < 2026.2.14
Vendor/Product OpenClaw / OpenClaw
Advisory GHSA-7xhj-55q9-pc3m

OpenClaw versions 2.0.0-beta3 prior to 2026.2.14 contain a path traversal vulnerability in hook transform module loading that allows arbitrary JavaScript execution. The hooks.mappings[].transform.module parameter accepts absolute paths and traversal sequences, enabling attackers with configuration write access to load and execute malicious modules with gateway process privileges.

References:


CVE-2026-28453 โ€” OpenClaw < 2026.2.14 - Zip Slip Path Traversal in TAR Archive Extraction

Field Detail
CVSS 8.3 (HIGH) โ€” CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
CWE CWE-22 (Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'))
Affected < 2026.2.14
Vendor/Product OpenClaw / OpenClaw
Advisory GHSA-p25h-9q54-ffvw

OpenClaw versions prior to 2026.2.14 fail to validate TAR archive entry paths during extraction, allowing path traversal sequences to write files outside the intended directory. Attackers can craft malicious archives with traversal sequences like ../../ to write files outside extraction boundaries, potentially enabling configuration tampering and code execution.

References:


CVE-2026-32036 โ€” OpenClaw < 2026.2.26- Authentication Bypass via Encoded Dot-Segment Traversal in /api/channels

Field Detail
CVSS 8.3 (HIGH) โ€” CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N
CWE CWE-289 (CWE-289 Authentication Bypass by Alternate Name)
Affected < 2026.2.26
Vendor/Product OpenClaw / OpenClaw
Advisory GHSA-mwxv-35wr-4vvj

OpenClaw gateway plugin versions prior to 2026.2.26 contain a path traversal vulnerability that allows remote attackers to bypass route authentication checks by manipulating /api/channels paths with encoded dot-segment traversal sequences. Attackers can craft alternate paths using encoded traversal patterns to access protected plugin channel routes when handlers normalize the incoming path, circumventing security controls.

References:


CVE-2026-35618 โ€” OpenClaw < 2026.3.23 - Replay Identity Drift via Query-Only Variants in Plivo V2 Verification

Field Detail
CVSS 8.3 (HIGH) โ€” CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N
CWE CWE-294 (CWE-294 Authentication Bypass by Capture-replay)
Affected < 2026.3.23
Vendor/Product OpenClaw / OpenClaw
Advisory GHSA-cg6c-q2hx-69h7

OpenClaw before 2026.3.23 contains a replay identity vulnerability in Plivo V2 signature verification that allows attackers to bypass replay protection by modifying query parameters. The verification path derives replay keys from the full URL including query strings instead of the canonicalized base URL, enabling attackers to mint new verified request keys through unsigned query-only changes to signed requests.

References:


CVE-2026-28469 โ€” OpenClaw Google Chat shared-path webhook target ambiguity allowed cross-account policy-context misrouting

Field Detail
CVSS 8.2 (HIGH) โ€” CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
CWE CWE-639 (Authorization Bypass Through User-Controlled Key)
Affected < 2026.2.14
Vendor/Product OpenClaw / OpenClaw
Advisory GHSA-rq6g-px6m-c248

OpenClaw versions prior to 2026.2.14 contain a webhook routing vulnerability in the Google Chat monitor component that allows cross-account policy context misrouting when multiple webhook targets share the same HTTP path. Attackers can exploit first-match request verification semantics to process inbound webhook events under incorrect account contexts, bypassing intended allowlists and session policies.

References:


CVE-2026-32045 โ€” OpenClaw < 2026.2.21 - Authentication Bypass in HTTP Gateway Routes via Tokenless Tailscale Auth

Field Detail
CVSS 8.2 (HIGH) โ€” CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
CWE CWE-290 (CWE-290: Authentication Bypass by Spoofing)
Affected < 2026.2.21
Vendor/Product OpenClaw / OpenClaw
Advisory GHSA-hff7-ccv5-52f8

OpenClaw versions prior to 2026.2.21 incorrectly apply tokenless Tailscale header authentication to HTTP gateway routes, allowing bypass of token and password requirements. Attackers on trusted networks can exploit this misconfiguration to access HTTP gateway routes without proper authentication credentials.

References:


CVE-2026-25157 โ€” OpenClaw/Clawdbot has OS Command Injection via Project Root Path in sshNodeCommand

Field Detail
CVSS 7.8 (HIGH) โ€” CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
CWE CWE-78 (CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'))
Affected < 2026.1.29
Vendor/Product openclaw / openclaw
Advisory GHSA-q284-4pvr-m585

OpenClaw is a personal AI assistant. Prior to version 2026.1.29, there is an OS command injection vulnerability via the Project Root Path in sshNodeCommand. The sshNodeCommand function constructed a shell script without properly escaping the user-supplied project path in an error message. When the cd command failed, the unescaped path was interpolated directly into an echo statement, allowing arbitrary command execution on the remote SSH host. The parseSSHTarget function did not validate that SSH target strings could not begin with a dash. An attacker-supplied target like -oProxyCommand=... would be interpreted as an SSH configuration flag rather than a hostname, allowing arbitrary command execution on the local machine. This issue has been patched in version 2026.1.29.


CVE-2026-35650 โ€” OpenClaw < 2026.3.22 - Environment Variable Override Bypass via Inconsistent Sanitization

Field Detail
CVSS 7.7 (HIGH) โ€” CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CWE CWE-15 (CWE-15: External Control of System or Configuration Setting)
Affected < 2026.3.22
Vendor/Product OpenClaw / OpenClaw
Advisory GHSA-39pp-xp36-q6mg

OpenClaw before 2026.3.22 contains an environment variable override handling vulnerability that allows attackers to bypass the shared host environment policy through inconsistent sanitization paths. Attackers can supply blocked or malformed override keys that slip through inconsistent validation to execute arbitrary code with unintended environment variables.

References:


CVE-2026-35666 โ€” OpenClaw < 2026.3.22 - Allowlist Bypass via Unregistered Time Dispatch Wrapper

Field Detail
CVSS 7.7 (HIGH) โ€” CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CWE CWE-706 (CWE-706: Use of Incorrectly-Resolved Name or Reference)
Affected < 2026.3.22
Vendor/Product OpenClaw / OpenClaw
Advisory GHSA-qm9x-v7cx-7rq4

OpenClaw before 2026.3.22 contains an allowlist bypass vulnerability in system.run approvals that fails to unwrap /usr/bin/time wrappers. Attackers can bypass executable binding restrictions by using an unregistered time wrapper to reuse approval state for inner commands.

References:


CVE-2026-27487 โ€” OpenClaw: Prevent shell injection in macOS keychain credential write

Field Detail
CVSS 7.6 (HIGH) โ€” CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:L
CWE CWE-78 (CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'))
Affected < 2026.2.14
Vendor/Product openclaw / openclaw
Advisory GHSA-4564-pvr2-qq4h

OpenClaw is a personal AI assistant. In versions 2026.2.13 and below, when using macOS, the Claude CLI keychain credential refresh path constructed a shell command to write the updated JSON blob into Keychain via security add-generic-password -w .... Because OAuth tokens are user-controlled data, this created an OS command injection risk. This issue has been fixed in version 2026.2.14.

References:


CVE-2026-32007 โ€” OpenClaw < 2026.2.23 - Sandbox Bypass in apply_patch Tool via Workspace-Only Check Bypass

Field Detail
CVSS 7.6 (HIGH) โ€” CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
CWE CWE-22 (CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'))
Affected < 2026.2.23
Vendor/Product OpenClaw / OpenClaw
Advisory GHSA-h9xm-j4qg-fvpg

OpenClaw versions prior to 2026.2.23 contain a path traversal vulnerability in the experimental apply_patch tool that allows attackers with sandbox access to modify files outside the workspace directory by exploiting inconsistent enforcement of workspace-only checks on mounted paths. Attackers can use apply_patch operations on writable mounts outside the workspace root to access and modify arbitrary files on the system.

References:


CVE-2026-26319 โ€” OpenClaw has Missing Webhook Authentication in Telnyx Provider Allowing Unauthenticated Requests

Field Detail
CVSS 7.5 (HIGH) โ€” CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CWE CWE-306 (CWE-306: Missing Authentication for Critical Function)
Affected < 2026.2.14
Vendor/Product openclaw / openclaw
Advisory GHSA-4hg8-92x6-h2f3

OpenClaw is a personal AI assistant. Versions 2026.2.13 and below allow the optional @openclaw/voice-call plugin Telnyx webhook handler to accept unsigned inbound webhook requests when telnyx.publicKey is not configured, enabling unauthenticated callers to forge Telnyx events. Telnyx webhooks are expected to be authenticated via Ed25519 signature verification. In affected versions, TelnyxProvider.verifyWebhook() could effectively fail open when no Telnyx public key was configured, allowing arbitrary HTTP POST requests to the voice-call webhook endpoint to be treated as legitimate Telnyx events. This only impacts deployments where the Voice Call plugin is installed, enabled, and the webhook endpoint is reachable from the attacker (for example, publicly exposed via a tunnel/proxy). The issue has been fixed in version 2026.2.14.

References:


CVE-2026-25474 โ€” OpenClaw has a Telegram webhook request forgery (missing channels.telegram.webhookSecret) โ†’ auth bypass

Field Detail
CVSS 7.5 (HIGH) โ€” CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CWE CWE-345 (CWE-345: Insufficient Verification of Data Authenticity)
Affected < 2026.2.1
Vendor/Product openclaw / openclaw
Advisory GHSA-mp5h-m6qj-6292

OpenClaw is a personal AI assistant. In versions 2026.1.30 and below, if channels.telegram.webhookSecret is not set when in Telegram webhook mode, OpenClaw may accept webhook HTTP requests without verifying Telegramโ€™s secret token header. In deployments where the webhook endpoint is reachable by an attacker, this can allow forged Telegram updates (for example spoofing message.from.id). If an attacker can reach the webhook endpoint, they may be able to send forged updates that are processed as if they came from Telegram. Depending on enabled commands/tools and configuration, this could lead to unintended bot actions. Note: Telegram webhook mode is not enabled by default. It is enabled only when channels.telegram.webhookUrl is configured. This issue has been fixed in version 2026.2.1.

References:


CVE-2026-26321 โ€” OpenClaw has a local file disclosure via sendMediaFeishu in Feishu extension

Field Detail
CVSS 7.5 (HIGH) โ€” CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CWE CWE-22 (CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'))
Affected < 2026.2.14
Vendor/Product openclaw / openclaw
Advisory GHSA-8jpq-5h99-ff5r

OpenClaw is a personal AI assistant. Prior to OpenClaw version 2026.2.14, the Feishu extension previously allowed sendMediaFeishu to treat attacker-controlled mediaUrl values as local filesystem paths and read them directly. If an attacker can influence tool calls (directly or via prompt injection), they may be able to exfiltrate local files by supplying paths such as /etc/passwd as mediaUrl. Upgrade to OpenClaw 2026.2.14 or newer to receive a fix. The fix removes direct local file reads from this path and routes media loading through hardened helpers that enforce local-root restrictions.

References:


CVE-2026-28458 โ€” OpenClaw's Browser Relay /cdp websocket is missing auth which could allow cross-tab cookie access

Field Detail
CVSS 7.4 (HIGH) โ€” CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
CWE CWE-306 (Missing Authentication for Critical Function)
Affected < 2026.2.1
Vendor/Product OpenClaw / OpenClaw
Advisory GHSA-mr32-vwc2-5j6h

OpenClaw version 2026.1.20 prior to 2026.2.1 contains a vulnerability in the Browser Relay (extension must be installed and enabled) /cdp WebSocket endpoint in which it does not require authentication tokens, allowing websites to connect via loopback and access sensitive data. Attackers can exploit this by connecting to ws://127.0.0.1:18792/cdp to steal session cookies and execute JavaScript in other browser tabs.

References:


CVE-2026-28473 โ€” OpenClaw < 2026.2.2 - Authorization Bypass via /approve Chat Command

Field Detail
CVSS 7.2 (HIGH) โ€” CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N
CWE CWE-863 (Incorrect Authorization)
Affected < 2026.2.2
Vendor/Product OpenClaw / OpenClaw
Advisory GHSA-mqpw-46fh-299h

OpenClaw versions prior to 2026.2.2 contain an authorization bypass vulnerability where clients with operator.write scope can approve or deny exec approval requests by sending the /approve chat command. The /approve command path invokes exec.approval.resolve through an internal privileged gateway client, bypassing the operator.approvals permission check that protects direct RPC calls.

References:


CVE-2026-35653 โ€” OpenClaw < 2026.3.24 - Incorrect Authorization in POST /reset-profile via browser.request

Field Detail
CVSS 7.2 (HIGH) โ€” CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N
CWE CWE-863 (CWE-863: Incorrect Authorization)
Affected < 2026.3.24
Vendor/Product OpenClaw / OpenClaw
Advisory GHSA-xp9r-prpg-373r

OpenClaw before 2026.3.24 contains an incorrect authorization vulnerability in the POST /reset-profile endpoint that allows authenticated callers with operator.write access to browser.request to bypass profile mutation restrictions. Attackers can invoke POST /reset-profile through the browser.request surface to stop the running browser, close Playwright connections, and move profile directories to Trash, crossing intended privilege boundaries.

References:


CVE-2026-26317 โ€” OpenClaw affected by cross-site request forgery (CSRF) through loopback browser mutation endpoints

Field Detail
CVSS 7.1 (HIGH) โ€” CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L
CWE CWE-352 (CWE-352: Cross-Site Request Forgery (CSRF))
Affected <= 2026.1.24-3
Vendor/Product openclaw / clawdbot
Advisory GHSA-3fqr-4cg8-h96q

OpenClaw is a personal AI assistant. Prior to 2026.2.14, browser-facing localhost mutation routes accepted cross-origin browser requests without explicit Origin/Referer validation. Loopback binding reduces remote exposure but does not prevent browser-initiated requests from malicious origins. A malicious website can trigger unauthorized state changes against a victim's local OpenClaw browser control plane (for example opening tabs, starting/stopping the browser, mutating storage/cookies) if the browser control service is reachable on loopback in the victim's browser context. Starting in version 2026.2.14, mutating HTTP methods (POST/PUT/PATCH/DELETE) are rejected when the request indicates a non-loopback Origin/Referer (or Sec-Fetch-Site: cross-site). Other mitigations include enabling browser control auth (token/password) and avoid running with auth disabled.

Naming note: Uses old name openclaw/clawdbot as vendor/product. References:


CVE-2026-22169 โ€” OpenClaw < 2026.2.22 - Allowlist Bypass via sort Configuration in safeBins

Field Detail
CVSS 7.1 (HIGH) โ€” CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CWE CWE-78 (Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78))
Affected < 2026.2.22
Vendor/Product OpenClaw / OpenClaw
Advisory GHSA-vmqr-rc7x-3446

OpenClaw versions prior to 2026.2.22 contain an allowlist bypass vulnerability in the safeBins configuration that allows attackers to invoke external helpers through the compress-program option. When sort is explicitly added to tools.exec.safeBins, remote attackers can bypass intended safe-bin approval constraints by leveraging the compress-program parameter to execute unauthorized external programs.

References:


CVE-2026-22175 โ€” OpenClaw < 2026.2.23 - Exec Approval Bypass via Unrecognized Multiplexer Shell Wrappers

Field Detail
CVSS 7.1 (HIGH) โ€” CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N
CWE CWE-184 (CWE-184: Incomplete List of Disallowed Inputs)
Affected < 2026.2.23
Vendor/Product OpenClaw / OpenClaw
Advisory GHSA-gwqp-86q6-w47g

OpenClaw versions prior to 2026.2.23 contain an exec approval bypass vulnerability in allowlist mode where allow-always grants could be circumvented through unrecognized multiplexer shell wrappers like busybox and toybox sh -c commands. Attackers can exploit this by invoking arbitrary payloads under the same multiplexer wrapper to satisfy stored allowlist rules, bypassing intended execution restrictions.

References:


CVE-2026-22168 โ€” OpenClaw < 2026.2.21 - Command Injection via cmd.exe /c Trailing Arguments in system.run

Field Detail
CVSS 7.1 (HIGH) โ€” CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
CWE CWE-88 (CWE-88 Argument Injection or Modification)
Affected < 2026.2.21
Vendor/Product OpenClaw / OpenClaw
Advisory GHSA-5v6x-rfc3-7qfr

OpenClaw versions prior to 2026.2.21 contain an approval-integrity mismatch vulnerability in system.run that allows authenticated operators to execute arbitrary trailing arguments after cmd.exe /c while approval text reflects only a benign command. Attackers can smuggle malicious arguments through cmd.exe /c to achieve local command execution on trusted Windows nodes with mismatched audit logs.

References:


CVE-2026-29607 โ€” OpenClaw < 2026.2.22 - Authorization Bypass via allow-always Wrapper Persistence

Field Detail
CVSS 7.1 (HIGH) โ€” CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CWE CWE-78 (Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78))
Affected < 2026.2.22
Vendor/Product OpenClaw / OpenClaw
Advisory GHSA-6j27-pc5c-m8w8

OpenClaw versions prior to 2026.2.22 contain an authorization bypass vulnerability in allow-always wrapper persistence that allows attackers to bypass approval checks by persisting wrapper-level allowlist entries instead of validating inner executable intent. Remote attackers can approve benign wrapped system.run commands and subsequently execute different payloads without approval, enabling remote code execution on gateway and node-host execution flows.

References:


CVE-2026-28459 โ€” OpenClaw < 2026.2.12 - Arbitrary File Write via Untrusted sessionFile Path

Field Detail
CVSS 7.1 (HIGH) โ€” CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N
CWE CWE-73 (External Control of File Name or Path)
Affected < 2026.2.12
Vendor/Product OpenClaw / OpenClaw
Advisory GHSA-64qx-vpxx-mvqf

OpenClaw versions prior to 2026.2.12 fail to validate the sessionFile path parameter, allowing authenticated gateway clients to write transcript data to arbitrary locations on the host filesystem. Attackers can supply a sessionFile path outside the sessions directory to create files and append data repeatedly, potentially causing configuration corruption or denial of service.

References:


CVE-2026-32027 โ€” OpenClaw < 2026.2.26 - Improper Authorization via DM Pairing Store Identity Inheritance in Group Allowlist

Field Detail
CVSS 7.1 (HIGH) โ€” CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
CWE CWE-22 (CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'))
Affected < 2026.2.26
Vendor/Product OpenClaw / OpenClaw
Advisory GHSA-jv6r-27ww-4gw4

OpenClaw versions prior to 2026.2.26 contain an authorization bypass vulnerability where DM pairing-store identities are incorrectly eligible for group allowlist authorization checks. Attackers can exploit this cross-context authorization flaw by using a sender approved via DM pairing to satisfy group sender allowlist checks without explicit presence in groupAllowFrom, bypassing group message access controls.

References:


CVE-2026-32976 โ€” OpenClaw < 2026.3.11 - Account-Scoped configWrites Policy Bypass via Channel Commands

Field Detail
CVSS 7.1 (HIGH) โ€” CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
CWE CWE-639 (Authorization Bypass Through User-Controlled Key)
Affected < 2026.3.11
Vendor/Product OpenClaw / OpenClaw
Advisory GHSA-8jhh-jcqg-mj5p

OpenClaw before 2026.3.11 contains an authorization bypass vulnerability allowing channel commands to mutate protected sibling-account configuration despite configWrites restrictions. Attackers with authorized access on one account can execute channel commands like /config set channels..accounts. to modify configuration on target accounts with configWrites: false.

References:


CVE-2026-35631 โ€” OpenClaw < 2026.3.22 - Missing Authorization Enforcement in Internal ACP Chat Commands

Field Detail
CVSS 7.1 (HIGH) โ€” CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
CWE CWE-862 (CWE-862 Missing Authorization)
Affected < 2026.3.22
Vendor/Product OpenClaw / OpenClaw
Advisory GHSA-3w6x-gv34-mqpf

OpenClaw before 2026.3.22 fails to enforce operator.admin scope on mutating internal ACP chat commands, allowing unauthorized modifications. Attackers without admin privileges can execute mutating control-plane actions by directly invoking affected ACP commands to bypass authorization gates.

References:


CVE-2026-35644 โ€” OpenClaw < 2026.3.22 - Credential Exposure via baseUrl Fields in Gateway Snapshots

Field Detail
CVSS 7.1 (HIGH) โ€” CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
CWE CWE-312 (CWE-312: Cleartext Storage of Sensitive Information)
Affected < 2026.3.22
Vendor/Product OpenClaw / OpenClaw
Advisory GHSA-ppwq-6v66-5m6j

OpenClaw before 2026.3.22 contains an information disclosure vulnerability that allows attackers with operator.read scope to expose credentials embedded in channel baseUrl and httpUrl fields. Attackers can access gateway snapshots via config.get and channels.status endpoints to retrieve sensitive authentication information from URL userinfo components.

References:


CVE-2026-35657 โ€” OpenClaw < 2026.3.25 - Authorization Bypass in HTTP Session History Route

Field Detail
CVSS 7.1 (HIGH) โ€” CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
CWE CWE-863 (CWE-863: Incorrect Authorization)
Affected < 2026.3.25
Vendor/Product OpenClaw / OpenClaw
Advisory GHSA-5jvj-hxmh-6h6j

OpenClaw before 2026.3.25 contains an authorization bypass vulnerability in the HTTP /sessions/:sessionKey/history route that skips operator.read scope validation. Attackers can access session history without proper operator read permissions by sending HTTP requests to the vulnerable endpoint.

References:


CVE-2026-40037 โ€” OpenClaw: fetchWithSsrFGuard replays unsafe request bodies across cross-origin redirects

Field Detail
CVSS 7.1 (HIGH) โ€” CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
CWE CWE-601 (CWE-601 URL Redirection to Untrusted Site ('Open Redirect'))
Affected < 2026.3.31
Vendor/Product OpenClaw / OpenClaw
Advisory GHSA-qx8j-g322-qj6m

OpenClaw before 2026.3.31 (patched in 2026.4.8) contains a request body replay vulnerability in fetchWithSsrFGuard that allows unsafe request bodies to be resent across cross-origin redirects. Attackers can exploit this by triggering redirects to exfiltrate sensitive request data or headers to unintended origins.

References:


CVE-2026-22176 โ€” OpenClaw < 2026.2.19 - Command Injection via Unescaped Environment Variables in Windows Scheduled Task Script Generation

Field Detail
CVSS 6.9 (MEDIUM) โ€” CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N
CWE CWE-78 (Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78))
Affected < 2026.2.19
Vendor/Product OpenClaw / OpenClaw
Advisory GHSA-pj5x-38rw-6fph

OpenClaw versions prior to 2026.2.19 contain a command injection vulnerability in Windows Scheduled Task script generation where environment variables are written to gateway.cmd using unquoted set KEY=VALUE assignments, allowing shell metacharacters to break out of assignment context. Attackers can inject arbitrary commands through environment variable values containing metacharacters like &, |, ^, %, or ! to achieve command execution when the scheduled task script is generated and executed.

References:


CVE-2026-22177 โ€” OpenClaw < 2026.2.21 - Environment Variable Injection via Config env.vars

Field Detail
CVSS 6.9 (MEDIUM) โ€” CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N
CWE CWE-15 (CWE-15: External Control of System or Configuration Setting)
Affected < 2026.2.21
Vendor/Product OpenClaw / OpenClaw
Advisory GHSA-8fmp-37rc-p5g7

OpenClaw versions prior to 2026.2.21 fail to filter dangerous process-control environment variables from config env.vars, allowing startup-time code execution. Attackers can inject variables like NODE_OPTIONS or LD_* through configuration to execute arbitrary code in the OpenClaw gateway service runtime context.

References:


CVE-2026-28480 โ€” OpenClaw Telegram allowlist authorization accepted mutable usernames

Field Detail
CVSS 6.9 (MEDIUM) โ€” CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
CWE CWE-290 (Authentication Bypass by Spoofing)
Affected < 2026.2.14
Vendor/Product OpenClaw / OpenClaw
Advisory GHSA-mj5r-hh7j-4gxf

OpenClaw versions prior to 2026.2.14 contain an authorization bypass vulnerability where Telegram allowlist matching accepts mutable usernames instead of immutable numeric sender IDs. Attackers can spoof identity by obtaining recycled usernames to bypass allowlist restrictions and interact with bots as unauthorized senders.

References:


CVE-2026-32975 โ€” OpenClaw < 2026.3.12 - Weak Authorization via Mutable Group Names in Zalouser Allowlist

Field Detail
CVSS 6.9 (MEDIUM) โ€” CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
CWE CWE-807 (Reliance on Untrusted Inputs in a Security Decision)
Affected < 2026.3.12
Vendor/Product OpenClaw / OpenClaw
Advisory GHSA-f5mf-3r52-r83w

OpenClaw before 2026.3.12 contains a weak authorization vulnerability in Zalouser allowlist mode that matches mutable group display names instead of stable group identifiers. Attackers can create groups with identical names to allowlisted groups to bypass channel authorization and route messages from unintended groups to the agent.

References:


CVE-2026-32919 โ€” OpenClaw < 2026.3.11 - Unauthorized Session Reset via agent Slash Commands

Field Detail
CVSS 6.9 (MEDIUM) โ€” CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N
CWE CWE-863 (Incorrect Authorization)
Affected < 2026.3.11
Vendor/Product OpenClaw / OpenClaw
Advisory GHSA-jf6w-m8jw-jfxc

OpenClaw before 2026.3.11 contains an authorization bypass vulnerability allowing write-scoped callers to reach admin-only session reset logic. Attackers with operator.write scope can issue agent requests containing /new or /reset slash commands to reset targeted conversation state without holding operator.admin privileges.

References:


CVE-2026-35627 โ€” OpenClaw < 2026.3.22 - Unauthenticated Cryptographic Work in Nostr Inbound DM Handling

Field Detail
CVSS 6.9 (MEDIUM) โ€” CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N
CWE CWE-696 (CWE-696: Incorrect Behavior Order)
Affected < 2026.3.22
Vendor/Product OpenClaw / OpenClaw
Advisory GHSA-65h8-27jh-q8wv

OpenClaw before 2026.3.22 performs cryptographic and dispatch operations on inbound Nostr direct messages before enforcing sender and pairing policy validation. Attackers can trigger unauthorized pre-authentication computation by sending crafted DM messages, enabling denial of service through resource exhaustion.

References:


CVE-2026-35633 โ€” OpenClaw < 2026.3.22 - Unbounded Memory Allocation via Remote Media Error Responses

Field Detail
CVSS 6.9 (MEDIUM) โ€” CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
CWE CWE-789 (Uncontrolled Memory Allocation)
Affected < 2026.3.22
Vendor/Product OpenClaw / OpenClaw
Advisory GHSA-4qwc-c7g9-4xcw

OpenClaw before 2026.3.22 contains an unbounded memory allocation vulnerability in remote media HTTP error handling that allows attackers to trigger excessive memory consumption. Attackers can send crafted HTTP error responses with large bodies to remote media endpoints, causing the application to allocate unbounded memory before failure handling occurs.

References:


CVE-2026-34510 โ€” OpenClaw < 2026.3.22 - Remote File URL Acceptance in Windows Media Loaders

Field Detail
CVSS 6.9 (MEDIUM) โ€” CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
CWE CWE-41 (CWE-41: Improper Resolution of Path Equivalence)
Affected < 2026.3.22
Vendor/Product OpenClaw / OpenClaw
Advisory GHSA-h3x4-hc5v-v2gm

OpenClaw before 2026.3.22 contains a path traversal vulnerability in Windows media loaders that accepts remote-host file URLs and UNC-style paths before local-path validation. Attackers can exploit this by providing network-hosted file targets that are treated as local content, bypassing intended access restrictions.

References:


CVE-2026-35652 โ€” OpenClaw < 2026.3.22 - Unauthorized Action Execution via Callback Dispatch

Field Detail
CVSS 6.9 (MEDIUM) โ€” CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N
CWE CWE-696 (CWE-696: Incorrect Behavior Order)
Affected < 2026.3.22
Vendor/Product OpenClaw / OpenClaw
Advisory GHSA-8883-9w57-vwv6

OpenClaw before 2026.3.22 contains an authorization bypass vulnerability in interactive callback dispatch that allows non-allowlisted senders to execute action handlers. Attackers can bypass sender authorization checks by dispatching callbacks before normal security validation completes, enabling unauthorized actions.

References:


CVE-2026-35647 โ€” OpenClaw < 2026.3.25 - Direct Message Policy Bypass via Verification Notices

Field Detail
CVSS 6.9 (MEDIUM) โ€” CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
CWE CWE-288 (CWE-288: Authentication Bypass Using an Alternate Path or Channel)
Affected < 2026.3.25
Vendor/Product OpenClaw / OpenClaw
Advisory GHSA-9wqx-g2cw-vc7r

OpenClaw before 2026.3.25 contains an access control vulnerability where verification notices bypass DM policy checks and reply to unpaired peers. Attackers can send verification notices to users outside allowed direct message policies by exploiting insufficient access validation before message transmission.

References:


CVE-2026-35654 โ€” OpenClaw < 2026.3.25 - Authorization Bypass in Microsoft Teams Feedback Invoke

Field Detail
CVSS 6.9 (MEDIUM) โ€” CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
CWE CWE-288 (CWE-288: Authentication Bypass Using an Alternate Path or Channel)
Affected < 2026.3.25
Vendor/Product OpenClaw / OpenClaw
Advisory GHSA-rf6h-5gpw-qrgq

OpenClaw before 2026.3.25 contains an authorization bypass vulnerability in Microsoft Teams feedback invokes that allows unauthorized senders to record session feedback. Attackers can bypass sender allowlist checks via feedback invoke endpoints to trigger unauthorized feedback recording or reflection.

References:


CVE-2026-35667 โ€” OpenClaw < 2026.3.24 - Improper Process Termination via Unpatched killProcessTree in shell-utils.ts

Field Detail
CVSS 6.9 (MEDIUM) โ€” CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N
CWE CWE-404 (CWE-404 Improper Resource Shutdown or Release)
Affected < 2026.3.24
Vendor/Product OpenClaw / OpenClaw
Advisory GHSA-3298-56p6-rpw2

OpenClaw before 2026.3.24 contains an incomplete fix for CVE-2026-27486 where the !stop chat command uses an unpatched killProcessTree function from shell-utils.ts that sends SIGKILL immediately without graceful SIGTERM shutdown. Attackers can trigger process termination via the !stop command, causing data corruption, resource leaks, and skipped security-sensitive cleanup operations.

References:


CVE-2026-32024 โ€” OpenClaw < 2026.2.22 - Symlink Traversal in Avatar Handling

Field Detail
CVSS 6.8 (MEDIUM) โ€” CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
CWE CWE-59 (CWE-59: Improper Link Resolution Before File Access ('Link Following'))
Affected < 2026.2.22
Vendor/Product OpenClaw / OpenClaw
Advisory GHSA-rx3g-mvc3-qfjf

OpenClaw versions prior to 2026.2.22 contain a symlink traversal vulnerability in avatar handling that allows attackers to read arbitrary files outside the configured workspace boundary. Remote attackers can exploit this by requesting avatar resources through gateway surfaces to disclose local files accessible to the OpenClaw process.

References:


CVE-2026-29612 โ€” OpenClaw < 2026.2.14 - Denial of Service via Large Base64 Media File Decoding

Field Detail
CVSS 6.8 (MEDIUM) โ€” CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
CWE CWE-770 (Allocation of Resources Without Limits or Throttling)
Affected < 2026.2.14
Vendor/Product OpenClaw / OpenClaw
Advisory GHSA-w2cg-vxx6-5xjg

OpenClaw versions prior to 2026.2.14 decode base64-backed media inputs into buffers before enforcing decoded-size budget limits, allowing attackers to trigger large memory allocations. Remote attackers can supply oversized base64 payloads to cause memory pressure and denial of service.

References:


CVE-2026-28452 โ€” OpenClaw affected by denial of service through unguarded archive extraction allowing high expansion/resource abuse (ZIP/TAR)

Field Detail
CVSS 6.7 (MEDIUM) โ€” CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
CWE CWE-770 (Allocation of Resources Without Limits or Throttling)
Affected < 2026.2.14
Vendor/Product OpenClaw / OpenClaw
Advisory GHSA-h89v-j3x9-8wqj

OpenClaw versions prior to 2026.2.14 contain a denial of service vulnerability in the extractArchive function within src/infra/archive.ts that allows attackers to consume excessive CPU, memory, and disk resources through high-expansion ZIP and TAR archives. Remote attackers can trigger resource exhaustion by providing maliciously crafted archive files during install or update operations, causing service degradation or system unavailability.

References:


CVE-2026-32044 โ€” OpenClaw < 2026.3.2 - Tar Archive Safety Bypass in Skills Installation

Field Detail
CVSS 6.7 (MEDIUM) โ€” CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
CWE CWE-409 (CWE-409 Improper Handling of Highly Compressed Data (Data Amplification))
Affected < 2026.3.2
Vendor/Product OpenClaw / OpenClaw
Advisory GHSA-77hf-7fqf-f227

OpenClaw versions prior to 2026.3.2 contain an archive extraction vulnerability in the tar.bz2 installer path that bypasses safety checks enforced on other archive formats. Attackers can craft malicious tar.bz2 skill archives to bypass special-entry blocking and extracted-size guardrails, causing local denial of service during skill installation.

References:


CVE-2026-26328 โ€” OpenClaw iMessage group allowlist authorization inherited DM pairing-store identities

Field Detail
CVSS 6.5 (MEDIUM) โ€” CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
CWE CWE-284 (CWE-284: Improper Access Control), CWE-863 (CWE-863: Incorrect Authorization)
Affected <= 2026.1.24-3
Vendor/Product openclaw / clawdbot
Advisory GHSA-g34w-4xqq-h79m

OpenClaw is a personal AI assistant. Prior to version 2026.2.14, under iMessage groupPolicy=allowlist, group authorization could be satisfied by sender identities coming from the DM pairing store, broadening DM trust into group contexts. Version 2026.2.14 fixes the issue.

Naming note: Uses old name openclaw/clawdbot as vendor/product. References:


CVE-2026-28449 โ€” OpenClaw < 2026.2.25 - Webhook Replay Attack via Missing Durable Replay Suppression

Field Detail
CVSS 6.3 (MEDIUM) โ€” CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N
CWE CWE-294 (CWE-294 Authentication Bypass by Capture-replay)
Affected < 2026.2.25
Vendor/Product OpenClaw / OpenClaw
Advisory GHSA-r9q5-c7qc-p26w

OpenClaw versions prior to 2026.2.25 lack durable replay state for Nextcloud Talk webhook events, allowing valid signed webhook requests to be replayed without suppression. Attackers can capture and replay previously valid signed webhook requests to trigger duplicate inbound message processing and cause integrity or availability issues.

References:


CVE-2026-28395 โ€” OpenClaw 2026.1.14-1 < 2026.2.12 - Unintended Public Binding of Chrome Extension Relay via Wildcard cdpUrl

Field Detail
CVSS 6.3 (MEDIUM) โ€” CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N
CWE CWE-1327 (Binding to an Unrestricted IP Address)
Affected < 2026.2.12
Vendor/Product OpenClaw / OpenClaw
Advisory GHSA-qw99-grcx-4pvm

OpenClaw version 2026.1.14-1 prior to 2026.2.12 contain an improper network binding vulnerability in the Chrome extension (must be installed and enabled) relay server that treats wildcard hosts as loopback addresses, allowing the relay HTTP/WS server to bind to all interfaces when a wildcard cdpUrl is configured. Remote attackers can access relay HTTP endpoints off-host to leak service presence and port information, or conduct denial-of-service and brute-force attacks against the relay token header.

References:


CVE-2026-28451 โ€” OpenClaw < 2026.2.14 - SSRF via Feishu Extension Media Fetching

Field Detail
CVSS 6.3 (MEDIUM) โ€” CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:L/SI:L/SA:L
CWE CWE-918 (Server-Side Request Forgery (SSRF))
Affected < 2026.2.14
Vendor/Product OpenClaw / OpenClaw
Advisory GHSA-x22m-j5qq-j49m

OpenClaw versions prior to 2026.2.14 contain server-side request forgery vulnerabilities in the Feishu extension that allow attackers to fetch attacker-controlled remote URLs without SSRF protections via sendMediaFeishu function and markdown image processing. Attackers can influence tool calls through direct manipulation or prompt injection to trigger requests to internal services and re-upload responses as Feishu media.

References:


CVE-2026-28471 โ€” OpenClaw 2026.1.14-1 < 2026.2.2 - Allowlist Bypass via displayName and Cross-Homeserver localpart Matching in Matrix Plugin

Field Detail
CVSS 6.3 (MEDIUM) โ€” CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
CWE CWE-287 (Improper Authentication)
Affected < 2026.2.2
Vendor/Product OpenClaw / OpenClaw
Advisory GHSA-rmxw-jxxx-4cpc

OpenClaw version 2026.1.14-1 prior to 2026.2.2, with the Matrix plugin installed and enabled, contain a vulnerability in which DM allowlist matching could be bypassed by exact-matching against sender display names and localparts without homeserver validation. Remote Matrix users can impersonate allowed identities by using attacker-controlled display names or matching localparts from different homeservers to reach the routing and agent pipeline.

References:


CVE-2026-32031 โ€” OpenClaw < 2026.2.26 - Authentication Bypass via Path Canonicalization Mismatch in /api/channels Gateway

Field Detail
CVSS 6.3 (MEDIUM) โ€” CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
CWE CWE-288 (CWE-288: Authentication Bypass Using an Alternate Path or Channel)
Affected < 2026.2.26
Vendor/Product OpenClaw / OpenClaw
Advisory GHSA-8j2w-6fmm-m587

OpenClaw versions prior to 2026.2.26 server-http contains an authentication bypass vulnerability in gateway authentication for plugin channel endpoints due to path canonicalization mismatch between the gateway guard and plugin handler routing. Attackers can bypass authentication by sending requests with alternative path encodings to access protected plugin channel APIs without proper gateway authentication.

References:


CVE-2026-32050 โ€” OpenClaw < 2026.2.25 - Unauthorized Reaction Status Event Enqueue via Access Check Bypass

Field Detail
CVSS 6.3 (MEDIUM) โ€” CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
CWE CWE-863 (CWE-863: Incorrect Authorization)
Affected < 2026.2.25
Vendor/Product OpenClaw / OpenClaw
Advisory GHSA-792q-qw95-f446

OpenClaw versions prior to 2026.2.25 contain an access control vulnerability in signal reaction notification handling that allows unauthorized senders to enqueue status events before authorization checks are applied. Attackers can exploit the reaction-only event path in event-handler.ts to queue signal reaction status lines for sessions without proper DM or group access validation.

References:


CVE-2026-33580 โ€” OpenClaw < 2026.3.28 - Brute Force Attack via Missing Rate Limiting on Webhook Shared Secret Authentication

Field Detail
CVSS 6.3 (MEDIUM) โ€” CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
CWE CWE-307 (CWE-307 Improper Restriction of Excessive Authentication Attempts)
Affected < 2026.3.28
Vendor/Product OpenClaw / OpenClaw
Advisory GHSA-9528-x887-j2fp

OpenClaw before 2026.3.28 contains a missing rate limiting vulnerability in the Nextcloud Talk webhook authentication that allows attackers to brute-force weak shared secrets. Attackers who can reach the webhook endpoint can exploit this to forge inbound webhook events by repeatedly attempting authentication without throttling.

References:


CVE-2026-35628 โ€” OpenClaw < 2026.3.25 - Brute-Force Attack via Missing Telegram Webhook Rate Limiting

Field Detail
CVSS 6.3 (MEDIUM) โ€” CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
CWE CWE-307 (CWE-307 Improper Restriction of Excessive Authentication Attempts)
Affected < 2026.3.25
Vendor/Product OpenClaw / OpenClaw
Advisory GHSA-vcx4-4qxg-mfp4

OpenClaw before 2026.3.25 contains a missing rate limiting vulnerability in Telegram webhook authentication that allows attackers to brute-force weak webhook secrets. The vulnerability enables repeated authentication guesses without throttling, permitting attackers to systematically guess webhook secrets through brute-force attacks.

References:


CVE-2026-35656 โ€” OpenClaw < 2026.3.22 - XFF Loopback Spoofing Bypass in Canvas Authentication and Rate Limiter

Field Detail
CVSS 6.3 (MEDIUM) โ€” CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
CWE CWE-290 (CWE-290: Authentication Bypass by Spoofing)
Affected < 2026.3.22
Vendor/Product OpenClaw / OpenClaw
Advisory GHSA-844j-xrrq-wgh4

OpenClaw before 2026.3.22 contains an authentication bypass vulnerability in the X-Forwarded-For header processing when trustedProxies is configured, allowing attackers to spoof loopback hops. Remote attackers can inject forged forwarding headers to bypass canvas authentication and rate-limiting protections by masquerading as loopback clients.

References:


CVE-2026-32057 โ€” OpenClaw < 2026.2.25 - Authentication Bypass via Control UI client.id Parameter

Field Detail
CVSS 6 (MEDIUM) โ€” CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N
CWE CWE-807 (CWE-807 Reliance on Untrusted Inputs in a Security Decision)
Affected < 2026.2.25
Vendor/Product OpenClaw / OpenClaw
Advisory GHSA-vvgp-4c28-m3jm

OpenClaw versions prior to 2026.2.25 contain an authentication bypass vulnerability in the trusted-proxy Control UI pairing mechanism that accepts client.id=control-ui without proper device identity verification. An authenticated node role websocket client can exploit this by using the control-ui client identifier to skip pairing requirements and gain unauthorized access to node event execution flows.

References:


CVE-2026-34511 โ€” OpenClaw < 2026.4.2 - PKCE Verifier Exposure via OAuth State Parameter

Field Detail
CVSS 6 (MEDIUM) โ€” CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
CWE CWE-330 (CWE-330 Use of Insufficiently Random Values)
Affected < 2026.4.2
Vendor/Product OpenClaw / OpenClaw
Advisory GHSA-9jpj-g8vv-j5mf

OpenClaw before 2026.4.2 reuses the PKCE verifier as the OAuth state parameter in the Gemini OAuth flow, exposing it through the redirect URL. Attackers who capture the redirect URL can obtain both the authorization code and PKCE verifier, defeating PKCE protection and enabling token redemption.

References:


CVE-2026-28477 โ€” OpenClaw < 2026.2.14 - OAuth State Validation Bypass in Manual Chutes Login Flow

Field Detail
CVSS 5.9 (MEDIUM) โ€” CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N
CWE CWE-352 (Cross-Site Request Forgery (CSRF))
Affected < 2026.2.14
Vendor/Product OpenClaw / OpenClaw
Advisory GHSA-7rcp-mxpq-72pj

OpenClaw versions prior to 2026.2.14 contain an oauth state validation bypass vulnerability in the manual Chutes login flow that allows attackers to bypass CSRF protection. An attacker can convince a user to paste attacker-controlled OAuth callback data, enabling credential substitution and token persistence for unauthorized accounts.

References:


CVE-2026-27009 โ€” OpenClaw affected by Stored XSS in Control UI via unsanitized assistant name/avatar in inline script injection

Field Detail
CVSS 5.8 (MEDIUM) โ€” CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:N
CWE CWE-79 (CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'))
Affected < 2026.2.15
Vendor/Product openclaw / openclaw
Advisory GHSA-37gc-85xm-2ww6

OpenClaw is a personal AI assistant. Prior to version 2026.2.15, a atored XSS issue in the OpenClaw Control UI when rendering assistant identity (name/avatar) into an inline <script> tag without script-context-safe escaping. A crafted value containing </script> could break out of the script tag and execute attacker-controlled JavaScript in the Control UI origin. Version 2026.2.15 removed inline script injection and serve bootstrap config from a JSON endpoint and added a restrictive Content Security Policy for the Control UI (script-src 'self', no inline scripts).

References:


CVE-2026-27670 โ€” OpenClaw < 2026.3.2 - Arbitrary File Write via ZIP Extraction Parent Symlink Race Condition

Field Detail
CVSS 5.8 (MEDIUM) โ€” CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N
CWE CWE-367 (CWE-367: Time-of-check Time-of-use (TOCTOU) Race Condition)
Affected < 2026.3.2
Vendor/Product OpenClaw / OpenClaw
Advisory GHSA-r54r-wmmq-mh84

OpenClaw versions prior to 2026.3.2 contain a race condition vulnerability in ZIP extraction that allows local attackers to write files outside the intended destination directory. Attackers can exploit a time-of-check-time-of-use race between path validation and file write operations by rebinding parent directory symlinks to redirect writes outside the extraction root.

References:


CVE-2026-31995 โ€” OpenClaw 2026.1.21 < 2026.2.19 - Command Injection via Windows Shell Fallback in Lobster Extension

Field Detail
CVSS 5.8 (MEDIUM) โ€” CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N
CWE CWE-78 (Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78))
Affected < 2026.2.19
Vendor/Product OpenClaw / OpenClaw
Advisory GHSA-fg3m-vhrr-8gj6

OpenClaw versions 2026.1.21 prior to 2026.2.19 contain a command injection vulnerability in the Lobster extension's Windows shell fallback mechanism that allows attackers to inject arbitrary commands through tool-provided arguments. When spawn failures trigger shell fallback with shell: true, attackers can exploit cmd.exe command interpretation to execute malicious commands by controlling workflow arguments.

References:


CVE-2026-32000 โ€” OpenClaw < 2026.2.19 - Command Injection via Windows Shell Fallback in Lobster Tool Execution

Field Detail
CVSS 5.8 (MEDIUM) โ€” CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N
CWE CWE-78 (Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78))
Affected < 2026.2.19
Vendor/Product OpenClaw / OpenClaw
Advisory GHSA-7fcc-cw49-xm78

OpenClaw versions prior to 2026.2.19 contain a command injection vulnerability in the Lobster extension tool execution that uses Windows shell fallback with shell: true after spawn failures. Attackers can inject shell metacharacters in command arguments to execute arbitrary commands when subprocess launch fails with EINVAL or ENOENT errors.

References:


CVE-2026-32052 โ€” OpenClaw < 2026.2.24 - Hidden Command Execution via Shell-Wrapper Positional argv Carriers

Field Detail
CVSS 5.8 (MEDIUM) โ€” CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:A/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N
CWE CWE-436 (Interpretation Conflict)
Affected < 2026.2.24
Vendor/Product OpenClaw / OpenClaw
Advisory GHSA-6rcp-vxwf-3mfp

OpenClaw versions prior to 2026.2.24 contain a command injection vulnerability in the system.run shell-wrapper that allows attackers to execute hidden commands by injecting positional argv carriers after inline shell payloads. Attackers can craft misleading approval text while executing arbitrary commands through trailing positional arguments that bypass display context validation.

References:


CVE-2026-32977 โ€” OpenClaw < 2026.3.11 - Sandbox Boundary Bypass via Unanchored writeFile Commit Path

Field Detail
CVSS 5.8 (MEDIUM) โ€” CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N
CWE CWE-367 (Time-of-check Time-of-use (TOCTOU) Race Condition)
Affected < 2026.3.11
Vendor/Product OpenClaw / OpenClaw
Advisory GHSA-xvx8-77m6-gwg6

OpenClaw before 2026.3.11 contains a sandbox boundary bypass vulnerability in the fs-bridge writeFile commit step that uses an unanchored container path during the final move operation. An attacker can exploit a time-of-check-time-of-use race condition by modifying parent paths inside the sandbox to redirect committed files outside the validated writable path within the container mount namespace.

References:


CVE-2026-33574 โ€” OpenClaw < 2026.3.8 - Path Traversal via Tools Root Rebinding in Skills Download

Field Detail
CVSS 5.8 (MEDIUM) โ€” CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N
CWE CWE-367 (Time-of-check Time-of-use (TOCTOU) Race Condition)
Affected < 2026.3.8
Vendor/Product OpenClaw / OpenClaw
Advisory GHSA-vhwf-4x96-vqx2

OpenClaw before 2026.3.8 contains a path traversal vulnerability in the skills download installer that validates the tools root lexically but reuses the mutable path during archive download and copy operations. A local attacker can rebind the tools-root path between validation and final write to redirect the installer outside the intended tools directory.

References:


CVE-2026-32988 โ€” OpenClaw < 2026.3.11 - Sandbox Boundary Bypass via Unvalidated Temporary File Creation

Field Detail
CVSS 5.8 (MEDIUM) โ€” CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N
CWE CWE-367 (Time-of-check Time-of-use (TOCTOU) Race Condition)
Affected < 2026.3.11
Vendor/Product OpenClaw / OpenClaw
Advisory GHSA-mj4p-rc52-m843

OpenClaw before 2026.3.11 contains a sandbox boundary bypass vulnerability in fs-bridge staged writes where temporary file creation and population are not pinned to a verified parent directory. Attackers can exploit a race condition in parent-path alias changes to write attacker-controlled bytes outside the intended validated path before the final guarded replace step executes.

References:


CVE-2026-28457 โ€” OpenClaw < 2026.2.14 - Path Traversal in Sandbox Skill Mirroring via Name Parameter

Field Detail
CVSS 5.6 (MEDIUM) โ€” CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N
CWE CWE-22 (Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'))
Affected < 2026.2.14
Vendor/Product OpenClaw / OpenClaw
Advisory GHSA-xw4p-pw82-hqr7

OpenClaw versions prior to 2026.2.14 contain a path traversal vulnerability in sandbox skill mirroring (must be enabled) that uses the skill frontmatter name parameter unsanitized when copying skills into the sandbox workspace. Attackers who provide a crafted skill package with traversal sequences like ../ or absolute paths in the name field can write files outside the sandbox workspace root directory.

References:


CVE-2026-31989 โ€” OpenClaw < 2026.3.1 - Server-Side Request Forgery via web_search Citation Redirect

Field Detail
CVSS 5.3 (MEDIUM) โ€” CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:L/SI:L/SA:L
CWE CWE-918 (CWE-918 Server-Side Request Forgery (SSRF))
Affected < 2026.3.1
Vendor/Product OpenClaw / OpenClaw
Advisory GHSA-g99v-8hwm-g76g

OpenClaw versions prior to 2026.3.1 contain a server-side request forgery vulnerability in web_search citation redirect resolution that uses a private-network-allowing SSRF policy. An attacker who can influence citation redirect targets can trigger internal-network requests from the OpenClaw host to loopback, private, or internal destinations.

References:


CVE-2026-32001 โ€” OpenClaw < 2026.2.22 - Node Role Device-Identity Bypass via WebSocket Authentication

Field Detail
CVSS 5.3 (MEDIUM) โ€” CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
CWE CWE-863 (CWE-863: Incorrect Authorization)
Affected < 2026.2.22
Vendor/Product OpenClaw / OpenClaw
Advisory GHSA-rv2q-f2h5-6xmg

OpenClaw versions prior to 2026.2.22 contain an authentication bypass vulnerability that allows clients authenticated with a shared gateway token to connect as role=node without device identity verification. Attackers can exploit this by claiming the node role during WebSocket handshake to inject unauthorized node.event calls, triggering agent.request and voice.transcript flows without proper device pairing.

References:


CVE-2026-32921 โ€” OpenClaw < 2026.3.8 - Script Content Modification via Mutable Operand Binding in system.run

Field Detail
CVSS 5.3 (MEDIUM) โ€” CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
CWE CWE-367 (Time-of-check Time-of-use (TOCTOU) Race Condition)
Affected < 2026.3.8
Vendor/Product OpenClaw / OpenClaw
Advisory GHSA-8g75-q649-6pv6

OpenClaw before 2026.3.8 contains an approval bypass vulnerability in system.run where mutable script operands are not bound across approval and execution phases. Attackers can obtain approval for script execution, modify the approved script file before execution, and execute different content while maintaining the same approved command shape.

References:


CVE-2026-33578 โ€” OpenClaw < 2026.3.28 - Sender Policy Allowlist Bypass via Policy Downgrade in Google Chat and Zalouser Extensions

Field Detail
CVSS 5.3 (MEDIUM) โ€” CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
CWE CWE-863 (CWE-863 Incorrect Authorization)
Affected < 2026.3.28
Vendor/Product OpenClaw / OpenClaw
Advisory GHSA-63mg-xp9j-jfcm

OpenClaw before 2026.3.28 contains a sender policy bypass vulnerability in the Google Chat and Zalouser extensions where route-level group allowlist policies silently downgrade to open policy. Attackers can exploit this policy resolution flaw to bypass sender restrictions and interact with bots despite configured allowlist restrictions.

References:


CVE-2026-35619 โ€” OpenClaw < 2026.3.24 - Authorization Bypass via HTTP /v1/models Endpoint

Field Detail
CVSS 5.3 (MEDIUM) โ€” CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
CWE CWE-863 (CWE-863: Incorrect Authorization)
Affected < 2026.3.24
Vendor/Product OpenClaw / OpenClaw
Advisory GHSA-68f8-9mhj-h2mp

OpenClaw before 2026.3.24 contains an authorization bypass vulnerability in the HTTP /v1/models endpoint that fails to enforce operator read scope requirements. Attackers with only operator.approvals scope can enumerate gateway model metadata through the HTTP compatibility route, bypassing the stricter WebSocket RPC authorization checks.

References:


CVE-2026-34425 โ€” OpenClaw - Shell-Bleed Protection Preflight Validation Bypass

Field Detail
CVSS 5.3 (MEDIUM) โ€” CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
CWE CWE-184 (CWE-184 Incomplete List of Disallowed Inputs)
Affected < 8aceaf5d0f0ec552b75a792f7f0a3bfa5b091513
Vendor/Product OpenClaw / OpenClaw
Advisory GHSA-fvx6-pj3r-5q4q

OpenClaw versions prior to commit 8aceaf5 contain a preflight validation bypass vulnerability in shell-bleed protection that allows attackers to execute blocked script content by using piped or complex command forms that the parser fails to recognize. Attackers can craft commands such as piped execution, command substitution, or subshell invocation to bypass the validateScriptFileForShellBleed() validation checks and execute arbitrary script content that would otherwise be blocked.

References:


CVE-2026-35629 โ€” OpenClaw < 2026.3.25 - Server-Side Request Forgery via Unguarded Configured Base URLs in Channel Extensions

Field Detail
CVSS 5.3 (MEDIUM) โ€” CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:L/SI:L/SA:L
CWE CWE-918 (CWE-918 Server-Side Request Forgery (SSRF))
Affected < 2026.3.25
Vendor/Product OpenClaw / OpenClaw
Advisory GHSA-rhfg-j8jq-7v2h

OpenClaw before 2026.3.25 contains a server-side request forgery vulnerability in multiple channel extensions that fail to properly guard configured base URLs against SSRF attacks. Attackers can exploit unprotected fetch() calls against configured endpoints to rebind requests to blocked internal destinations and access restricted resources.

References:


CVE-2026-35642 โ€” OpenClaw < 2026.3.25 - Authorization Bypass in Group Reactions via requireMention Bypass

Field Detail
CVSS 5.3 (MEDIUM) โ€” CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
CWE CWE-288 (CWE-288: Authentication Bypass Using an Alternate Path or Channel)
Affected < 2026.3.25
Vendor/Product OpenClaw / OpenClaw
Advisory GHSA-mw7w-g3mg-xqm7

OpenClaw before 2026.3.25 contains an authorization bypass vulnerability where group reaction events bypass the requireMention access control mechanism. Attackers can trigger reactions in mention-gated groups to enqueue agent-visible system events that should remain restricted.

References:


CVE-2026-32020 โ€” OpenClaw < 2026.2.22 - Arbitrary File Read via Symlink Following in Static File Handler

Field Detail
CVSS 4.8 (MEDIUM) โ€” CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
CWE CWE-59 (CWE-59: Improper Link Resolution Before File Access ('Link Following'))
Affected < 2026.2.22
Vendor/Product OpenClaw / OpenClaw
Advisory GHSA-5ghc-98wh-gwwf

OpenClaw versions prior to 2026.2.22 contain a path traversal vulnerability in the static file handler that follows symbolic links, allowing out-of-root file reads. Attackers can place symlinks under the Control UI root directory to bypass directory confinement checks and read arbitrary files outside the intended root.

References:


CVE-2026-27486 โ€” OpenClaw: Process Safety - Unvalidated PID Kill via SIGKILL in Process Cleanup

Field Detail
CVSS 4.3 (MEDIUM) โ€” CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:H
CWE CWE-283 (CWE-283: Unverified Ownership)
Affected < 2026.2.14
Vendor/Product openclaw / openclaw
Advisory GHSA-jfv4-h8mc-jcp8

OpenClaw is a personal AI assistant. In versions 2026.2.13 and below of the OpenClaw CLI, the process cleanup uses system-wide process enumeration and pattern matching to terminate processes without verifying if they are owned by the current OpenClaw process. On shared hosts, unrelated processes can be terminated if they match the pattern. The CLI runner cleanup helpers can kill processes matched by command-line patterns without validating process ownership. This issue has been fixed in version 2026.2.14.

References:


CVE-2026-32040 โ€” OpenClaw < 2026.2.23 - HTML Injection via Unvalidated Image MIME Type in Data-URL Interpolation

Field Detail
CVSS 2.4 (LOW) โ€” CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
CWE CWE-79 (CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'))
Affected < 2026.2.23
Vendor/Product OpenClaw / OpenClaw
Advisory GHSA-2ww6-868g-2c56

OpenClaw versions prior to 2026.2.23 contain an html injection vulnerability in the HTML session exporter that allows attackers to execute arbitrary javascript by injecting malicious mimeType values in image content blocks. Attackers can craft session entries with specially crafted mimeType attributes that break out of the img src data-URL context to achieve cross-site scripting when exported HTML is opened.

References:


CVE-2026-34506 โ€” OpenClaw < 2026.3.8 - Sender Allowlist Bypass in Microsoft Teams Plugin via Route Allowlist Configuration

Field Detail
CVSS 2.3 (LOW) โ€” CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
CWE CWE-863 (CWE-863: Incorrect Authorization)
Affected < 2026.3.8
Vendor/Product OpenClaw / OpenClaw
Advisory GHSA-g7cr-9h7q-4qxq

OpenClaw before 2026.3.8 contains a sender allowlist bypass vulnerability in its Microsoft Teams plugin that allows unauthorized senders to bypass intended authorization checks. When a team/channel route allowlist is configured with an empty groupAllowFrom parameter, the message handler synthesizes wildcard sender authorization, permitting any sender in the matched team/channel to trigger replies in allowlisted Teams routes.

References:


CVE-2026-35648 โ€” OpenClaw < 2026.3.22 - Policy Bypass via Unvalidated Queued Node Actions

Field Detail
CVSS 2.3 (LOW) โ€” CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
CWE CWE-367 (CWE-367: Time-of-check Time-of-use (TOCTOU) Race Condition)
Affected < 2026.3.22
Vendor/Product OpenClaw / OpenClaw
Advisory GHSA-wj55-88gf-x564

OpenClaw before 2026.3.22 contains a policy bypass vulnerability where queued node actions are not revalidated against current command policy when delivered. Attackers can exploit stale allowlists or declarations that survive policy tightening to execute unauthorized commands.

References:


CVE-2026-35624 โ€” OpenClaw < 2026.3.22 - Policy Confusion via Room Name Collision in Nextcloud Talk

Field Detail
CVSS 2.3 (LOW) โ€” CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
CWE CWE-807 (CWE-807 Reliance on Untrusted Inputs in a Security Decision)
Affected < 2026.3.22
Vendor/Product OpenClaw / OpenClaw
Advisory GHSA-xhq5-45pm-2gjr

OpenClaw before 2026.3.22 contains a policy confusion vulnerability in room authorization that matches colliding room names instead of stable room tokens. Attackers can exploit similarly named rooms to bypass allowlist policies and gain unauthorized access to protected Nextcloud Talk rooms.

References:


CVE-2026-32970 โ€” OpenClaw < 2026.3.11 - Credential Fallback Logic Bypass via Unavailable Local Auth SecretRefs

Field Detail
CVSS 2 (LOW) โ€” CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
CWE CWE-636 (Not Failing Securely ('Failing Open'))
Affected < 2026.3.11
Vendor/Product OpenClaw / OpenClaw
Advisory GHSA-qvr7-g57c-mrc7

OpenClaw before 2026.3.11 contains a credential fallback vulnerability where unavailable local gateway.auth.token and gateway.auth.password SecretRefs are treated as unset, allowing fallback to remote credentials in local mode. Attackers can exploit misconfigured local auth references to cause CLI and helper paths to select incorrect credential sources, potentially bypassing intended local authentication boundaries.

References:



โณ CVE Publication Pipeline

Of 15 GHSAs with CVE IDs, 15 are fully published and 0 remain RESERVED.

graph LR
    A["1๏ธโƒฃ GitHub Reserves<br/>CVE ID<br/><b>RESERVED</b>"] --> B["2๏ธโƒฃ GHSA Goes Public<br/>with CVE ID Shown"]
    B --> C["3๏ธโƒฃ CNA Submits<br/>CVE Record via<br/>CVE Services<br/><b>PUBLISHED</b>"]
    C --> D["4๏ธโƒฃ cvelistV5 Bot<br/>Commits JSON File"]

    style A fill:#fee,stroke:#c33,color:#333
    style B fill:#fff3cd,stroke:#856404,color:#333
    style C fill:#d4edda,stroke:#155724,color:#333
    style D fill:#cce5ff,stroke:#004085,color:#333
Loading
CVE ID State cvelistV5 GHSA Published CNA
CVE-2026-24763 โœ… PUBLISHED โœ… 2026-02-02 GitHub_M
CVE-2026-25157 โœ… PUBLISHED โœ… 2026-02-02 GitHub_M
CVE-2026-25253 โœ… PUBLISHED โœ… 2026-02-02 mitre
CVE-2026-26317 โœ… PUBLISHED โœ… 2026-02-18 GitHub_M
CVE-2026-26328 โœ… PUBLISHED โœ… 2026-02-18 GitHub_M
CVE-2026-28452 โœ… PUBLISHED โœ… 2026-02-18 VulnCheck
CVE-2026-28458 โœ… PUBLISHED โœ… 2026-02-17 VulnCheck
CVE-2026-28469 โœ… PUBLISHED โœ… 2026-02-18 VulnCheck
CVE-2026-28478 โœ… PUBLISHED โœ… 2026-02-18 VulnCheck
CVE-2026-28480 โœ… PUBLISHED โœ… 2026-02-18 VulnCheck
CVE-2026-29612 โœ… PUBLISHED โœ… 2026-02-18 VulnCheck
CVE-2026-34425 โœ… PUBLISHED โœ… 2026-04-06 VulnCheck
CVE-2026-34511 โœ… PUBLISHED โœ… 2026-04-04 VulnCheck
CVE-2026-40037 โœ… PUBLISHED โœ… 2026-04-09 VulnCheck
CVE-2026-6011 โœ… PUBLISHED โŒ 2026-04-10 โ€”

๐Ÿ”‘ Key Insights

Insight Detail
Dominant Weakness 40% of categorized issues relate to Allowlist Bypass (40/99)
V5 Sync Rate 15/15 CVE IDs (100%) have full cvelistV5 records
Advisory Velocity 139 security advisories across 2026-02-02 โ†’ 2026-04-10
Top Severity 2 Critical + 38 High = 40 high-impact issues (29%)

Vulnerability Categories

Category Count Examples
OS Command Injection (CWE-78) 18 PATH injection, SSH command injection, Docker exec, keychain writes
Path Traversal (CWE-22) 6 MEDIA: paths, plugin install, browser downloads, Zip Slip, transcript paths
SSRF 10 Image tool fetch, Feishu extension, attachment/media URLs, IPv6 bypass
Auth Bypass / Missing Auth 11 WebSocket config.apply, webhook verification, browser relay, sandbox bridge
Allowlist Bypass 40 Telegram usernames, Matrix displayName, Slack DM, Twitch, voice-call
Injection (XSS/CSRF/Prompt) 9 XSS in Control UI, prompt injection via Slack/CWD/logs, CSRF
Denial of Service 5 Unbounded media fetch, webhook body buffering, archive expansion

๐Ÿ“‹ All Security Advisories (139)

Critical & High Severity

GHSA CVE Severity Title Published
GHSA-r3v5-2grc-429h โ€” High Duplicate Advisory: OpenClaw Gateway: RCE and Privilege Escalation from operator.pairing to operator.admin via device.pair.approve 2026-04-10
GHSA-j56c-wpqm-h24x โ€” High Duplicate Advisory: OpenClaw: Plivo V2 verified replay identity drifts on query-only variants 2026-04-10
GHSA-qx8j-g322-qj6m CVE-2026-40037 High OpenClaw: fetchWithSsrFGuard replays unsafe request bodies across cross-origin redirects 2026-04-09
GHSA-5wj5-87vq-39xm โ€” High OpenClaw: Node Pairing Reconnect Command Escalation Bypasses operator.admin Scope Requirement 2026-04-09
GHSA-7437-7hg8-frrw โ€” High OpenClaw: HGRCPATH, CARGO_BUILD_RUSTC_WRAPPER, RUSTC_WRAPPER, and MAKEFLAGS missing from exec env denylist โ€” RCE via build tool env injection (GHSA-cm8v-2vh9-cxf3 class) 2026-04-09
GHSA-jf56-mccx-5f3f โ€” High OpenClaw: Authenticated /hooks/wake and mapped wake payloads are promoted into the trusted System: prompt channel 2026-04-09
GHSA-gfmx-pph7-g46x โ€” High OpenClaw: Lower-trust background runtime output is injected into trusted System: events, and local async exec completion misses the intended exec-event downgrade 2026-04-09
GHSA-pg8g-f2hf-x82m โ€” High Duplicate Advisory: OpenClaw: fetchWithSsrFGuard replays unsafe request bodies across cross-origin redirects 2026-04-09
GHSA-vfw7-6rhc-6xxg โ€” High OpenClaw Has Incomplete Fix for CVE-2026-4039: CLI Backend Environment Variable Injection via Workspace Config 2026-04-07
GHSA-9jpj-g8vv-j5mf CVE-2026-34511 High OpenClaw: Gemini OAuth exposed the PKCE verifier through the OAuth state parameter 2026-04-04
GHSA-q9w8-cf67-r238 โ€” High OpenClaw: macOS Tailnet DNS Spoofing & Credential Exfiltration 2026-04-03
GHSA-gg9v-mgcp-v6m7 โ€” High OpenClaw: Unbound bootstrap setup codes allow privilege escalation during pairing 2026-04-03
GHSA-h5hg-h7rr-gpf3 โ€” High OpenClaw: Node browser proxy allowProfiles bypass through persistent profile mutation and runtime profile selection 2026-04-03
GHSA-gjm7-hw8f-73rq โ€” High OpenClaw: Paired node escalates to gateway RCE via unrestricted node.event agent dispatch 2026-04-03
GHSA-9p3r-hh9g-5cmg โ€” Critical OpenClaw: Sandbox escape via TOCTOU race in remote FS bridge readFile 2026-04-03
GHSA-g374-mggx-p6xc โ€” High OpenClaw: Incomplete scope-clearing fix allows operator.admin escalation via trusted-proxy auth mode 2026-04-03
GHSA-f6pf-4gjx-c94r โ€” High OpenClaw: Media Parsing Path Traversal Leads to Arbitrary File Read 2026-04-03
GHSA-v3qc-wrwx-j3pw โ€” High OpenClaw: Agentic Consent Bypass โ€” LLM Agent Can Silently Disable Exec Approval via config.patch 2026-04-03
GHSA-g8xp-qx39-9jq9 โ€” High OpenClaw: Incomplete host-env-security-policy allows untrusted model to substitute compiler binaries via env overrides 2026-04-03
GHSA-xj9w-5r6q-x6v4 โ€” High OpenClaw: Device-Paired Node Skips Node Scope Gate โ†’ Host RCE.md 2026-04-03
GHSA-57gh-m6rq-54cf โ€” High OpenClaw: Self-Whitelisting in appendLocalMediaParentRoots Allows Arbitrary File Read & Credential Exfiltration 2026-04-03
GHSA-cwf8-44x6-32c2 โ€” High OpenClaw: OpenShell Mirror Sync โ€” Sandbox Escape via Unrestricted File Sync + Symlink Traversal 2026-04-03
GHSA-qcj9-wwgw-6gm8 โ€” High OpenClaw: Workspace .env can override the bundled plugin trust root 2026-04-03
GHSA-rq6g-px6m-c248 CVE-2026-28469 High OpenClaw Google Chat shared-path webhook target ambiguity allowed cross-account policy-context misrouting 2026-02-18
GHSA-3fqr-4cg8-h96q CVE-2026-26317 High OpenClaw affected by cross-site request forgery (CSRF) through loopback browser mutation endpoints 2026-02-18
GHSA-q447-rj3r-2cgh CVE-2026-28478 High OpenClaw affected by denial of service via unbounded webhook request body buffering 2026-02-18
GHSA-mr32-vwc2-5j6h CVE-2026-28458 High OpenClaw's Browser Relay /cdp websocket is missing auth which could allow cross-tab cookie access 2026-02-17
GHSA-q284-4pvr-m585 CVE-2026-25157 High OpenClaw/Clawdbot has OS Command Injection via Project Root Path in sshNodeCommand 2026-02-02
GHSA-g8p2-7wf7-98mq CVE-2026-25253 High OpenClaw/Clawdbot has 1-Click RCE via Authentication Token Exfiltration From gatewayUrl 2026-02-02
GHSA-mc68-q9jw-2h3v CVE-2026-24763 High OpenClaw/Clawdbot Docker Execution has Authenticated Command Injection via PATH Environment Variable 2026-02-02
GHSA-r2c6-8jc8-g32w โ€” High Duplicate Advisory: 1-Click RCE via Authentication Token Exfiltration From gatewayUrl 2026-02-02

Medium Severity

GHSA CVE Severity Title Published
GHSA-p6j4-wvmc-vx2h โ€” Medium Duplicate Advisory: OpenClaw: Tlon cite expansion happens before channel and DM authorization is complete 2026-04-10
GHSA-59xc-5v89-r7pr โ€” Medium Duplicate Advisory: OpenClaw: Synology Chat Webhook Pre-Auth Rate-Limit Bypass Enables Brute-Force Guessing of Webhook Token 2026-04-10
GHSA-hm63-vwj4-mj2q โ€” Medium Duplicate Advisory: OpenClaw: Remote media error responses could trigger unbounded memory allocation before failure 2026-04-10
GHSA-2j53-2c28-g9v2 โ€” Medium Duplicate Advisory: OpenClaw: Nostr inbound DMs could trigger unauthenticated crypto work before sender policy enforcement 2026-04-10
GHSA-8f9r-gr6r-x63q โ€” Medium Duplicate Advisory: OpenClaw: Feishu webhook reads and parses unauthenticated request bodies before signature validation 2026-04-10
GHSA-8j7f-g9gv-7jhc โ€” Medium Duplicate Advisory: OpenClaw: SSRF via Unguarded Configured Base URLs in Multiple Channel Extensions (Incomplete Fix for CVE-2026-28476) 2026-04-10
GHSA-9gvx-vj57-vqqx โ€” Medium Duplicate Advisory: OpenClaw: Gateway Canvas local-direct requests bypass Canvas HTTP and WebSocket authentication 2026-04-10
GHSA-36cp-mh65-x882 โ€” Medium Duplicate Advisory: OpenClaw is vulnerable to unauthenticated resource exhaustion through its voice call webhook handling 2026-04-10
GHSA-g8mc-c5f2-mqg7 โ€” Medium Duplicate Advisory: OpenClaw Bypasses DM Policy Separation via Synology Chat Webhook Path Collision 2026-04-10
GHSA-ccx3-fw7q-rr2r โ€” Medium OpenClaw: Multiple Code Paths Missing Base64 Pre-Allocation Size Checks 2026-04-09
GHSA-3vvq-q2qc-7rmp โ€” Medium OpenClaw B-M3: ClawHub package downloads are not enforced with integrity verification 2026-04-09
GHSA-w9j9-w4cp-6wgr โ€” Medium OpenClaw Host-Exec Environment Variable Injection 2026-04-09
GHSA-w8g9-x8gx-crmm โ€” Medium OpenClaw: Strict browser SSRF bypass in Playwright redirect handling leaves private targets reachable 2026-04-09
GHSA-vr5g-mmx7-h897 โ€” Medium OpenClaw has Browser SSRF Policy Bypass via Interaction-Triggered Navigation 2026-04-09
GHSA-67mf-f936-ppxf โ€” Medium OpenClaw node.pair.approve placed in operator.write scope instead of operator.pairing allows unprivileged pairing approval 2026-04-09
GHSA-3fv3-6p2v-gxwj โ€” Medium OpenClaw QQ Bot Extension missing SSRF Protection on All Media Fetch Paths 2026-04-09
GHSA-5h3f-885m-v22w โ€” Medium OpenClaw: Existing WS sessions survive shared gateway token rotation 2026-04-09
GHSA-vc32-h5mq-453v โ€” Medium OpenClaw: /allowlist omits owner-only enforcement for cross-channel allowlist writes 2026-04-09
GHSA-68x5-xx89-w9mm โ€” Medium OpenClaw: resolvedAuth closure becomes stale after config reload 2026-04-09
GHSA-cmfr-9m2r-xwhq โ€” Medium OpenClaw node.invoke(browser.proxy) bypasses browser.request persistent profile-mutation guard 2026-04-09
GHSA-whf9-3hcx-gq54 โ€” Medium OpenClaw device.token.rotate mints tokens for unapproved roles, bypassing device role-upgrade pairing 2026-04-09
GHSA-qqq7-4hxc-x63c โ€” Medium OpenClaw: Shared reply MEDIA - paths are treated as trusted and can trigger cross-channel local file exfiltration 2026-04-09
GHSA-q2gc-xjqw-qp89 โ€” Medium OpenClaw: strictInlineEval explicit-approval boundary bypassed by approval-timeout fallback on gateway and node exec hosts 2026-04-09
GHSA-83f3-hh45-vfw9 โ€” Medium OpenClaw: Android accepted cleartext remote gateway endpoints and sent stored credentials over ws:// 2026-04-07
GHSA-jj6q-rrrf-h66h โ€” Medium OpenClaw: Shared-secret comparison call sites leaked length information through timing 2026-04-07
GHSA-rxmx-g7hr-8mx4 โ€” Medium OpenClaw: Zalo replay dedupe keys could suppress messages across chats or senders 2026-04-07
GHSA-fh32-73r9-rgh5 โ€” Medium OpenClaw: Trailing-dot localhost CDP hosts could bypass remote loopback protections 2026-04-07
GHSA-w6wx-jq6j-6mcj โ€” Medium OpenClaw: pnpm dlx approvals did not bind local script operands 2026-04-07
GHSA-98ch-45wp-ch47 โ€” Medium OpenClaw: Windows-compatible env override keys could bypass system.run approval binding 2026-04-07
GHSA-2f7j-rp58-mr42 โ€” Medium OpenClaw: Gateway hello snapshots exposed host config and state paths to non-admin clients 2026-04-07
GHSA-2qrv-rc5x-2g2h โ€” Medium OpenClaw: Untrusted workspace channel shadows could execute during built-in channel setup 2026-04-07
GHSA-5hff-46vh-rxmw โ€” Medium OpenClaw: Read-scoped identity-bearing HTTP clients could kill sessions via /sessions/:sessionKey/kill 2026-04-07
GHSA-4p4f-fc8q-84m3 โ€” Medium OpenClaw: iOS A2UI bridge trusted generic local-network pages for agent.request dispatch 2026-04-07
GHSA-846p-hgpv-vphc โ€” Medium OpenClaw: QQ Bot structured payloads could read arbitrary local files 2026-04-07
GHSA-m34q-h93w-vg5x โ€” Medium OpenClaw: OpenShell mirror mode could delete arbitrary remote directories when roots were mis-scoped 2026-04-07
GHSA-wwfp-w96m-c6x8 โ€” Medium OpenClaw: Pairing pending-request caps were enforced per channel instead of per account 2026-04-07
GHSA-h43v-27wg-5mf9 โ€” Medium OpenClaw: Forged Nostr DMs could create pairing state before signature verification 2026-04-07
GHSA-wpc6-37g7-8q4w โ€” Medium OpenClaw: Shell init-file options could satisfy exec allowlist script matching 2026-04-07
GHSA-42mx-vp8m-j7qh โ€” Medium OpenClaw: OpenShell mirror mode can convert untrusted sandbox files into explicitly enabled workspace hooks and execute them on the host during gateway startup 2026-04-07
GHSA-fwjq-xwfj-gv75 โ€” Medium OpenClaw: session_status still bypasses configured tools.sessions.visibility for unsandboxed invocations 2026-04-07
GHSA-3q42-xmxv-9vfr โ€” Medium OpenClaw: Gateway operator.write Can Reach Admin-Class Talk Voice Config Persistence via chat.send 2026-04-07
GHSA-vjx8-8p7h-82gr โ€” Medium OpenClaw: Marketplace Plugin Download Follows Redirects Without SSRF Protection 2026-04-07
GHSA-4g5x-2jfc-xm98 โ€” Medium OpenClaw: Tlon media downloads can bypass core safety limits and exhaust disk 2026-04-07
GHSA-h2v7-xc88-xx8c โ€” Medium OpenClaw: /phone arm//phone disarm Bypasses operator.admin Scope Check for External Channels 2026-04-07
GHSA-fvx6-pj3r-5q4q CVE-2026-34425 Medium OpenClaw's complex interpreter pipelines could skip exec script preflight validation 2026-04-06
GHSA-ch86-pxr9-j9h9 โ€” Medium Duplicate Advisory: OpenClaw: Gemini OAuth exposed the PKCE verifier through the OAuth state parameter 2026-04-03
GHSA-6336-qqw9-v6x6 โ€” Medium OpenClaw: Discord Component Interaction Misclassifies Group DM as Direct Message 2026-04-03
GHSA-9f4w-67g7-mqwv โ€” Medium OpenClaw: Endpoint persists after trust decline, leaking gateway credentials 2026-04-03
GHSA-3xv9-89fm-7h4r โ€” Medium OpenClaw: diffs viewer misclassifies proxied remote requests as loopback when allowRemoteViewer is disabled 2026-04-03
GHSA-rvvf-6vh3-9j43 โ€” Medium OpenClaw: Discord Slash Commands Bypass Group DM Channel Allowlist 2026-04-03
GHSA-f693-58pc-2gfr โ€” Medium OpenClaw: Telegram legacy allowFrom migration fans default-account trust into all named accounts 2026-04-03
GHSA-cqgw-44wg-44rf โ€” Medium OpenClaw: Discord voice manager bypasses channel-level member access allowlist 2026-04-03
GHSA-m6fx-m8hc-572m โ€” Medium OpenClaw: Telegram audio preflight transcription enables resource consumption by unauthorized senders 2026-04-03
GHSA-2w79-r9g8-wmcr โ€” Medium OpenClaw: Voice-call still parses large WebSocket frames before start validation (Incomplete fix for CVE-2026-32062) 2026-04-03
GHSA-6p8r-6m93-557f โ€” Medium OpenClaw: Fake DeviceToken Bypasses Shared Auth Rate Limiting 2026-04-03
GHSA-cg7q-fg22-4g98 โ€” Medium OpenClaw: Host exec environment sanitization misses package, registry, Docker, compiler, and TLS override variables 2026-04-03
GHSA-58q2-7r52-jq62 โ€” Medium OpenClaw: Path traversal via inbound channel attachment path in ACP dispatch allows arbitrary file read 2026-04-03
GHSA-hr8g-2q7x-3f4w โ€” Medium OpenClaw Has a Gateway Control Interface Information Disclosure Vulnerability 2026-04-03
GHSA-rm5c-4rmf-vvhw โ€” Medium OpenClaw: Sandbox file operations use check-then-act, bypassing fd-based TOCTOU defenses 2026-04-03
GHSA-w85g-3h6x-4xh2 โ€” Medium OpenClaw: Image pixel-limit guard can fail open on sips and allow decompression-bomb DoS 2026-04-03
GHSA-9gp8-hjxr-6f34 โ€” Medium OpenClaw: Host exec environment overrides miss proxy, TLS, Docker, and Git TLS controls 2026-04-03
GHSA-hhff-fj5f-qg48 โ€” Medium OpenClaw runs Discord audio preflight transcription before member authorization 2026-04-03
GHSA-mhr7-2xmv-4c4q โ€” Medium OpenClaw: HTTP operator endpoints lack browser-origin validation in trusted-proxy mode 2026-04-03
GHSA-p464-m8x6-vhv8 โ€” Medium OpenClaw: MS Teams webhook parses body before JWT validation, enabling unauthenticated resource exhaustion 2026-04-03
GHSA-68v4-hmwv-f43h โ€” Medium OpenClaw: Media download follows cross-origin redirects with Authorization headers intact 2026-04-03
GHSA-rf75-g96h-j3rm โ€” Medium Duplicate Advisory: OpenClaw's complex interpreter pipelines could skip exec script preflight validation 2026-04-02
GHSA-mj5r-hh7j-4gxf CVE-2026-28480 Medium OpenClaw Telegram allowlist authorization accepted mutable usernames 2026-02-18
GHSA-h89v-j3x9-8wqj CVE-2026-28452 Medium OpenClaw affected by denial of service through unguarded archive extraction allowing high expansion/resource abuse (ZIP/TAR) 2026-02-18
GHSA-w2cg-vxx6-5xjg CVE-2026-29612 Medium OpenClaw: denial of service through large base64 media files allocating large buffers before limit checks 2026-02-18
GHSA-g34w-4xqq-h79m CVE-2026-26328 Medium OpenClaw iMessage group allowlist authorization inherited DM pairing-store identities 2026-02-18

Low Severity

GHSA CVE Severity Title Published
GHSA-52vj-fvrv-7q82 CVE-2026-6011 Low OpenClaw vulnerable to SSRF in src/agents/tools/web-fetch.ts 2026-04-10
GHSA-cm8v-2vh9-cxf3 โ€” Low OpenClaw: GIT_DIR and related git plumbing env vars missing from exec env denylist (GHSA-m866-6qv5-p2fg variant) 2026-04-09
GHSA-4f8g-77mw-3rxc โ€” Low OpenClaw: Gateway plugin HTTP auth: gateway widens identity-bearing operator.read requests into runtime operator.write 2026-04-09
GHSA-5fc7-f62m-8983 โ€” Low OpenClaw: Feishu docx upload_file/upload_image Bypasses Workspace-Only Filesystem Policy (GHSA-qf48-qfv4-jjm9 Incomplete Fix) 2026-04-09
GHSA-25wv-8phj-8p7r โ€” Low OpenClaw: Concurrent async auth attempts can bypass the intended shared-secret rate-limit budget on Tailscale-capable paths 2026-04-09
GHSA-fqrj-m88p-qf3v โ€” Low OpenClaw: Zalo replay dedupe cache could suppress events across authenticated webhook targets 2026-04-07
GHSA-767m-xrhc-fxm7 โ€” Low OpenClaw: Gateway operator.write Can Reach Admin-Class Telegram Config and Cron Persistence via send 2026-04-07
GHSA-x2m8-53h4-6hch โ€” Low OpenClaw: Discord voice ingress authorization can be bypassed via channel, name, and stale-role validation gaps 2026-04-03
GHSA-3pm9-5j7m-59vc โ€” Low OpenClaw: Tlon Startup Migration Rehydrates Empty-Array Revocations From File Config 2026-04-03
GHSA-rfqg-qgf8-xr9x โ€” Low OpenClaw: Gateway device.token.rotate does not terminate active WebSocket sessions after credential rotation 2026-04-03
GHSA-37v6-fxx8-xjmx โ€” Low OpenClaw: Telnyx Webhook Replay Detection Bypass via Base64 Signature Re-encoding 2026-04-03
GHSA-chm2-m3w2-wcxm โ€” Low OpenClaw Google Chat spoofing access with allowlist authorized mutable email principal despite sender-ID mismatch 2026-02-17

Repo-Only Advisories (~26 more)

These advisories are listed on the repo security page but not yet indexed in the GitHub Advisory Database. See the full advisory list for details.

Show 26 repo-only advisories
GHSA Severity Title Published
GHSA-g5cg-8x5w-7jpm Critical Heartbeat context inheritance bypasses sandbox via senderIsOwner escalation 2026-03-31
GHSA-2x4x-cc5g-qmmg High node.pair.approve missing callerScopes validation allows low-privilege operator to approve malicious nodes 2026-03-29
GHSA-3cw3-5vxw-g2h3 High CLI Remote Onboarding Persists Unauthenticated Discovery Endpoint and Exfiltrates Gateway Credentials 2026-03-29
GHSA-3qpv-xf3v-mm45 High Workspace .env can override the bundled hooks root and load attacker hook code 2026-03-31
GHSA-7ggg-pvrf-458v High PIP_INDEX_URL and UV_INDEX_URL bypass host exec env sanitization and redirect Python package-index traffic 2026-03-31
GHSA-8689-gm9g-jgr6 High Voice-call Plivo V3 webhook replay key uses unsorted URL, allowing replay via query-parameter reordering 2026-03-29
GHSA-98hh-7ghg-x6rq High Discord text /approve bypasses channels.discord.execApprovals.approvers and allows non-approvers to resolve pending exec approvals 2026-03-29
GHSA-fv94-qvg8-xqpw High SSH sandbox tar upload follows symlinks, enabling arbitrary file write on remote host 2026-03-31
GHSA-qxgf-hmcj-3xw3 High SSRF via unguarded image download in fal provider 2026-03-29
GHSA-63mg-xp9j-jfcm Medium Google Chat and Zalouser group sender allowlist bypass via policy downgrade 2026-03-29
GHSA-877v-w3f5-3pcq Medium Feishu thread history and quoted messages bypass sender allowlist 2026-03-31
GHSA-9528-x887-j2fp Medium Nextcloud Talk webhook missing rate limiting on shared secret authentication 2026-03-29
GHSA-9q7v-8mr7-g23p Medium SSRF via Unguarded fetch() in Marketplace Plugin Download and Ollama Model Discovery 2026-03-31
GHSA-chfm-xgc4-47rj Medium MSTeams thread history bypasses sender allowlist via Graph API 2026-03-31
GHSA-jjw7-3vjf-fg5j Medium OpenClaw Nostr privateKey config redaction bypass leaks plaintext signing key via config.get 2026-03-31
GHSA-jp4j-q5fc-58gv Medium Discord component interaction ingress skips guild/channel policy enforcement 2026-03-29
GHSA-mhgq-xpfq-6r66 Medium Unauthenticated plugin-auth HTTP routes receive operator runtime scopes 2026-03-31
GHSA-qm77-8qjp-4vcm Medium Slack thread context could include messages from non-allowlisted senders 2026-04-02
GHSA-rg8m-3943-vm6q Medium Matrix thread root and reply context bypass sender allowlist 2026-03-31
GHSA-v2v2-f783-358j Medium Zalo channel downloads media before sender authorization 2026-03-29
GHSA-89r3-6x4j-v7wf Low Voice-call Plivo replay mutates in-process callback origin before replay rejection 2026-03-31
GHSA-cwq8-6f96-g3q4 Low Security Scan Failure Does Not Block Plugin Installation (Fail-Open) 2026-03-31
GHSA-gj9q-8w99-mp8j Low TOCTOU read in exec script preflight 2026-04-15
GHSA-hhq4-97c2-p447 Low Zalo webhook replay cache cross-target messageId scope bypass 2026-03-31
GHSA-j9pv-rrcj-6pfx Low SSH-based sandbox backends pass unsanitized process.env to child processes 2026-03-31
GHSA-qcc3-jqwp-5vh2 Low LINE webhook handler lacks shared pre-auth concurrency budget before signature verification 2026-03-31

Naming Inconsistencies

The OpenClaw project has been renamed multiple times, causing inconsistencies across CVE records:

CVE vendor product packageURL Description Names
CVE-2026-32922 OpenClaw OpenClaw pkg:npm/openclaw OpenClaw
CVE-2026-28474 OpenClaw nextcloud-talk pkg:npm/openclaw-nextcloud-talk OpenClaw
CVE-2026-32987 OpenClaw OpenClaw pkg:npm/openclaw OpenClaw
CVE-2026-28391 OpenClaw OpenClaw pkg:npm/openclaw OpenClaw
CVE-2026-28446 OpenClaw OpenClaw pkg:npm/openclaw OpenClaw
CVE-2026-32917 OpenClaw OpenClaw pkg:npm/openclaw OpenClaw
CVE-2026-25253 OpenClaw OpenClaw pkg:npm/clawdbot OpenClaw / clawdbot / Moltbot
CVE-2026-24763 clawdbot clawdbot โ€” OpenClaw (formerly Clawdbot)
CVE-2026-22171 OpenClaw OpenClaw pkg:npm/openclaw OpenClaw
CVE-2026-32973 OpenClaw OpenClaw pkg:npm/openclaw OpenClaw
CVE-2026-28461 OpenClaw OpenClaw pkg:npm/openclaw OpenClaw
CVE-2026-28478 OpenClaw OpenClaw pkg:npm/openclaw OpenClaw
CVE-2026-32049 OpenClaw OpenClaw pkg:npm/openclaw OpenClaw
CVE-2026-32980 OpenClaw OpenClaw pkg:npm/openclaw OpenClaw
CVE-2026-32982 OpenClaw OpenClaw pkg:npm/openclaw OpenClaw
CVE-2026-33573 OpenClaw OpenClaw pkg:npm/openclaw OpenClaw
CVE-2026-35639 OpenClaw OpenClaw pkg:npm/openclaw OpenClaw
CVE-2026-35638 OpenClaw OpenClaw pkg:npm/openclaw OpenClaw
CVE-2026-27001 openclaw openclaw โ€” OpenClaw
CVE-2026-33579 OpenClaw OpenClaw pkg:npm/openclaw OpenClaw
CVE-2026-34503 OpenClaw OpenClaw pkg:npm/openclaw OpenClaw
CVE-2026-33577 OpenClaw OpenClaw pkg:npm/openclaw OpenClaw
CVE-2026-28450 OpenClaw OpenClaw pkg:npm/openclaw OpenClaw
CVE-2026-28393 OpenClaw OpenClaw pkg:npm/openclaw OpenClaw
CVE-2026-28453 OpenClaw OpenClaw pkg:npm/openclaw OpenClaw
CVE-2026-32036 OpenClaw OpenClaw pkg:npm/openclaw OpenClaw
CVE-2026-35618 OpenClaw OpenClaw pkg:npm/openclaw OpenClaw
CVE-2026-28469 OpenClaw OpenClaw pkg:npm/openclaw OpenClaw
CVE-2026-32045 OpenClaw OpenClaw pkg:npm/openclaw OpenClaw
CVE-2026-25157 openclaw openclaw โ€” OpenClaw
CVE-2026-35650 OpenClaw OpenClaw pkg:npm/openclaw OpenClaw
CVE-2026-35666 OpenClaw OpenClaw pkg:npm/openclaw OpenClaw
CVE-2026-27487 openclaw openclaw โ€” OpenClaw
CVE-2026-32007 OpenClaw OpenClaw pkg:npm/openclaw OpenClaw
CVE-2026-26319 openclaw openclaw โ€” OpenClaw
CVE-2026-25474 openclaw openclaw โ€” OpenClaw
CVE-2026-26321 openclaw openclaw โ€” OpenClaw
CVE-2026-28458 OpenClaw OpenClaw pkg:npm/openclaw OpenClaw
CVE-2026-28473 OpenClaw OpenClaw pkg:npm/openclaw OpenClaw
CVE-2026-35653 OpenClaw OpenClaw pkg:npm/openclaw OpenClaw
CVE-2026-26317 openclaw clawdbot โ€” OpenClaw (formerly Clawdbot)
CVE-2026-22169 OpenClaw OpenClaw pkg:npm/openclaw OpenClaw
CVE-2026-22175 OpenClaw OpenClaw pkg:npm/openclaw OpenClaw
CVE-2026-22168 OpenClaw OpenClaw pkg:npm/openclaw OpenClaw
CVE-2026-29607 OpenClaw OpenClaw pkg:npm/openclaw OpenClaw
CVE-2026-28459 OpenClaw OpenClaw pkg:npm/openclaw OpenClaw
CVE-2026-32027 OpenClaw OpenClaw pkg:npm/openclaw OpenClaw
CVE-2026-32976 OpenClaw OpenClaw pkg:npm/openclaw OpenClaw
CVE-2026-35631 OpenClaw OpenClaw pkg:npm/openclaw OpenClaw
CVE-2026-35644 OpenClaw OpenClaw pkg:npm/openclaw OpenClaw
CVE-2026-35657 OpenClaw OpenClaw pkg:npm/openclaw OpenClaw
CVE-2026-40037 OpenClaw OpenClaw pkg:npm/openclaw OpenClaw
CVE-2026-22176 OpenClaw OpenClaw pkg:npm/openclaw OpenClaw
CVE-2026-22177 OpenClaw OpenClaw pkg:npm/openclaw OpenClaw
CVE-2026-28480 OpenClaw OpenClaw pkg:npm/openclaw OpenClaw
CVE-2026-32975 OpenClaw OpenClaw pkg:npm/openclaw OpenClaw
CVE-2026-32919 OpenClaw OpenClaw pkg:npm/openclaw OpenClaw
CVE-2026-35627 OpenClaw OpenClaw pkg:npm/openclaw OpenClaw
CVE-2026-35633 OpenClaw OpenClaw pkg:npm/openclaw OpenClaw
CVE-2026-34510 OpenClaw OpenClaw pkg:npm/openclaw OpenClaw
CVE-2026-35652 OpenClaw OpenClaw pkg:npm/openclaw OpenClaw
CVE-2026-35647 OpenClaw OpenClaw pkg:npm/openclaw OpenClaw
CVE-2026-35654 OpenClaw OpenClaw pkg:npm/openclaw OpenClaw
CVE-2026-35667 OpenClaw OpenClaw pkg:npm/openclaw OpenClaw
CVE-2026-32024 OpenClaw OpenClaw pkg:npm/openclaw OpenClaw
CVE-2026-29612 OpenClaw OpenClaw pkg:npm/openclaw OpenClaw
CVE-2026-28452 OpenClaw OpenClaw pkg:npm/openclaw OpenClaw
CVE-2026-32044 OpenClaw OpenClaw pkg:npm/openclaw OpenClaw
CVE-2026-26328 openclaw clawdbot โ€” OpenClaw (formerly Clawdbot)
CVE-2026-28449 OpenClaw OpenClaw pkg:npm/openclaw OpenClaw
CVE-2026-28395 OpenClaw OpenClaw pkg:npm/openclaw OpenClaw
CVE-2026-28451 OpenClaw OpenClaw pkg:npm/openclaw OpenClaw
CVE-2026-28471 OpenClaw OpenClaw pkg:npm/openclaw OpenClaw
CVE-2026-32031 OpenClaw OpenClaw pkg:npm/openclaw OpenClaw
CVE-2026-32050 OpenClaw OpenClaw pkg:npm/openclaw OpenClaw
CVE-2026-33580 OpenClaw OpenClaw pkg:npm/openclaw OpenClaw
CVE-2026-35628 OpenClaw OpenClaw pkg:npm/openclaw OpenClaw
CVE-2026-35656 OpenClaw OpenClaw pkg:npm/openclaw OpenClaw
CVE-2026-32057 OpenClaw OpenClaw pkg:npm/openclaw OpenClaw
CVE-2026-34511 OpenClaw OpenClaw pkg:npm/openclaw OpenClaw
CVE-2026-28477 OpenClaw OpenClaw pkg:npm/openclaw OpenClaw
CVE-2026-27009 openclaw openclaw โ€” OpenClaw
CVE-2026-27670 OpenClaw OpenClaw pkg:npm/openclaw OpenClaw
CVE-2026-31995 OpenClaw OpenClaw pkg:npm/openclaw OpenClaw
CVE-2026-32000 OpenClaw OpenClaw pkg:npm/openclaw OpenClaw
CVE-2026-32052 OpenClaw OpenClaw pkg:npm/openclaw OpenClaw
CVE-2026-32977 OpenClaw OpenClaw pkg:npm/openclaw OpenClaw
CVE-2026-33574 OpenClaw OpenClaw pkg:npm/openclaw OpenClaw
CVE-2026-32988 OpenClaw OpenClaw pkg:npm/openclaw OpenClaw
CVE-2026-28457 OpenClaw OpenClaw pkg:npm/openclaw OpenClaw
CVE-2026-31989 OpenClaw OpenClaw pkg:npm/openclaw OpenClaw
CVE-2026-32001 OpenClaw OpenClaw pkg:npm/openclaw OpenClaw
CVE-2026-32921 OpenClaw OpenClaw pkg:npm/openclaw OpenClaw
CVE-2026-33578 OpenClaw OpenClaw pkg:npm/openclaw OpenClaw
CVE-2026-35619 OpenClaw OpenClaw pkg:npm/openclaw OpenClaw
CVE-2026-34425 OpenClaw OpenClaw pkg:npm/openclaw OpenClaw
CVE-2026-35629 OpenClaw OpenClaw pkg:npm/openclaw OpenClaw
CVE-2026-35642 OpenClaw OpenClaw pkg:npm/openclaw OpenClaw
CVE-2026-32020 OpenClaw OpenClaw pkg:npm/openclaw OpenClaw
CVE-2026-27486 openclaw openclaw โ€” OpenClaw
CVE-2026-32040 OpenClaw OpenClaw pkg:npm/openclaw OpenClaw
CVE-2026-34506 OpenClaw OpenClaw pkg:npm/openclaw OpenClaw
CVE-2026-35648 OpenClaw OpenClaw pkg:npm/openclaw OpenClaw
CVE-2026-35624 OpenClaw OpenClaw pkg:npm/openclaw OpenClaw
CVE-2026-32970 OpenClaw OpenClaw pkg:npm/openclaw OpenClaw

Data Sources

Source URL
CVE List v5 CVEProject/cvelistV5
GitHub Advisory DB github.com/advisories
Repo Security Tab openclaw/openclaw/security
CVE Services API https://cveawg.mitre.org/api/cve-id/{CVE-ID}

Auto-generated by update_readme.py ยท Updated hourly via GitHub Actions
Data: ghsa-advisories.json ยท cves.json ยท cve-pipeline-status.json

Maintained by Jerry Gamblin ยท OpenClawCVEs

Contributors

github-actions[bot]jgamblin

Issues