Dependency scanning
Check whether Openclaw is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
CVE-2026-53832
OpenClaw: Same-host trusted-proxy deployments could accept local forged identity headers
GHSA-35c7-4r45-9gv3
Duplicate Advisory: OpenClaw: QQBot pre-dispatch slash commands could skip allowFrom checks
GHSA-chqm-wxm2-w73w
Duplicate Advisory: OpenClaw: Mattermost handlers could fall open when channel type was missing
CVE-2026-53834
OpenClaw: QQBot pre-dispatch slash commands could skip allowFrom checks
CVE-2026-53837
OpenClaw: Mattermost handlers could fall open when channel type was missing
GHSA-3qg8-hq7j-jj33
Duplicate Advisory: OpenClaw: Same-host trusted-proxy deployments could accept local forged identity headers
CVE-2026-53833
OpenClaw: QQBot streaming command could mutate config without explicit allowFrom
GHSA-r27j-fxmq-rg2q
Duplicate Advisory: OpenClaw: QQBot streaming command could mutate config without explicit allowFrom
GHSA-c85p-9pvr-f7f5
Duplicate Advisory: OpenClaw: Node pairing reconnection could confuse approval scope state
CVE-2026-53838
OpenClaw: Node pairing reconnection could confuse approval scope state
GHSA-gwcq-453v-2frr
Duplicate Advisory: OpenClaw's POSIX node system.run safe-bin allowlist could be widened by shell expansion
CVE-2026-53831
OpenClaw's POSIX node system.run safe-bin allowlist could be widened by shell expansion
GHSA-ffhm-8fwq-7q27
Duplicate Advisory: OpenClaw: PowerShell encoded-command aliases could miss exec allowlist checks
CVE-2026-53836
OpenClaw: PowerShell encoded-command aliases could miss exec allowlist checks
CVE-2026-53830
OpenClaw: Slack and Zalo webhook secrets could remain active after secrets.reload
GHSA-p68j-q8j9-jwf5
Duplicate Advisory: OpenClaw: Slack and Zalo webhook secrets could remain active after secrets.reload
CVE-2026-62208
OpenClaw MCP SSE redirects could forward Authorization headers
CVE-2026-53820
OpenClaw: Bundle MCP loopback could miss its exec denylist on session spawn
CVE-2026-53829
OpenClaw: Exec approval display truncation could hide the command being approved
CVE-2026-41338
OpenClaw: Sandbox file operations use check-then-act, bypassing fd-based TOCTOU defenses
CVE-2026-53821
OpenClaw: Trusted-proxy Control UI WebSocket accepted client-declared scopes before pairing
CVE-2026-35625
OpenClaw: Silent privilege escalation via gateway shared-auth reconnect
CVE-2026-35642
OpenClaw: BlueBubbles Group Reactions Bypass requireMention and Still Enqueue Agent-Visible System Events
CVE-2026-43581
OpenClaw: Sandbox browser CDP relay could expose DevTools protocol on 0.0.0.0
CVE-2026-53839
OpenClaw: Trusted retry endpoint checks could match hostname prefixes
CVE-2026-3690
OpenClaw Canvas Authentication Bypass Vulnerability
CVE-2026-43577
OpenClaw: Browser interaction routes could pivot into local CDP and regain file reads
CVE-2026-35638
OpenClaw's Trusted-proxy Control UI sessions retain privileged scopes without device identity on device-less allow paths
CVE-2026-44115
OpenClaw's exec allowlist analysis rejects shell expansion in unquoted heredocs
CVE-2026-53807
OpenClaw: Telegram interactive callbacks could skip commands.allowFrom
CVE-2026-35636
OpenClaw: `session_status` sessionId resolution bypasses sandboxed session-tree visibility
CVE-2026-53828
OpenClaw: Native command authorization could skip owner-command enforcement
CVE-2026-43570
OpenClaw contains a symlink traversal vulnerability
CVE-2026-29609
OpenClaw affected by denial of service via unbounded URL-backed media fetch
CVE-2026-32063
OpenClaw Improperly Neutralizes Line Breaks in systemd Unit Generation Enables Local Command Execution (Linux)
CVE-2026-3691
OpenClaw: macOS beta onboarding exposed PKCE verifier via OAuth state
CVE-2026-32914
OpenClaw: Command-authorized non-owners could reach owner-only `/config` and `/debug` surfaces
CVE-2026-44996
OpenClaw: Webchat audio embedding could read local files without local-root containment
CVE-2026-53827
OpenClaw: message.action forwarding could send Gateway credentials to model-supplied loopback URLs
CVE-2026-44111
OpenClaw: QMD memory_get restricts reads to canonical or indexed memory paths
CVE-2026-44993
OpenClaw: Feishu card actions could misclassify DMs and skip dmPolicy
CVE-2026-41350
OpenClaw: `session_status` still bypasses configured `tools.sessions.visibility` for unsandboxed invocations
CVE-2026-41362
OpenClaw: Zalo replay dedupe cache could suppress events across authenticated webhook targets
CVE-2026-41340
OpenClaw: Telegram legacy allowFrom migration fans default-account trust into all named accounts
CVE-2026-45006
OpenClaw's gateway config mutation guard allowed unsafe model-driven config writes
CVE-2026-3689
OpenClaw Canvas Path Traversal Information Disclosure Vulnerability
CVE-2026-35631
OpenClaw's mutating internal ACP chat commands missed operator.admin scope enforcement
CVE-2026-43578
OpenClaw: Heartbeat owner downgrade missed local async exec completion events
CVE-2026-43575
OpenClaw: Sandbox noVNC helper route exposed interactive browser session credentials
CVE-2026-41334
OpenClaw: Image pixel-limit guard can fail open on sips and allow decompression-bomb DoS
CVE-2026-41345
OpenClaw: Media download follows cross-origin redirects with Authorization headers intact
CVE-2026-34507
OpenClaw: QQBot admin commands could skip DM-only and allowFrom policy
CVE-2026-53822
OpenClaw: Shell wrapper argv could change between approval and execution
CVE-2026-41909
OpenClaw: Paired-device pairing actions were not limited to the caller device
CVE-2026-41366
OpenClaw: Self-Whitelisting in appendLocalMediaParentRoots Allows Arbitrary File Read & Credential Exfiltration
CVE-2026-53826
OpenClaw: Sandboxed session spawn could expose the real workspace path to child prompts
CVE-2026-41361
OpenClaw SSRF guard misses four IPv6 special-use ranges
CVE-2026-33575
OpenClaw: Pairing setup codes exposed long-lived shared gateway credentials instead of short-lived bootstrap tokens
CVE-2026-34512
OpenClaw: Gateway HTTP /sessions/:sessionKey/kill Reaches Admin Kill Path Without Caller Scope Binding
CVE-2026-43579
OpenClaw: Nostr profile mutation routes allowed operator.write config persistence
CVE-2026-41360
OpenClaw: pnpm dlx approvals did not bind local script operands
CVE-2026-44994
OpenClaw's Gateway Control UI bootstrap config required Gateway auth
CVE-2026-53825
OpenClaw: memory-wiki ingest could read local files with operator.write scope
CVE-2026-53835
OpenClaw: Feishu dynamic-agent bindings could miss configWrites enforcement
CVE-2026-41370
OpenClaw: Path traversal via inbound channel attachment path in ACP dispatch allows arbitrary file read
CVE-2026-41357
OpenClaw: SSH-based sandbox backends pass unsanitized process.env to child processes
CVE-2026-53823
OpenClaw: Slack allowFrom could bind to mutable display names
CVE-2026-45001
OpenClaw: Agent gateway config mutations could change protected operator settings
CVE-2026-32975
OpenClaw's Zalouser allowlist authorization matched mutable group names by default
CVE-2026-44998
OpenClaw: Bundled MCP/LSP tools could bypass configured tool policy
CVE-2026-41353
OpenClaw: Node browser proxy `allowProfiles` bypass through persistent profile mutation and runtime profile selection
CVE-2026-41349
OpenClaw: Agentic Consent Bypass — LLM Agent Can Silently Disable Exec Approval via `config.patch`
CVE-2026-45000
OpenClaw: Browser CDP profile creation skipped strict-mode SSRF checks
CVE-2026-53808
OpenClaw: Skill Workshop apply flow could override pending approval
CVE-2026-33573
OpenClaw: Gateway `agent` calls could override the workspace boundary
CVE-2026-53824
OpenClaw: Mattermost slash token revocation could lag until monitor refresh
CVE-2026-32972
OpenClaw: `browser.request` let `operator.write` persist admin-only browser profile changes
CVE-2026-34426
OpenClaw: Windows media loaders accepted remote-host file URLs before local path validation
CVE-2026-34426
OpenClaw: Windows-compatible env override keys could bypass system.run approval binding
CVE-2026-32846
OpenClaw is vulnerable to Path Traversal through path validation bypass
CVE-2026-32846
OpenClaw: Media Parsing Path Traversal Leads to Arbitrary File Read
CVE-2026-32915
OpenClaw: Leaf subagents could steer sibling sessions across sandbox boundaries
CVE-2026-32919
OpenClaw: Write-scoped callers could reach admin-only session reset logic through `agent`
CVE-2026-32923
OpenClaw: Discord guild reaction ingress could bypass users and roles allowlists
CVE-2026-32906
OpenClaw's Slack plugin approvals used the exec approver gate for plugin actions
CVE-2026-32008
OpenClaw browser navigation guard allowed non-network URL schemes, enabling authenticated browser-tool users to access file:// local files
CVE-2026-32987
OpenClaw bootstrap setup codes could be replayed to escalate pending pairing scopes before approval
CVE-2026-32924
OpenClaw: Feishu reaction events could bypass group authorization and mention gating
CVE-2026-32922
OpenClaw: Pairing-scoped device tokens could mint `operator.admin` and reach node RCE
CVE-2026-32973
OpenClaw: Exec approval allowlist patterns overmatched on POSIX paths
CVE-2026-32917
OpneClaw accepts unsanitized iMessage attachment paths which allowed SCP remote-path command injection
CVE-2026-32051
OpenClaw's authorization mismatch allowed write-scope agent runs to reach owner-only tools
CVE-2026-41371
OpenClaw Gateway `operator.write` can reach admin-only session reset via `chat.send` `/reset`
CVE-2026-35673
OpenClaw: Browser debug/export routes could reuse already-open blocked tabs
CVE-2026-32982
OpenClaw Telegram media fetch errors exposed bot tokens in logged file URLs
CVE-2026-32976
OpenClaw: Channel commands could bypass account-scoped `configWrites` restrictions
CVE-2026-35674
OpenClaw: Scoped chat.send route inheritance could bypass admin command scope gates
CVE-2026-32905
OpenClaw: Non-owner chat senders could issue device-pairing bootstrap codes
CVE-2026-32988
OpenClaw: Sandbox staged writes could escape the verified parent directory before commit
CVE-2026-35620
OpenClaw: Non-owner command-authorized sender can change the owner-only `/send` session delivery policy
Browse more npm advisories
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes