Vulnerabilities
CVE-2026-62208
OpenClaw MCP SSE redirects could forward Authorization headers
CVE-2026-53820
OpenClaw: Bundle MCP loopback could miss its exec denylist on session spawn
CVE-2026-53829
OpenClaw: Exec approval display truncation could hide the command being approved
CVE-2026-41338
OpenClaw: Sandbox file operations use check-then-act, bypassing fd-based TOCTOU defenses
CVE-2026-53821
OpenClaw: Trusted-proxy Control UI WebSocket accepted client-declared scopes before pairing
CVE-2026-35625
OpenClaw: Silent privilege escalation via gateway shared-auth reconnect
CVE-2026-35642
OpenClaw: BlueBubbles Group Reactions Bypass requireMention and Still Enqueue Agent-Visible System Events
CVE-2026-53834
OpenClaw: QQBot pre-dispatch slash commands could skip allowFrom checks
CVE-2026-53836
OpenClaw: PowerShell encoded-command aliases could miss exec allowlist checks
CVE-2026-43581
OpenClaw: Sandbox browser CDP relay could expose DevTools protocol on 0.0.0.0
CVE-2026-53839
OpenClaw: Trusted retry endpoint checks could match hostname prefixes
CVE-2026-3690
OpenClaw Canvas Authentication Bypass Vulnerability
CVE-2026-43577
OpenClaw: Browser interaction routes could pivot into local CDP and regain file reads
CVE-2026-35638
OpenClaw's Trusted-proxy Control UI sessions retain privileged scopes without device identity on device-less allow paths
CVE-2026-44115
OpenClaw's exec allowlist analysis rejects shell expansion in unquoted heredocs
CVE-2026-53807
OpenClaw: Telegram interactive callbacks could skip commands.allowFrom
CVE-2026-53838
OpenClaw: Node pairing reconnection could confuse approval scope state
CVE-2026-35636
OpenClaw: `session_status` sessionId resolution bypasses sandboxed session-tree visibility
CVE-2026-53837
OpenClaw: Mattermost handlers could fall open when channel type was missing
CVE-2026-53828
OpenClaw: Native command authorization could skip owner-command enforcement
CVE-2026-53831
OpenClaw's POSIX node system.run safe-bin allowlist could be widened by shell expansion
CVE-2026-43570
OpenClaw contains a symlink traversal vulnerability
CVE-2026-29609
OpenClaw affected by denial of service via unbounded URL-backed media fetch
CVE-2026-32063
OpenClaw Improperly Neutralizes Line Breaks in systemd Unit Generation Enables Local Command Execution (Linux)
CVE-2026-3691
OpenClaw: macOS beta onboarding exposed PKCE verifier via OAuth state
CVE-2026-32914
OpenClaw: Command-authorized non-owners could reach owner-only `/config` and `/debug` surfaces
CVE-2026-53830
OpenClaw: Slack and Zalo webhook secrets could remain active after secrets.reload
CVE-2026-44996
OpenClaw: Webchat audio embedding could read local files without local-root containment
CVE-2026-53827
OpenClaw: message.action forwarding could send Gateway credentials to model-supplied loopback URLs
CVE-2026-44111
OpenClaw: QMD memory_get restricts reads to canonical or indexed memory paths
CVE-2026-44993
OpenClaw: Feishu card actions could misclassify DMs and skip dmPolicy
CVE-2026-41350
OpenClaw: `session_status` still bypasses configured `tools.sessions.visibility` for unsandboxed invocations
CVE-2026-41362
OpenClaw: Zalo replay dedupe cache could suppress events across authenticated webhook targets
CVE-2026-41340
OpenClaw: Telegram legacy allowFrom migration fans default-account trust into all named accounts
CVE-2026-45006
OpenClaw's gateway config mutation guard allowed unsafe model-driven config writes
CVE-2026-3689
OpenClaw Canvas Path Traversal Information Disclosure Vulnerability
CVE-2026-35631
OpenClaw's mutating internal ACP chat commands missed operator.admin scope enforcement
CVE-2026-43578
OpenClaw: Heartbeat owner downgrade missed local async exec completion events
CVE-2026-43575
OpenClaw: Sandbox noVNC helper route exposed interactive browser session credentials
CVE-2026-53832
OpenClaw: Same-host trusted-proxy deployments could accept local forged identity headers
CVE-2026-41334
OpenClaw: Image pixel-limit guard can fail open on sips and allow decompression-bomb DoS
CVE-2026-41345
OpenClaw: Media download follows cross-origin redirects with Authorization headers intact
CVE-2026-34507
OpenClaw: QQBot admin commands could skip DM-only and allowFrom policy
CVE-2026-53822
OpenClaw: Shell wrapper argv could change between approval and execution
CVE-2026-41909
OpenClaw: Paired-device pairing actions were not limited to the caller device
CVE-2026-41366
OpenClaw: Self-Whitelisting in appendLocalMediaParentRoots Allows Arbitrary File Read & Credential Exfiltration
CVE-2026-53826
OpenClaw: Sandboxed session spawn could expose the real workspace path to child prompts
CVE-2026-41361
OpenClaw SSRF guard misses four IPv6 special-use ranges
CVE-2026-33575
OpenClaw: Pairing setup codes exposed long-lived shared gateway credentials instead of short-lived bootstrap tokens
CVE-2026-53833
OpenClaw: QQBot streaming command could mutate config without explicit allowFrom
CVE-2026-34512
OpenClaw: Gateway HTTP /sessions/:sessionKey/kill Reaches Admin Kill Path Without Caller Scope Binding
CVE-2026-43579
OpenClaw: Nostr profile mutation routes allowed operator.write config persistence
CVE-2026-41360
OpenClaw: pnpm dlx approvals did not bind local script operands
CVE-2026-44994
OpenClaw's Gateway Control UI bootstrap config required Gateway auth
CVE-2026-53825
OpenClaw: memory-wiki ingest could read local files with operator.write scope
CVE-2026-53835
OpenClaw: Feishu dynamic-agent bindings could miss configWrites enforcement
CVE-2026-41370
OpenClaw: Path traversal via inbound channel attachment path in ACP dispatch allows arbitrary file read
CVE-2026-41357
OpenClaw: SSH-based sandbox backends pass unsanitized process.env to child processes
CVE-2026-53823
OpenClaw: Slack allowFrom could bind to mutable display names
CVE-2026-45001
OpenClaw: Agent gateway config mutations could change protected operator settings
CVE-2026-32975
OpenClaw's Zalouser allowlist authorization matched mutable group names by default
CVE-2026-44998
OpenClaw: Bundled MCP/LSP tools could bypass configured tool policy
CVE-2026-41353
OpenClaw: Node browser proxy `allowProfiles` bypass through persistent profile mutation and runtime profile selection
CVE-2026-41349
OpenClaw: Agentic Consent Bypass — LLM Agent Can Silently Disable Exec Approval via `config.patch`
CVE-2026-45000
OpenClaw: Browser CDP profile creation skipped strict-mode SSRF checks
CVE-2026-53808
OpenClaw: Skill Workshop apply flow could override pending approval
CVE-2026-33573
OpenClaw: Gateway `agent` calls could override the workspace boundary
CVE-2026-53824
OpenClaw: Mattermost slash token revocation could lag until monitor refresh
CVE-2026-32972
OpenClaw: `browser.request` let `operator.write` persist admin-only browser profile changes
CVE-2026-34426
OpenClaw: Windows media loaders accepted remote-host file URLs before local path validation
CVE-2026-34426
OpenClaw: Windows-compatible env override keys could bypass system.run approval binding
CVE-2026-32846
OpenClaw is vulnerable to Path Traversal through path validation bypass
CVE-2026-32846
OpenClaw: Media Parsing Path Traversal Leads to Arbitrary File Read
CVE-2026-32915
OpenClaw: Leaf subagents could steer sibling sessions across sandbox boundaries
CVE-2026-32919
OpenClaw: Write-scoped callers could reach admin-only session reset logic through `agent`
CVE-2026-32923
OpenClaw: Discord guild reaction ingress could bypass users and roles allowlists
CVE-2026-32906
OpenClaw's Slack plugin approvals used the exec approver gate for plugin actions
CVE-2026-32008
OpenClaw browser navigation guard allowed non-network URL schemes, enabling authenticated browser-tool users to access file:// local files
CVE-2026-32987
OpenClaw bootstrap setup codes could be replayed to escalate pending pairing scopes before approval
CVE-2026-32924
OpenClaw: Feishu reaction events could bypass group authorization and mention gating
CVE-2026-32922
OpenClaw: Pairing-scoped device tokens could mint `operator.admin` and reach node RCE
CVE-2026-32973
OpenClaw: Exec approval allowlist patterns overmatched on POSIX paths
CVE-2026-32917
OpneClaw accepts unsanitized iMessage attachment paths which allowed SCP remote-path command injection
CVE-2026-32051
OpenClaw's authorization mismatch allowed write-scope agent runs to reach owner-only tools
CVE-2026-41371
OpenClaw Gateway `operator.write` can reach admin-only session reset via `chat.send` `/reset`
CVE-2026-35673
OpenClaw: Browser debug/export routes could reuse already-open blocked tabs
CVE-2026-32982
OpenClaw Telegram media fetch errors exposed bot tokens in logged file URLs
CVE-2026-32976
OpenClaw: Channel commands could bypass account-scoped `configWrites` restrictions
CVE-2026-35674
OpenClaw: Scoped chat.send route inheritance could bypass admin command scope gates
CVE-2026-32905
OpenClaw: Non-owner chat senders could issue device-pairing bootstrap codes
CVE-2026-32988
OpenClaw: Sandbox staged writes could escape the verified parent directory before commit
CVE-2026-35620
OpenClaw: Non-owner command-authorized sender can change the owner-only `/send` session delivery policy
GHSA-vqvg-86cc-cg83
OpenClaw: Mutating internal `/allowlist` chat commands missed `operator.admin` scope enforcement
CVE-2026-41368
OpenClaw safeBins jq `$ENV` filter bypass allows environment variable disclosure
CVE-2026-35644
OpenClaw Exposes Credentials Embedded in baseUrl Fields via config.get and channels.status
CVE-2026-41367
OpenClaw's Discord component interaction ingress skips guild/channel policy enforcement
CVE-2026-22177
OpenClaw's config env vars allowed startup env injection into service runtime
GHSA-w9j9-w4cp-6wgr
OpenClaw Host-Exec Environment Variable Injection
CVE-2026-35630
OpenClaw: QQBot native approval buttons did not enforce configured approver identity
GHSA-hx4v-668p-g2qr
Duplicate Advisory: OpenClaw: QQBot native approval buttons did not enforce configured approver identity
Ready to move
Start Securing
Free, no credit card | First findings in minutes