100 Total advisories
100 Vulnerabilities
0 Malware

Vulnerabilities

MEDIUM 6.5
npm

CVE-2026-62208

OpenClaw MCP SSE redirects could forward Authorization headers

UNKNOWN
npm

CVE-2026-53820

OpenClaw: Bundle MCP loopback could miss its exec denylist on session spawn

HIGH 8.0
npm

CVE-2026-53829

OpenClaw: Exec approval display truncation could hide the command being approved

UNKNOWN
npm

CVE-2026-41338

OpenClaw: Sandbox file operations use check-then-act, bypassing fd-based TOCTOU defenses

HIGH 8.8
npm

CVE-2026-53821

OpenClaw: Trusted-proxy Control UI WebSocket accepted client-declared scopes before pairing

UNKNOWN
npm

CVE-2026-35625

OpenClaw: Silent privilege escalation via gateway shared-auth reconnect

UNKNOWN
npm

CVE-2026-35642

OpenClaw: BlueBubbles Group Reactions Bypass requireMention and Still Enqueue Agent-Visible System Events

UNKNOWN
npm

CVE-2026-53834

OpenClaw: QQBot pre-dispatch slash commands could skip allowFrom checks

UNKNOWN
npm

CVE-2026-53836

OpenClaw: PowerShell encoded-command aliases could miss exec allowlist checks

UNKNOWN
npm

CVE-2026-43581

OpenClaw: Sandbox browser CDP relay could expose DevTools protocol on 0.0.0.0

UNKNOWN
npm

CVE-2026-53839

OpenClaw: Trusted retry endpoint checks could match hostname prefixes

HIGH 7.4
npm

CVE-2026-3690

OpenClaw Canvas Authentication Bypass Vulnerability

UNKNOWN
npm

CVE-2026-43577

OpenClaw: Browser interaction routes could pivot into local CDP and regain file reads

UNKNOWN
npm

CVE-2026-35638

OpenClaw's Trusted-proxy Control UI sessions retain privileged scopes without device identity on device-less allow paths

UNKNOWN
npm

CVE-2026-44115

OpenClaw's exec allowlist analysis rejects shell expansion in unquoted heredocs

UNKNOWN
npm

CVE-2026-53807

OpenClaw: Telegram interactive callbacks could skip commands.allowFrom

UNKNOWN
npm

CVE-2026-53838

OpenClaw: Node pairing reconnection could confuse approval scope state

UNKNOWN
npm

CVE-2026-35636

OpenClaw: `session_status` sessionId resolution bypasses sandboxed session-tree visibility

UNKNOWN
npm

CVE-2026-53837

OpenClaw: Mattermost handlers could fall open when channel type was missing

UNKNOWN
npm

CVE-2026-53828

OpenClaw: Native command authorization could skip owner-command enforcement

HIGH 7.1
npm

CVE-2026-53831

OpenClaw's POSIX node system.run safe-bin allowlist could be widened by shell expansion

MEDIUM 6.5
npm

CVE-2026-43570

OpenClaw contains a symlink traversal vulnerability

HIGH 7.5
npm

CVE-2026-29609

OpenClaw affected by denial of service via unbounded URL-backed media fetch

UNKNOWN
npm

CVE-2026-32063

OpenClaw Improperly Neutralizes Line Breaks in systemd Unit Generation Enables Local Command Execution (Linux)

UNKNOWN
npm

CVE-2026-3691

OpenClaw: macOS beta onboarding exposed PKCE verifier via OAuth state

HIGH 8.8
npm

CVE-2026-32914

OpenClaw: Command-authorized non-owners could reach owner-only `/config` and `/debug` surfaces

UNKNOWN
npm

CVE-2026-53830

OpenClaw: Slack and Zalo webhook secrets could remain active after secrets.reload

UNKNOWN
npm

CVE-2026-44996

OpenClaw: Webchat audio embedding could read local files without local-root containment

UNKNOWN
npm

CVE-2026-53827

OpenClaw: message.action forwarding could send Gateway credentials to model-supplied loopback URLs

UNKNOWN
npm

CVE-2026-44111

OpenClaw: QMD memory_get restricts reads to canonical or indexed memory paths

UNKNOWN
npm

CVE-2026-44993

OpenClaw: Feishu card actions could misclassify DMs and skip dmPolicy

UNKNOWN
npm

CVE-2026-41350

OpenClaw: `session_status` still bypasses configured `tools.sessions.visibility` for unsandboxed invocations

UNKNOWN
npm

CVE-2026-41362

OpenClaw: Zalo replay dedupe cache could suppress events across authenticated webhook targets

UNKNOWN
npm

CVE-2026-41340

OpenClaw: Telegram legacy allowFrom migration fans default-account trust into all named accounts

HIGH 8.8
npm

CVE-2026-45006

OpenClaw's gateway config mutation guard allowed unsafe model-driven config writes

UNKNOWN
npm

CVE-2026-3689

OpenClaw Canvas Path Traversal Information Disclosure Vulnerability

UNKNOWN
npm

CVE-2026-35631

OpenClaw's mutating internal ACP chat commands missed operator.admin scope enforcement

UNKNOWN
npm

CVE-2026-43578

OpenClaw: Heartbeat owner downgrade missed local async exec completion events

UNKNOWN
npm

CVE-2026-43575

OpenClaw: Sandbox noVNC helper route exposed interactive browser session credentials

UNKNOWN
npm

CVE-2026-53832

OpenClaw: Same-host trusted-proxy deployments could accept local forged identity headers

UNKNOWN
npm

CVE-2026-41334

OpenClaw: Image pixel-limit guard can fail open on sips and allow decompression-bomb DoS

UNKNOWN
npm

CVE-2026-41345

OpenClaw: Media download follows cross-origin redirects with Authorization headers intact

UNKNOWN
npm

CVE-2026-34507

OpenClaw: QQBot admin commands could skip DM-only and allowFrom policy

UNKNOWN
npm

CVE-2026-53822

OpenClaw: Shell wrapper argv could change between approval and execution

UNKNOWN
npm

CVE-2026-41909

OpenClaw: Paired-device pairing actions were not limited to the caller device

UNKNOWN
npm

CVE-2026-41366

OpenClaw: Self-Whitelisting in appendLocalMediaParentRoots Allows Arbitrary File Read & Credential Exfiltration

UNKNOWN
npm

CVE-2026-53826

OpenClaw: Sandboxed session spawn could expose the real workspace path to child prompts

LOW 3.1
npm

CVE-2026-41361

OpenClaw SSRF guard misses four IPv6 special-use ranges

UNKNOWN
npm

CVE-2026-33575

OpenClaw: Pairing setup codes exposed long-lived shared gateway credentials instead of short-lived bootstrap tokens

UNKNOWN
npm

CVE-2026-53833

OpenClaw: QQBot streaming command could mutate config without explicit allowFrom

UNKNOWN
npm

CVE-2026-34512

OpenClaw: Gateway HTTP /sessions/:sessionKey/kill Reaches Admin Kill Path Without Caller Scope Binding

UNKNOWN
npm

CVE-2026-43579

OpenClaw: Nostr profile mutation routes allowed operator.write config persistence

UNKNOWN
npm

CVE-2026-41360

OpenClaw: pnpm dlx approvals did not bind local script operands

UNKNOWN
npm

CVE-2026-44994

OpenClaw's Gateway Control UI bootstrap config required Gateway auth

MEDIUM 6.5
npm

CVE-2026-53825

OpenClaw: memory-wiki ingest could read local files with operator.write scope

LOW 3.1
npm

CVE-2026-53835

OpenClaw: Feishu dynamic-agent bindings could miss configWrites enforcement

UNKNOWN
npm

CVE-2026-41370

OpenClaw: Path traversal via inbound channel attachment path in ACP dispatch allows arbitrary file read

UNKNOWN
npm

CVE-2026-41357

OpenClaw: SSH-based sandbox backends pass unsanitized process.env to child processes

UNKNOWN
npm

CVE-2026-53823

OpenClaw: Slack allowFrom could bind to mutable display names

UNKNOWN
npm

CVE-2026-45001

OpenClaw: Agent gateway config mutations could change protected operator settings

UNKNOWN
npm

CVE-2026-32975

OpenClaw's Zalouser allowlist authorization matched mutable group names by default

UNKNOWN
npm

CVE-2026-44998

OpenClaw: Bundled MCP/LSP tools could bypass configured tool policy

UNKNOWN
npm

CVE-2026-41353

OpenClaw: Node browser proxy `allowProfiles` bypass through persistent profile mutation and runtime profile selection

UNKNOWN
npm

CVE-2026-41349

OpenClaw: Agentic Consent Bypass — LLM Agent Can Silently Disable Exec Approval via `config.patch`

UNKNOWN
npm

CVE-2026-45000

OpenClaw: Browser CDP profile creation skipped strict-mode SSRF checks

MEDIUM 5.3
npm

CVE-2026-53808

OpenClaw: Skill Workshop apply flow could override pending approval

HIGH 8.8
npm

CVE-2026-33573

OpenClaw: Gateway `agent` calls could override the workspace boundary

UNKNOWN
npm

CVE-2026-53824

OpenClaw: Mattermost slash token revocation could lag until monitor refresh

HIGH 7.1
npm

CVE-2026-32972

OpenClaw: `browser.request` let `operator.write` persist admin-only browser profile changes

UNKNOWN
npm

CVE-2026-34426

OpenClaw: Windows media loaders accepted remote-host file URLs before local path validation

UNKNOWN
npm

CVE-2026-34426

OpenClaw: Windows-compatible env override keys could bypass system.run approval binding

HIGH 7.5
npm

CVE-2026-32846

OpenClaw is vulnerable to Path Traversal through path validation bypass

UNKNOWN
npm

CVE-2026-32846

OpenClaw: Media Parsing Path Traversal Leads to Arbitrary File Read

HIGH 8.8
npm

CVE-2026-32915

OpenClaw: Leaf subagents could steer sibling sessions across sandbox boundaries

MEDIUM 6.1
npm

CVE-2026-32919

OpenClaw: Write-scoped callers could reach admin-only session reset logic through `agent`

MEDIUM 5.4
npm

CVE-2026-32923

OpenClaw: Discord guild reaction ingress could bypass users and roles allowlists

UNKNOWN
npm

CVE-2026-32906

OpenClaw's Slack plugin approvals used the exec approver gate for plugin actions

MEDIUM 6.5
npm

CVE-2026-32008

OpenClaw browser navigation guard allowed non-network URL schemes, enabling authenticated browser-tool users to access file:// local files

UNKNOWN
npm

CVE-2026-32987

OpenClaw bootstrap setup codes could be replayed to escalate pending pairing scopes before approval

UNKNOWN
npm

CVE-2026-32924

OpenClaw: Feishu reaction events could bypass group authorization and mention gating

CRITICAL 9.9
npm

CVE-2026-32922

OpenClaw: Pairing-scoped device tokens could mint `operator.admin` and reach node RCE

UNKNOWN
npm

CVE-2026-32973

OpenClaw: Exec approval allowlist patterns overmatched on POSIX paths

UNKNOWN
npm

CVE-2026-32917

OpneClaw accepts unsanitized iMessage attachment paths which allowed SCP remote-path command injection

UNKNOWN
npm

CVE-2026-32051

OpenClaw's authorization mismatch allowed write-scope agent runs to reach owner-only tools

UNKNOWN
npm

CVE-2026-41371

OpenClaw Gateway `operator.write` can reach admin-only session reset via `chat.send` `/reset`

MEDIUM 6.5
npm

CVE-2026-35673

OpenClaw: Browser debug/export routes could reuse already-open blocked tabs

UNKNOWN
npm

CVE-2026-32982

OpenClaw Telegram media fetch errors exposed bot tokens in logged file URLs

MEDIUM 6.5
npm

CVE-2026-32976

OpenClaw: Channel commands could bypass account-scoped `configWrites` restrictions

HIGH 8.8
npm

CVE-2026-35674

OpenClaw: Scoped chat.send route inheritance could bypass admin command scope gates

HIGH 8.3
npm

CVE-2026-32905

OpenClaw: Non-owner chat senders could issue device-pairing bootstrap codes

HIGH 7.5
npm

CVE-2026-32988

OpenClaw: Sandbox staged writes could escape the verified parent directory before commit

MEDIUM 5.4
npm

CVE-2026-35620

OpenClaw: Non-owner command-authorized sender can change the owner-only `/send` session delivery policy

MEDIUM 6.5
npm

GHSA-vqvg-86cc-cg83

OpenClaw: Mutating internal `/allowlist` chat commands missed `operator.admin` scope enforcement

HIGH 7.7
npm

CVE-2026-41368

OpenClaw safeBins jq `$ENV` filter bypass allows environment variable disclosure

UNKNOWN
npm

CVE-2026-35644

OpenClaw Exposes Credentials Embedded in baseUrl Fields via config.get and channels.status

UNKNOWN
npm

CVE-2026-41367

OpenClaw's Discord component interaction ingress skips guild/channel policy enforcement

HIGH 8.8
npm

CVE-2026-22177

OpenClaw's config env vars allowed startup env injection into service runtime

UNKNOWN
npm

GHSA-w9j9-w4cp-6wgr

OpenClaw Host-Exec Environment Variable Injection

HIGH 8.0
npm

CVE-2026-35630

OpenClaw: QQBot native approval buttons did not enforce configured approver identity

HIGH 8.0
npm

GHSA-hx4v-668p-g2qr

Duplicate Advisory: OpenClaw: QQBot native approval buttons did not enforce configured approver identity

Ready to move

Start Securing

Free, no credit card | First findings in minutes