VulnSea

OpenClaw vulnerabilities

CVEs whose affected-version data names the OpenClaw package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

138 CVEsRSS

CVE-2026-32921Medium· 6.3
5mo ago

OpenClaw before 2026.3.8 contains an approval bypass vulnerability in system.run where mutable script operands are not bound across approval and execution phases

OpenClaw before 2026.3.8 contains an approval bypass vulnerability in system.run where mutable script operands are not bound across approval and execution phases. Attackers can obtain approval for script execution, modify the approved sc…

▾ Sunlitopenclaw · openclawEPSS 0.20%via NVD
CVE-2026-32920High· 8.4
5mo ago

OpenClaw before 2026.3.12 automatically discovers and loads plugins from .OpenClaw/extensions/ without explicit trust verification, allowing arbitrary code execution

OpenClaw before 2026.3.12 automatically discovers and loads plugins from .OpenClaw/extensions/ without explicit trust verification, allowing arbitrary code execution. Attackers can execute malicious code by including crafted workspace pl…

▾ Twilightopenclaw · openclawEPSS 0.33%via NVD
CVE-2026-32917Critical· 9.8
5mo ago

OpenClaw before 2026.3.13 contains a remote command injection vulnerability in the iMessage attachment staging flow that allows attackers to execute arbitrary commands on configured remote hosts

OpenClaw before 2026.3.13 contains a remote command injection vulnerability in the iMessage attachment staging flow that allows attackers to execute arbitrary commands on configured remote hosts. The vulnerability exists because unsaniti…

▾ Midnightopenclaw · openclawEPSS 2.0%via NVD
CVE-2026-32916Critical· 9.4
5mo ago

OpenClaw versions 2026.3.7 before 2026.3.11 contain an authorization bypass vulnerability where plugin subagent routes execute gateway methods through a synthetic operator client with broad administrative scopes

OpenClaw versions 2026.3.7 before 2026.3.11 contain an authorization bypass vulnerability where plugin subagent routes execute gateway methods through a synthetic operator client with broad administrative scopes. Remote unauthenticated r…

▾ Midnightopenclaw · openclawEPSS 0.46%via NVD
CVE-2026-34506Medium· 4.3
5mo ago

OpenClaw before 2026.3.8 contains a sender allowlist bypass vulnerability in its Microsoft Teams plugin that allows unauthorized senders to bypass intended authorization checks

OpenClaw before 2026.3.8 contains a sender allowlist bypass vulnerability in its Microsoft Teams plugin that allows unauthorized senders to bypass intended authorization checks. When a team/channel route allowlist is configured with an e…

▾ Sunlitopenclaw · openclawEPSS 0.27%via NVD
CVE-2026-34505Medium· 6.5
5mo ago

OpenClaw before 2026.3.12 applies rate limiting only after successful webhook authentication, allowing attackers to bypass rate limits and brute-force webhook secrets

OpenClaw before 2026.3.12 applies rate limiting only after successful webhook authentication, allowing attackers to bypass rate limits and brute-force webhook secrets. Attackers can submit repeated authentication requests with invalid se…

▾ Sunlitopenclaw · openclawEPSS 0.27%via NVD
CVE-2026-34504High· 8.3
5mo ago

OpenClaw before 2026.3.28 contains a server-side request forgery vulnerability in the fal provider image-generation-provider.ts component that allows attackers to fetch internal URLs

OpenClaw before 2026.3.28 contains a server-side request forgery vulnerability in the fal provider image-generation-provider.ts component that allows attackers to fetch internal URLs. A malicious or compromised fal relay can exploit ungu…

▾ Twilightopenclaw · openclawEPSS 0.23%via NVD
CVE-2026-34503High· 8.1
5mo ago

OpenClaw before 2026.3.28 fails to disconnect active WebSocket sessions when devices are removed or tokens are revoked

OpenClaw before 2026.3.28 fails to disconnect active WebSocket sessions when devices are removed or tokens are revoked. Attackers with revoked credentials can maintain unauthorized access through existing live sessions until forced recon…

▾ Twilightopenclaw · openclawEPSS 0.33%via NVD
CVE-2026-33581Medium· 6.5
5mo ago

OpenClaw before 2026.3.24 contains a sandbox bypass vulnerability in the message tool that allows attackers to read arbitrary local files by using mediaUrl and fileUrl alias parameters that bypass localRoots validation

OpenClaw before 2026.3.24 contains a sandbox bypass vulnerability in the message tool that allows attackers to read arbitrary local files by using mediaUrl and fileUrl alias parameters that bypass localRoots validation. Remote attackers …

▾ Sunlitopenclaw · openclawEPSS 0.56%via NVD
CVE-2026-33580Medium· 6.5
5mo ago

OpenClaw before 2026.3.28 contains a missing rate limiting vulnerability in the Nextcloud Talk webhook authentication that allows attackers to brute-force weak shared secrets

OpenClaw before 2026.3.28 contains a missing rate limiting vulnerability in the Nextcloud Talk webhook authentication that allows attackers to brute-force weak shared secrets. Attackers who can reach the webhook endpoint can exploit this…

▾ Sunlitopenclaw · openclawEPSS 0.36%via NVD
CVE-2026-33579Critical· 9.9PoC
5mo ago

OpenClaw before 2026.3.28 contains a privilege escalation vulnerability in the /pair approve command path that fails to forward caller scopes into the core approval check

OpenClaw before 2026.3.28 contains a privilege escalation vulnerability in the /pair approve command path that fails to forward caller scopes into the core approval check. A caller with pairing privileges but without admin privileges can…

▾ Abyssalopenclaw · openclawEPSS 0.83%via NVD
CVE-2026-33578Medium· 4.3
5mo ago

OpenClaw before 2026.3.28 contains a sender policy bypass vulnerability in the Google Chat and Zalouser extensions where route-level group allowlist policies silently downgrade to open policy

OpenClaw before 2026.3.28 contains a sender policy bypass vulnerability in the Google Chat and Zalouser extensions where route-level group allowlist policies silently downgrade to open policy. Attackers can exploit this policy resolution…

▾ Sunlitopenclaw · openclawEPSS 0.30%via NVD
CVE-2026-33577High· 8.1
5mo ago

OpenClaw before 2026.3.28 contains an insufficient scope validation vulnerability in the node pairing approval path that allows low-privilege operators to approve nodes with broader scopes

OpenClaw before 2026.3.28 contains an insufficient scope validation vulnerability in the node pairing approval path that allows low-privilege operators to approve nodes with broader scopes. Attackers can exploit missing callerScopes vali…

▾ Twilightopenclaw · openclawEPSS 0.38%via NVD
CVE-2026-33576Medium· 6.5
5mo ago

OpenClaw before 2026.3.28 downloads and stores inbound media from Zalo channels before validating sender authorization

OpenClaw before 2026.3.28 downloads and stores inbound media from Zalo channels before validating sender authorization. Unauthorized senders can force network fetches and disk writes to the media store by sending messages that are subseq…

▾ Sunlitopenclaw · openclawEPSS 0.36%via NVD
CVE-2026-32896Medium· 4.8
6mo ago

The BlueBubbles webhook handler in OpenClaw versions prior to 2026.2.21 contains a passwordless fallback authentication path that allows unauthenticated webhook events in certain reverse-proxy or local routing configurations

The BlueBubbles webhook handler in OpenClaw versions prior to 2026.2.21 contains a passwordless fallback authentication path that allows unauthenticated webhook events in certain reverse-proxy or local routing configurations. Attackers c…

▾ Sunlitopenclaw · openclawEPSS 0.25%via NVD
CVE-2026-22172Critical· 9.9
6mo ago

OpenClaw < 2026.3.12 - Scope Elevation in WebSocket Shared-Auth Connections

OpenClaw versions prior to 2026.3.12 contain an authorization bypass vulnerability in the WebSocket connect path that allows shared-token or password-authenticated connections to self-declare elevated scopes without server-side binding. …

▾ MidnightOpenClaw · OpenClawEPSS 0.56%via CVEORG
CVE-2026-28474Critical· 9.8
6mo ago

OpenClaw's Nextcloud Talk plugin versions prior to 2026.2.6 accept equality matching on the mutable actor.name display name field for allowlist validation, allowing attackers to bypass DM and room allowlists

OpenClaw's Nextcloud Talk plugin versions prior to 2026.2.6 accept equality matching on the mutable actor.name display name field for allowlist validation, allowing attackers to bypass DM and room allowlists. An attacker can change their…

▾ Midnightopenclaw · openclawEPSS 0.48%via NVD
CVE-2026-28465Medium· 5.9
6mo ago

OpenClaw's voice-call plugin versions before 2026.2.3 contain an improper authentication vulnerability in webhook verification that allows remote attackers to bypass verification by supplying untrusted forwarded headers

OpenClaw's voice-call plugin versions before 2026.2.3 contain an improper authentication vulnerability in webhook verification that allows remote attackers to bypass verification by supplying untrusted forwarded headers. Attackers can sp…

▾ Sunlitopenclaw · openclawEPSS 0.37%via NVD
OpenClaw vulnerabilities (CVEs) — page 5 · VulnSea