VulnSea

Openclaw vulnerabilities

CVEs whose affected-version data names the Openclaw package (npm). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

201 CVEsRSS

CVE-2026-100529Medium· 6.4
yesterday

OpenClaw versions before 2026.8.1 contain an authorization scope widening vulnerability in file-transfer allow-always approvals that allows attackers to reuse standing grants for unreviewed paths

OpenClaw versions before 2026.8.1 contain an authorization scope widening vulnerability in file-transfer allow-always approvals that allows attackers to reuse standing grants for unreviewed paths. Attackers can exploit glob metacharacter…

▾ SunlitOpenClaw · OpenClawEPSS 0.21%via NVD
CVE-2026-100528Medium· 5.4
yesterday

OpenClaw (npm package 'openclaw') before 2026.8.1 could send third-party provider credentials to the wrong endpoint

OpenClaw (npm package 'openclaw') before 2026.8.1 could send third-party provider credentials to the wrong endpoint. In affected versions, when a third-party provider uses an OpenAI-compatible API and the resolved model metadata lacks a …

▾ SunlitOpenClaw · OpenClawEPSS 0.24%via NVD
CVE-2026-100527Medium· 5.3
yesterday

OpenClaw before 2026.8.2 contains a denial of service vulnerability in the Browser extension relay that allows unauthenticated network sources to exhaust pending-authentication capacity

OpenClaw before 2026.8.2 contains a denial of service vulnerability in the Browser extension relay that allows unauthenticated network sources to exhaust pending-authentication capacity. Attackers can hold every pending slot by maintaini…

▾ SunlitOpenClaw · OpenClawEPSS 0.35%via NVD
CVE-2026-94094Medium· 4.3PoC
1w ago

A flaw has been found in OpenClaw up to 2026.9.5

A flaw has been found in OpenClaw up to 2026.9.5. Affected is the function createCanvasHostHandler of the file extensions/canvas/src/host/server.ts of the component Canvas Host Route. Executing a manipulation can lead to denial of servic…

▾ TwilightEPSS 0.47%via NVD
CVE-2026-62196High· 8.3
2mo ago

OpenClaw versions 2026.3.22 before 2026.6.6 contain an authorization bypass vulnerability where WhatsApp group IDs can satisfy elevated sender allowlists

OpenClaw versions 2026.3.22 before 2026.6.6 contain an authorization bypass vulnerability where WhatsApp group IDs can satisfy elevated sender allowlists. Attackers with lower-trust access can perform actions requiring stronger authoriza…

▾ Twilightopenclaw · openclawEPSS 0.40%via NVD
CVE-2026-59261High· 7.1
2mo ago

OpenClaw < 2026.5.28 - Credential Override via Workspace Dotenv Files

OpenClaw before 2026.5.28 contains a credential exposure vulnerability where workspace dotenv files can override provider credentials. Attackers with lower-trust access to configured input paths can expose sensitive data and credentials …

▾ TwilightOpenClaw · OpenClawEPSS 0.27%via CVEORG
GHSA-c29c-2q9c-pc86High
2mo ago

OpenClaw: Slack allowFrom could bind to mutable display names

OpenClaw: Slack allowFrom could bind to mutable display names

▾ Twilightopenclaw · openclawvia GHSA
GHSA-qjpc-qf9m-xwmrHigh· 8.8
2mo ago

OpenClaw: Trusted-proxy Control UI WebSocket accepted client-declared scopes before pairing

OpenClaw: Trusted-proxy Control UI WebSocket accepted client-declared scopes before pairing

▾ Twilightopenclaw · openclawvia GHSA
GHSA-gp79-m99v-gjmhMedium
2mo ago

OpenClaw: Mattermost handlers could fall open when channel type was missing

OpenClaw: Mattermost handlers could fall open when channel type was missing

▾ Sunlitopenclaw · openclawvia GHSA
GHSA-w4v6-g3wm-w36cCritical
2mo ago

OpenClaw: QQBot admin commands could skip DM-only and allowFrom policy

OpenClaw: QQBot admin commands could skip DM-only and allowFrom policy

▾ Midnightopenclaw · openclawvia GHSA
GHSA-grc3-2j34-p6gmMedium
2mo ago

OpenClaw: message.action forwarding could send Gateway credentials to model-supplied loopback URLs

OpenClaw: message.action forwarding could send Gateway credentials to model-supplied loopback URLs

▾ Sunlitopenclaw · openclawvia GHSA
GHSA-hcm3-8f6r-6xwgMedium· 6.5
2mo ago

OpenClaw: Browser debug/export routes could reuse already-open blocked tabs

OpenClaw: Browser debug/export routes could reuse already-open blocked tabs

▾ Sunlitopenclaw · openclawvia GHSA
GHSA-xr4f-mjxj-w6w5High· 8.3
2mo ago

OpenClaw: Non-owner chat senders could issue device-pairing bootstrap codes

OpenClaw: Non-owner chat senders could issue device-pairing bootstrap codes

▾ Twilightopenclaw · openclawvia GHSA
GHSA-77pv-3w4q-vrj5Medium
2mo ago

OpenClaw: QQBot pre-dispatch slash commands could skip allowFrom checks

OpenClaw: QQBot pre-dispatch slash commands could skip allowFrom checks

▾ Sunlitopenclaw · openclawvia GHSA
CVE-2026-53819High· 8.8
2mo ago

OpenClaw: Workspace .env could override Homebrew executable selection for skill install flows

OpenClaw: Workspace .env could override Homebrew executable selection for skill install flows

▾ Twilightopenclaw · openclawEPSS 0.41%via GHSA
CVE-2026-53813High· 7.8
2mo ago

OpenClaw: Fake package roots could influence memory-core artifact loading

OpenClaw: Fake package roots could influence memory-core artifact loading

▾ Twilightopenclaw · openclawEPSS 0.17%via GHSA
CVE-2026-53809Medium· 3.8
2mo ago

OpenClaw: Embedded runner policy could be confused by provider aliases

OpenClaw: Embedded runner policy could be confused by provider aliases

▾ Sunlitopenclaw · openclawEPSS 0.13%via GHSA
GHSA-6c4r-g249-wv3cMedium
2mo ago

OpenClaw: Sandboxed session spawn could expose the real workspace path to child prompts

OpenClaw: Sandboxed session spawn could expose the real workspace path to child prompts

▾ Sunlitopenclaw · openclawvia GHSA
GHSA-3wqp-prf6-2m72Low· 3.1
2mo ago

OpenClaw: Feishu dynamic-agent bindings could miss configWrites enforcement

OpenClaw: Feishu dynamic-agent bindings could miss configWrites enforcement

▾ Sunlitopenclaw · openclawvia GHSA
GHSA-275c-xpvc-jgfwMedium
2mo ago

OpenClaw: Slack and Zalo webhook secrets could remain active after secrets.reload

OpenClaw: Slack and Zalo webhook secrets could remain active after secrets.reload

▾ Sunlitopenclaw · openclawvia GHSA
CVE-2026-53818Medium· 6.6
2mo ago

OpenClaw: MCP loopback could skip owner-only tool policy for non-owner callers

OpenClaw: MCP loopback could skip owner-only tool policy for non-owner callers

▾ Sunlitopenclaw · openclawEPSS 0.14%via GHSA
CVE-2026-53806High· 8.8
2mo ago

OpenClaw: Combined POSIX shell options could confuse exec revalidation

OpenClaw: Combined POSIX shell options could confuse exec revalidation

▾ Twilightopenclaw · openclawEPSS 0.61%via GHSA
CVE-2026-53816High· 7.2
2mo ago

OpenClaw: Paired nodes could forge exec lifecycle events without system.run provenance

OpenClaw: Paired nodes could forge exec lifecycle events without system.run provenance

▾ Twilightopenclaw · openclawEPSS 0.50%via GHSA
GHSA-4m3v-q747-pc6hMedium
2mo ago

OpenClaw: Mattermost slash token revocation could lag until monitor refresh

OpenClaw: Mattermost slash token revocation could lag until monitor refresh

▾ Sunlitopenclaw · openclawvia GHSA
CVE-2026-53811High· 8.8
2mo ago

OpenClaw: Matrix allowFrom could bind to mutable display names

OpenClaw: Matrix allowFrom could bind to mutable display names

▾ Twilightopenclaw · openclawEPSS 0.45%via GHSA
GHSA-w5ww-7chg-mxcqHigh
2mo ago

OpenClaw: Telegram interactive callbacks could skip commands.allowFrom

OpenClaw: Telegram interactive callbacks could skip commands.allowFrom

▾ Twilightopenclaw · openclawvia GHSA
GHSA-77q5-rr5v-x43qHigh
2mo ago

OpenClaw: Trusted retry endpoint checks could match hostname prefixes

OpenClaw: Trusted retry endpoint checks could match hostname prefixes

▾ Twilightopenclaw · openclawvia GHSA
GHSA-j472-gf56-x589High
2mo ago

OpenClaw: PowerShell encoded-command aliases could miss exec allowlist checks

OpenClaw: PowerShell encoded-command aliases could miss exec allowlist checks

▾ Twilightopenclaw · openclawvia GHSA
GHSA-p73f-w79w-jqr5High
2mo ago

OpenClaw: Native command authorization could skip owner-command enforcement

OpenClaw: Native command authorization could skip owner-command enforcement

▾ Twilightopenclaw · openclawvia GHSA
CVE-2026-53815High· 6.5
2mo ago

OpenClaw: Message read actions could skip channel allowlist checks

OpenClaw: Message read actions could skip channel allowlist checks

▾ Twilightopenclaw · openclawEPSS 0.36%via GHSA
Openclaw vulnerabilities (CVEs) — page 3 · VulnSea