Openclaw vulnerabilities
CVEs whose affected-version data names the Openclaw package (npm). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
201 CVEsRSS
CVE-2026-100529Medium· 6.4OpenClaw versions before 2026.8.1 contain an authorization scope widening vulnerability in file-transfer allow-always approvals that allows attackers to reuse standing grants for unreviewed paths
OpenClaw versions before 2026.8.1 contain an authorization scope widening vulnerability in file-transfer allow-always approvals that allows attackers to reuse standing grants for unreviewed paths. Attackers can exploit glob metacharacter…
CVE-2026-100528Medium· 5.4OpenClaw (npm package 'openclaw') before 2026.8.1 could send third-party provider credentials to the wrong endpoint
OpenClaw (npm package 'openclaw') before 2026.8.1 could send third-party provider credentials to the wrong endpoint. In affected versions, when a third-party provider uses an OpenAI-compatible API and the resolved model metadata lacks a …
CVE-2026-100527Medium· 5.3OpenClaw before 2026.8.2 contains a denial of service vulnerability in the Browser extension relay that allows unauthenticated network sources to exhaust pending-authentication capacity
OpenClaw before 2026.8.2 contains a denial of service vulnerability in the Browser extension relay that allows unauthenticated network sources to exhaust pending-authentication capacity. Attackers can hold every pending slot by maintaini…
CVE-2026-94094Medium· 4.3PoCA flaw has been found in OpenClaw up to 2026.9.5
A flaw has been found in OpenClaw up to 2026.9.5. Affected is the function createCanvasHostHandler of the file extensions/canvas/src/host/server.ts of the component Canvas Host Route. Executing a manipulation can lead to denial of servic…
CVE-2026-62196High· 8.3OpenClaw versions 2026.3.22 before 2026.6.6 contain an authorization bypass vulnerability where WhatsApp group IDs can satisfy elevated sender allowlists
OpenClaw versions 2026.3.22 before 2026.6.6 contain an authorization bypass vulnerability where WhatsApp group IDs can satisfy elevated sender allowlists. Attackers with lower-trust access can perform actions requiring stronger authoriza…
CVE-2026-59261High· 7.1OpenClaw < 2026.5.28 - Credential Override via Workspace Dotenv Files
OpenClaw before 2026.5.28 contains a credential exposure vulnerability where workspace dotenv files can override provider credentials. Attackers with lower-trust access to configured input paths can expose sensitive data and credentials …
GHSA-c29c-2q9c-pc86HighOpenClaw: Slack allowFrom could bind to mutable display names
OpenClaw: Slack allowFrom could bind to mutable display names
GHSA-qjpc-qf9m-xwmrHigh· 8.8OpenClaw: Trusted-proxy Control UI WebSocket accepted client-declared scopes before pairing
OpenClaw: Trusted-proxy Control UI WebSocket accepted client-declared scopes before pairing
GHSA-gp79-m99v-gjmhMediumOpenClaw: Mattermost handlers could fall open when channel type was missing
OpenClaw: Mattermost handlers could fall open when channel type was missing
GHSA-w4v6-g3wm-w36cCriticalOpenClaw: QQBot admin commands could skip DM-only and allowFrom policy
OpenClaw: QQBot admin commands could skip DM-only and allowFrom policy
GHSA-grc3-2j34-p6gmMediumOpenClaw: message.action forwarding could send Gateway credentials to model-supplied loopback URLs
OpenClaw: message.action forwarding could send Gateway credentials to model-supplied loopback URLs
GHSA-hcm3-8f6r-6xwgMedium· 6.5OpenClaw: Browser debug/export routes could reuse already-open blocked tabs
OpenClaw: Browser debug/export routes could reuse already-open blocked tabs
GHSA-xr4f-mjxj-w6w5High· 8.3OpenClaw: Non-owner chat senders could issue device-pairing bootstrap codes
OpenClaw: Non-owner chat senders could issue device-pairing bootstrap codes
GHSA-77pv-3w4q-vrj5MediumOpenClaw: QQBot pre-dispatch slash commands could skip allowFrom checks
OpenClaw: QQBot pre-dispatch slash commands could skip allowFrom checks
CVE-2026-53819High· 8.8OpenClaw: Workspace .env could override Homebrew executable selection for skill install flows
OpenClaw: Workspace .env could override Homebrew executable selection for skill install flows
CVE-2026-53813High· 7.8OpenClaw: Fake package roots could influence memory-core artifact loading
OpenClaw: Fake package roots could influence memory-core artifact loading
CVE-2026-53809Medium· 3.8OpenClaw: Embedded runner policy could be confused by provider aliases
OpenClaw: Embedded runner policy could be confused by provider aliases
GHSA-6c4r-g249-wv3cMediumOpenClaw: Sandboxed session spawn could expose the real workspace path to child prompts
OpenClaw: Sandboxed session spawn could expose the real workspace path to child prompts
GHSA-3wqp-prf6-2m72Low· 3.1OpenClaw: Feishu dynamic-agent bindings could miss configWrites enforcement
OpenClaw: Feishu dynamic-agent bindings could miss configWrites enforcement
GHSA-275c-xpvc-jgfwMediumOpenClaw: Slack and Zalo webhook secrets could remain active after secrets.reload
OpenClaw: Slack and Zalo webhook secrets could remain active after secrets.reload
CVE-2026-53818Medium· 6.6OpenClaw: MCP loopback could skip owner-only tool policy for non-owner callers
OpenClaw: MCP loopback could skip owner-only tool policy for non-owner callers
CVE-2026-53806High· 8.8OpenClaw: Combined POSIX shell options could confuse exec revalidation
OpenClaw: Combined POSIX shell options could confuse exec revalidation
CVE-2026-53816High· 7.2OpenClaw: Paired nodes could forge exec lifecycle events without system.run provenance
OpenClaw: Paired nodes could forge exec lifecycle events without system.run provenance
GHSA-4m3v-q747-pc6hMediumOpenClaw: Mattermost slash token revocation could lag until monitor refresh
OpenClaw: Mattermost slash token revocation could lag until monitor refresh
CVE-2026-53811High· 8.8OpenClaw: Matrix allowFrom could bind to mutable display names
OpenClaw: Matrix allowFrom could bind to mutable display names
GHSA-w5ww-7chg-mxcqHighOpenClaw: Telegram interactive callbacks could skip commands.allowFrom
OpenClaw: Telegram interactive callbacks could skip commands.allowFrom
GHSA-77q5-rr5v-x43qHighOpenClaw: Trusted retry endpoint checks could match hostname prefixes
OpenClaw: Trusted retry endpoint checks could match hostname prefixes
GHSA-j472-gf56-x589HighOpenClaw: PowerShell encoded-command aliases could miss exec allowlist checks
OpenClaw: PowerShell encoded-command aliases could miss exec allowlist checks
GHSA-p73f-w79w-jqr5HighOpenClaw: Native command authorization could skip owner-command enforcement
OpenClaw: Native command authorization could skip owner-command enforcement
CVE-2026-53815High· 6.5OpenClaw: Message read actions could skip channel allowlist checks
OpenClaw: Message read actions could skip channel allowlist checks