CVEs we hold for Openclaw
Records whose assigning authority named Openclaw as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-91836OpenClaw ClawScan Static Scanner static_scanner.go incomplete comparison with missing factorsOpenClaw ClawScan
CVE-2026-91835OpenClaw ClawScan File Classifier static_scanner.go IsBinaryFile interpretation conflictOpenClaw ClawScan
CVE-2026-8305OpenClaw bluebubbles Webhook monitor.ts handleBlueBubblesWebhookRequest improper authenticationn/a OpenClaw
CVE-2026-62217OpenClaw 2026.5.14-beta.1 < 2026.5.27 Authentication Bypass via exec approvalsOpenClaw
CVE-2026-62214OpenClaw < 2026.5.28 Bot Framework SSRF via serviceUrl Parameter Validationopenclaw msteams
CVE-2026-62209OpenClaw 2026.5.10-beta.1 < 2026.6.5 Authorization Bypass via agent-mode dispatchOpenClaw
CVE-2026-53865OpenClaw < 2026.5.2 - Arbitrary Command Execution via Workspace-Derived Service PATHOpenClaw
CVE-2026-53864OpenClaw < 2026.5.26 - Insufficient Environment Variable Sanitization in Node.js Control VariablesOpenClaw
CVE-2026-53862OpenClaw < 2026.5.12 - Bootstrap Token Replay via Pending Pairing Scope WideningOpenClaw
CVE-2026-53861OpenClaw < 2026.5.6 - Allowlist Bypass via Combined POSIX Inline Flags on macOSOpenClaw
CVE-2026-53860OpenClaw < 2026.5.7 - Sender Policy Bypass via Mutable Conversation Identifiers in BlueBubblesOpenClaw
CVE-2026-53859OpenClaw < 2026.5.26 - Hostname Validation Bypass via Trailing-Dot InconsistencyOpenClaw
CVE-2026-53858OpenClaw < 2026.5.2 - Arbitrary Runtime Dependency Loading via STATE_DIRECTORY Environment VariableOpenClaw
CVE-2026-53856OpenClaw 2026.4.23 < 2026.4.24 - Insecure File Permissions in Config Recovery via OpenClaw.jsonOpenClaw
CVE-2026-53855OpenClaw < 2026.4.2 - Shell Positional Parameters Bypass in Inline-Eval ChecksOpenClaw
CVE-2026-53854OpenClaw < 2026.4.25 - Privilege Escalation via ownerAllowFrom Wildcard Inheritance in Internal/Webchat CommandsOpenClaw
CVE-2026-53853OpenClaw < 2026.5.12 - Argument Pattern Bypass in Exec Allowlist via Linux and macOSOpenClaw
CVE-2026-53849OpenClaw < 2026.5.7 - Privilege Escalation via Mutable Discord Display Names in allowFromOpenClaw
CVE-2026-53846OpenClaw < 2026.4.29 - Arbitrary Package Manager Execution via Workspace .env npm_execpathOpenClaw
CVE-2026-53845OpenClaw < 2026.5.6 - Skill-Command Dispatch Hook Bypass via Before-Tool-Call Hook SkippingOpenClaw
CVE-2026-53844OpenClaw < 2026.4.29 - Session Visibility Check Bypass in Shared Memory SearchOpenClaw
CVE-2026-53843OpenClaw < 2026.5.26 - Node Token Revocation Bypass via Pairing-Scoped Device SessionOpenClaw
CVE-2026-53842OpenClaw < 2026.5.2 - Arbitrary Python Runtime Execution via CLOUDSDK_PYTHON Environment VariableOpenClaw
CVE-2026-53841OpenClaw < 2026.5.12 - Cross-Site Scripting via Unsafe Markdown Links in Exported Session HTMLOpenClaw
CVE-2026-53840OpenClaw < 2026.5.12 - Custom Header Leakage via MCP Streamable HTTP Cross-Origin RedirectsOpenClaw
CVE-2026-53839OpenClaw < 2026.5.7 - Hostname Prefix Matching Bypass in Trusted Retry Endpoint ValidationOpenClaw
CVE-2026-53837OpenClaw < 2026.5.6 - Missing Channel Type Validation in Mattermost Event HandlersOpenClaw
CVE-2026-53836OpenClaw < 2026.5.12 - Allowlist Bypass via PowerShell Encoded-Command AliasesOpenClaw
CVE-2026-53835OpenClaw < 2026.5.6 - Config-Write Enforcement Bypass in Feishu Dynamic-Agent BindingsOpenClaw
CVE-2026-53834OpenClaw < 2026.4.27 - Authorization Bypass in QQBot Pre-dispatch Slash CommandsOpenClaw
CVE-2026-53833QQBot for OpenClaw < 2026.4.29 - Authorization Bypass via QQBot Streaming CommandOpenClaw
CVE-2026-53832OpenClaw < 2026.5.18 - Identity Header Forgery via Trusted-Proxy ConfigurationOpenClaw
CVE-2026-53831OpenClaw < 2026.5.18 - Arbitrary File Read via Shell Expansion in system.run Safe-bin AllowlistOpenClaw
CVE-2026-53828OpenClaw < 2026.5.6 - Native Command Authorization Bypass via Owner-Command EnforcementOpenClaw
CVE-2026-53827OpenClaw < 2026.5.2 - Credential Exposure via Model-Supplied Loopback URLs in message.action ForwardingOpenClaw
CVE-2026-53825OpenClaw < 2026.4.7 - Arbitrary Local File Read via memory-wiki Ingest with operator.write ScopeOpenClaw
CVE-2026-53824Mattermost plugin for OpenClaw < 2026.4.24 - Slash Token Revocation Lag via Monitor Refresh DelayOpenClaw
CVE-2026-53823OpenClaw < 2026.5.3 - Privilege Escalation via Mutable Slack Display Names in allowFromOpenClaw
CVE-2026-53822OpenClaw < 2026.5.18 - Command Argument Modification via Shell Wrapper Between Approval and ExecutionOpenClaw
CVE-2026-53820OpenClaw < 2026.5.12 - Exec Denylist Bypass in Bundle MCP Loopback Session SpawnOpenClaw
CVE-2026-53819OpenClaw < 2026.5.27 - Arbitrary Homebrew Executable Execution via Workspace .env OverrideOpenClaw
CVE-2026-53814OpenClaw < 2026.5.20 - Privilege Escalation via Hook-Triggered CLI MCP Tool AuthorityOpenClaw
CVE-2026-53813OpenClaw < 2026.4.25 - Arbitrary Artifact Loading via Fake Package Root ResolutionOpenClaw
CVE-2026-53812OpenClaw < 2026.5.18 - Private-Network Navigation Bypass via Browser Act InteractionsOpenClaw
CVE-2026-53811OpenClaw < 2026.5.7 - Privilege Escalation via Mutable Display Names in Matrix allowFromOpenClaw
CVE-2026-53810OpenClaw < 2026.5.18 - Arbitrary Code Execution via Unscanned Marketplace Runtime Extension MetadataOpenClaw
CVE-2026-53807OpenClaw < 2026.5.6 - Authorization Bypass in Telegram Interactive Callbacks via commands.allowFromOpenClaw
CVE-2026-45006OpenClaw < 2026.4.23 - Unsafe Config Mutation via Gateway Tool Denylist BypassOpenClaw
CVE-2026-45005OpenClaw < 2026.4.23 - Webhook Route Secret Cache Not Invalidated After RotationOpenClaw
CVE-2026-45004OpenClaw < 2026.4.23 - Arbitrary Code Execution via setup-api.js in Current Working DirectoryOpenClaw
CVE-2026-45003OpenClaw < 2026.4.22 - Connector Endpoint Host Override via Workspace dotenv FilesOpenClaw
CVE-2026-45001OpenClaw < 2026.4.20 - Gateway Config Mutation Guard Bypass via Agent Tool AccessOpenClaw
CVE-2026-45000OpenClaw < 2026.4.20 - Server-Side Request Forgery via Browser CDP Profile CreationOpenClaw
CVE-2026-44999OpenClaw < 2026.4.20 - Improper Trust Labeling in Isolated Cron Awareness EventsOpenClaw
CVE-2026-44997OpenClaw < 2026.4.22 - Security Envelope Constraint Bypass in ACP Child SessionsOpenClaw
CVE-2026-44995OpenClaw < 2026.4.20 - Arbitrary Code Execution via MCP stdio Environment VariablesOpenClaw
CVE-2026-44994OpenClaw < 2026.4.22 - Authentication Bypass in Gateway Control UI Bootstrap Config EndpointOpenClaw
CVE-2026-44993OpenClaw < 2026.4.20 - Direct Message Misclassification in Feishu Card ActionsOpenClaw
CVE-2026-44992OpenClaw 2026.4.5 through 2026.4.19 - MiniMax API Host Override via Workspace dotenvOpenClaw
CVE-2026-44991OpenClaw < 2026.4.21 - Authorization Bypass in Owner-Enforced Commands via Wildcard Channel SendersOpenClaw
CVE-2026-44117OpenClaw < 2026.4.20 - Server-Side Request Forgery in QQBot Direct Media UploadOpenClaw
CVE-2026-44116OpenClaw < 2026.4.22 - Server-Side Request Forgery in Zalo Photo URL ValidationOpenClaw
CVE-2026-44115OpenClaw < 2026.4.22 - Shell Expansion Bypass in Unquoted Heredocs via Exec AllowlistOpenClaw
CVE-2026-44114OpenClaw < 2026.4.20 - Environment Variable Namespace Collision via Workspace dotenvOpenClaw
CVE-2026-44113OpenClaw < 2026.4.22 - Time-of-Check/Time-of-Use Race Condition in OpenShell FS BridgeOpenClaw
CVE-2026-44112OpenClaw < 2026.4.22 - Symlink Swap Race Condition in OpenShell FS Bridge WritesOpenClaw
CVE-2026-44110OpenClaw < 2026.4.15 - Authorization Bypass in Matrix Room Control Commands via DM Pairing StoreOpenClaw
CVE-2026-44109OpenClaw < 2026.4.15 - Authentication Bypass in Feishu Webhook and Card-Action ValidationOpenClaw
CVE-2026-43585OpenClaw < 2026.4.15 - Bearer Token Validation Bypass via Stale SecretRef ResolutionOpenClaw
CVE-2026-43584OpenClaw < 2026.4.10 - Insufficient Environment Variable Denylist in Exec PolicyOpenClaw
CVE-2026-43583OpenClaw 2026.4.10 < 2026.4.14 - Loss of Group Tool-Policy Context in Delivery Queue RecoveryOpenClaw
CVE-2026-43581OpenClaw < 2026.4.10 - Chrome DevTools Protocol Exposure via Overly Broad CDP Relay BindingOpenClaw
CVE-2026-43580OpenClaw < 2026.4.10 - Incomplete Navigation Guard Coverage in Browser InteractionsOpenClaw
CVE-2026-43579OpenClaw < 2026.4.10 - Insufficient Access Control in Nostr Profile Mutation RoutesOpenClaw
CVE-2026-43578OpenClaw 2026.3.31 < 2026.4.10 - Privilege Escalation via Missed Async Exec Completion Events in Heartbeat Owner…OpenClaw
CVE-2026-43575OpenClaw 2026.2.21 < 2026.4.10 - Authentication Bypass in Sandbox noVNC Helper RouteOpenClaw
CVE-2026-43573OpenClaw < 2026.4.10 - SSRF Policy Bypass in Existing-Session Browser Interaction RoutesOpenClaw
CVE-2026-43572OpenClaw 2026.4.10 < 2026.4.14 - Missing Sender Authorization in Microsoft Teams SSO Invoke HandlerOpenClaw
CVE-2026-43571OpenClaw < 2026.4.10 - Untrusted Workspace Plugin Shadow Resolution in Channel SetupOpenClaw
CVE-2026-43570OpenClaw 2026.3.22 < 2026.4.5 - Symlink Traversal in Remote Marketplace Repository Path HandlingOpenClaw
CVE-2026-43569OpenClaw < 2026.4.9 - Untrusted Provider Plugin Auto-enablement via Workspace Provider AuthOpenClaw
CVE-2026-43568OpenClaw 2026.4.5 through 2026.4.9 - Privilege Escalation via Memory Dreaming Configuration in /dreaming EndpointOpenClaw
CVE-2026-43566OpenClaw 2026.4.7 < 2026.4.14 - Privilege Escalation via Untrusted Webhook Wake EventsOpenClaw
CVE-2026-43535OpenClaw < 2026.4.14 - Authorization Context Reuse in Collect-Mode Queue BatchesOpenClaw
CVE-2026-43532OpenClaw 2026.4.7 < 2026.4.10 - Sandbox Media Normalization Bypass via Discord Event Cover ImageOpenClaw
CVE-2026-43530OpenClaw 2026.2.23 < 2026.4.12 - Weakened Exec Approval Binding via busybox and toybox Applet ExecutionOpenClaw
CVE-2026-43529OpenClaw < 2026.4.10 - Time-of-Check-Time-of-Use (TOCTOU) Race Condition in exec Script Preflight ValidatorOpenClaw
CVE-2026-43528OpenClaw < 2026.4.14 - Redaction Bypass via sourceConfig and runtimeConfig AliasesOpenClaw
CVE-2026-43527OpenClaw < 2026.4.14 - Server-Side Request Forgery via Private Network NavigationOpenClaw
CVE-2026-43526OpenClaw < 2026.4.12 - Server-Side Request Forgery via QQBot Reply Media URL HandlingOpenClaw
CVE-2026-42438OpenClaw 2026.4.9 < 2026.4.10 - Sender Policy Bypass in Host Media Attachment ReadsOpenClaw
CVE-2026-42437OpenClaw 2026.4.9 < 2026.4.10 - Denial of Service via Oversized WebSocket Frames in Voice-call Realtime PathOpenClaw
CVE-2026-42436OpenClaw < 2026.4.14 - Internal Page Content Exposure via Browser Snapshot and Screenshot RoutesOpenClaw
CVE-2026-42435OpenClaw 2026.2.22 < 2026.4.12 - Shell-Wrapper Detection Bypass via Environment Variable Assignment InjectionOpenClaw
CVE-2026-42434OpenClaw 2026.4.5 < 2026.4.10 - Sandbox Escape via host Parameter Override in Exec RoutingOpenClaw
CVE-2026-42433OpenClaw < 2026.4.10 - Unauthorized Matrix Profile Config Persistence Access via operator.write Message ToolsOpenClaw
CVE-2026-42431OpenClaw < 2026.4.8 - Persistent Profile Mutation via node.invoke(browser.proxy) BypassOpenClaw
CVE-2026-42430OpenClaw < 2026.4.8 - Strict Browser SSRF Bypass via Playwright Redirect HandlingOpenClaw
CVE-2026-42429OpenClaw < 2026.4.8 - Privilege Escalation via Gateway Plugin HTTP AuthenticationOpenClaw
CVE-2026-42427OpenClaw < 2026.4.8 - Remote Code Execution via Build Tool Environment Variable InjectionOpenClaw
CVE-2026-42426OpenClaw < 2026.4.8 - Improper Authorization in node.pair.approve via operator.write ScopeOpenClaw
CVE-2026-42423OpenClaw < 2026.4.8 - strictInlineEval Approval Boundary Bypass via Approval-Timeout FallbackOpenClaw
CVE-2026-42421OpenClaw < 2026.4.8 - WebSocket Session Persistence via Shared Gateway Token RotationOpenClaw
CVE-2026-41915OpenClaw < 2026.4.8 - Git Environment Variable Injection via Unfiltered Exec EnvironmentOpenClaw
CVE-2026-41913OpenClaw < 2026.4.4 - Rate-Limit Bypass via Concurrent Async Authentication AttemptsOpenClaw
CVE-2026-41912OpenClaw < 2026.4.8 - Server-Side Request Forgery Policy Bypass via Interaction-Triggered NavigationOpenClaw
CVE-2026-41911OpenClaw < 2026.4.8 - Workspace-Only Filesystem Policy Bypass via docx upload_file/upload_imageOpenClaw
CVE-2026-41910OpenClaw < 2026.4.8 - Missing Owner-Only Enforcement in /allowlist Cross-Channel WritesOpenClaw
CVE-2026-41909OpenClaw < 2026.4.20 - Improper Authorization in Paired-Device Pairing ActionsOpenClaw
200 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.