Vulnerability index

Browse CVEs

530 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Openclaw HIGH 8.8
CVE-2026-62228

OpenClaw before 2026.6.5 contain an authorization bypass vulnerability in node exec approvals that allows lower-trust callers to execute actions beyo…

Fix: 2026.6.5+
Fix from $1,950 2026-07-17
Openclaw HIGH 8.8
CVE-2026-62229

OpenClaw before 2026.5.18 contain an authorization bypass vulnerability in exec allowlist glob matching that allows lower-trust callers to execute ac…

Fix: 2026.5.18+
Fix from $1,950 2026-07-17
Openclaw HIGH 7.7
CVE-2026-62227

OpenClaw 2026.4.14 before 2026.5.26 contain a server-side request forgery vulnerability in browser snapshot routes that fail to validate post-navigat…

Fix: 2026.5.26+
Fix from $1,950 2026-07-17
Openclaw HIGH 8.8
CVE-2026-62223

OpenClaw before 2026.5.18 contain an authorization bypass vulnerability in the device-pair approval feature that allows lower-trust callers to execut…

Fix: 2026.5.18+
Fix from $1,950 2026-07-17
Openclaw HIGH 8.5
CVE-2026-62226

OpenClaw 2026.3.28 before 2026.5.19 contain an authorization bypass vulnerability in the browser act route that fails to properly validate current-ta…

Fix: 2026.5.19+
Fix from $1,950 2026-07-17
Openclaw HIGH 7.8
CVE-2026-62222

OpenClaw before 2026.5.22 contain a vulnerability in setup-mode discovery that allows loading of untrusted workspace plugins. Attackers with lower-tr…

Fix: 2026.5.22+
Fix from $1,950 2026-07-17
Openclaw MEDIUM 5.4
CVE-2026-62221

OpenClaw 2026.5.12 before 2026.5.26 contain an incorrect authorization vulnerability in the ClickClack allowFrom feature. When the affected feature i…

Fix: 2026.5.26+
Fix from $1,600 2026-07-17
Openclaw MEDIUM 5.4
CVE-2026-62225

OpenClaw versions before 2026.5.18 contain an authorization bypass vulnerability in skill command dispatch that allows lower-trust callers to execute…

Fix: 2026.5.18+
Fix from $1,600 2026-07-17
Openclaw HIGH 8.8
CVE-2026-62217

OpenClaw 2026.5.14-beta.1 before 2026.5.27 contain an authorization flaw in the QQBot exec approvals feature. When the feature is enabled and reachab…

Fix: 2026.5.27+
Fix from $1,950 2026-07-17
Openclaw HIGH 8.8
CVE-2026-62218

OpenClaw 2026.1.20 before 2026.5.27 contain an authorization bypass vulnerability in the device.pair.approve feature that allows lower-trust callers …

Fix: 2026.5.27+
Fix from $1,950 2026-07-17
Openclaw HIGH 8.0
CVE-2026-62215

OpenClaw versions before 2026.6.5 contain an authentication bypass vulnerability in HTTP Canvas responses that allows lower-trust callers to forge tr…

Fix: 2026.6.5+
Fix from $1,950 2026-07-17
Openclaw HIGH 7.1
CVE-2026-62219

OpenClaw 2026.2.12 before 2026.5.26 contain an authorization bypass vulnerability in the hooks allowedAgentIds validation. A lower-trust caller or co…

Fix: 2026.5.26+
Fix from $1,950 2026-07-17
Openclaw MEDIUM 6.5
CVE-2026-62214

OpenClaw versions before 2026.5.28 Bot Framework contains an improper input validation vulnerability that allows lower-trust callers to expose bot to…

Fix: 2026.5.28+
Fix from $1,600 2026-07-17
Openclaw MEDIUM 5.3
CVE-2026-62220

OpenClaw 2026.2.25 before 2026.5.26 allow a lower-trust caller or configured input path to bypass non-browser rate limits on WebSocket authentication…

Fix: 2026.5.26+
Fix from $1,600 2026-07-17
Openclaw MEDIUM 5.0
CVE-2026-62216

OpenClaw 2026.4.20 before 2026.5.28 contain a policy bypass in the QQBot media upload feature. A lower-trust caller or configured input path could ca…

Fix: 2026.5.28+
Fix from $1,600 2026-07-17
Openclaw HIGH 8.8
CVE-2026-62207

OpenClaw versions before 2026.6.5 contain an authentication bypass vulnerability that allows lower-trust callers to reach admin-scoped tools. Attacke…

Fix: 2026.6.5+
Fix from $1,950 2026-07-17
Openclaw HIGH 8.1
CVE-2026-62209

OpenClaw versions 2026.5.10-beta.1 before 2026.6.5 contain an authorization bypass in the ClickClack agent-mode dispatch feature, which could ignore …

Fix: 2026.6.5+
Fix from $1,950 2026-07-17
Openclaw HIGH 7.1
CVE-2026-62212

OpenClaw before 2026.5.28 contains a race condition in the MS Teams safeFetch DNS rebinding check. When the affected feature is enabled and reachable…

Fix: 2026.5.28+
Fix from $1,950 2026-07-17
Openclaw MEDIUM 6.5
CVE-2026-62208

OpenClaw before 2026.6.5 could forward Authorization headers during MCP SSE redirects. When the affected feature is enabled and reachable, a lower-tr…

Fix: 2026.6.5+
Fix from $1,600 2026-07-17
Openclaw MEDIUM 6.5
CVE-2026-62210

OpenClaw versions before 2026.6.1 contain a denial of service vulnerability where remote media URLs can trigger slow-read attacks that exhaust gatewa…

Fix: 2026.6.1+
Fix from $1,600 2026-07-17
Openclaw MEDIUM 6.5
CVE-2026-62213

OpenClaw versions before 2026.5.27 contain a token leakage vulnerability in MS Teams outbound requests that allows lower-trust callers to expose Bot …

Fix: 2026.5.27+
Fix from $1,600 2026-07-17
Openclaw MEDIUM 5.0
CVE-2026-62211

OpenClaw versions before 2026.6.1 contain a credential redaction bypass vulnerability in the trajectory export feature that allows lower-trust caller…

Fix: 2026.6.1+
Fix from $1,600 2026-07-17
Openclaw HIGH 8.8
CVE-2026-62202

OpenClaw versions 2026.6.1 before 2026.6.9 contain a privilege escalation vulnerability in isolated cron jobs that allows lower-trust callers to rega…

Fix: 2026.6.9+
Fix from $1,950 2026-07-17
Openclaw HIGH 8.8
CVE-2026-62203

OpenClaw versions before 2026.6.6 contain an environment variable filtering vulnerability in host exec that fails to properly sanitize rustup startup…

Fix: 2026.6.6+
Fix from $1,950 2026-07-17
Openclaw HIGH 7.7
CVE-2026-62201

OpenClaw versions before 2026.6.6 contain a network policy bypass vulnerability in the sandbox exec-server that allows lower-trust callers to reach i…

Fix: 2026.6.6+
Fix from $1,950 2026-07-17
Openclaw HIGH 7.1
CVE-2026-62205

OpenClaw versions 2026.4.12-beta.1 before 2026.6.6 contain a missing-authorization vulnerability in the MS Teams message actions feature. When the af…

Fix: 2026.6.6+
Fix from $1,950 2026-07-17
Openclaw HIGH 7.1
CVE-2026-62206

OpenClaw versions before 2026.6.9 contain a missing authorization vulnerability in Discord moderation actions. In affected versions, a lower-trust ca…

Fix: 2026.6.9+
Fix from $1,950 2026-07-17
Openclaw HIGH 8.8
CVE-2026-62199

OpenClaw versions before 2026.6.6 contain a flaw in host exec environment filtering that can miss interpreter startup variables. When the affected fe…

Fix: 2026.6.6+
Fix from $1,950 2026-07-13
Openclaw HIGH 8.8
CVE-2026-62200

OpenClaw versions before 2026.6.6 contain a flaw in host exec environment filtering that could allow Git ext transport to be abused. When the affecte…

Fix: 2026.6.6+
Fix from $1,950 2026-07-13
Openclaw HIGH 8.5
CVE-2026-62197

OpenClaw before 2026.6.6 contains a policy bypass vulnerability in browser CDP discovery that accepts blocked WebSocket URLs. Attackers with lower-tr…

Fix: 2026.6.6+
Fix from $1,950 2026-07-13