Vulnerability index

Browse CVEs

530 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Openclaw HIGH 7.4
CVE-2026-35629

OpenClaw before 2026.3.25 contains a server-side request forgery vulnerability in multiple channel extensions that fail to properly guard configured …

Fix: 2026.3.25+
Fix from $1,950 2026-04-09
Openclaw MEDIUM 6.5
CVE-2026-35628

OpenClaw before 2026.3.25 contains a missing rate limiting vulnerability in Telegram webhook authentication that allows attackers to brute-force weak…

Fix: 2026.3.25+
Fix from $1,600 2026-04-09
Openclaw MEDIUM 6.5
CVE-2026-35631

OpenClaw before 2026.3.22 fails to enforce operator.admin scope on mutating internal ACP chat commands, allowing unauthorized modifications. Attacker…

Fix: 2026.3.22+
Fix from $1,600 2026-04-09
Openclaw MEDIUM 5.3
CVE-2026-35626

OpenClaw before 2026.3.22 contains an unauthenticated resource exhaustion vulnerability in voice call webhook handling that buffers request bodies be…

Fix: 2026.3.22+
Fix from $1,600 2026-04-09
Openclaw HIGH 7.8
CVE-2026-35625

OpenClaw before 2026.3.25 contains a privilege escalation vulnerability where silent local shared-auth reconnects auto-approve scope-upgrade requests…

Fix: 2026.3.25+
Fix from $1,950 2026-04-09
Openclaw HIGH 7.1
CVE-2026-35622

OpenClaw before 2026.3.22 contains an improper authentication verification vulnerability in Google Chat app-url webhook handling that accepts add-on …

Fix: 2026.3.22+
Fix from $1,950 2026-04-09
Openclaw MEDIUM 6.5
CVE-2026-35618

OpenClaw before 2026.3.23 contains a replay identity vulnerability in Plivo V2 signature verification that allows attackers to bypass replay protecti…

Fix: 2026.3.23+
Fix from $1,600 2026-04-09
Openclaw MEDIUM 6.5
CVE-2026-35623

OpenClaw before 2026.3.25 contains a missing rate limiting vulnerability in webhook authentication that allows attackers to brute-force weak webhook …

Fix: 2026.3.25+
Fix from $1,600 2026-04-09
Openclaw MEDIUM 5.4
CVE-2026-35624

OpenClaw before 2026.3.22 contains a policy confusion vulnerability in room authorization that matches colliding room names instead of stable room to…

Fix: 2026.3.22+
Fix from $1,600 2026-04-09
Openclaw HIGH 8.1
CVE-2026-34512

OpenClaw before 2026.3.25 contains an improper access control vulnerability in the HTTP /sessions/:sessionKey/kill route that allows any bearer-authe…

Fix: 2026.3.25+
Fix from $1,950 2026-04-09
Openclaw MEDIUM 5.4
CVE-2026-35617

OpenClaw before 2026.3.25 contains an authorization bypass vulnerability in Google Chat group policy enforcement that relies on mutable space display…

Fix: 2026.3.25+
Fix from $1,600 2026-04-09
Openclaw MEDIUM 6.5
CVE-2026-40037

OpenClaw before 2026.3.31 (patched in 2026.4.8) contains a request body replay vulnerability in fetchWithSsrFGuard that allows unsafe request bodies …

Fix: 2026.4.8+
Fix from $1,600 2026-04-08
Openclaw MEDIUM 5.9
CVE-2026-34511

OpenClaw before 2026.4.2 reuses the PKCE verifier as the OAuth state parameter in the Gemini OAuth flow, exposing it through the redirect URL. Attack…

Fix: 2026.4.2+
Fix from $1,600 2026-04-03
Openclaw HIGH 7.3
CVE-2026-34426

OpenClaw versions prior to commit b57b680 contain an approval bypass vulnerability due to inconsistent environment variable normalization between app…

Fix: 2026.4.2+
Fix from $1,950 2026-04-02
Openclaw MEDIUM 5.3
CVE-2026-34510

OpenClaw before 2026.3.22 contains a path traversal vulnerability in Windows media loaders that accepts remote-host file URLs and UNC-style paths bef…

Fix: 2026.3.22+
Fix from $1,600 2026-04-01
Openclaw HIGH 8.3
CVE-2026-34504

OpenClaw before 2026.3.28 contains a server-side request forgery vulnerability in the fal provider image-generation-provider.ts component that allows…

Fix: 2026.3.28+
Fix from $1,950 2026-03-31
Openclaw HIGH 8.1
CVE-2026-34503

OpenClaw before 2026.3.28 fails to disconnect active WebSocket sessions when devices are removed or tokens are revoked. Attackers with revoked creden…

Fix: 2026.3.28+
Fix from $1,950 2026-03-31
Openclaw HIGH 8.6
CVE-2026-33581

OpenClaw before 2026.3.24 contains a sandbox bypass vulnerability in the message tool that allows attackers to read arbitrary local files by using me…

Fix: 2026.3.24+
Fix from $1,950 2026-03-31
Openclaw MEDIUM 6.5
CVE-2026-33580

OpenClaw before 2026.3.28 contains a missing rate limiting vulnerability in the Nextcloud Talk webhook authentication that allows attackers to brute-…

Fix: 2026.3.28+
Fix from $1,600 2026-03-31
Openclaw CRITICAL 9.9
CVE-2026-33579

OpenClaw before 2026.3.28 contains a privilege escalation vulnerability in the /pair approve command path that fails to forward caller scopes into th…

Fix: 2026.3.28+
Fix from $2,300 2026-03-31
Openclaw HIGH 8.1
CVE-2026-33577

OpenClaw before 2026.3.28 contains an insufficient scope validation vulnerability in the node pairing approval path that allows low-privilege operato…

Fix: 2026.3.28+
Fix from $1,950 2026-03-31
Openclaw MEDIUM 6.5
CVE-2026-33576

OpenClaw before 2026.3.28 downloads and stores inbound media from Zalo channels before validating sender authorization. Unauthorized senders can forc…

Fix: 2026.3.28+
Fix from $1,600 2026-03-31
Openclaw HIGH 7.5
CVE-2026-32988

OpenClaw before 2026.3.11 contains a sandbox boundary bypass vulnerability in fs-bridge staged writes where temporary file creation and population ar…

Fix: 2026.3.11+
Fix from $1,950 2026-03-31
Openclaw MEDIUM 6.5
CVE-2026-34505

OpenClaw before 2026.3.12 applies rate limiting only after successful webhook authentication, allowing attackers to bypass rate limits and brute-forc…

Fix: 2026.3.12+
Fix from $1,600 2026-03-31
Openclaw HIGH 8.0
CVE-2026-32971

OpenClaw before 2026.3.11 contains an approval-integrity vulnerability in node-host system.run approvals that displays extracted shell payloads inste…

Fix: 2026.3.11+
Fix from $1,950 2026-03-31
Openclaw HIGH 7.5
CVE-2026-32982

OpenClaw before 2026.3.13 contains an information disclosure vulnerability in the fetchRemoteMedia function that exposes Telegram bot tokens in error…

Fix: 2026.3.13+
Fix from $1,950 2026-03-31
Openclaw MEDIUM 6.5
CVE-2026-32976

OpenClaw before 2026.3.11 contains an authorization bypass vulnerability allowing channel commands to mutate protected sibling-account configuration …

Fix: 2026.3.11+
Fix from $1,600 2026-03-31
Openclaw MEDIUM 6.3
CVE-2026-32977

OpenClaw before 2026.3.11 contains a sandbox boundary bypass vulnerability in the fs-bridge writeFile commit step that uses an unanchored container p…

Fix: 2026.3.11+
Fix from $1,600 2026-03-31
Openclaw CRITICAL 9.8
CVE-2026-32916

OpenClaw versions 2026.3.7 before 2026.3.11 contain an authorization bypass vulnerability where plugin subagent routes execute gateway methods throug…

Fix: 2026.3.11+
Fix from $2,300 2026-03-31
Openclaw CRITICAL 9.8
CVE-2026-32917

OpenClaw before 2026.3.13 contains a remote command injection vulnerability in the iMessage attachment staging flow that allows attackers to execute …

Fix: 2026.3.13+
Fix from $2,300 2026-03-31