Vulnerability index

Browse CVEs

530 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Openclaw MEDIUM 5.3
CVE-2026-32029

OpenClaw versions prior to 2026.2.21 improperly parse the left-most X-Forwarded-For header value when requests originate from configured trusted prox…

Fix: 2026.2.21+
Fix from $1,600 2026-03-19
Openclaw HIGH 8.6
CVE-2026-32026

OpenClaw versions prior to 2026.2.24 contain an improper path validation vulnerability in sandbox media handling that allows absolute paths under the…

Fix: 2026.2.24+
Fix from $1,950 2026-03-19
Openclaw HIGH 7.5
CVE-2026-32025

OpenClaw versions prior to 2026.2.25 contain an authentication hardening gap in browser-origin WebSocket clients that allows attackers to bypass orig…

Fix: 2026.2.25+
Fix from $1,950 2026-03-19
Openclaw MEDIUM 6.5
CVE-2026-32027

OpenClaw versions prior to 2026.2.26 contain an authorization bypass vulnerability where DM pairing-store identities are incorrectly eligible for gro…

Fix: 2026.2.26+
Fix from $1,600 2026-03-19
Openclaw MEDIUM 5.3
CVE-2026-32028

OpenClaw versions prior to 2026.2.25 fail to enforce dmPolicy and allowFrom authorization checks on Discord direct-message reaction notifications, al…

Fix: 2026.2.25+
Fix from $1,600 2026-03-19
Openclaw HIGH 7.5
CVE-2026-32024

OpenClaw versions prior to 2026.2.22 contain a symlink traversal vulnerability in avatar handling that allows attackers to read arbitrary files outsi…

Fix: 2026.2.22+
Fix from $1,950 2026-03-19
Openclaw HIGH 7.1
CVE-2026-32023

OpenClaw versions prior to 2026.2.24 contain an approval gating bypass vulnerability in system.run allowlist mode where nested transparent dispatch w…

Fix: 2026.2.24+
Fix from $1,950 2026-03-19
Openclaw MEDIUM 6.5
CVE-2026-32021

OpenClaw versions prior to 2026.2.22 contain an authorization bypass vulnerability in the Feishu allowFrom allowlist implementation that accepts muta…

Fix: 2026.2.22+
Fix from $1,600 2026-03-19
Openclaw MEDIUM 6.5
CVE-2026-32022

OpenClaw versions prior to 2026.2.21 contain a stdin-only policy bypass vulnerability in the grep tool within tools.exec.safeBins that allows attacke…

Fix: 2026.2.21+
Fix from $1,600 2026-03-19
Openclaw HIGH 7.8
CVE-2026-32016

OpenClaw versions prior to 2026.2.22 on macOS contain a path validation bypass vulnerability in the exec-approval allowlist mode that allows local at…

Fix: 2026.2.22+
Fix from $1,950 2026-03-19
Openclaw HIGH 7.1
CVE-2026-32017

OpenClaw versions prior to 2026.2.19 contain an allowlist bypass vulnerability in the exec safeBins policy that allows attackers to write arbitrary f…

Fix: 2026.2.19+
Fix from $1,950 2026-03-19
Openclaw MEDIUM 5.5
CVE-2026-32020

OpenClaw versions prior to 2026.2.22 contain a path traversal vulnerability in the static file handler that follows symbolic links, allowing out-of-r…

Fix: 2026.2.22+
Fix from $1,600 2026-03-19
Openclaw MEDIUM 5.3
CVE-2026-32019

OpenClaw versions prior to 2026.2.22 contain incomplete IPv4 special-use range validation in the isPrivateIpv4() function, allowing requests to RFC-r…

Fix: 2026.2.22+
Fix from $1,600 2026-03-19
Openclaw HIGH 8.8
CVE-2026-32013

OpenClaw versions prior to 2026.2.25 contain a symlink traversal vulnerability in the agents.files.get and agents.files.set methods that allows readi…

Fix: 2026.2.25+
Fix from $1,950 2026-03-19
Openclaw HIGH 8.0
CVE-2026-32014

OpenClaw versions prior to 2026.2.26 contain a metadata spoofing vulnerability where reconnect platform and deviceFamily fields are accepted from the…

Fix: 2026.2.26+
Fix from $1,950 2026-03-19
Openclaw HIGH 7.8
CVE-2026-32015

OpenClaw versions 2026.1.21 prior to 2026.2.19 contain a path hijacking vulnerability in tools.exec.safeBins that allows attackers to bypass allowlis…

Fix: 2026.2.19+
Fix from $1,950 2026-03-19
Openclaw HIGH 7.5
CVE-2026-32011

OpenClaw versions prior to 2026.3.2 contain a denial of service vulnerability in webhook handlers for BlueBubbles and Google Chat that parse request …

Fix: 2026.3.2+
Fix from $1,950 2026-03-19
Openclaw HIGH 8.8
CVE-2026-32010

OpenClaw versions prior to 2026.2.22 contain an allowlist bypass vulnerability in the safe-bin configuration when sort is manually added to tools.exe…

Fix: 2026.2.22+
Fix from $1,950 2026-03-19
Openclaw HIGH 8.1
CVE-2026-32007

OpenClaw versions prior to 2026.2.23 contain a path traversal vulnerability in the experimental apply_patch tool that allows attackers with sandbox a…

Fix: 2026.2.23+
Fix from $1,950 2026-03-19
Openclaw HIGH 7.8
CVE-2026-32009

OpenClaw versions prior to 2026.2.24 contain a policy bypass vulnerability in the safeBins allowlist evaluation that trusts static default directorie…

Fix: 2026.2.24+
Fix from $1,950 2026-03-19
Openclaw MEDIUM 6.5
CVE-2026-32008

OpenClaw versions prior to 2026.2.21 contain an improper URL scheme validation vulnerability in the assertBrowserNavigationAllowed() function that al…

Fix: 2026.2.21+
Fix from $1,600 2026-03-19
Openclaw HIGH 8.2
CVE-2026-32004

OpenClaw versions prior to 2026.3.2 contain an authentication bypass vulnerability in the /api/channels route classification due to canonicalization …

Fix: 2026.3.2+
Fix from $1,950 2026-03-19
Openclaw HIGH 8.1
CVE-2026-32005

OpenClaw versions prior to 2026.2.25 fail to enforce sender authorization checks for interactive callbacks including block_action, view_submission, a…

Fix: 2026.2.22+
Fix from $1,950 2026-03-19
Openclaw HIGH 7.2
CVE-2026-32003

OpenClaw versions prior to 2026.2.22 contain an environment variable injection vulnerability in the system.run function that allows attackers to bypa…

Fix: 2026.2.22+
Fix from $1,950 2026-03-19
Openclaw MEDIUM 6.5
CVE-2026-32002

OpenClaw versions prior to 2026.2.23 contain a sandbox bypass vulnerability in the sandboxed image tool that fails to enforce tools.fs.workspaceOnly …

Fix: 2026.2.23+
Fix from $1,600 2026-03-19
Openclaw MEDIUM 5.4
CVE-2026-32001

OpenClaw versions prior to 2026.2.22 contain an authentication bypass vulnerability that allows clients authenticated with a shared gateway token to …

Fix: 2026.2.22+
Fix from $1,600 2026-03-19
Openclaw HIGH 8.6
CVE-2026-31998

OpenClaw versions 2026.2.22 and 2026.2.23 contain an authorization bypass vulnerability in the synology-chat channel plugin where dmPolicy set to all…

Fix: 2026.2.24+
Fix from $1,950 2026-03-19
Openclaw HIGH 7.8
CVE-2026-31999

OpenClaw versions 2026.2.26 prior to 2026.3.1 on Windows contain a current working directory injection vulnerability in wrapper resolution for .cmd/.…

Fix: 2026.3.1+
Fix from $1,950 2026-03-19
Openclaw HIGH 7.1
CVE-2026-32000

OpenClaw versions prior to 2026.2.19 contain a command injection vulnerability in the Lobster extension tool execution that uses Windows shell fallba…

Fix: 2026.2.19+
Fix from $1,950 2026-03-19
Openclaw MEDIUM 6.7
CVE-2026-31997

OpenClaw versions prior to 2026.3.1 fail to pin executable identity for non-path-like argv[0] tokens in system.run approvals, allowing post-approval …

Fix: 2026.3.1+
Fix from $1,600 2026-03-19