Vulnerability index

Browse CVEs

530 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Openclaw HIGH 8.8
CVE-2026-31992

OpenClaw versions prior to 2026.2.23 contain an allowlist bypass vulnerability in system.run guardrails that allows authenticated operators to execut…

Fix: 2026.2.23+
Fix from $1,950 2026-03-19
Openclaw HIGH 7.8
CVE-2026-31994

OpenClaw versions prior to 2026.2.19 contain a local command injection vulnerability in Windows scheduled task script generation due to unsafe handli…

Fix: 2026.2.19+
Fix from $1,950 2026-03-19
Openclaw HIGH 7.0
CVE-2026-31995

OpenClaw versions 2026.1.21 prior to 2026.2.19 contain a command injection vulnerability in the Lobster extension's Windows shell fallback mechanism …

Fix: 2026.2.19+
Fix from $1,950 2026-03-19
Openclaw MEDIUM 6.4
CVE-2026-31993

OpenClaw versions prior to 2026.2.22 contain an allowlist parsing mismatch vulnerability in the macOS companion app that allows authenticated operato…

Fix: 2026.2.22+
Fix from $1,600 2026-03-19
Openclaw HIGH 7.1
CVE-2026-31990

OpenClaw versions prior to 2026.3.2 contain a vulnerability in the stageSandboxMedia function in which it fails to validate destination symlinks duri…

Fix: 2026.3.2+
Fix from $1,950 2026-03-19
Openclaw MEDIUM 6.8
CVE-2026-29607

OpenClaw versions prior to 2026.2.22 contain an authorization bypass vulnerability in allow-always wrapper persistence that allows attackers to bypas…

Fix: 2026.2.22+
Fix from $1,600 2026-03-19
Openclaw MEDIUM 6.7
CVE-2026-29608

OpenClaw 2026.3.1 contains an approval integrity vulnerability in system.run node-host execution where argv rewriting changes command semantics. Atta…

Patch available
Fix from $1,600 2026-03-19
Openclaw MEDIUM 6.3
CVE-2026-31989

OpenClaw versions prior to 2026.3.1 contain a server-side request forgery vulnerability in web_search citation redirect resolution that uses a privat…

Fix: 2026.3.1+
Fix from $1,600 2026-03-19
Openclaw HIGH 7.5
CVE-2026-28461

OpenClaw versions prior to 2026.3.1 contain an unbounded memory growth vulnerability in the Zalo webhook endpoint that allows unauthenticated attacke…

Fix: 2026.3.1+
Fix from $1,950 2026-03-19
Openclaw HIGH 7.1
CVE-2026-28460

OpenClaw versions prior to 2026.2.22 contain an allowlist bypass vulnerability in system.run that allows attackers to execute non-allowlisted command…

Fix: 2026.2.22+
Fix from $1,950 2026-03-19
Openclaw MEDIUM 6.5
CVE-2026-28449

OpenClaw versions prior to 2026.2.25 lack durable replay state for Nextcloud Talk webhook events, allowing valid signed webhook requests to be replay…

Fix: 2026.2.25+
Fix from $1,600 2026-03-19
Openclaw MEDIUM 5.3
CVE-2026-27670

OpenClaw versions prior to 2026.3.2 contain a race condition vulnerability in ZIP extraction that allows local attackers to write files outside the i…

Fix: 2026.3.2+
Fix from $1,600 2026-03-19
Openclaw HIGH 8.8
CVE-2026-27566

OpenClaw versions prior to 2026.2.22 contain an allowlist bypass vulnerability in system.run exec analysis that fails to unwrap env and shell-dispatc…

Fix: 2026.2.22+
Fix from $1,950 2026-03-19
Openclaw HIGH 7.8
CVE-2026-22176

OpenClaw versions prior to 2026.2.19 contain a command injection vulnerability in Windows Scheduled Task script generation where environment variable…

Fix: 2026.2.19+
Fix from $1,950 2026-03-19
Openclaw HIGH 7.5
CVE-2026-27523

OpenClaw versions prior to 2026.2.24 contain a sandbox bind validation vulnerability allowing attackers to bypass allowed-root and blocked-path check…

Fix: 2026.2.24+
Fix from $1,950 2026-03-18
Openclaw MEDIUM 6.1
CVE-2026-22217

OpenClaw version 2026.2.22 prior to 2026.2.23 contains an arbitrary code execution vulnerability in shell-env that allows attackers to execute attack…

Fix: 2026.2.23+
Fix from $1,600 2026-03-18
Openclaw MEDIUM 5.5
CVE-2026-27522

OpenClaw versions prior to 2026.2.24 contain a local media root bypass vulnerability in sendAttachment and setGroupIcon message actions when sandboxR…

Fix: 2026.2.24+
Fix from $1,600 2026-03-18
Openclaw HIGH 8.2
CVE-2026-22178

OpenClaw versions prior to 2026.2.19 construct RegExp objects directly from unescaped Feishu mention metadata in the stripBotMention function, allowi…

Fix: 2026.2.19+
Fix from $1,950 2026-03-18
Openclaw HIGH 7.6
CVE-2026-22181

OpenClaw versions prior to 2026.3.2 contain a DNS pinning bypass vulnerability in strict URL fetch paths that allows attackers to circumvent SSRF gua…

Fix: 2026.3.2+
Fix from $1,950 2026-03-18
Openclaw HIGH 7.2
CVE-2026-22179

OpenClaw versions prior to 2026.2.22 in macOS node-host system.run contain an allowlist bypass vulnerability that allows remote attackers to execute …

Fix: 2026.2.22+
Fix from $1,950 2026-03-18
Openclaw MEDIUM 5.3
CVE-2026-22180

OpenClaw versions prior to 2026.3.2 contain a path-confinement bypass vulnerability in browser output handling that allows writes outside intended ro…

Fix: 2026.3.2+
Fix from $1,600 2026-03-18
Openclaw CRITICAL 9.1
CVE-2026-22171

OpenClaw versions prior to 2026.2.19 contain a path traversal vulnerability in the Feishu media download flow where untrusted media keys are interpol…

Fix: 2026.2.19+
Fix from $2,300 2026-03-18
Openclaw HIGH 8.8
CVE-2026-22177

OpenClaw versions prior to 2026.2.21 fail to filter dangerous process-control environment variables from config env.vars, allowing startup-time code …

Fix: 2026.2.21+
Fix from $1,950 2026-03-18
Openclaw HIGH 7.1
CVE-2026-22175

OpenClaw versions prior to 2026.2.23 contain an exec approval bypass vulnerability in allowlist mode where allow-always grants could be circumvented …

Fix: 2026.2.23+
Fix from $1,950 2026-03-18
Openclaw MEDIUM 6.8
CVE-2026-22174

OpenClaw versions prior to 2026.2.22 inject the x-OpenClaw-relay-token header into Chrome CDP probe traffic on loopback interfaces, allowing local pr…

Fix: 2026.2.22+
Fix from $1,600 2026-03-18
Openclaw MEDIUM 6.5
CVE-2026-22170

OpenClaw versions prior to 2026.2.22 with the optional BlueBubbles plugin contain an access control bypass vulnerability where empty allowFrom config…

Fix: 2026.2.22+
Fix from $1,600 2026-03-18
Openclaw HIGH 8.8
CVE-2026-22168

OpenClaw versions prior to 2026.2.21 contain an approval-integrity mismatch vulnerability in system.run that allows authenticated operators to execut…

Fix: 2026.2.21+
Fix from $1,950 2026-03-18
Openclaw MEDIUM 6.7
CVE-2026-22169

OpenClaw versions prior to 2026.2.22 contain an allowlist bypass vulnerability in the safeBins configuration that allows attackers to invoke external…

Fix: 2026.2.22+
Fix from $1,600 2026-03-18
Openclaw HIGH 8.1
CVE-2026-32302

OpenClaw is a personal AI assistant. Prior to 2026.3.11, browser-originated WebSocket connections could bypass origin validation when gateway.auth.mo…

Fix: 2026.3.11+
Fix from $1,950 2026-03-13
Openclaw HIGH 8.8
CVE-2026-4039

A vulnerability was determined in OpenClaw 2026.2.19-2. This vulnerability affects the function applySkillConfigenvOverrides of the component Skill E…

Fix: 2026.2.21+
Fix from $1,950 2026-03-12