Vulnerability index

Browse CVEs

530 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Openclaw MEDIUM 5.5
CVE-2026-4040

A vulnerability was identified in OpenClaw up to 2026.2.17. This issue affects the function tools.exec.safeBins of the component File Existence Handl…

Fix: 2026.2.19+
Fix from $1,600 2026-03-12
Openclaw CRITICAL 9.8
CVE-2026-30741

A remote code execution (RCE) vulnerability in OpenClaw Agent Platform v2026.2.6 allows attackers to execute arbitrary code via a Request-Side prompt…

Fix: after 2026.2.6
Fix from $2,300 2026-03-11
Openclaw HIGH 7.8
CVE-2026-32063

OpenClaw version 2026.2.19-2 prior to 2026.2.21 contains a command injection vulnerability in systemd unit file generation where attacker-controlled …

Fix: 2026.2.21+
Fix from $1,950 2026-03-11
Openclaw HIGH 7.5
CVE-2026-32062

OpenClaw versions 2026.2.21-2 up to, but not including, 2026.2.22, and @openclaw/voice-call versions 2026.2.21 up to, but not including, 2026.2.22 ac…

Fix: 2026.2.22+
Fix from $1,950 2026-03-11
Openclaw HIGH 8.8
CVE-2026-32059

OpenClaw version 2026.2.22-2 prior to 2026.2.23 tools.exec.safeBins validation for sort command fails to properly validate GNU long-option abbreviati…

Fix: 2026.2.23+
Fix from $1,950 2026-03-11
Openclaw HIGH 8.8
CVE-2026-32060

OpenClaw versions prior to 2026.2.14 contain a path traversal vulnerability in apply_patch that allows attackers to write or delete files outside the…

Fix: 2026.2.14+
Fix from $1,950 2026-03-11
Openclaw HIGH 8.8
CVE-2026-29610

OpenClaw versions prior to 2026.2.14 contain a command hijacking vulnerability that allows attackers to execute unintended binaries by manipulating P…

Fix: 2026.2.14+
Fix from $1,950 2026-03-05
Openclaw HIGH 7.5
CVE-2026-29609

OpenClaw versions prior to 2026.2.14 contain a denial of service vulnerability in the fetchWithGuard function that allocates entire response payloads…

Fix: 2026.2.14+
Fix from $1,950 2026-03-05
Openclaw HIGH 7.5
CVE-2026-29611

OpenClaw versions prior to 2026.2.14 contain a local file inclusion vulnerability in BlueBubbles extension (must be installed and enabled) media path…

Fix: 2026.2.14+
Fix from $1,950 2026-03-05
Openclaw HIGH 7.5
CVE-2026-29612

OpenClaw versions prior to 2026.2.14 decode base64-backed media inputs into buffers before enforcing decoded-size budget limits, allowing attackers t…

Fix: 2026.2.14+
Fix from $1,950 2026-03-05
Openclaw MEDIUM 5.9
CVE-2026-29613

OpenClaw versions prior to 2026.2.12 contain a vulnerability in the BlueBubbles (optional plugin) webhook handler in which it authenticates requests …

Fix: 2026.2.12+
Fix from $1,600 2026-03-05
Openclaw HIGH 7.8
CVE-2026-28485

OpenClaw versions 2026.1.5 prior to 2026.2.12 fail to enforce mandatory authentication on the /agent/act browser-control HTTP route, allowing unautho…

Fix: 2026.2.12+
Fix from $1,950 2026-03-05
Openclaw HIGH 7.1
CVE-2026-28482

OpenClaw versions prior to 2026.2.12 construct transcript file paths using unsanitized sessionId parameters and sessionFile paths without enforcing d…

Fix: 2026.2.12+
Fix from $1,950 2026-03-05
Openclaw MEDIUM 6.5
CVE-2026-29606

OpenClaw versions prior to 2026.2.14 contain a webhook signature-verification bypass in the voice-call extension that allows unauthenticated requests…

Fix: 2026.2.14+
Fix from $1,600 2026-03-05
Openclaw MEDIUM 5.5
CVE-2026-28486

OpenClaw versions 2026.1.16-2 prior to 2026.2.14 contain a path traversal vulnerability in archive extraction during installation commands that allow…

Fix: 2026.2.14+
Fix from $1,600 2026-03-05
Openclaw CRITICAL 9.1
CVE-2026-28479

OpenClaw versions prior to 2026.2.15 use SHA-1 to hash sandbox identifier cache keys for Docker and browser sandbox configurations, which is deprecat…

Fix: 2026.2.15+
Fix from $2,300 2026-03-05
Openclaw HIGH 7.5
CVE-2026-28478

OpenClaw versions prior to 2026.2.13 contain a denial of service vulnerability in webhook handlers that buffer request bodies without strict byte or …

Fix: 2026.2.13+
Fix from $1,950 2026-03-05
Openclaw HIGH 7.5
CVE-2026-28481

OpenClaw versions 2026.1.30 and earlier, contain an information disclosure vulnerability, patched in 2026.2.1, in the MS Teams attachment downloader …

Fix: after 2026.1.30
Fix from $1,950 2026-03-05
Openclaw HIGH 7.1
CVE-2026-28477

OpenClaw versions prior to 2026.2.14 contain an oauth state validation bypass vulnerability in the manual Chutes login flow that allows attackers to …

Fix: 2026.2.14+
Fix from $1,950 2026-03-05
Openclaw MEDIUM 6.5
CVE-2026-28480

OpenClaw versions prior to 2026.2.14 contain an authorization bypass vulnerability where Telegram allowlist matching accepts mutable usernames instea…

Fix: 2026.2.14+
Fix from $1,600 2026-03-05
Openclaw CRITICAL 9.8
CVE-2026-28472

OpenClaw versions prior to 2026.2.2 contain a vulnerability in the gateway WebSocket connect handshake in which it allows skipping device identity ch…

Fix: 2026.2.2+
Fix from $2,300 2026-03-05
Openclaw CRITICAL 9.8
CVE-2026-28474

OpenClaw's Nextcloud Talk plugin versions prior to 2026.2.6 accept equality matching on the mutable actor.name display name field for allowlist valid…

Fix: 2026.2.6+
Fix from $2,300 2026-03-05
Openclaw HIGH 8.1
CVE-2026-28473

OpenClaw versions prior to 2026.2.2 contain an authorization bypass vulnerability where clients with operator.write scope can approve or deny exec ap…

Fix: 2026.2.2+
Fix from $1,950 2026-03-05
Openclaw MEDIUM 5.8
CVE-2026-28476

OpenClaw versions prior to 2026.2.14 contain a server-side request forgery vulnerability in the optional Tlon Urbit extension that accepts user-provi…

Fix: 2026.2.14+
Fix from $1,600 2026-03-05
Openclaw CRITICAL 9.8
CVE-2026-28470

OpenClaw versions prior to 2026.2.2 contain an exec approvals (must be enabled) allowlist bypass vulnerability that allows attackers to execute arbit…

Fix: 2026.2.2+
Fix from $2,300 2026-03-05
Openclaw HIGH 7.7
CVE-2026-28468

OpenClaw versions 2026.1.29-beta.1 prior to 2026.2.14 contain a vulnerability in the sandbox browser bridge server in which it accepts requests witho…

Fix: 2026.2.14+
Fix from $1,950 2026-03-05
Openclaw HIGH 7.5
CVE-2026-28469

OpenClaw versions prior to 2026.2.14 contain a webhook routing vulnerability in the Google Chat monitor component that allows cross-account policy co…

Fix: 2026.2.14+
Fix from $1,950 2026-03-05
Openclaw MEDIUM 5.3
CVE-2026-28471

OpenClaw version 2026.1.14-1 prior to 2026.2.2, with the Matrix plugin installed and enabled, contain a vulnerability in which DM allowlist matching …

Fix: 2026.2.2+
Fix from $1,600 2026-03-05
Openclaw CRITICAL 9.9
CVE-2026-28466

OpenClaw versions prior to 2026.2.14 contain a vulnerability in the gateway in which it fails to sanitize internal approval fields in node.invoke par…

Fix: 2026.2.14+
Fix from $2,300 2026-03-05
Openclaw HIGH 8.6
CVE-2026-28467

OpenClaw versions prior to 2026.2.2 contain a server-side request forgery vulnerability in attachment and media URL hydration that allows remote atta…

Fix: 2026.2.2+
Fix from $1,950 2026-03-05