Vulnerability index

Browse CVEs

530 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Openclaw HIGH 7.5
CVE-2026-28464

OpenClaw versions prior to 2026.2.12 use non-constant-time string comparison for hook token validation, allowing attackers to infer tokens through ti…

Fix: 2026.2.12+
Fix from $1,950 2026-03-05
Openclaw HIGH 7.5
CVE-2026-28465

OpenClaw's voice-call plugin versions before 2026.2.3 contain an improper authentication vulnerability in webhook verification that allows remote att…

Fix: 2026.2.3+
Fix from $1,950 2026-03-05
Openclaw MEDIUM 5.5
CVE-2026-28463

OpenClaw versions prior to 2026.2.14 contain an arbitrary file read vulnerability in the exec-approvals allowlist validation that checks pre-expansio…

Fix: 2026.2.14+
Fix from $1,600 2026-03-05
Openclaw CRITICAL 9.1
CVE-2026-28462

OpenClaw versions prior to 2026.2.13 contain a vulnerability in the browser control API in which it accepts user-supplied output paths for trace and …

Fix: 2026.2.13+
Fix from $2,300 2026-03-05
Openclaw HIGH 8.1
CVE-2026-28459

OpenClaw versions prior to 2026.2.12 fail to validate the sessionFile path parameter, allowing authenticated gateway clients to write transcript data…

Fix: 2026.2.12+
Fix from $1,950 2026-03-05
Openclaw HIGH 7.9
CVE-2026-28457

OpenClaw versions prior to 2026.2.14 contain a path traversal vulnerability in sandbox skill mirroring (must be enabled) that uses the skill frontmat…

Fix: 2026.2.14+
Fix from $1,950 2026-03-05
Openclaw HIGH 7.2
CVE-2026-28456

OpenClaw versions 2026.1.5 prior to 2026.2.14 contain a vulnerability in the Gateway in which it does not sufficiently constrain configured hook modu…

Fix: 2026.2.14+
Fix from $1,950 2026-03-05
Openclaw MEDIUM 5.4
CVE-2026-28458

OpenClaw version 2026.1.20 prior to 2026.2.1 contains a vulnerability in the Browser Relay (extension must be installed and enabled) /cdp WebSocket e…

Fix: 2026.2.1+
Fix from $1,600 2026-03-05
Openclaw CRITICAL 9.8
CVE-2026-28453

OpenClaw versions prior to 2026.2.14 fail to validate TAR archive entry paths during extraction, allowing path traversal sequences to write files out…

Fix: 2026.2.14+
Fix from $2,300 2026-03-05
Openclaw CRITICAL 9.8
CVE-2026-28454

OpenClaw versions prior to 2026.2.2 fail to validate webhook secrets in Telegram webhook mode (must be enabled), allowing unauthenticated HTTP POST r…

Fix: 2026.2.2+
Fix from $2,300 2026-03-05
Openclaw CRITICAL 9.3
CVE-2026-28451

OpenClaw versions prior to 2026.2.14 contain server-side request forgery vulnerabilities in the Feishu extension that allow attackers to fetch attack…

Fix: 2026.2.14+
Fix from $2,300 2026-03-05
Openclaw HIGH 8.2
CVE-2026-28450

OpenClaw versions prior to 2026.2.12 with the optional Nostr plugin enabled expose unauthenticated HTTP endpoints at /api/channels/nostr/:accountId/p…

Fix: 2026.2.12+
Fix from $1,950 2026-03-05
Openclaw MEDIUM 6.5
CVE-2026-28452

OpenClaw versions prior to 2026.2.14 contain a denial of service vulnerability in the extractArchive function within src/infra/archive.ts that allows…

Fix: 2026.2.14+
Fix from $1,600 2026-03-05
Openclaw CRITICAL 9.8
CVE-2026-28446

OpenClaw versions prior to 2026.2.1 with the voice-call extension installed and enabled contain an authentication bypass vulnerability in inbound all…

Fix: 2026.2.2+
Fix from $2,300 2026-03-05
Openclaw CRITICAL 9.4
CVE-2026-28448

OpenClaw versions 2026.1.29 prior to 2026.2.1 contain a vulnerability in the Twitch plugin (must be installed and enabled) in which it fails to enfor…

Fix: 2026.2.1+
Fix from $2,300 2026-03-05
Openclaw CRITICAL 9.1
CVE-2026-28395

OpenClaw version 2026.1.14-1 prior to 2026.2.12 contains an improper network binding vulnerability in the Chrome extension (must be installed and ena…

Fix: 2026.2.12+
Fix from $2,300 2026-03-05
Openclaw MEDIUM 6.5
CVE-2026-28447

OpenClaw versions 2026.1.29-beta.1 prior to 2026.2.1 contain a path traversal vulnerability in plugin installation that allows malicious plugin packa…

Fix: 2026.2.1+
Fix from $1,600 2026-03-05
Openclaw CRITICAL 9.8
CVE-2026-28391

OpenClaw versions prior to 2026.2.2 fail to properly validate Windows cmd.exe metacharacters in allowlist-gated exec requests (non-default configurat…

Fix: 2026.2.2+
Fix from $2,300 2026-03-05
Openclaw CRITICAL 9.8
CVE-2026-28392

OpenClaw versions prior to 2026.2.14 contain a privilege escalation vulnerability in the Slack slash-command handler that incorrectly authorizes any …

Fix: 2026.2.14+
Fix from $2,300 2026-03-05
Openclaw CRITICAL 9.8
CVE-2026-28393

OpenClaw versions 2.0.0-beta3 prior to 2026.2.14 contain a path traversal vulnerability in hook transform module loading that allows arbitrary JavaSc…

Fix: 2026.2.14+
Fix from $2,300 2026-03-05
Openclaw MEDIUM 6.5
CVE-2026-28394

OpenClaw versions prior to 2026.2.15 contain a denial of service vulnerability in the web_fetch tool that allows attackers to crash the Gateway proce…

Fix: 2026.2.15+
Fix from $1,600 2026-03-05
Openclaw HIGH 8.8
CVE-2026-28363

In OpenClaw before 2026.2.23, tools.exec.safeBins validation for sort could be bypassed via GNU long-option abbreviations (such as --compress-prog) i…

Fix: 2026.2.23+
Fix from $1,950 2026-02-27
Openclaw HIGH 8.0
CVE-2026-27487

OpenClaw is a personal AI assistant. In versions 2026.2.13 and below, when using macOS, the Claude CLI keychain credential refresh path constructed a…

Fix: 2026.2.14+
Fix from $1,950 2026-02-21
Openclaw HIGH 7.3
CVE-2026-27488

OpenClaw is a personal AI assistant. In versions 2026.2.17 and below, Cron webhook delivery in src/gateway/server-cron.ts uses fetch() directly, so w…

Fix: after 2026.2.17
Fix from $1,950 2026-02-21
Openclaw MEDIUM 5.3
CVE-2026-27486

OpenClaw is a personal AI assistant. In versions 2026.2.13 and below of the OpenClaw CLI, the process cleanup uses system-wide process enumeration an…

Fix: 2026.2.14+
Fix from $1,600 2026-02-21
Openclaw MEDIUM 6.7
CVE-2026-27008

OpenClaw is a personal AI assistant. Prior to version 2026.2.15, a bug in `download` skill installation allowed `targetDir` values from skill frontma…

Fix: 2026.2.15+
Fix from $1,600 2026-02-20
Openclaw MEDIUM 5.8
CVE-2026-27009

OpenClaw is a personal AI assistant. Prior to version 2026.2.15, a atored XSS issue in the OpenClaw Control UI when rendering assistant identity (nam…

Fix: 2026.2.15+
Fix from $1,600 2026-02-20
Openclaw MEDIUM 5.5
CVE-2026-27004

OpenClaw is a personal AI assistant. Prior to version 2026.2.15, in some shared-agent deployments, OpenClaw session tools (`sessions_list`, `sessions…

Fix: 2026.2.15+
Fix from $1,600 2026-02-20
Openclaw CRITICAL 9.8
CVE-2026-27002

OpenClaw is a personal AI assistant. Prior to version 2026.2.15, a configuration injection issue in the Docker tool sandbox could allow dangerous Doc…

Fix: 2026.2.15+
Fix from $2,300 2026-02-20
Openclaw HIGH 7.8
CVE-2026-27001

OpenClaw is a personal AI assistant. Prior to version 2026.2.15, OpenClaw embedded the current working directory (workspace path) into the agent syst…

Fix: 2026.2.15+
Fix from $1,950 2026-02-20