Vulnerability index

Browse CVEs

530 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Openclaw HIGH 8.3
CVE-2026-62195

OpenClaw versions 2026.5.20 before 2026.6.6 contain an authorization bypass vulnerability in the MCP loopback feature that allows lower-trust callers…

Fix: 2026.6.6+
Fix from $1,950 2026-07-13
Openclaw HIGH 8.3
CVE-2026-62196

OpenClaw versions 2026.3.22 before 2026.6.6 contain an authorization bypass vulnerability where WhatsApp group IDs can satisfy elevated sender allowl…

Fix: 2026.6.6+
Fix from $1,950 2026-07-13
Openclaw MEDIUM 5.4
CVE-2026-62198

OpenClaw versions 2026.5.28 before 2026.6.6 contain an authorization bypass vulnerability in native web search that allows lower-trust callers to per…

Fix: 2026.6.6+
Fix from $1,600 2026-07-13
Openclaw HIGH 8.8
CVE-2026-62190

OpenClaw versions before 2026.6.9 contain an authorization bypass vulnerability in the flock wrapper that allows lower-trust callers to execute or pe…

Fix: 2026.6.9+
Fix from $1,950 2026-07-13
Openclaw HIGH 8.8
CVE-2026-62194

OpenClaw versions 2026.5.20 before 2026.6.9 contain a privilege escalation vulnerability in plugin install commands that allows lower-trust callers t…

Fix: 2026.6.9+
Fix from $1,950 2026-07-13
Openclaw HIGH 8.1
CVE-2026-62192

OpenClaw versions 2026.6.6 before 2026.6.9 contain an authorization bypass vulnerability in Discord guild actions that allows lower-trust callers to …

Fix: 2026.6.9+
Fix from $1,950 2026-07-13
Openclaw HIGH 7.1
CVE-2026-62189

OpenClaw versions before 2026.6.9 contain a symlink following vulnerability in the mirror sync feature that allows lower-trust callers to perform act…

Fix: 2026.6.9+
Fix from $1,950 2026-07-13
Openclaw HIGH 7.1
CVE-2026-62191

OpenClaw versions 2026.6.6 before 2026.6.9 contain an authorization bypass vulnerability in message mutation handling that allows lower-trust callers…

Fix: 2026.6.9+
Fix from $1,950 2026-07-13
Openclaw MEDIUM 6.5
CVE-2026-62193

OpenClaw versions 2026.6.5 before 2026.6.9 contain a vulnerability in the plugin install wrappers that could skip the install policy (authorization) …

Fix: 2026.6.9+
Fix from $1,600 2026-07-13
Openclaw\/feishu HIGH 8.1
CVE-2026-62187

OpenClaw Feishu tools (npm package @openclaw/feishu) in versions <= 2026.6.6 could ignore per-account disablement. A lower-trust caller or a configur…

Fix: 2026.6.9+
Fix from $1,950 2026-07-13
Openclaw\/feishu HIGH 8.1
CVE-2026-62188

OpenClaw @openclaw/feishu versions 2026.6.6 and earlier contain an incorrect authorization vulnerability in which the Feishu permission tools could i…

Fix: 2026.6.9+
Fix from $1,950 2026-07-13
Openclaw HIGH 7.6
CVE-2026-62186

OpenClaw versions before 2026.6.8 contain an authorization bypass vulnerability in OpenAI-compatible HTTP model overrides that allows lower-trust cal…

Fix: 2026.6.8+
Fix from $1,950 2026-07-13
Openclaw MEDIUM 6.5
CVE-2026-59261

OpenClaw before 2026.5.28 contains a credential exposure vulnerability where workspace dotenv files can override provider credentials. Attackers with…

Fix: 2026.5.28+
Fix from $1,600 2026-07-08
Openclaw HIGH 8.1
CVE-2026-53866

OpenClaw before 2026.5.12 contains an allowlist bypass vulnerability in shell inline-command parsing that allows authenticated operators to execute u…

Fix: 2026.5.12+
Fix from $1,950 2026-06-16
Openclaw CRITICAL 9.8
CVE-2026-53861

OpenClaw before 2026.5.6 contains an allowlist bypass vulnerability in the macOS Swift exec feature that misses combined POSIX inline-command flags. …

Fix: 2026.5.6+
Fix from $2,300 2026-06-16
Openclaw HIGH 8.1
CVE-2026-53864

OpenClaw before 2026.5.26 contains an insufficient sanitization vulnerability in the host environment sanitizer that allows Node.js control variables…

Fix: 2026.5.26+
Fix from $1,950 2026-06-16
Openclaw HIGH 7.1
CVE-2026-53865

OpenClaw before 2026.5.2 contains a path traversal vulnerability in maintenance task execution that allows workspace-derived service paths to influen…

Fix: 2026.5.26+
Fix from $1,950 2026-06-16
Openclaw MEDIUM 6.5
CVE-2026-53863

OpenClaw before 2026.4.25 contains an input validation vulnerability in tool group policy callers that accept unvalidated group IDs. Attackers who ca…

Fix: 2026.4.25+
Fix from $1,600 2026-06-16
Openclaw MEDIUM 5.4
CVE-2026-53862

OpenClaw before 2026.5.12 contains a bootstrap token replay vulnerability allowing callers with pending token access to reuse tokens with broader req…

Fix: 2026.5.12+
Fix from $1,600 2026-06-16
Openclaw HIGH 8.1
CVE-2026-53857

OpenClaw before 2026.5.3 contains a policy enforcement vulnerability where Zalo contacts with mutable display metadata could match allowFrom policy e…

Fix: 2026.5.3+
Fix from $1,950 2026-06-16
Openclaw HIGH 7.1
CVE-2026-53858

OpenClaw before 2026.5.2 contains an environment variable injection vulnerability where workspace .env STATE_DIRECTORY could influence bundled runtim…

Fix: 2026.5.2+
Fix from $1,950 2026-06-16
Openclaw MEDIUM 6.5
CVE-2026-53859

OpenClaw before 2026.5.26 contains a hostname validation vulnerability allowing attackers to bypass blocklist comparisons using trailing-dot notation…

Fix: 2026.5.26+
Fix from $1,600 2026-06-16
Openclaw MEDIUM 5.5
CVE-2026-53856

OpenClaw 2026.4.23 before 2026.4.24 contains an insecure file permissions vulnerability in config recovery that restores OpenClaw.json with overly br…

Mitigation only
Fix from $1,600 2026-06-16
Openclaw MEDIUM 5.4
CVE-2026-53860

OpenClaw before 2026.5.7 contains a sender policy bypass vulnerability in BlueBubbles that allows participants to match allowlist entries through con…

Fix: 2026.5.7+
Fix from $1,600 2026-06-16
Openclaw HIGH 8.3
CVE-2026-53853

OpenClaw before 2026.5.12 contains an argument pattern validation bypass in the exec allowlist that allows attackers to execute disallowed arguments …

Fix: 2026.5.12+
Fix from $1,950 2026-06-16
Openclaw HIGH 8.1
CVE-2026-53849

OpenClaw before 2026.5.7 contains a privilege escalation vulnerability where the allowFrom feature improperly validates Discord account identity usin…

Fix: 2026.5.7+
Fix from $1,950 2026-06-16
Openclaw HIGH 8.1
CVE-2026-53855

OpenClaw before 2026.4.2 contains an inline-eval bypass vulnerability allowing authenticated operators to weaken strict allowlist checks via shell po…

Fix: 2026.4.2+
Fix from $1,950 2026-06-16
Openclaw MEDIUM 6.5
CVE-2026-53854

OpenClaw before 2026.4.25 contains a privilege escalation vulnerability in internal and webchat command authentication that allows senders to inherit…

Fix: 2026.4.25+
Fix from $1,600 2026-06-16
Openclaw MEDIUM 5.5
CVE-2026-53850

OpenClaw before 2026.4.25 contains a control scope enforcement bypass vulnerability in the focus command that allows authenticated callers to execute…

Fix: 2026.4.25+
Fix from $1,600 2026-06-16
Openclaw MEDIUM 5.4
CVE-2026-53852

OpenClaw before 2026.4.25 contains a scope containment bypass vulnerability in device re-pairing that allows authenticated operators to restore broad…

Fix: 2026.4.25+
Fix from $1,600 2026-06-16