Vulnerability index

Browse CVEs

530 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Openclaw MEDIUM 5.3
CVE-2026-53851

OpenClaw before 2026.5.12 contains a notification bypass vulnerability allowing Slack reaction events to enter the agent pipeline despite disabled re…

Fix: 2026.5.12+
Fix from $1,600 2026-06-16
Openclaw HIGH 8.8
CVE-2026-53843

OpenClaw before 2026.5.26 contains an authorization bypass vulnerability where a surviving pairing-scoped device session can re-establish node token …

Fix: 2026.5.26+
Fix from $1,950 2026-06-16
Openclaw HIGH 7.1
CVE-2026-53842

OpenClaw before 2026.5.2 contains an environment variable injection vulnerability allowing workspace .env files to influence Python runtime selection…

Fix: 2026.5.2+
Fix from $1,950 2026-06-16
Openclaw HIGH 7.1
CVE-2026-53846

OpenClaw before 2026.4.29 contains a path traversal vulnerability in the install helper that allows workspace .env files to override the npm_execpath…

Fix: 2026.4.29+
Fix from $1,950 2026-06-16
Openclaw MEDIUM 6.5
CVE-2026-53844

OpenClaw before 2026.4.29 contains a session visibility check bypass vulnerability in shared memory search that allows authenticated callers to acces…

Fix: 2026.4.29+
Fix from $1,600 2026-06-16
Openclaw MEDIUM 5.4
CVE-2026-53847

OpenClaw before 2026.5.6 contains a privilege escalation vulnerability in the Active Memory write scope that allows Gateway operators with operator.w…

Fix: 2026.5.6+
Fix from $1,600 2026-06-16
Openclaw HIGH 7.1
CVE-2026-53840

OpenClaw before 2026.5.12 contains an information disclosure vulnerability in streamable-http MCP servers that forwards operator-configured custom he…

Fix: 2026.5.12+
Fix from $1,950 2026-06-16
Openclaw MEDIUM 6.1
CVE-2026-53841

OpenClaw before 2026.5.12 contains a cross-site scripting vulnerability in exported session HTML that preserves unsafe javascript: and data: links in…

Fix: 2026.5.12+
Fix from $1,600 2026-06-16
Openclaw CRITICAL 9.8
CVE-2026-53838

OpenClaw before 2026.5.27 contains a state mutation vulnerability in node pairing reconnection that allows paired nodes to confuse approval scope dec…

Fix: 2026.5.27+
Fix from $2,300 2026-06-12
Openclaw HIGH 8.8
CVE-2026-53836

OpenClaw before 2026.5.12 contains an allowlist bypass vulnerability in PowerShell encoded-command handling that allows attackers to execute encoded …

Fix: 2026.5.12+
Fix from $1,950 2026-06-12
Openclaw MEDIUM 6.5
CVE-2026-53834

OpenClaw before 2026.4.27 contains an authorization bypass vulnerability in QQBot pre-dispatch slash commands that allows authenticated senders to sk…

Fix: 2026.4.27+
Fix from $1,600 2026-06-12
Openclaw MEDIUM 6.5
CVE-2026-53839

OpenClaw before 2026.5.7 contains a hostname validation vulnerability in retry endpoint checks that allows matching hostname prefixes instead of exac…

Fix: 2026.5.7+
Fix from $1,600 2026-06-12
Openclaw MEDIUM 5.3
CVE-2026-53837

OpenClaw before 2026.5.6 contains an improper access control vulnerability in Mattermost event handlers that fails to validate channel type metadata.…

Fix: 2026.5.6+
Fix from $1,600 2026-06-12
Openclaw HIGH 8.8
CVE-2026-53828

OpenClaw before 2026.5.6 contains an authorization bypass vulnerability in native command handling that allows authenticated senders to execute owner…

Fix: 2026.5.6+
Fix from $1,950 2026-06-12
Openclaw HIGH 8.1
CVE-2026-53831

OpenClaw before 2026.5.18 contains a policy enforcement vulnerability in system.run safe-bin allowlist validation that allows shell expansion to modi…

Fix: 2026.5.18+
Fix from $1,950 2026-06-12
Openclaw HIGH 8.0
CVE-2026-53829

OpenClaw before 2026.5.18 contains an approval display truncation vulnerability allowing authenticated users to hide command suffixes from approvers.…

Fix: 2026.5.18+
Fix from $1,950 2026-06-12
Openclaw HIGH 7.1
CVE-2026-53832

OpenClaw before 2026.5.18 contains an identity header validation vulnerability allowing local same-host callers to forge trusted-proxy identity heade…

Fix: 2026.5.18+
Fix from $1,950 2026-06-12
Openclaw MEDIUM 6.5
CVE-2026-53827

OpenClaw before 2026.5.2 contains a credential exposure vulnerability in message.action forwarding that allows model-controlled metadata to forward a…

Fix: 2026.5.2+
Fix from $1,600 2026-06-12
Openclaw MEDIUM 6.5
CVE-2026-53830

OpenClaw before 2026.4.22 contains a webhook secret revocation bypass vulnerability allowing callers with old Slack and Zalo webhook secrets to remai…

Fix: 2026.4.22+
Fix from $1,600 2026-06-12
Openclaw MEDIUM 6.5
CVE-2026-53833

OpenClaw before 2026.4.29 contains an authorization bypass vulnerability in the QQBot streaming command that allows authenticated senders to mutate c…

Fix: 2026.4.29+
Fix from $1,600 2026-06-12
Openclaw HIGH 8.8
CVE-2026-53821

OpenClaw before 2026.5.18 accepts WebSocket client-declared operator scopes before binding to server-approved pairing or trusted-proxy authorization …

Fix: 2026.5.18+
Fix from $1,950 2026-06-12
Openclaw HIGH 8.8
CVE-2026-53822

OpenClaw before 2026.5.18 contains a command injection vulnerability where shell wrapper argv could change between approval and execution. Attackers …

Fix: 2026.5.18+
Fix from $1,950 2026-06-12
Openclaw HIGH 8.1
CVE-2026-53823

OpenClaw before 2026.5.3 contains a privilege escalation vulnerability in the allowFrom feature that binds to mutable Slack display names. Attackers …

Fix: 2026.5.3+
Fix from $1,950 2026-06-12
Openclaw MEDIUM 6.6
CVE-2026-53820

OpenClaw before 2026.5.12 contains an exec denylist bypass vulnerability in the bundle MCP loopback session-spawn path that allows authenticated call…

Fix: 2026.5.12+
Fix from $1,600 2026-06-12
Openclaw MEDIUM 6.5
CVE-2026-53824

OpenClaw before 2026.4.24 contains a token revocation vulnerability allowing callers with revoked slash tokens to continue executing commands during …

Fix: 2026.4.24+
Fix from $1,600 2026-06-12
Openclaw MEDIUM 6.5
CVE-2026-53825

OpenClaw before 2026.4.7 contains an arbitrary file read vulnerability in the memory-wiki ingest feature that allows authenticated Gateway operators …

Fix: 2026.4.7+
Fix from $1,600 2026-06-12
Openclaw HIGH 7.8
CVE-2026-53819

OpenClaw before 2026.5.27 contains an arbitrary code execution vulnerability in skill install flows where workspace .env files can override the Homeb…

Fix: 2026.5.27+
Fix from $1,950 2026-06-11
Openclaw MEDIUM 6.6
CVE-2026-53818

OpenClaw before 2026.4.24 contains an authorization bypass vulnerability in the MCP loopback feature that allows non-owner callers to skip owner-only…

Fix: 2026.4.24+
Fix from $1,600 2026-06-11
Openclaw HIGH 8.8
CVE-2026-53810

OpenClaw before 2026.5.18 contains a code execution vulnerability where marketplace runtime extension metadata can redirect loading toward unscanned …

Fix: 2026.5.18+
Fix from $1,950 2026-06-11
Openclaw HIGH 8.8
CVE-2026-53811

OpenClaw before 2026.5.7 contains a privilege escalation vulnerability in the Matrix allowFrom feature that allows authenticated accounts to match po…

Fix: 2026.5.7+
Fix from $1,950 2026-06-11