Vulnerability index

Browse CVEs

530 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Openclaw HIGH 8.8
CVE-2026-53817

OpenClaw before 2026.5.22 contains a locality validation vulnerability in Control UI pairing that allows attackers with network access to spoof local…

Fix: 2026.5.22+
Fix from $1,950 2026-06-11
Openclaw HIGH 8.3
CVE-2026-53814

OpenClaw before 2026.5.20 contains a privilege escalation vulnerability where hook-triggered agent runs incorrectly receive owner-scoped MCP loopback…

Fix: 2026.5.20+
Fix from $1,950 2026-06-11
Openclaw HIGH 7.8
CVE-2026-53813

OpenClaw before 2026.4.25 contains a path traversal vulnerability in memory-core artifact loading where workspace state influences local package root…

Fix: 2026.4.25+
Fix from $1,950 2026-06-11
Openclaw HIGH 7.7
CVE-2026-53812

OpenClaw before 2026.5.18 contains a server-side request forgery vulnerability in browser control that allows authenticated users to bypass private-n…

Fix: 2026.5.18+
Fix from $1,950 2026-06-11
Openclaw HIGH 7.2
CVE-2026-53816

OpenClaw before 2026.5.18 contains an insufficient provenance validation vulnerability in node event handling that allows paired nodes to forge exec …

Fix: 2026.5.18+
Fix from $1,950 2026-06-11
Openclaw MEDIUM 6.5
CVE-2026-53815

OpenClaw before 2026.5.19 contains an authorization bypass vulnerability in message read actions that skips channel allowlist checks. Lower-trust cal…

Fix: 2026.5.19+
Fix from $1,600 2026-06-11
Openclaw HIGH 8.8
CVE-2026-53806

OpenClaw before 2026.5.12 contains a shell option parsing vulnerability that allows combined POSIX shell flags to bypass exec revalidation checks. At…

Fix: 2026.5.12+
Fix from $1,950 2026-06-11
Openclaw HIGH 8.8
CVE-2026-53807

OpenClaw before 2026.5.6 contains an authorization bypass vulnerability in Telegram interactive callbacks that allows authenticated users to skip com…

Fix: 2026.5.6+
Fix from $1,950 2026-06-11
Openclaw MEDIUM 6.5
CVE-2026-53808

OpenClaw before 2026.5.6 contains an approval policy bypass vulnerability in the Skill Workshop apply flow that allows agent tool calls to set apply:…

Fix: 2026.5.6+
Fix from $1,600 2026-06-11
Openclaw HIGH 8.8
CVE-2026-35674

OpenClaw before 2026.5.18 contains a scope bypass vulnerability in the Gateway chat.send route that allows scoped clients to execute privileged comma…

Fix: 2026.5.18+
Fix from $1,950 2026-05-29
Openclaw HIGH 8.0
CVE-2026-35630

OpenClaw before 2026.5.18 contains an authorization bypass vulnerability in QQBot native approval buttons that fails to enforce configured approver i…

Fix: 2026.5.18+
Fix from $1,950 2026-05-29
Openclaw MEDIUM 6.5
CVE-2026-35673

OpenClaw before 2026.4.29 contains an SSRF policy bypass vulnerability in browser debug and export routes that allows reuse of already-open blocked t…

Fix: 2026.4.29+
Fix from $1,600 2026-05-29
Openclaw HIGH 8.3
CVE-2026-32905

OpenClaw before 2026.5.4 contains an authorization bypass vulnerability in the bundled device-pair plugin that allows non-owner authorized chat sende…

Fix: 2026.5.4+
Fix from $1,950 2026-05-29
Openclaw MEDIUM 5.4
CVE-2026-34507

OpenClaw before 2026.4.29 contains a policy bypass vulnerability in QQBot admin commands that allows authenticated senders to skip DM-only and allowF…

Fix: 2026.4.29+
Fix from $1,600 2026-05-29
Openclaw CRITICAL 9.8
CVE-2026-8305

A vulnerability was detected in OpenClaw up to 2026.1.24. The impacted element is the function handleBlueBubblesWebhookRequest of the file extensions…

Fix: 2026.2.12+
Fix from $2,300 2026-05-11
Openclaw HIGH 8.8
CVE-2026-45006

OpenClaw before 2026.4.23 contains an improper access control vulnerability in the gateway tool's config.apply and config.patch operations that allow…

Fix: 2026.4.23+
Fix from $1,950 2026-05-11
Openclaw HIGH 7.8
CVE-2026-45004

OpenClaw before 2026.4.23 contains an arbitrary code execution vulnerability in the bundled plugin setup resolver that loads setup-api.js from proces…

Fix: 2026.4.23+
Fix from $1,950 2026-05-11
Openclaw HIGH 7.1
CVE-2026-45001

OpenClaw before 2026.4.20 contains a guard bypass vulnerability in the agent-facing gateway config.patch and config.apply endpoints that fails to pro…

Fix: 2026.4.20+
Fix from $1,950 2026-05-11
Openclaw MEDIUM 6.0
CVE-2026-45005

OpenClaw before 2026.4.23 caches resolved webhook route secrets backed by SecretRef values, allowing stale secrets to remain valid after rotation and…

Fix: 2026.4.23+
Fix from $1,600 2026-05-11
Openclaw MEDIUM 5.3
CVE-2026-45002

OpenClaw before 2026.4.20 contains a hook session-key bypass vulnerability that allows attackers to circumvent the hooks.allowRequestSessionKey opt-i…

Fix: 2026.4.20+
Fix from $1,600 2026-05-11
Openclaw MEDIUM 5.0
CVE-2026-45000

OpenClaw before 2026.4.20 contains a server-side request forgery vulnerability in browser CDP profile creation that skips strict-mode SSRF policy che…

Fix: 2026.4.20+
Fix from $1,600 2026-05-11
Openclaw MEDIUM 5.0
CVE-2026-45003

OpenClaw before 2026.4.22 allows workspace dotenv files to override connector endpoint hosts for Matrix, Mattermost, IRC, and Synology connectors. At…

Fix: 2026.4.22+
Fix from $1,600 2026-05-11
Openclaw HIGH 7.3
CVE-2026-44995

OpenClaw before 2026.4.20 contains an improper environment variable validation vulnerability in MCP stdio server configuration that allows attackers …

Fix: 2026.4.20+
Fix from $1,950 2026-05-11
Openclaw MEDIUM 5.4
CVE-2026-44993

OpenClaw before 2026.4.20 contains a message classification vulnerability in Feishu card-action callbacks that misclassifies direct messages as group…

Fix: 2026.4.20+
Fix from $1,600 2026-05-11
Openclaw MEDIUM 5.4
CVE-2026-44998

OpenClaw before 2026.4.20 contains a tool policy bypass vulnerability allowing bundled MCP and LSP tools to circumvent configured tool restrictions. …

Fix: 2026.4.20+
Fix from $1,600 2026-05-11
Openclaw MEDIUM 5.3
CVE-2026-44994

OpenClaw before 2026.4.22 contains an authentication bypass vulnerability in the Control UI bootstrap config endpoint that allows unauthenticated att…

Fix: 2026.4.22+
Fix from $1,600 2026-05-11
Openclaw MEDIUM 5.3
CVE-2026-44999

OpenClaw before 2026.4.20 fails to properly preserve untrusted labels for isolated cron awareness events, allowing webhook-triggered cron agent outpu…

Fix: 2026.4.20+
Fix from $1,600 2026-05-11
Openclaw MEDIUM 5.0
CVE-2026-44992

OpenClaw versions 2026.4.5 before 2026.4.20 contain an environment variable injection vulnerability allowing workspace dotenv to override MINIMAX_API…

Fix: 2026.4.20+
Fix from $1,600 2026-05-11
Openclaw CRITICAL 9.6
CVE-2026-44112

OpenClaw before 2026.4.22 contains a time-of-check/time-of-use race condition in OpenShell sandbox filesystem writes that allows attackers to redirec…

Fix: 2026.4.22+
Fix from $2,300 2026-05-06
Openclaw HIGH 8.8
CVE-2026-44115

OpenClaw before 2026.4.22 contains an exec allowlist analysis vulnerability allowing shell expansion hiding in unquoted heredoc bodies. Attackers can…

Fix: 2026.4.22+
Fix from $1,950 2026-05-06