Vulnerability index

Browse CVEs

530 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Openclaw HIGH 8.6
CVE-2026-44116

OpenClaw before 2026.4.22 contains a server-side request forgery vulnerability in the Zalo plugin's sendPhoto function that fails to validate outboun…

Fix: 2026.4.22+
Fix from $1,950 2026-05-06
Openclaw HIGH 7.8
CVE-2026-44114

OpenClaw before 2026.4.20 fails to properly reserve the OPENCLAW_ runtime-control environment namespace in workspace dotenv files, allowing attackers…

Fix: 2026.4.20+
Fix from $1,950 2026-05-06
Openclaw HIGH 7.8
CVE-2026-44118

OpenClaw before 2026.4.22 derives loopback MCP owner context from spoofable server-issued bearer tokens in request headers. Non-owner loopback client…

Fix: 2026.4.22+
Fix from $1,950 2026-05-06
Openclaw HIGH 7.7
CVE-2026-44113

OpenClaw before 2026.4.22 contains a time-of-check/time-of-use race condition in the OpenShell filesystem bridge that allows attackers to read files …

Fix: 2026.4.22+
Fix from $1,950 2026-05-06
Openclaw MEDIUM 5.8
CVE-2026-44117

OpenClaw before 2026.4.20 contains a server-side request forgery vulnerability in QQBot direct media upload that skips URL validation. Attackers can …

Fix: 2026.4.20+
Fix from $1,600 2026-05-06
Openclaw CRITICAL 9.8
CVE-2026-43585

OpenClaw before 2026.4.15 captures resolved bearer-auth configuration at startup, allowing revoked tokens to remain valid after SecretRef rotation. G…

Fix: 2026.4.15+
Fix from $2,300 2026-05-06
Openclaw CRITICAL 9.8
CVE-2026-44109

OpenClaw before 2026.4.15 contains an authentication bypass vulnerability in Feishu webhook and card-action validation that allows unauthenticated re…

Fix: 2026.4.15+
Fix from $2,300 2026-05-06
Openclaw HIGH 8.8
CVE-2026-43584

OpenClaw before 2026.4.10 contains an insufficient environment variable denylist vulnerability in its exec environment policy that allows operator-su…

Fix: 2026.4.10+
Fix from $1,950 2026-05-06
Openclaw HIGH 8.8
CVE-2026-44110

OpenClaw before 2026.4.15 contains an authorization bypass vulnerability in Matrix room control-command authorization that trusts DM pairing-store en…

Fix: 2026.4.15+
Fix from $1,950 2026-05-06
Openclaw MEDIUM 6.5
CVE-2026-43583

OpenClaw versions 2026.4.10 before 2026.4.14 fail to persist session context during delivery queue recovery for media replay. Attackers can exploit r…

Fix: 2026.4.14+
Fix from $1,600 2026-05-06
Openclaw MEDIUM 6.3
CVE-2026-43582

OpenClaw before 2026.4.10 contains a server-side request forgery vulnerability in browser navigation policy that allows attackers to bypass hostname …

Fix: 2026.4.10+
Fix from $1,600 2026-05-06
Openclaw CRITICAL 9.8
CVE-2026-43575

OpenClaw versions 2026.2.21 before 2026.4.10 contain an authentication bypass vulnerability in the sandbox noVNC helper route that exposes interactiv…

Fix: 2026.4.10+
Fix from $2,300 2026-05-06
Openclaw CRITICAL 9.6
CVE-2026-43581

OpenClaw before 2026.4.10 contains an improper network binding vulnerability in the sandbox browser CDP relay that exposes Chrome DevTools Protocol o…

Fix: 2026.4.10+
Fix from $2,300 2026-05-06
Openclaw CRITICAL 9.1
CVE-2026-43578

OpenClaw versions 2026.3.31 before 2026.4.10 contain a privilege escalation vulnerability where heartbeat owner downgrade detection misses local back…

Fix: 2026.4.10+
Fix from $2,300 2026-05-06
Openclaw HIGH 7.7
CVE-2026-43576

OpenClaw before 2026.4.5 contains a server-side request forgery vulnerability in the CDP /json/version WebSocket endpoint that allows attackers to pi…

Fix: 2026.4.5+
Fix from $1,950 2026-05-06
Openclaw HIGH 7.7
CVE-2026-43580

OpenClaw before 2026.4.10 contains an incomplete navigation guard vulnerability that allows attackers to trigger navigation without complete SSRF pol…

Fix: 2026.4.10+
Fix from $1,950 2026-05-06
Openclaw MEDIUM 6.5
CVE-2026-43577

OpenClaw before 2026.4.9 contains a file read vulnerability allowing attackers to bypass navigation guards through browser act/evaluate interactions.…

Fix: 2026.4.9+
Fix from $1,600 2026-05-06
Openclaw MEDIUM 6.5
CVE-2026-43579

OpenClaw before 2026.4.10 contains an insufficient access control vulnerability in Nostr plugin HTTP profile routes that allows operators with write …

Fix: 2026.4.10+
Fix from $1,600 2026-05-06
Openclaw HIGH 7.7
CVE-2026-43573

OpenClaw before 2026.4.10 contains a server-side request forgery policy bypass vulnerability in existing-session browser interaction routes. Attacker…

Fix: 2026.4.10+
Fix from $1,950 2026-05-05
Openclaw MEDIUM 6.5
CVE-2026-43574

OpenClaw before 2026.4.12 contains an improper authorization vulnerability in helper-backed channels where empty resolved approver lists are interpre…

Fix: 2026.4.12+
Fix from $1,600 2026-05-05
Openclaw MEDIUM 5.3
CVE-2026-43572

OpenClaw versions 2026.4.10 before 2026.4.14 contain a missing authorization vulnerability in the Microsoft Teams SSO invoke handler that fails to ap…

Fix: 2026.4.14+
Fix from $1,600 2026-05-05
Openclaw CRITICAL 9.8
CVE-2026-43566

OpenClaw versions 2026.4.7 before 2026.4.14 contain a privilege escalation vulnerability where heartbeat owner downgrade logic skips webhook wake eve…

Fix: 2026.4.14+
Fix from $2,300 2026-05-05
Openclaw HIGH 8.8
CVE-2026-43569

OpenClaw before 2026.4.9 contains an authentication bypass vulnerability allowing untrusted workspace plugins to be auto-enabled during non-interacti…

Fix: 2026.4.9+
Fix from $1,950 2026-05-05
Openclaw HIGH 8.8
CVE-2026-43571

OpenClaw before 2026.4.10 contains a plugin trust bypass vulnerability that allows channel setup catalog lookups to resolve workspace plugin shadows …

Fix: 2026.4.10+
Fix from $1,950 2026-05-05
Openclaw MEDIUM 6.5
CVE-2026-43567

OpenClaw before 2026.4.10 contains a path traversal vulnerability in the screen_record tool's outPath parameter that bypasses workspace-only filesyst…

Fix: 2026.4.10+
Fix from $1,600 2026-05-05
Openclaw MEDIUM 6.5
CVE-2026-43568

OpenClaw versions 2026.4.5 before 2026.4.10 contain a privilege escalation vulnerability allowing write-scoped operators to modify persistent memory …

Fix: 2026.4.10+
Fix from $1,600 2026-05-05
Openclaw MEDIUM 6.5
CVE-2026-43570

OpenClaw versions 2026.3.22 before 2026.4.5 contain a symlink traversal vulnerability in remote marketplace repository path handling that allows atta…

Fix: 2026.4.5+
Fix from $1,600 2026-05-05
Openclaw CRITICAL 9.8
CVE-2026-43534

OpenClaw before 2026.4.10 contains an input validation vulnerability that allows external hook metadata to be enqueued as trusted system events. Atta…

Fix: 2026.4.10+
Fix from $2,300 2026-05-05
Openclaw HIGH 8.8
CVE-2026-43530

OpenClaw versions 2026.2.23 before 2026.4.12 contain a weakened exec approval binding vulnerability in busybox and toybox applet execution that allow…

Fix: 2026.4.12+
Fix from $1,950 2026-05-05
Openclaw HIGH 8.8
CVE-2026-43531

OpenClaw before 2026.4.9 contains an environment variable injection vulnerability allowing malicious workspace .env files to set runtime-control vari…

Fix: 2026.4.9+
Fix from $1,950 2026-05-05