Vulnerability index

Browse CVEs

530 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Openclaw HIGH 8.6
CVE-2026-43533

OpenClaw before 2026.4.10 contains an arbitrary file read vulnerability in QQBot media tags that allows attackers to reference host-local paths outsi…

Fix: 2026.4.10+
Fix from $1,950 2026-05-05
Openclaw HIGH 8.1
CVE-2026-43535

OpenClaw before 2026.4.14 contains an authorization context reuse vulnerability in collect-mode queue batches that allows messages from different sen…

Fix: 2026.4.14+
Fix from $1,950 2026-05-05
Openclaw HIGH 7.7
CVE-2026-43532

OpenClaw versions 2026.4.7 before 2026.4.10 fail to normalize Discord event cover image parameters in sandbox media processing. Attackers can bypass …

Fix: 2026.4.10+
Fix from $1,950 2026-05-05
Openclaw CRITICAL 9.3
CVE-2026-43526

OpenClaw before 2026.4.12 contains a server-side request forgery vulnerability in QQBot reply media URL handling that allows attackers to fetch arbit…

Fix: 2026.4.12+
Fix from $2,300 2026-05-05
Openclaw HIGH 8.5
CVE-2026-42439

OpenClaw before 2026.4.10 contains a server-side request forgery policy bypass vulnerability in the browser tabs action select and close routes. Atta…

Fix: 2026.4.10+
Fix from $1,950 2026-05-05
Openclaw HIGH 7.7
CVE-2026-42438

OpenClaw versions 2026.4.9 before 2026.4.10 contain a sender policy bypass vulnerability in the outbound host-media attachment read helper that allow…

Patch available
Fix from $1,950 2026-05-05
Openclaw HIGH 7.7
CVE-2026-43527

OpenClaw before 2026.4.14 contains a server-side request forgery vulnerability in browser SSRF policy that allows private-network navigation by defau…

Fix: 2026.4.14+
Fix from $1,950 2026-05-05
Openclaw MEDIUM 6.5
CVE-2026-43528

OpenClaw before 2026.4.14 contains a redaction bypass vulnerability that allows authenticated gateway clients to receive unredacted secrets through s…

Fix: 2026.4.14+
Fix from $1,600 2026-05-05
Openclaw HIGH 8.1
CVE-2026-42431

OpenClaw before 2026.4.8 contains a security bypass vulnerability in node.invoke(browser.proxy) that allows mutation of persistent browser profiles. …

Fix: 2026.4.8+
Fix from $1,950 2026-04-28
Openclaw HIGH 7.8
CVE-2026-42432

OpenClaw before 2026.4.8 contains a privilege escalation vulnerability allowing previously paired nodes to reconnect with exec-capable commands witho…

Fix: 2026.4.8+
Fix from $1,950 2026-04-28
Openclaw HIGH 8.8
CVE-2026-42426

OpenClaw before 2026.4.8 contains an improper authorization vulnerability where the node.pair.approve method accepts operator.write scope instead of …

Fix: 2026.4.8+
Fix from $1,950 2026-04-28
Openclaw HIGH 7.5
CVE-2026-42423

OpenClaw before 2026.4.8 contains an approval-timeout fallback mechanism that bypasses strictInlineEval explicit-approval requirements on gateway and…

Fix: 2026.4.8+
Fix from $1,950 2026-04-28
Openclaw HIGH 7.1
CVE-2026-42428

OpenClaw versions before 2026.4.8 fail to enforce integrity verification on downloaded plugin archives. Attackers can install malicious or tampered p…

Fix: 2026.4.8+
Fix from $1,950 2026-04-28
Openclaw HIGH 7.1
CVE-2026-42429

OpenClaw before 2026.4.8 contains a privilege escalation vulnerability in the gateway plugin HTTP authentication mechanism that escalates identity-be…

Fix: 2026.4.8+
Fix from $1,950 2026-04-28
Openclaw MEDIUM 6.5
CVE-2026-42430

OpenClaw before 2026.4.8 contains a server-side request forgery vulnerability in Playwright redirect handling that allows attackers to bypass strict …

Fix: 2026.4.8+
Fix from $1,600 2026-04-28
Openclaw MEDIUM 5.3
CVE-2026-42427

OpenClaw before 2026.4.8 contains a remote code execution vulnerability caused by missing environment variable denylist entries for HGRCPATH, CARGO_B…

Fix: 2026.4.8+
Fix from $1,600 2026-04-28
Openclaw MEDIUM 5.0
CVE-2026-42424

OpenClaw before 2026.4.8 treats shared reply MEDIA paths as trusted, allowing crafted references to trigger cross-channel local file exfiltration. At…

Fix: 2026.4.8+
Fix from $1,600 2026-04-28
Openclaw HIGH 8.8
CVE-2026-42422

OpenClaw before 2026.4.8 contains a role bypass vulnerability in the device.token.rotate function that allows minting tokens for unapproved roles. At…

Fix: 2026.4.8+
Fix from $1,950 2026-04-28
Openclaw HIGH 8.5
CVE-2026-41914

OpenClaw before 2026.4.8 contains a server-side request forgery vulnerability in QQ Bot media download paths that bypass SSRF protection. Attackers c…

Fix: 2026.4.8+
Fix from $1,950 2026-04-28
Openclaw MEDIUM 6.5
CVE-2026-42420

OpenClaw before 2026.4.8 contains improper input validation in base64 decode paths that allocate memory before enforcing decoded-size limits. Attacke…

Fix: 2026.4.8+
Fix from $1,600 2026-04-28
Openclaw MEDIUM 6.1
CVE-2026-41915

OpenClaw before 2026.4.8 fails to remove git plumbing environment variables from the execution environment before host exec operations. Attackers can…

Fix: 2026.4.8+
Fix from $1,600 2026-04-28
Openclaw MEDIUM 5.4
CVE-2026-41916

OpenClaw before 2026.4.8 contains an authentication state management vulnerability where the resolvedAuth closure becomes stale after configuration r…

Fix: 2026.4.8+
Fix from $1,600 2026-04-28
Openclaw MEDIUM 5.4
CVE-2026-42421

OpenClaw before 2026.4.8 contains a session management vulnerability where existing WebSocket sessions survive shared gateway token rotation. Attacke…

Fix: 2026.4.8+
Fix from $1,600 2026-04-28
Openclaw HIGH 7.6
CVE-2026-41912

OpenClaw before 2026.4.8 contains a server-side request forgery policy bypass vulnerability allowing attackers to trigger navigations bypassing norma…

Fix: 2026.4.8+
Fix from $1,950 2026-04-28
Openclaw HIGH 7.5
CVE-2026-41405

OpenClaw before 2026.3.31 parses MS Teams webhook request bodies before performing JWT validation, allowing unauthenticated attackers to trigger reso…

Fix: 2026.3.31+
Fix from $1,950 2026-04-28
Openclaw MEDIUM 6.5
CVE-2026-41408

OpenClaw before 2026.3.31 contains a resource exhaustion vulnerability in media downloads that bypasses core safety limits for file size, count, and …

Fix: 2026.3.31+
Fix from $1,600 2026-04-28
Openclaw MEDIUM 6.5
CVE-2026-41911

OpenClaw before 2026.4.8 contains a filesystem policy bypass vulnerability in docx upload processing that allows local file reads outside workspace b…

Fix: 2026.4.8+
Fix from $1,600 2026-04-28
Openclaw MEDIUM 5.4
CVE-2026-41406

OpenClaw before 2026.3.31 contains a sender allowlist bypass vulnerability that allows remote attackers to access restricted messages. Attackers can …

Fix: 2026.3.31+
Fix from $1,600 2026-04-28
Openclaw MEDIUM 5.3
CVE-2026-41407

OpenClaw before 2026.4.2 contains a timing side channel vulnerability in shared-secret comparison call sites that use early length-mismatch checks in…

Fix: 2026.4.2+
Fix from $1,600 2026-04-28
Openclaw CRITICAL 9.6
CVE-2026-41397

OpenClaw before 2026.3.31 contains a sandbox escape vulnerability allowing attackers to traverse directory boundaries through symlink exploitation du…

Fix: 2026.3.31+
Fix from $2,300 2026-04-28