Vulnerability index

Browse CVEs

530 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Openclaw HIGH 8.1
CVE-2026-41364

OpenClaw before 2026.3.31 contains a symlink following vulnerability in SSH sandbox tar upload that allows remote attackers to write arbitrary files.…

Fix: 2026.3.31+
Fix from $1,950 2026-04-28
Openclaw MEDIUM 6.5
CVE-2026-41363

OpenClaw versions 2026.2.6 through 2026.3.24 contain a path traversal vulnerability in the Feishu extension resolveUploadInput function that bypasses…

Fix: 2026.3.28+
Fix from $1,600 2026-04-28
Openclaw MEDIUM 5.5
CVE-2026-41366

OpenClaw before 2026.3.31 contains a local roots self-whitelisting vulnerability in appendLocalMediaParentRoots that allows model-initiated arbitrary…

Fix: 2026.3.31+
Fix from $1,600 2026-04-28
Openclaw MEDIUM 5.4
CVE-2026-41365

OpenClaw before 2026.3.31 contains a sender allowlist bypass vulnerability in MS Teams thread history fetched via Graph API. Attackers can retrieve t…

Fix: 2026.3.31+
Fix from $1,600 2026-04-28
Openclaw MEDIUM 5.0
CVE-2026-41367

OpenClaw versions 2026.2.14 through 2026.3.24 fail to consistently apply guild and channel policy gates to Discord button and component interactions.…

Fix: 2026.3.28+
Fix from $1,600 2026-04-28
Openclaw HIGH 8.8
CVE-2026-41359

OpenClaw before 2026.3.28 contains a privilege escalation vulnerability allowing authenticated operators with write permissions to access admin-class…

Fix: 2026.3.28+
Fix from $1,950 2026-04-23
Openclaw HIGH 7.1
CVE-2026-41361

OpenClaw before 2026.3.28 contains an SSRF guard bypass vulnerability that fails to block four IPv6 special-use ranges. Attackers can exploit this by…

Fix: 2026.3.28+
Fix from $1,950 2026-04-23
Openclaw MEDIUM 6.7
CVE-2026-41360

OpenClaw before 2026.4.2 contains an approval integrity vulnerability in pnpm dlx that fails to bind local script operands consistently with pnpm exe…

Fix: 2026.4.2+
Fix from $1,600 2026-04-23
Openclaw MEDIUM 5.4
CVE-2026-41356

OpenClaw before 2026.3.31 fails to terminate active WebSocket sessions when rotating device tokens. Attackers with previously compromised credentials…

Fix: 2026.3.31+
Fix from $1,600 2026-04-23
Openclaw MEDIUM 5.4
CVE-2026-41358

OpenClaw before 2026.4.2 fails to filter Slack thread context by sender allowlist, allowing non-allowlisted messages to enter agent context. Attacker…

Fix: 2026.4.2+
Fix from $1,600 2026-04-23
Openclaw HIGH 8.8
CVE-2026-41352

OpenClaw before 2026.3.31 contains a remote code execution vulnerability where a device-paired node can bypass the node scope gate authentication mec…

Fix: 2026.3.31+
Fix from $1,950 2026-04-23
Openclaw HIGH 8.1
CVE-2026-41353

OpenClaw before 2026.3.22 contains an access control bypass vulnerability in the allowProfiles feature that allows attackers to circumvent profile re…

Fix: 2026.3.22+
Fix from $1,950 2026-04-23
Openclaw HIGH 7.3
CVE-2026-41355

OpenClaw before 2026.3.28 contains an arbitrary code execution vulnerability in mirror mode that converts untrusted sandbox files into workspace hook…

Fix: 2026.3.28+
Fix from $1,950 2026-04-23
Openclaw MEDIUM 5.3
CVE-2026-41351

OpenClaw before 2026.3.31 contains a replay detection bypass vulnerability in webhook signature handling that treats Base64 and Base64URL encoded sig…

Fix: 2026.3.31+
Fix from $1,600 2026-04-23
Openclaw MEDIUM 5.3
CVE-2026-41354

OpenClaw before 2026.4.2 contains an insufficient scope vulnerability in Zalo webhook replay dedupe keys that allows legitimate events from different…

Fix: 2026.4.2+
Fix from $1,600 2026-04-23
Openclaw HIGH 8.8
CVE-2026-41349

OpenClaw before 2026.3.28 contains an agentic consent bypass vulnerability allowing LLM agents to silently disable execution approval via config.patc…

Fix: 2026.3.28+
Fix from $1,950 2026-04-23
Openclaw HIGH 7.5
CVE-2026-41346

OpenClaw 2026.2.26 before 2026.3.31 enforces pending pairing-request caps per channel file instead of per account, allowing attackers to exhaust the …

Fix: 2026.3.31+
Fix from $1,950 2026-04-23
Openclaw HIGH 7.1
CVE-2026-41347

OpenClaw before 2026.3.31 lacks browser-origin validation in HTTP operator endpoints when operating in trusted-proxy mode, allowing cross-site reques…

Fix: 2026.3.31+
Fix from $1,950 2026-04-23
Openclaw MEDIUM 5.4
CVE-2026-41348

OpenClaw before 2026.3.31 contains an authorization bypass vulnerability in Discord slash command and autocomplete paths that fail to enforce group D…

Fix: 2026.3.31+
Fix from $1,600 2026-04-23
Openclaw MEDIUM 5.3
CVE-2026-41345

OpenClaw before 2026.3.31 contains a credential exposure vulnerability in media download functionality that forwards Authorization headers across cro…

Fix: 2026.3.31+
Fix from $1,600 2026-04-23
Openclaw HIGH 8.8
CVE-2026-41344

OpenClaw before 2026.3.28 contains a privilege escalation vulnerability in the chat.send endpoint that allows write-scoped gateway callers to persist…

Fix: 2026.3.28+
Fix from $1,950 2026-04-23
Openclaw HIGH 8.1
CVE-2026-41342

OpenClaw before 2026.3.28 contains an authentication bypass vulnerability in the remote onboarding component that persists unauthenticated discovery …

Fix: 2026.3.28+
Fix from $1,950 2026-04-23
Openclaw MEDIUM 6.5
CVE-2026-41340

OpenClaw before 2026.3.31 contains an authentication boundary vulnerability where Telegram legacy allowFrom migration incorrectly fans default-accoun…

Fix: 2026.3.31+
Fix from $1,600 2026-04-23
Openclaw MEDIUM 5.4
CVE-2026-41341

OpenClaw before 2026.3.31 contains a logic error in Discord component interaction routing that misclassifies group direct messages as direct messages…

Fix: 2026.3.31+
Fix from $1,600 2026-04-23
Openclaw MEDIUM 5.3
CVE-2026-41343

OpenClaw before 2026.3.31 lacks a shared pre-auth concurrency budget on the public LINE webhook path, allowing attackers to cause transient availabil…

Fix: 2026.3.31+
Fix from $1,600 2026-04-23
Openclaw HIGH 7.8
CVE-2026-41336

OpenClaw before 2026.3.31 allows workspace .env files to override the OPENCLAW_BUNDLED_HOOKS_DIR environment variable, enabling loading of attacker-c…

Fix: 2026.3.31+
Fix from $1,950 2026-04-23
Openclaw MEDIUM 6.5
CVE-2026-41334

OpenClaw before 2026.3.31 contains a decompression bomb vulnerability in image processing that fails to properly enforce pixel-limit guards on sips. …

Fix: 2026.3.31+
Fix from $1,600 2026-04-23
Openclaw MEDIUM 5.3
CVE-2026-41335

OpenClaw before 2026.3.31 contains an information disclosure vulnerability in the Control Interface bootstrap JSON that exposes version and assistant…

Fix: 2026.3.31+
Fix from $1,600 2026-04-23
Openclaw MEDIUM 5.3
CVE-2026-41337

OpenClaw before 2026.3.31 contains a callback origin mutation vulnerability in Plivo voice-call replay that allows attackers to mutate in-process cal…

Fix: 2026.3.31+
Fix from $1,600 2026-04-23
Openclaw MEDIUM 5.0
CVE-2026-41338

OpenClaw before 2026.3.31 contains a time-of-check-time-of-use vulnerability in sandbox file operations that allows attackers to bypass fd-based defe…

Fix: 2026.3.31+
Fix from $1,600 2026-04-23