Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 8.8
CVE-2026-32920
OpenClaw before 2026.3.12 automatically discovers and loads plugins from .OpenClaw/extensions/ without explicit trust verification, allowing arbitrar…
Openclaw
2026.3.12+
MEDIUM 5.0
CVE-2026-32921
OpenClaw before 2026.3.8 contains an approval bypass vulnerability in system.run where mutable script operands are not bound across approval and exec…
Openclaw
2026.3.8+
HIGH 7.5
CVE-2026-33575
OpenClaw before 2026.3.12 embeds long-lived shared gateway credentials directly in pairing setup codes generated by /pair endpoint and OpenClaw qr co…
Openclaw
2026.3.12+
CRITICAL 9.8
CVE-2026-32987
OpenClaw before 2026.3.13 allows bootstrap setup codes to be replayed during device pairing verification in src/infra/device-bootstrap.ts. Attackers …
Openclaw
2026.3.13+
HIGH 8.8
CVE-2026-33573
OpenClaw before 2026.3.11 contains an authorization bypass vulnerability in the gateway agent RPC that allows authenticated operators with operator.w…
Openclaw
2026.3.11+
HIGH 7.5
CVE-2026-32980
OpenClaw before 2026.3.13 reads and buffers Telegram webhook request bodies before validating the x-telegram-bot-api-secret-token header, allowing un…
Openclaw
2026.3.13+
MEDIUM 6.7
CVE-2026-32979
OpenClaw before 2026.3.11 contains an approval integrity vulnerability allowing attackers to execute rewritten local code by modifying scripts betwee…
Openclaw
2026.3.11+
MEDIUM 5.5
CVE-2026-33572
OpenClaw before 2026.2.17 creates session transcript JSONL files with overly broad default permissions, allowing local users to read transcript conte…
Openclaw
2026.2.17+
CRITICAL 9.8
CVE-2026-32973
OpenClaw before 2026.3.11 contains an exec allowlist bypass vulnerability where matchesExecAllowlistPattern improperly normalizes patterns with lower…
Openclaw
2026.3.11+
CRITICAL 9.8
CVE-2026-32974
OpenClaw before 2026.3.12 contains an authentication bypass vulnerability in Feishu webhook mode when only verificationToken is configured without en…
Openclaw
2026.3.12+
CRITICAL 9.8
CVE-2026-32975
OpenClaw before 2026.3.12 contains a weak authorization vulnerability in Zalouser allowlist mode that matches mutable group display names instead of …
Openclaw
2026.3.12+
HIGH 7.5
CVE-2026-32978
OpenClaw before 2026.3.11 contains an approval integrity vulnerability where system.run approvals fail to bind mutable file operands for certain scri…
Openclaw
2026.3.11+
HIGH 7.1
CVE-2026-32972
OpenClaw before 2026.3.11 contains an authorization bypass vulnerability allowing authenticated operators with only operator.write permission to acce…
Openclaw
2026.3.11+
CRITICAL 9.9
CVE-2026-32922
OpenClaw before 2026.3.11 contains a privilege escalation vulnerability in device.token.rotate that allows callers with operator.pairing scope to min…
Openclaw
2026.3.11+
CRITICAL 9.8
CVE-2026-32924
OpenClaw before 2026.3.12 contains an authorization bypass vulnerability where Feishu reaction events with omitted chat_type are misclassified as p2p…
Openclaw
2026.3.12+
HIGH 8.4
CVE-2026-32918
OpenClaw before 2026.3.11 contains a session sandbox escape vulnerability in the session_status tool that allows sandboxed subagents to access parent…
Openclaw
2026.3.11+
MEDIUM 6.1
CVE-2026-32919
OpenClaw before 2026.3.11 contains an authorization bypass vulnerability allowing write-scoped callers to reach admin-only session reset logic. Attac…
Openclaw
2026.3.11+
MEDIUM 5.4
CVE-2026-32923
OpenClaw before 2026.3.11 contains an authorization bypass vulnerability in Discord guild reaction ingestion that fails to enforce member users and r…
Openclaw
2026.3.11+
HIGH 8.8
CVE-2026-32914
OpenClaw before 2026.3.12 contains an insufficient access control vulnerability in the /config and /debug command handlers that allows command-author…
Openclaw
2026.3.12+
HIGH 8.8
CVE-2026-32915
OpenClaw before 2026.3.11 contains a sandbox boundary bypass vulnerability allowing leaf subagents to access the subagents control surface and resolv…
Openclaw
2026.3.11+
HIGH 7.5
CVE-2026-32846
OpenClaw before 2026.3.28 contains a path traversal vulnerability in media parsing that allows attackers to read arbitrary files by bypassing path va…
Openclaw
after 2026.3.23
CRITICAL 9.1
CVE-2026-32913
OpenClaw before 2026.3.7 contains an improper header validation vulnerability in fetchWithSsrFGuard that forwards custom authorization headers across…
Openclaw
2026.3.7+
MEDIUM 6.1
CVE-2026-27646
OpenClaw versions prior to 2026.3.7 contain a sandbox escape vulnerability in the /acp spawn command that allows authorized sandboxed sessions to ini…
Openclaw
2026.3.7+
MEDIUM 5.3
CVE-2026-27183
OpenClaw versions prior to 2026.3.7 contain a shell approval gating bypass vulnerability in system.run dispatch-wrapper handling that allows attacker…
Openclaw
2026.3.7+
HIGH 8.1
CVE-2026-32067
OpenClaw versions prior to 2026.2.26 contain an authorization bypass vulnerability in the pairing-store access control for direct message pairing pol…
Openclaw
2026.2.26+
MEDIUM 6.5
CVE-2026-32896
The BlueBubbles webhook handler in OpenClaw versions prior to 2026.2.21 contains a passwordless fallback authentication path that allows unauthentica…
Openclaw
2026.2.21+
MEDIUM 5.4
CVE-2026-32895
OpenClaw versions prior to 2026.2.26 fail to enforce sender authorization in member and message subtype system event handlers, allowing unauthorized …
Openclaw
2026.2.26+
MEDIUM 5.4
CVE-2026-32898
OpenClaw versions prior to 2026.2.23 contain an authorization bypass vulnerability in the ACP client that auto-approves tool calls based on untrusted…
Openclaw
2026.2.23+
MEDIUM 5.3
CVE-2026-32897
OpenClaw versions prior to 2026.2.22 reuse gateway.auth.token as a fallback hash secret for owner-ID prompt obfuscation when commands.ownerDisplay is…
Openclaw
2026.2.22+
CRITICAL 9.8
CVE-2026-32056
OpenClaw versions prior to 2026.2.22 fail to sanitize shell startup environment variables HOME and ZDOTDIR in the system.run function, allowing attac…
Openclaw
2026.2.22+