Vulnerability index

Browse CVEs

530 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.8 CVE-2026-32920 OpenClaw before 2026.3.12 automatically discovers and loads plugins from .OpenClaw/extensions/ without explicit trust verification, allowing arbitrar… Openclaw 2026.3.12+ Fix from $1,9502026-03-31 MEDIUM 5.0 CVE-2026-32921 OpenClaw before 2026.3.8 contains an approval bypass vulnerability in system.run where mutable script operands are not bound across approval and exec… Openclaw 2026.3.8+ Fix from $1,6002026-03-31 HIGH 7.5 CVE-2026-33575 OpenClaw before 2026.3.12 embeds long-lived shared gateway credentials directly in pairing setup codes generated by /pair endpoint and OpenClaw qr co… Openclaw 2026.3.12+ Fix from $1,9502026-03-29 CRITICAL 9.8 CVE-2026-32987 OpenClaw before 2026.3.13 allows bootstrap setup codes to be replayed during device pairing verification in src/infra/device-bootstrap.ts. Attackers … Openclaw 2026.3.13+ Fix from $2,3002026-03-29 HIGH 8.8 CVE-2026-33573 OpenClaw before 2026.3.11 contains an authorization bypass vulnerability in the gateway agent RPC that allows authenticated operators with operator.w… Openclaw 2026.3.11+ Fix from $1,9502026-03-29 HIGH 7.5 CVE-2026-32980 OpenClaw before 2026.3.13 reads and buffers Telegram webhook request bodies before validating the x-telegram-bot-api-secret-token header, allowing un… Openclaw 2026.3.13+ Fix from $1,9502026-03-29 MEDIUM 6.7 CVE-2026-32979 OpenClaw before 2026.3.11 contains an approval integrity vulnerability allowing attackers to execute rewritten local code by modifying scripts betwee… Openclaw 2026.3.11+ Fix from $1,6002026-03-29 MEDIUM 5.5 CVE-2026-33572 OpenClaw before 2026.2.17 creates session transcript JSONL files with overly broad default permissions, allowing local users to read transcript conte… Openclaw 2026.2.17+ Fix from $1,6002026-03-29 CRITICAL 9.8 CVE-2026-32973 OpenClaw before 2026.3.11 contains an exec allowlist bypass vulnerability where matchesExecAllowlistPattern improperly normalizes patterns with lower… Openclaw 2026.3.11+ Fix from $2,3002026-03-29 CRITICAL 9.8 CVE-2026-32974 OpenClaw before 2026.3.12 contains an authentication bypass vulnerability in Feishu webhook mode when only verificationToken is configured without en… Openclaw 2026.3.12+ Fix from $2,3002026-03-29 CRITICAL 9.8 CVE-2026-32975 OpenClaw before 2026.3.12 contains a weak authorization vulnerability in Zalouser allowlist mode that matches mutable group display names instead of … Openclaw 2026.3.12+ Fix from $2,3002026-03-29 HIGH 7.5 CVE-2026-32978 OpenClaw before 2026.3.11 contains an approval integrity vulnerability where system.run approvals fail to bind mutable file operands for certain scri… Openclaw 2026.3.11+ Fix from $1,9502026-03-29 HIGH 7.1 CVE-2026-32972 OpenClaw before 2026.3.11 contains an authorization bypass vulnerability allowing authenticated operators with only operator.write permission to acce… Openclaw 2026.3.11+ Fix from $1,9502026-03-29 CRITICAL 9.9 CVE-2026-32922 OpenClaw before 2026.3.11 contains a privilege escalation vulnerability in device.token.rotate that allows callers with operator.pairing scope to min… Openclaw 2026.3.11+ Fix from $2,3002026-03-29 CRITICAL 9.8 CVE-2026-32924 OpenClaw before 2026.3.12 contains an authorization bypass vulnerability where Feishu reaction events with omitted chat_type are misclassified as p2p… Openclaw 2026.3.12+ Fix from $2,3002026-03-29 HIGH 8.4 CVE-2026-32918 OpenClaw before 2026.3.11 contains a session sandbox escape vulnerability in the session_status tool that allows sandboxed subagents to access parent… Openclaw 2026.3.11+ Fix from $1,9502026-03-29 MEDIUM 6.1 CVE-2026-32919 OpenClaw before 2026.3.11 contains an authorization bypass vulnerability allowing write-scoped callers to reach admin-only session reset logic. Attac… Openclaw 2026.3.11+ Fix from $1,6002026-03-29 MEDIUM 5.4 CVE-2026-32923 OpenClaw before 2026.3.11 contains an authorization bypass vulnerability in Discord guild reaction ingestion that fails to enforce member users and r… Openclaw 2026.3.11+ Fix from $1,6002026-03-29 HIGH 8.8 CVE-2026-32914 OpenClaw before 2026.3.12 contains an insufficient access control vulnerability in the /config and /debug command handlers that allows command-author… Openclaw 2026.3.12+ Fix from $1,9502026-03-29 HIGH 8.8 CVE-2026-32915 OpenClaw before 2026.3.11 contains a sandbox boundary bypass vulnerability allowing leaf subagents to access the subagents control surface and resolv… Openclaw 2026.3.11+ Fix from $1,9502026-03-29 HIGH 7.5 CVE-2026-32846 OpenClaw before 2026.3.28 contains a path traversal vulnerability in media parsing that allows attackers to read arbitrary files by bypassing path va… Openclaw after 2026.3.23 Fix from $1,9502026-03-26 CRITICAL 9.1 CVE-2026-32913 OpenClaw before 2026.3.7 contains an improper header validation vulnerability in fetchWithSsrFGuard that forwards custom authorization headers across… Openclaw 2026.3.7+ Fix from $2,3002026-03-23 MEDIUM 6.1 CVE-2026-27646 OpenClaw versions prior to 2026.3.7 contain a sandbox escape vulnerability in the /acp spawn command that allows authorized sandboxed sessions to ini… Openclaw 2026.3.7+ Fix from $1,6002026-03-23 MEDIUM 5.3 CVE-2026-27183 OpenClaw versions prior to 2026.3.7 contain a shell approval gating bypass vulnerability in system.run dispatch-wrapper handling that allows attacker… Openclaw 2026.3.7+ Fix from $1,6002026-03-23 HIGH 8.1 CVE-2026-32067 OpenClaw versions prior to 2026.2.26 contain an authorization bypass vulnerability in the pairing-store access control for direct message pairing pol… Openclaw 2026.2.26+ Fix from $1,9502026-03-21 MEDIUM 6.5 CVE-2026-32896 The BlueBubbles webhook handler in OpenClaw versions prior to 2026.2.21 contains a passwordless fallback authentication path that allows unauthentica… Openclaw 2026.2.21+ Fix from $1,6002026-03-21 MEDIUM 5.4 CVE-2026-32895 OpenClaw versions prior to 2026.2.26 fail to enforce sender authorization in member and message subtype system event handlers, allowing unauthorized … Openclaw 2026.2.26+ Fix from $1,6002026-03-21 MEDIUM 5.4 CVE-2026-32898 OpenClaw versions prior to 2026.2.23 contain an authorization bypass vulnerability in the ACP client that auto-approves tool calls based on untrusted… Openclaw 2026.2.23+ Fix from $1,6002026-03-21 MEDIUM 5.3 CVE-2026-32897 OpenClaw versions prior to 2026.2.22 reuse gateway.auth.token as a fallback hash secret for owner-ID prompt obfuscation when commands.ownerDisplay is… Openclaw 2026.2.22+ Fix from $1,6002026-03-21 CRITICAL 9.8 CVE-2026-32056 OpenClaw versions prior to 2026.2.22 fail to sanitize shell startup environment variables HOME and ZDOTDIR in the system.run function, allowing attac… Openclaw 2026.2.22+ Fix from $2,3002026-03-21