Vulnerability index

Browse CVEs

530 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.3 CVE-2026-32029 OpenClaw versions prior to 2026.2.21 improperly parse the left-most X-Forwarded-For header value when requests originate from configured trusted prox… Openclaw 2026.2.21+ Fix from $1,6002026-03-19 HIGH 8.6 CVE-2026-32026 OpenClaw versions prior to 2026.2.24 contain an improper path validation vulnerability in sandbox media handling that allows absolute paths under the… Openclaw 2026.2.24+ Fix from $1,9502026-03-19 HIGH 7.5 CVE-2026-32025 OpenClaw versions prior to 2026.2.25 contain an authentication hardening gap in browser-origin WebSocket clients that allows attackers to bypass orig… Openclaw 2026.2.25+ Fix from $1,9502026-03-19 MEDIUM 6.5 CVE-2026-32027 OpenClaw versions prior to 2026.2.26 contain an authorization bypass vulnerability where DM pairing-store identities are incorrectly eligible for gro… Openclaw 2026.2.26+ Fix from $1,6002026-03-19 MEDIUM 5.3 CVE-2026-32028 OpenClaw versions prior to 2026.2.25 fail to enforce dmPolicy and allowFrom authorization checks on Discord direct-message reaction notifications, al… Openclaw 2026.2.25+ Fix from $1,6002026-03-19 HIGH 7.5 CVE-2026-32024 OpenClaw versions prior to 2026.2.22 contain a symlink traversal vulnerability in avatar handling that allows attackers to read arbitrary files outsi… Openclaw 2026.2.22+ Fix from $1,9502026-03-19 HIGH 7.1 CVE-2026-32023 OpenClaw versions prior to 2026.2.24 contain an approval gating bypass vulnerability in system.run allowlist mode where nested transparent dispatch w… Openclaw 2026.2.24+ Fix from $1,9502026-03-19 MEDIUM 6.5 CVE-2026-32021 OpenClaw versions prior to 2026.2.22 contain an authorization bypass vulnerability in the Feishu allowFrom allowlist implementation that accepts muta… Openclaw 2026.2.22+ Fix from $1,6002026-03-19 MEDIUM 6.5 CVE-2026-32022 OpenClaw versions prior to 2026.2.21 contain a stdin-only policy bypass vulnerability in the grep tool within tools.exec.safeBins that allows attacke… Openclaw 2026.2.21+ Fix from $1,6002026-03-19 HIGH 7.8 CVE-2026-32016 OpenClaw versions prior to 2026.2.22 on macOS contain a path validation bypass vulnerability in the exec-approval allowlist mode that allows local at… Openclaw 2026.2.22+ Fix from $1,9502026-03-19 HIGH 7.1 CVE-2026-32017 OpenClaw versions prior to 2026.2.19 contain an allowlist bypass vulnerability in the exec safeBins policy that allows attackers to write arbitrary f… Openclaw 2026.2.19+ Fix from $1,9502026-03-19 MEDIUM 5.5 CVE-2026-32020 OpenClaw versions prior to 2026.2.22 contain a path traversal vulnerability in the static file handler that follows symbolic links, allowing out-of-r… Openclaw 2026.2.22+ Fix from $1,6002026-03-19 MEDIUM 5.3 CVE-2026-32019 OpenClaw versions prior to 2026.2.22 contain incomplete IPv4 special-use range validation in the isPrivateIpv4() function, allowing requests to RFC-r… Openclaw 2026.2.22+ Fix from $1,6002026-03-19 HIGH 8.8 CVE-2026-32013 OpenClaw versions prior to 2026.2.25 contain a symlink traversal vulnerability in the agents.files.get and agents.files.set methods that allows readi… Openclaw 2026.2.25+ Fix from $1,9502026-03-19 HIGH 8.0 CVE-2026-32014 OpenClaw versions prior to 2026.2.26 contain a metadata spoofing vulnerability where reconnect platform and deviceFamily fields are accepted from the… Openclaw 2026.2.26+ Fix from $1,9502026-03-19 HIGH 7.8 CVE-2026-32015 OpenClaw versions 2026.1.21 prior to 2026.2.19 contain a path hijacking vulnerability in tools.exec.safeBins that allows attackers to bypass allowlis… Openclaw 2026.2.19+ Fix from $1,9502026-03-19 HIGH 7.5 CVE-2026-32011 OpenClaw versions prior to 2026.3.2 contain a denial of service vulnerability in webhook handlers for BlueBubbles and Google Chat that parse request … Openclaw 2026.3.2+ Fix from $1,9502026-03-19 HIGH 8.8 CVE-2026-32010 OpenClaw versions prior to 2026.2.22 contain an allowlist bypass vulnerability in the safe-bin configuration when sort is manually added to tools.exe… Openclaw 2026.2.22+ Fix from $1,9502026-03-19 HIGH 8.1 CVE-2026-32007 OpenClaw versions prior to 2026.2.23 contain a path traversal vulnerability in the experimental apply_patch tool that allows attackers with sandbox a… Openclaw 2026.2.23+ Fix from $1,9502026-03-19 HIGH 7.8 CVE-2026-32009 OpenClaw versions prior to 2026.2.24 contain a policy bypass vulnerability in the safeBins allowlist evaluation that trusts static default directorie… Openclaw 2026.2.24+ Fix from $1,9502026-03-19 MEDIUM 6.5 CVE-2026-32008 OpenClaw versions prior to 2026.2.21 contain an improper URL scheme validation vulnerability in the assertBrowserNavigationAllowed() function that al… Openclaw 2026.2.21+ Fix from $1,6002026-03-19 HIGH 8.2 CVE-2026-32004 OpenClaw versions prior to 2026.3.2 contain an authentication bypass vulnerability in the /api/channels route classification due to canonicalization … Openclaw 2026.3.2+ Fix from $1,9502026-03-19 HIGH 8.1 CVE-2026-32005 OpenClaw versions prior to 2026.2.25 fail to enforce sender authorization checks for interactive callbacks including block_action, view_submission, a… Openclaw 2026.2.22+ Fix from $1,9502026-03-19 HIGH 7.2 CVE-2026-32003 OpenClaw versions prior to 2026.2.22 contain an environment variable injection vulnerability in the system.run function that allows attackers to bypa… Openclaw 2026.2.22+ Fix from $1,9502026-03-19 MEDIUM 6.5 CVE-2026-32002 OpenClaw versions prior to 2026.2.23 contain a sandbox bypass vulnerability in the sandboxed image tool that fails to enforce tools.fs.workspaceOnly … Openclaw 2026.2.23+ Fix from $1,6002026-03-19 MEDIUM 5.4 CVE-2026-32001 OpenClaw versions prior to 2026.2.22 contain an authentication bypass vulnerability that allows clients authenticated with a shared gateway token to … Openclaw 2026.2.22+ Fix from $1,6002026-03-19 HIGH 8.6 CVE-2026-31998 OpenClaw versions 2026.2.22 and 2026.2.23 contain an authorization bypass vulnerability in the synology-chat channel plugin where dmPolicy set to all… Openclaw 2026.2.24+ Fix from $1,9502026-03-19 HIGH 7.8 CVE-2026-31999 OpenClaw versions 2026.2.26 prior to 2026.3.1 on Windows contain a current working directory injection vulnerability in wrapper resolution for .cmd/.… Openclaw 2026.3.1+ Fix from $1,9502026-03-19 HIGH 7.1 CVE-2026-32000 OpenClaw versions prior to 2026.2.19 contain a command injection vulnerability in the Lobster extension tool execution that uses Windows shell fallba… Openclaw 2026.2.19+ Fix from $1,9502026-03-19 MEDIUM 6.7 CVE-2026-31997 OpenClaw versions prior to 2026.3.1 fail to pin executable identity for non-path-like argv[0] tokens in system.run approvals, allowing post-approval … Openclaw 2026.3.1+ Fix from $1,6002026-03-19