Vulnerability index

Browse CVEs

530 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.5 CVE-2026-4040 A vulnerability was identified in OpenClaw up to 2026.2.17. This issue affects the function tools.exec.safeBins of the component File Existence Handl… Openclaw 2026.2.19+ Fix from $1,6002026-03-12 CRITICAL 9.8 CVE-2026-30741 A remote code execution (RCE) vulnerability in OpenClaw Agent Platform v2026.2.6 allows attackers to execute arbitrary code via a Request-Side prompt… Openclaw after 2026.2.6 Fix from $2,3002026-03-11 HIGH 7.8 CVE-2026-32063 OpenClaw version 2026.2.19-2 prior to 2026.2.21 contains a command injection vulnerability in systemd unit file generation where attacker-controlled … Openclaw 2026.2.21+ Fix from $1,9502026-03-11 HIGH 7.5 CVE-2026-32062 OpenClaw versions 2026.2.21-2 up to, but not including, 2026.2.22, and @openclaw/voice-call versions 2026.2.21 up to, but not including, 2026.2.22 ac… Openclaw 2026.2.22+ Fix from $1,9502026-03-11 HIGH 8.8 CVE-2026-32059 OpenClaw version 2026.2.22-2 prior to 2026.2.23 tools.exec.safeBins validation for sort command fails to properly validate GNU long-option abbreviati… Openclaw 2026.2.23+ Fix from $1,9502026-03-11 HIGH 8.8 CVE-2026-32060 OpenClaw versions prior to 2026.2.14 contain a path traversal vulnerability in apply_patch that allows attackers to write or delete files outside the… Openclaw 2026.2.14+ Fix from $1,9502026-03-11 HIGH 8.8 CVE-2026-29610 OpenClaw versions prior to 2026.2.14 contain a command hijacking vulnerability that allows attackers to execute unintended binaries by manipulating P… Openclaw 2026.2.14+ Fix from $1,9502026-03-05 HIGH 7.5 CVE-2026-29609 OpenClaw versions prior to 2026.2.14 contain a denial of service vulnerability in the fetchWithGuard function that allocates entire response payloads… Openclaw 2026.2.14+ Fix from $1,9502026-03-05 HIGH 7.5 CVE-2026-29611 OpenClaw versions prior to 2026.2.14 contain a local file inclusion vulnerability in BlueBubbles extension (must be installed and enabled) media path… Openclaw 2026.2.14+ Fix from $1,9502026-03-05 HIGH 7.5 CVE-2026-29612 OpenClaw versions prior to 2026.2.14 decode base64-backed media inputs into buffers before enforcing decoded-size budget limits, allowing attackers t… Openclaw 2026.2.14+ Fix from $1,9502026-03-05 MEDIUM 5.9 CVE-2026-29613 OpenClaw versions prior to 2026.2.12 contain a vulnerability in the BlueBubbles (optional plugin) webhook handler in which it authenticates requests … Openclaw 2026.2.12+ Fix from $1,6002026-03-05 HIGH 7.8 CVE-2026-28485 OpenClaw versions 2026.1.5 prior to 2026.2.12 fail to enforce mandatory authentication on the /agent/act browser-control HTTP route, allowing unautho… Openclaw 2026.2.12+ Fix from $1,9502026-03-05 HIGH 7.1 CVE-2026-28482 OpenClaw versions prior to 2026.2.12 construct transcript file paths using unsanitized sessionId parameters and sessionFile paths without enforcing d… Openclaw 2026.2.12+ Fix from $1,9502026-03-05 MEDIUM 6.5 CVE-2026-29606 OpenClaw versions prior to 2026.2.14 contain a webhook signature-verification bypass in the voice-call extension that allows unauthenticated requests… Openclaw 2026.2.14+ Fix from $1,6002026-03-05 MEDIUM 5.5 CVE-2026-28486 OpenClaw versions 2026.1.16-2 prior to 2026.2.14 contain a path traversal vulnerability in archive extraction during installation commands that allow… Openclaw 2026.2.14+ Fix from $1,6002026-03-05 CRITICAL 9.1 CVE-2026-28479 OpenClaw versions prior to 2026.2.15 use SHA-1 to hash sandbox identifier cache keys for Docker and browser sandbox configurations, which is deprecat… Openclaw 2026.2.15+ Fix from $2,3002026-03-05 HIGH 7.5 CVE-2026-28478 OpenClaw versions prior to 2026.2.13 contain a denial of service vulnerability in webhook handlers that buffer request bodies without strict byte or … Openclaw 2026.2.13+ Fix from $1,9502026-03-05 HIGH 7.5 CVE-2026-28481 OpenClaw versions 2026.1.30 and earlier, contain an information disclosure vulnerability, patched in 2026.2.1, in the MS Teams attachment downloader … Openclaw after 2026.1.30 Fix from $1,9502026-03-05 HIGH 7.1 CVE-2026-28477 OpenClaw versions prior to 2026.2.14 contain an oauth state validation bypass vulnerability in the manual Chutes login flow that allows attackers to … Openclaw 2026.2.14+ Fix from $1,9502026-03-05 MEDIUM 6.5 CVE-2026-28480 OpenClaw versions prior to 2026.2.14 contain an authorization bypass vulnerability where Telegram allowlist matching accepts mutable usernames instea… Openclaw 2026.2.14+ Fix from $1,6002026-03-05 CRITICAL 9.8 CVE-2026-28472 OpenClaw versions prior to 2026.2.2 contain a vulnerability in the gateway WebSocket connect handshake in which it allows skipping device identity ch… Openclaw 2026.2.2+ Fix from $2,3002026-03-05 CRITICAL 9.8 CVE-2026-28474 OpenClaw's Nextcloud Talk plugin versions prior to 2026.2.6 accept equality matching on the mutable actor.name display name field for allowlist valid… Openclaw 2026.2.6+ Fix from $2,3002026-03-05 HIGH 8.1 CVE-2026-28473 OpenClaw versions prior to 2026.2.2 contain an authorization bypass vulnerability where clients with operator.write scope can approve or deny exec ap… Openclaw 2026.2.2+ Fix from $1,9502026-03-05 MEDIUM 5.8 CVE-2026-28476 OpenClaw versions prior to 2026.2.14 contain a server-side request forgery vulnerability in the optional Tlon Urbit extension that accepts user-provi… Openclaw 2026.2.14+ Fix from $1,6002026-03-05 CRITICAL 9.8 CVE-2026-28470 OpenClaw versions prior to 2026.2.2 contain an exec approvals (must be enabled) allowlist bypass vulnerability that allows attackers to execute arbit… Openclaw 2026.2.2+ Fix from $2,3002026-03-05 HIGH 7.7 CVE-2026-28468 OpenClaw versions 2026.1.29-beta.1 prior to 2026.2.14 contain a vulnerability in the sandbox browser bridge server in which it accepts requests witho… Openclaw 2026.2.14+ Fix from $1,9502026-03-05 HIGH 7.5 CVE-2026-28469 OpenClaw versions prior to 2026.2.14 contain a webhook routing vulnerability in the Google Chat monitor component that allows cross-account policy co… Openclaw 2026.2.14+ Fix from $1,9502026-03-05 MEDIUM 5.3 CVE-2026-28471 OpenClaw version 2026.1.14-1 prior to 2026.2.2, with the Matrix plugin installed and enabled, contain a vulnerability in which DM allowlist matching … Openclaw 2026.2.2+ Fix from $1,6002026-03-05 CRITICAL 9.9 CVE-2026-28466 OpenClaw versions prior to 2026.2.14 contain a vulnerability in the gateway in which it fails to sanitize internal approval fields in node.invoke par… Openclaw 2026.2.14+ Fix from $2,3002026-03-05 HIGH 8.6 CVE-2026-28467 OpenClaw versions prior to 2026.2.2 contain a server-side request forgery vulnerability in attachment and media URL hydration that allows remote atta… Openclaw 2026.2.2+ Fix from $1,9502026-03-05