Vulnerability index

Browse CVEs

530 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2026-28464 OpenClaw versions prior to 2026.2.12 use non-constant-time string comparison for hook token validation, allowing attackers to infer tokens through ti… Openclaw 2026.2.12+ Fix from $1,9502026-03-05 HIGH 7.5 CVE-2026-28465 OpenClaw's voice-call plugin versions before 2026.2.3 contain an improper authentication vulnerability in webhook verification that allows remote att… Openclaw 2026.2.3+ Fix from $1,9502026-03-05 MEDIUM 5.5 CVE-2026-28463 OpenClaw versions prior to 2026.2.14 contain an arbitrary file read vulnerability in the exec-approvals allowlist validation that checks pre-expansio… Openclaw 2026.2.14+ Fix from $1,6002026-03-05 CRITICAL 9.1 CVE-2026-28462 OpenClaw versions prior to 2026.2.13 contain a vulnerability in the browser control API in which it accepts user-supplied output paths for trace and … Openclaw 2026.2.13+ Fix from $2,3002026-03-05 HIGH 8.1 CVE-2026-28459 OpenClaw versions prior to 2026.2.12 fail to validate the sessionFile path parameter, allowing authenticated gateway clients to write transcript data… Openclaw 2026.2.12+ Fix from $1,9502026-03-05 HIGH 7.9 CVE-2026-28457 OpenClaw versions prior to 2026.2.14 contain a path traversal vulnerability in sandbox skill mirroring (must be enabled) that uses the skill frontmat… Openclaw 2026.2.14+ Fix from $1,9502026-03-05 HIGH 7.2 CVE-2026-28456 OpenClaw versions 2026.1.5 prior to 2026.2.14 contain a vulnerability in the Gateway in which it does not sufficiently constrain configured hook modu… Openclaw 2026.2.14+ Fix from $1,9502026-03-05 MEDIUM 5.4 CVE-2026-28458 OpenClaw version 2026.1.20 prior to 2026.2.1 contains a vulnerability in the Browser Relay (extension must be installed and enabled) /cdp WebSocket e… Openclaw 2026.2.1+ Fix from $1,6002026-03-05 CRITICAL 9.8 CVE-2026-28453 OpenClaw versions prior to 2026.2.14 fail to validate TAR archive entry paths during extraction, allowing path traversal sequences to write files out… Openclaw 2026.2.14+ Fix from $2,3002026-03-05 CRITICAL 9.8 CVE-2026-28454 OpenClaw versions prior to 2026.2.2 fail to validate webhook secrets in Telegram webhook mode (must be enabled), allowing unauthenticated HTTP POST r… Openclaw 2026.2.2+ Fix from $2,3002026-03-05 CRITICAL 9.3 CVE-2026-28451 OpenClaw versions prior to 2026.2.14 contain server-side request forgery vulnerabilities in the Feishu extension that allow attackers to fetch attack… Openclaw 2026.2.14+ Fix from $2,3002026-03-05 HIGH 8.2 CVE-2026-28450 OpenClaw versions prior to 2026.2.12 with the optional Nostr plugin enabled expose unauthenticated HTTP endpoints at /api/channels/nostr/:accountId/p… Openclaw 2026.2.12+ Fix from $1,9502026-03-05 MEDIUM 6.5 CVE-2026-28452 OpenClaw versions prior to 2026.2.14 contain a denial of service vulnerability in the extractArchive function within src/infra/archive.ts that allows… Openclaw 2026.2.14+ Fix from $1,6002026-03-05 CRITICAL 9.8 CVE-2026-28446 OpenClaw versions prior to 2026.2.1 with the voice-call extension installed and enabled contain an authentication bypass vulnerability in inbound all… Openclaw 2026.2.2+ Fix from $2,3002026-03-05 CRITICAL 9.4 CVE-2026-28448 OpenClaw versions 2026.1.29 prior to 2026.2.1 contain a vulnerability in the Twitch plugin (must be installed and enabled) in which it fails to enfor… Openclaw 2026.2.1+ Fix from $2,3002026-03-05 CRITICAL 9.1 CVE-2026-28395 OpenClaw version 2026.1.14-1 prior to 2026.2.12 contains an improper network binding vulnerability in the Chrome extension (must be installed and ena… Openclaw 2026.2.12+ Fix from $2,3002026-03-05 MEDIUM 6.5 CVE-2026-28447 OpenClaw versions 2026.1.29-beta.1 prior to 2026.2.1 contain a path traversal vulnerability in plugin installation that allows malicious plugin packa… Openclaw 2026.2.1+ Fix from $1,6002026-03-05 CRITICAL 9.8 CVE-2026-28391 OpenClaw versions prior to 2026.2.2 fail to properly validate Windows cmd.exe metacharacters in allowlist-gated exec requests (non-default configurat… Openclaw 2026.2.2+ Fix from $2,3002026-03-05 CRITICAL 9.8 CVE-2026-28392 OpenClaw versions prior to 2026.2.14 contain a privilege escalation vulnerability in the Slack slash-command handler that incorrectly authorizes any … Openclaw 2026.2.14+ Fix from $2,3002026-03-05 CRITICAL 9.8 CVE-2026-28393 OpenClaw versions 2.0.0-beta3 prior to 2026.2.14 contain a path traversal vulnerability in hook transform module loading that allows arbitrary JavaSc… Openclaw 2026.2.14+ Fix from $2,3002026-03-05 MEDIUM 6.5 CVE-2026-28394 OpenClaw versions prior to 2026.2.15 contain a denial of service vulnerability in the web_fetch tool that allows attackers to crash the Gateway proce… Openclaw 2026.2.15+ Fix from $1,6002026-03-05 HIGH 8.8 CVE-2026-28363 In OpenClaw before 2026.2.23, tools.exec.safeBins validation for sort could be bypassed via GNU long-option abbreviations (such as --compress-prog) i… Openclaw 2026.2.23+ Fix from $1,9502026-02-27 HIGH 8.0 CVE-2026-27487 OpenClaw is a personal AI assistant. In versions 2026.2.13 and below, when using macOS, the Claude CLI keychain credential refresh path constructed a… Openclaw 2026.2.14+ Fix from $1,9502026-02-21 HIGH 7.3 CVE-2026-27488 OpenClaw is a personal AI assistant. In versions 2026.2.17 and below, Cron webhook delivery in src/gateway/server-cron.ts uses fetch() directly, so w… Openclaw after 2026.2.17 Fix from $1,9502026-02-21 MEDIUM 5.3 CVE-2026-27486 OpenClaw is a personal AI assistant. In versions 2026.2.13 and below of the OpenClaw CLI, the process cleanup uses system-wide process enumeration an… Openclaw 2026.2.14+ Fix from $1,6002026-02-21 MEDIUM 6.7 CVE-2026-27008 OpenClaw is a personal AI assistant. Prior to version 2026.2.15, a bug in `download` skill installation allowed `targetDir` values from skill frontma… Openclaw 2026.2.15+ Fix from $1,6002026-02-20 MEDIUM 5.8 CVE-2026-27009 OpenClaw is a personal AI assistant. Prior to version 2026.2.15, a atored XSS issue in the OpenClaw Control UI when rendering assistant identity (nam… Openclaw 2026.2.15+ Fix from $1,6002026-02-20 MEDIUM 5.5 CVE-2026-27004 OpenClaw is a personal AI assistant. Prior to version 2026.2.15, in some shared-agent deployments, OpenClaw session tools (`sessions_list`, `sessions… Openclaw 2026.2.15+ Fix from $1,6002026-02-20 CRITICAL 9.8 CVE-2026-27002 OpenClaw is a personal AI assistant. Prior to version 2026.2.15, a configuration injection issue in the Docker tool sandbox could allow dangerous Doc… Openclaw 2026.2.15+ Fix from $2,3002026-02-20 HIGH 7.8 CVE-2026-27001 OpenClaw is a personal AI assistant. Prior to version 2026.2.15, OpenClaw embedded the current working directory (workspace path) into the agent syst… Openclaw 2026.2.15+ Fix from $1,9502026-02-20