Vulnerability index

Browse CVEs

530 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.7 CVE-2026-26972 OpenClaw is a personal AI assistant. In versions 2026.1.12 through 2026.2.12, OpenClaw browser download helpers accepted an unsanitized output path. … Openclaw 2026.2.13+ Fix from $1,6002026-02-20 MEDIUM 5.5 CVE-2026-27003 OpenClaw is a personal AI assistant. Telegram bot tokens can appear in error messages and stack traces (for example, when request URLs include `https… Openclaw 2026.2.15+ Fix from $1,6002026-02-20 MEDIUM 6.5 CVE-2026-26328 OpenClaw is a personal AI assistant. Prior to version 2026.2.14, under iMessage `groupPolicy=allowlist`, group authorization could be satisfied by se… Openclaw 2026.2.14+ Fix from $1,6002026-02-20 MEDIUM 6.5 CVE-2026-26329 OpenClaw is a personal AI assistant. Prior to version 2026.2.14, authenticated attackers can read arbitrary files from the Gateway host by supplying … Openclaw 2026.2.14+ Fix from $1,6002026-02-20 MEDIUM 6.5 CVE-2026-26327 OpenClaw is a personal AI assistant. Discovery beacons (Bonjour/mDNS and DNS-SD) include TXT records such as `lanHost`, `tailnetDns`, `gatewayPort`, … Openclaw 2026.2.14+ Fix from $1,6002026-02-19 HIGH 8.8 CVE-2026-26323 OpenClaw is a personal AI assistant. Versions 2026.1.8 through 2026.2.13 have a command injection in the maintainer/dev script `scripts/update-clawtr… Openclaw 2026.2.14+ Fix from $1,9502026-02-19 HIGH 7.6 CVE-2026-26322 OpenClaw is a personal AI assistant. Prior to OpenClaw version 2026.2.14, the Gateway tool accepted a tool-supplied `gatewayUrl` without sufficient r… Openclaw 2026.2.14+ Fix from $1,9502026-02-19 HIGH 7.5 CVE-2026-26321 OpenClaw is a personal AI assistant. Prior to OpenClaw version 2026.2.14, the Feishu extension previously allowed `sendMediaFeishu` to treat attacker… Openclaw 2026.2.14+ Fix from $1,9502026-02-19 HIGH 7.5 CVE-2026-26324 OpenClaw is a personal AI assistant. Prior to version 2026.2.14, OpenClaw's SSRF protection could be bypassed using full-form IPv4-mapped IPv6 litera… Openclaw 2026.2.14+ Fix from $1,9502026-02-19 HIGH 7.2 CVE-2026-26325 OpenClaw is a personal AI assistant. Prior to version 2026.2.14, a mismatch between `rawCommand` and `command[]` in the node host `system.run` handle… Openclaw 2026.2.14+ Fix from $1,9502026-02-19 MEDIUM 6.5 CVE-2026-26320 OpenClaw is a personal AI assistant. OpenClaw macOS desktop client registers the `openclaw://` URL scheme. For `openclaw://agent` deep links without … Openclaw 2026.2.14+ Fix from $1,6002026-02-19 HIGH 7.5 CVE-2026-26319 OpenClaw is a personal AI assistant. Versions 2026.2.13 and below allow the optional @openclaw/voice-call plugin Telnyx webhook handler to accept uns… Openclaw 2026.2.14+ Fix from $1,9502026-02-19 HIGH 7.5 CVE-2026-26316 OpenClaw is a personal AI assistant. Prior to 2026.2.13, the optional BlueBubbles iMessage channel plugin could accept webhook requests as authentica… Openclaw 2026.2.13+ Fix from $1,9502026-02-19 HIGH 7.1 CVE-2026-26317 OpenClaw is a personal AI assistant. Prior to 2026.2.14, browser-facing localhost mutation routes accepted cross-origin browser requests without expl… Openclaw 2026.2.14+ Fix from $1,9502026-02-19 HIGH 7.5 CVE-2026-25474 OpenClaw is a personal AI assistant. In versions 2026.1.30 and below, if channels.telegram.webhookSecret is not set when in Telegram webhook mode, Op… Openclaw 2026.2.1+ Fix from $1,9502026-02-19 HIGH 8.4 CVE-2026-25593 OpenClaw is a personal AI assistant. Prior to 2026.1.20, an unauthenticated local client could use the Gateway WebSocket API to write config via conf… Openclaw 2026.1.20+ Fix from $1,9502026-02-06 MEDIUM 6.5 CVE-2026-25475 OpenClaw is a personal AI assistant. Prior to version 2026.1.30, the isValidMedia() function in src/media/parse.ts allows arbitrary file paths includ… Openclaw 2026.1.30+ Fix from $1,6002026-02-04 HIGH 7.5 CVE-2026-25157 OpenClaw is a personal AI assistant. Prior to version 2026.1.29, there is an OS command injection vulnerability via the Project Root Path in sshNodeC… Openclaw 2026.1.29+ Fix from $1,9502026-02-04 HIGH 8.8 CVE-2026-24763 OpenClaw (formerly Clawdbot) is a personal AI assistant you run on your own devices. Prior to 2026.1.29, a command injection vulnerability existed i… Openclaw 2026.1.29+ Fix from $1,9502026-02-02 HIGH 8.8 CVE-2026-25253EPSS 8% OpenClaw (aka clawdbot or Moltbot) before 2026.1.29 obtains a gatewayUrl value from a query string and automatically makes a WebSocket connection wit… Openclaw 2026.1.29+ Fix from $1,9502026-02-01