Vulnerability index

Browse CVEs

530 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.3 CVE-2026-62195 OpenClaw versions 2026.5.20 before 2026.6.6 contain an authorization bypass vulnerability in the MCP loopback feature that allows lower-trust callers… Openclaw 2026.6.6+ Fix from $1,9502026-07-13 HIGH 8.3 CVE-2026-62196 OpenClaw versions 2026.3.22 before 2026.6.6 contain an authorization bypass vulnerability where WhatsApp group IDs can satisfy elevated sender allowl… Openclaw 2026.6.6+ Fix from $1,9502026-07-13 MEDIUM 5.4 CVE-2026-62198 OpenClaw versions 2026.5.28 before 2026.6.6 contain an authorization bypass vulnerability in native web search that allows lower-trust callers to per… Openclaw 2026.6.6+ Fix from $1,6002026-07-13 HIGH 8.8 CVE-2026-62190 OpenClaw versions before 2026.6.9 contain an authorization bypass vulnerability in the flock wrapper that allows lower-trust callers to execute or pe… Openclaw 2026.6.9+ Fix from $1,9502026-07-13 HIGH 8.8 CVE-2026-62194 OpenClaw versions 2026.5.20 before 2026.6.9 contain a privilege escalation vulnerability in plugin install commands that allows lower-trust callers t… Openclaw 2026.6.9+ Fix from $1,9502026-07-13 HIGH 8.1 CVE-2026-62192 OpenClaw versions 2026.6.6 before 2026.6.9 contain an authorization bypass vulnerability in Discord guild actions that allows lower-trust callers to … Openclaw 2026.6.9+ Fix from $1,9502026-07-13 HIGH 7.1 CVE-2026-62189 OpenClaw versions before 2026.6.9 contain a symlink following vulnerability in the mirror sync feature that allows lower-trust callers to perform act… Openclaw 2026.6.9+ Fix from $1,9502026-07-13 HIGH 7.1 CVE-2026-62191 OpenClaw versions 2026.6.6 before 2026.6.9 contain an authorization bypass vulnerability in message mutation handling that allows lower-trust callers… Openclaw 2026.6.9+ Fix from $1,9502026-07-13 MEDIUM 6.5 CVE-2026-62193 OpenClaw versions 2026.6.5 before 2026.6.9 contain a vulnerability in the plugin install wrappers that could skip the install policy (authorization) … Openclaw 2026.6.9+ Fix from $1,6002026-07-13 HIGH 8.1 CVE-2026-62187 OpenClaw Feishu tools (npm package @openclaw/feishu) in versions <= 2026.6.6 could ignore per-account disablement. A lower-trust caller or a configur… Openclaw\/feishu 2026.6.9+ Fix from $1,9502026-07-13 HIGH 8.1 CVE-2026-62188 OpenClaw @openclaw/feishu versions 2026.6.6 and earlier contain an incorrect authorization vulnerability in which the Feishu permission tools could i… Openclaw\/feishu 2026.6.9+ Fix from $1,9502026-07-13 HIGH 7.6 CVE-2026-62186 OpenClaw versions before 2026.6.8 contain an authorization bypass vulnerability in OpenAI-compatible HTTP model overrides that allows lower-trust cal… Openclaw 2026.6.8+ Fix from $1,9502026-07-13 MEDIUM 6.5 CVE-2026-59261 OpenClaw before 2026.5.28 contains a credential exposure vulnerability where workspace dotenv files can override provider credentials. Attackers with… Openclaw 2026.5.28+ Fix from $1,6002026-07-08 HIGH 8.1 CVE-2026-53866 OpenClaw before 2026.5.12 contains an allowlist bypass vulnerability in shell inline-command parsing that allows authenticated operators to execute u… Openclaw 2026.5.12+ Fix from $1,9502026-06-16 CRITICAL 9.8 CVE-2026-53861 OpenClaw before 2026.5.6 contains an allowlist bypass vulnerability in the macOS Swift exec feature that misses combined POSIX inline-command flags. … Openclaw 2026.5.6+ Fix from $2,3002026-06-16 HIGH 8.1 CVE-2026-53864 OpenClaw before 2026.5.26 contains an insufficient sanitization vulnerability in the host environment sanitizer that allows Node.js control variables… Openclaw 2026.5.26+ Fix from $1,9502026-06-16 HIGH 7.1 CVE-2026-53865 OpenClaw before 2026.5.2 contains a path traversal vulnerability in maintenance task execution that allows workspace-derived service paths to influen… Openclaw 2026.5.26+ Fix from $1,9502026-06-16 MEDIUM 6.5 CVE-2026-53863 OpenClaw before 2026.4.25 contains an input validation vulnerability in tool group policy callers that accept unvalidated group IDs. Attackers who ca… Openclaw 2026.4.25+ Fix from $1,6002026-06-16 MEDIUM 5.4 CVE-2026-53862 OpenClaw before 2026.5.12 contains a bootstrap token replay vulnerability allowing callers with pending token access to reuse tokens with broader req… Openclaw 2026.5.12+ Fix from $1,6002026-06-16 HIGH 8.1 CVE-2026-53857 OpenClaw before 2026.5.3 contains a policy enforcement vulnerability where Zalo contacts with mutable display metadata could match allowFrom policy e… Openclaw 2026.5.3+ Fix from $1,9502026-06-16 HIGH 7.1 CVE-2026-53858 OpenClaw before 2026.5.2 contains an environment variable injection vulnerability where workspace .env STATE_DIRECTORY could influence bundled runtim… Openclaw 2026.5.2+ Fix from $1,9502026-06-16 MEDIUM 6.5 CVE-2026-53859 OpenClaw before 2026.5.26 contains a hostname validation vulnerability allowing attackers to bypass blocklist comparisons using trailing-dot notation… Openclaw 2026.5.26+ Fix from $1,6002026-06-16 MEDIUM 5.5 CVE-2026-53856 OpenClaw 2026.4.23 before 2026.4.24 contains an insecure file permissions vulnerability in config recovery that restores OpenClaw.json with overly br… Openclaw Mitigation only Fix from $1,6002026-06-16 MEDIUM 5.4 CVE-2026-53860 OpenClaw before 2026.5.7 contains a sender policy bypass vulnerability in BlueBubbles that allows participants to match allowlist entries through con… Openclaw 2026.5.7+ Fix from $1,6002026-06-16 HIGH 8.3 CVE-2026-53853 OpenClaw before 2026.5.12 contains an argument pattern validation bypass in the exec allowlist that allows attackers to execute disallowed arguments … Openclaw 2026.5.12+ Fix from $1,9502026-06-16 HIGH 8.1 CVE-2026-53849 OpenClaw before 2026.5.7 contains a privilege escalation vulnerability where the allowFrom feature improperly validates Discord account identity usin… Openclaw 2026.5.7+ Fix from $1,9502026-06-16 HIGH 8.1 CVE-2026-53855 OpenClaw before 2026.4.2 contains an inline-eval bypass vulnerability allowing authenticated operators to weaken strict allowlist checks via shell po… Openclaw 2026.4.2+ Fix from $1,9502026-06-16 MEDIUM 6.5 CVE-2026-53854 OpenClaw before 2026.4.25 contains a privilege escalation vulnerability in internal and webchat command authentication that allows senders to inherit… Openclaw 2026.4.25+ Fix from $1,6002026-06-16 MEDIUM 5.5 CVE-2026-53850 OpenClaw before 2026.4.25 contains a control scope enforcement bypass vulnerability in the focus command that allows authenticated callers to execute… Openclaw 2026.4.25+ Fix from $1,6002026-06-16 MEDIUM 5.4 CVE-2026-53852 OpenClaw before 2026.4.25 contains a scope containment bypass vulnerability in device re-pairing that allows authenticated operators to restore broad… Openclaw 2026.4.25+ Fix from $1,6002026-06-16