Vulnerability index

Browse CVEs

530 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.8 CVE-2026-53817 OpenClaw before 2026.5.22 contains a locality validation vulnerability in Control UI pairing that allows attackers with network access to spoof local… Openclaw 2026.5.22+ Fix from $1,9502026-06-11 HIGH 8.3 CVE-2026-53814 OpenClaw before 2026.5.20 contains a privilege escalation vulnerability where hook-triggered agent runs incorrectly receive owner-scoped MCP loopback… Openclaw 2026.5.20+ Fix from $1,9502026-06-11 HIGH 7.8 CVE-2026-53813 OpenClaw before 2026.4.25 contains a path traversal vulnerability in memory-core artifact loading where workspace state influences local package root… Openclaw 2026.4.25+ Fix from $1,9502026-06-11 HIGH 7.7 CVE-2026-53812 OpenClaw before 2026.5.18 contains a server-side request forgery vulnerability in browser control that allows authenticated users to bypass private-n… Openclaw 2026.5.18+ Fix from $1,9502026-06-11 HIGH 7.2 CVE-2026-53816 OpenClaw before 2026.5.18 contains an insufficient provenance validation vulnerability in node event handling that allows paired nodes to forge exec … Openclaw 2026.5.18+ Fix from $1,9502026-06-11 MEDIUM 6.5 CVE-2026-53815 OpenClaw before 2026.5.19 contains an authorization bypass vulnerability in message read actions that skips channel allowlist checks. Lower-trust cal… Openclaw 2026.5.19+ Fix from $1,6002026-06-11 HIGH 8.8 CVE-2026-53806 OpenClaw before 2026.5.12 contains a shell option parsing vulnerability that allows combined POSIX shell flags to bypass exec revalidation checks. At… Openclaw 2026.5.12+ Fix from $1,9502026-06-11 HIGH 8.8 CVE-2026-53807 OpenClaw before 2026.5.6 contains an authorization bypass vulnerability in Telegram interactive callbacks that allows authenticated users to skip com… Openclaw 2026.5.6+ Fix from $1,9502026-06-11 MEDIUM 6.5 CVE-2026-53808 OpenClaw before 2026.5.6 contains an approval policy bypass vulnerability in the Skill Workshop apply flow that allows agent tool calls to set apply:… Openclaw 2026.5.6+ Fix from $1,6002026-06-11 HIGH 8.8 CVE-2026-35674 OpenClaw before 2026.5.18 contains a scope bypass vulnerability in the Gateway chat.send route that allows scoped clients to execute privileged comma… Openclaw 2026.5.18+ Fix from $1,9502026-05-29 HIGH 8.0 CVE-2026-35630 OpenClaw before 2026.5.18 contains an authorization bypass vulnerability in QQBot native approval buttons that fails to enforce configured approver i… Openclaw 2026.5.18+ Fix from $1,9502026-05-29 MEDIUM 6.5 CVE-2026-35673 OpenClaw before 2026.4.29 contains an SSRF policy bypass vulnerability in browser debug and export routes that allows reuse of already-open blocked t… Openclaw 2026.4.29+ Fix from $1,6002026-05-29 HIGH 8.3 CVE-2026-32905 OpenClaw before 2026.5.4 contains an authorization bypass vulnerability in the bundled device-pair plugin that allows non-owner authorized chat sende… Openclaw 2026.5.4+ Fix from $1,9502026-05-29 MEDIUM 5.4 CVE-2026-34507 OpenClaw before 2026.4.29 contains a policy bypass vulnerability in QQBot admin commands that allows authenticated senders to skip DM-only and allowF… Openclaw 2026.4.29+ Fix from $1,6002026-05-29 CRITICAL 9.8 CVE-2026-8305 A vulnerability was detected in OpenClaw up to 2026.1.24. The impacted element is the function handleBlueBubblesWebhookRequest of the file extensions… Openclaw 2026.2.12+ Fix from $2,3002026-05-11 HIGH 8.8 CVE-2026-45006 OpenClaw before 2026.4.23 contains an improper access control vulnerability in the gateway tool's config.apply and config.patch operations that allow… Openclaw 2026.4.23+ Fix from $1,9502026-05-11 HIGH 7.8 CVE-2026-45004 OpenClaw before 2026.4.23 contains an arbitrary code execution vulnerability in the bundled plugin setup resolver that loads setup-api.js from proces… Openclaw 2026.4.23+ Fix from $1,9502026-05-11 HIGH 7.1 CVE-2026-45001 OpenClaw before 2026.4.20 contains a guard bypass vulnerability in the agent-facing gateway config.patch and config.apply endpoints that fails to pro… Openclaw 2026.4.20+ Fix from $1,9502026-05-11 MEDIUM 6.0 CVE-2026-45005 OpenClaw before 2026.4.23 caches resolved webhook route secrets backed by SecretRef values, allowing stale secrets to remain valid after rotation and… Openclaw 2026.4.23+ Fix from $1,6002026-05-11 MEDIUM 5.3 CVE-2026-45002 OpenClaw before 2026.4.20 contains a hook session-key bypass vulnerability that allows attackers to circumvent the hooks.allowRequestSessionKey opt-i… Openclaw 2026.4.20+ Fix from $1,6002026-05-11 MEDIUM 5.0 CVE-2026-45000 OpenClaw before 2026.4.20 contains a server-side request forgery vulnerability in browser CDP profile creation that skips strict-mode SSRF policy che… Openclaw 2026.4.20+ Fix from $1,6002026-05-11 MEDIUM 5.0 CVE-2026-45003 OpenClaw before 2026.4.22 allows workspace dotenv files to override connector endpoint hosts for Matrix, Mattermost, IRC, and Synology connectors. At… Openclaw 2026.4.22+ Fix from $1,6002026-05-11 HIGH 7.3 CVE-2026-44995 OpenClaw before 2026.4.20 contains an improper environment variable validation vulnerability in MCP stdio server configuration that allows attackers … Openclaw 2026.4.20+ Fix from $1,9502026-05-11 MEDIUM 5.4 CVE-2026-44993 OpenClaw before 2026.4.20 contains a message classification vulnerability in Feishu card-action callbacks that misclassifies direct messages as group… Openclaw 2026.4.20+ Fix from $1,6002026-05-11 MEDIUM 5.4 CVE-2026-44998 OpenClaw before 2026.4.20 contains a tool policy bypass vulnerability allowing bundled MCP and LSP tools to circumvent configured tool restrictions. … Openclaw 2026.4.20+ Fix from $1,6002026-05-11 MEDIUM 5.3 CVE-2026-44994 OpenClaw before 2026.4.22 contains an authentication bypass vulnerability in the Control UI bootstrap config endpoint that allows unauthenticated att… Openclaw 2026.4.22+ Fix from $1,6002026-05-11 MEDIUM 5.3 CVE-2026-44999 OpenClaw before 2026.4.20 fails to properly preserve untrusted labels for isolated cron awareness events, allowing webhook-triggered cron agent outpu… Openclaw 2026.4.20+ Fix from $1,6002026-05-11 MEDIUM 5.0 CVE-2026-44992 OpenClaw versions 2026.4.5 before 2026.4.20 contain an environment variable injection vulnerability allowing workspace dotenv to override MINIMAX_API… Openclaw 2026.4.20+ Fix from $1,6002026-05-11 CRITICAL 9.6 CVE-2026-44112 OpenClaw before 2026.4.22 contains a time-of-check/time-of-use race condition in OpenShell sandbox filesystem writes that allows attackers to redirec… Openclaw 2026.4.22+ Fix from $2,3002026-05-06 HIGH 8.8 CVE-2026-44115 OpenClaw before 2026.4.22 contains an exec allowlist analysis vulnerability allowing shell expansion hiding in unquoted heredoc bodies. Attackers can… Openclaw 2026.4.22+ Fix from $1,9502026-05-06