Vulnerability index

Browse CVEs

530 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.3 CVE-2026-41332 OpenClaw before 2026.3.28 contains an environment variable sanitization vulnerability where GIT_TEMPLATE_DIR and AWS_CONFIG_FILE are not blocked in t… Openclaw 2026.3.28+ Fix from $1,6002026-04-23 MEDIUM 6.5 CVE-2026-41908 OpenClaw before 2026.4.20 contains a scope enforcement bypass vulnerability in the assistant-media route that allows trusted-proxy callers without op… Openclaw 2026.4.20+ Fix from $1,6002026-04-23 MEDIUM 5.4 CVE-2026-41909 OpenClaw before 2026.4.20 contains an improper authorization vulnerability in paired-device pairing management that allows limited-scope sessions to … Openclaw 2026.4.20+ Fix from $1,6002026-04-23 CRITICAL 9.9 CVE-2026-41329 OpenClaw before 2026.3.31 contains a sandbox bypass vulnerability allowing attackers to escalate privileges via heartbeat context inheritance and sen… Openclaw 2026.3.31+ Fix from $2,3002026-04-21 HIGH 8.8 CVE-2026-41303 OpenClaw before 2026.3.28 contains an authorization bypass vulnerability in Discord text approval commands that allows non-approvers to resolve pendi… Openclaw 2026.3.28+ Fix from $1,9502026-04-21 MEDIUM 6.3 CVE-2026-41302 OpenClaw before 2026.3.31 contains a server-side request forgery vulnerability in the marketplace plugin download functionality that allows remote at… Openclaw 2026.3.31+ Fix from $1,6002026-04-21 MEDIUM 5.3 CVE-2026-41331 OpenClaw before 2026.3.31 contains a resource consumption vulnerability in Telegram audio preflight transcription that allows unauthorized group send… Openclaw 2026.3.31+ Fix from $1,6002026-04-21 HIGH 7.6 CVE-2026-41297 OpenClaw before 2026.3.31 contains a server-side request forgery vulnerability in the marketplace plugin download functionality that allows attackers… Openclaw 2026.3.31+ Fix from $1,9502026-04-21 HIGH 7.1 CVE-2026-41299 OpenClaw before 2026.3.28 contains an authorization bypass vulnerability in the chat.send gateway method where ACP-only provenance fields are gated b… Openclaw 2026.3.28+ Fix from $1,9502026-04-21 MEDIUM 6.5 CVE-2026-41300 OpenClaw before 2026.3.31 contains a trust-decline vulnerability that preserves attacker-discovered endpoints in remote onboarding flows. Attackers c… Openclaw 2026.3.31+ Fix from $1,6002026-04-21 MEDIUM 5.4 CVE-2026-41298 OpenClaw before 2026.4.2 fails to enforce write scopes on the POST /sessions/:sessionKey/kill endpoint in identity-bearing HTTP modes. Read-scoped ca… Openclaw 2026.4.2+ Fix from $1,6002026-04-21 MEDIUM 5.3 CVE-2026-41301 OpenClaw versions 2026.3.22 before 2026.3.31 contain a signature verification bypass vulnerability in the Nostr DM ingress path that allows pairing c… Openclaw 2026.3.31+ Fix from $1,6002026-04-21 HIGH 8.6 CVE-2026-41294 OpenClaw before 2026.3.28 loads the current working directory .env file before trusted state-dir configuration, allowing environment variable injecti… Openclaw 2026.3.28+ Fix from $1,9502026-04-21 HIGH 8.2 CVE-2026-41296 OpenClaw before 2026.3.31 contains a time-of-check-time-of-use race condition in the remote filesystem bridge readFile function that allows sandbox e… Openclaw 2026.3.31+ Fix from $1,9502026-04-21 HIGH 7.8 CVE-2026-41295 OpenClaw before 2026.4.2 contains an improper trust boundary vulnerability allowing untrusted workspace channel shadows to execute during built-in ch… Openclaw 2026.4.2+ Fix from $1,9502026-04-21 MEDIUM 5.7 CVE-2026-40045 OpenClaw before 2026.4.2 accepts non-loopback cleartext ws:// gateway endpoints and transmits stored gateway credentials over unencrypted connections… Openclaw 2026.4.2+ Fix from $1,6002026-04-21 MEDIUM 5.8 CVE-2026-41389 OpenClaw versions 2026.4.7 before 2026.4.15 fail to enforce local-root containment on tool-result media paths, allowing arbitrary local and UNC file … Openclaw 2026.4.15+ Fix from $1,6002026-04-20 MEDIUM 5.3 CVE-2026-3691 OpenClaw Client PKCE Verifier Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose stored credentials on affe… Openclaw 2026.2.25+ Fix from $1,6002026-04-11 HIGH 7.4 CVE-2026-3690 OpenClaw Canvas Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of… Openclaw 2026.2.19+ Fix from $1,9502026-04-11 MEDIUM 6.5 CVE-2026-3689 OpenClaw Canvas Path Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on … Openclaw 2026.2.21+ Fix from $1,6002026-04-11 HIGH 8.8 CVE-2026-35669 OpenClaw before 2026.3.25 contains a privilege escalation vulnerability in gateway-authenticated plugin HTTP routes that incorrectly mint operator.ad… Openclaw 2026.3.25+ Fix from $1,9502026-04-10 HIGH 8.1 CVE-2026-35670 OpenClaw before 2026.3.22 contains a webhook reply delivery vulnerability that allows attackers to rebind chat replies to unintended users by exploit… Openclaw 2026.3.22+ Fix from $1,9502026-04-10 HIGH 7.7 CVE-2026-35668 OpenClaw before 2026.3.24 contains a path traversal vulnerability in sandbox enforcement allowing sandboxed agents to read arbitrary files from other… Openclaw 2026.3.24+ Fix from $1,9502026-04-10 HIGH 8.8 CVE-2026-35663 OpenClaw before 2026.3.25 contains a privilege escalation vulnerability allowing non-admin operators to self-request broader scopes during backend re… Openclaw 2026.3.25+ Fix from $1,9502026-04-10 HIGH 8.8 CVE-2026-35666 OpenClaw before 2026.3.22 contains an allowlist bypass vulnerability in system.run approvals that fails to unwrap /usr/bin/time wrappers. Attackers c… Openclaw 2026.3.22+ Fix from $1,9502026-04-10 MEDIUM 6.1 CVE-2026-35667 OpenClaw before 2026.3.24 contains an incomplete fix for CVE-2026-27486 where the !stop chat command uses an unpatched killProcessTree function from … Openclaw 2026.3.24+ Fix from $1,6002026-04-10 MEDIUM 5.3 CVE-2026-35664 OpenClaw before 2026.3.25 contains an authentication bypass vulnerability in raw card send surface that allows unpaired recipients to mint legacy cal… Openclaw 2026.3.25+ Fix from $1,6002026-04-10 MEDIUM 5.3 CVE-2026-35665 OpenClaw before 2026.3.24 contains an incomplete fix for CVE-2026-32011 where the Feishu webhook handler accepts request bodies with permissive limit… Openclaw 2026.3.24+ Fix from $1,6002026-04-10 HIGH 8.1 CVE-2026-35660 OpenClaw before 2026.3.23 contains an insufficient access control vulnerability in the Gateway agent /reset endpoint that allows callers with operato… Openclaw 2026.3.23+ Fix from $1,9502026-04-10 MEDIUM 6.5 CVE-2026-35658 OpenClaw before 2026.3.2 contains a filesystem boundary bypass vulnerability in the image tool that fails to honor tools.fs.workspaceOnly restriction… Openclaw 2026.3.2+ Fix from $1,6002026-04-10