Openclaw vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-41365Lowopenclaw: OpenClaw: MSTeams thread history bypasses sender allowlist via Graph APICVE-2026-41343Mediumopenclaw: OpenClaw: LINE webhook handler lacks shared pre-auth concurrency budget before signature verificationCVE-2026-41376Lowopenclaw: OpenClaw: Matrix thread root and reply context bypass sender allowlistCVE-2026-41336Highopenclaw: OpenClaw: Workspace `.env` can override the bundled hooks root and load attacker hook codeCVE-2026-41406Mediumopenclaw: OpenClaw: Feishu thread history and quoted messages bypass sender allowlistCVE-2026-41329Criticalopenclaw: OpenClaw: Heartbeat context inheritance bypasses sandbox via senderIsOwner escalationCVE-2026-41402Lowopenclaw: OpenClaw: Zalo webhook replay cache cross-target messageId scope bypassCVE-2026-41385Mediumopenclaw: OpenClaw Nostr privateKey config redaction bypass leaks plaintext signing key via config.getCVE-2026-41391Highopenclaw: OpenClaw: PIP_INDEX_URL and UV_INDEX_URL bypass host exec env sanitization and redirect Python package-index trafficCVE-2026-41337Mediumopenclaw: OpenClaw: Voice-call Plivo replay mutates in-process callback origin before replay rejectionCVE-2026-41394Mediumopenclaw: OpenClaw: Unauthenticated plugin-auth HTTP routes receive operator runtime scopesCVE-2026-41294Criticalopenclaw: OpenClaw has a CWD `.env` environment variable injection which bypasses host-env policy and allows config takeoverCVE-2026-41380Highopenclaw: OpenClaw gateway exec allow-always over-trusts positional carrier executablesCVE-2026-34504Lowopenclaw: OpenClaw affected by SSRF via unguarded image download in fal providerCVE-2026-33578Mediumopenclaw: OpenClaw: Google Chat and Zalouser group sender allowlist bypass via policy downgradeGHSA-5R8F-96GM-5J6GHighopenclaw: OpenClaw Gateway `operator.write` can reach admin-only session reset via `chat.send` `/reset`CVE-2026-33577Mediumopenclaw: OpenClaw: node.pair.approve missing callerScopes validation allows low-privilege operator to approve malicious nodesCVE-2026-41390Highopenclaw: OpenClaw has a gateway exec allowlist allow-always bypass via unregistered /usr/bin/script wrapperCVE-2026-41387Highopenclaw: OpenClaw's incomplete host env sanitization blocklist allows supply-chain redirection via package-manager env overridesCVE-2026-33580Mediumopenclaw: OpenClaw's Nextcloud Talk webhook missing rate limiting on shared secret authenticationGHSA-G86V-F9QV-RH6MLowopenclaw: OpenClaw SSRF guard misses four IPv6 special-use rangesGHSA-JP4J-Q5FC-58GVMediumopenclaw: OpenClaw's Discord component interaction ingress skips guild/channel policy enforcementCVE-2026-41299Highopenclaw: OpenClaw: Gateway chat.send ACP-only provenance guard could be bypassed by client identity spoofingCVE-2026-41344Mediumopenclaw: OpenClaw: Gateway `operator.write` can reach admin-only persisted `verboseLevel` via `chat.send` `/verbose`CVE-2026-41332Mediumopenclaw: OpenClaw host-env blocklist missing `GIT_TEMPLATE_DIR` and `AWS_CONFIG_FILE` allows code execution via env override

Stop the waste.
Protect your environment with Kodem.