Openclaw vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-32055Highopenclaw: OpenClaw: workspace path guard bypass on non-existent out-of-root symlink leafGHSA-GP3Q-WPQ4-5C5HHighopenclaw: OpenClaw: LINE group allowlist scope mismatch with DM pairing-store entriesCVE-2026-34506Mediumopenclaw: OpenClaw's MS Teams sender allowlist bypass when route allowlist is configured and sender allowlist is emptyCVE-2026-33574Mediumopenclaw: OpenClaw's skills-install-download can be redirected outside the tools root by rebinding the validated base pathCVE-2026-32921Mediumopenclaw: OpenClaw's system.run approvals did not bind mutable script operands across approval and executionCVE-2026-27646Mediumopenclaw: OpenClaw: Sandboxed /acp spawn requests could initialize host ACP sessionsGHSA-9Q2P-VC84-2RWMMediumopenclaw: OpenClaw: system.run allow-always persistence included shell-commented payload tailsGHSA-HFPR-JHPQ-X4RMMediumopenclaw: OpenClaw: `operator.write` chat.send could reach admin-only config writesCVE-2026-27183Lowopenclaw: OpenClaw: system.run wrapper-depth boundary could skip shell approval gatingCVE-2026-32913Highopenclaw: OpenClaw: fetch-guard forwards custom authorization headers across cross-origin redirectsGHSA-PJVX-RX66-R3FGMediumopenclaw: OpenClaw: Cross-account sender authorization expansion in `/allowlist ... --store` account scopingGHSA-3H2Q-J2V4-6W5RMediumopenclaw: OpenClaw's system.run allowlist approval parsing missed PowerShell encoded-command wrappersGHSA-J425-WHC4-4JGCMediumopenclaw: OpenClaw's `system.run` env override filtering allowed dangerous helper-command pivotsGHSA-6RMX-GVVG-VH6JMediumopenclaw: OpenClaw's hooks count non-POST requests toward auth lockoutGHSA-RCHV-X836-W7XPHighopenclaw: OpenClaw's dashboard leaked gateway auth material via browser URL/query and localStorageCVE-2026-22170Mediumopenclaw: OpenClaw: BlueBubbles (optional plugin) pairing/allowlist mismatch when allowFrom is emptyGHSA-JJGJ-CPP9-CVPVMediumopenclaw: OpenClaw Vulnerable to Local File Exfiltration via MCP Tool Result MEDIA: Directive InjectionGHSA-3JX4-Q2M7-R496Highopenclaw: OpenClaw: Hardlink alias checks could bypass workspace-only file boundaries in specific configurationsGHSA-VVJH-F6P9-5VCFHighopenclaw: OpenClaw Canvas Authentication Bypass VulnerabilityCVE-2026-32002Mediumopenclaw: OpenClaw's image tool bypasses tools.fs.workspaceOnly on sandbox mount paths and exfiltrates out-of-workspace imagesCVE-2026-32019Mediumopenclaw: OpenClaw has incomplete IPv4 special-use SSRF blocking in web fetch guardGHSA-9MPH-4F7V-FMVHMediumopenclaw: OpenClaw has agent avatar symlink traversal in gateway session metadataGHSA-F6H3-846H-2R8WMediumopenclaw: OpenClaw's elevated allowFrom accepted broader identity signals than specified within sender-scoped authorizationCVE-2026-32067Lowopenclaw: OpenClaw has cross-account DM pairing authorization bypass via unscoped pairing store accessGHSA-8CP7-RP8R-MG77Mediumopenclaw: OpenClaw has SSRF guard bypass via IPv6 transition over ISATAP

Stop the waste.
Protect your environment with Kodem.