Openclaw vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-32005Highopenclaw: OpenClaw: Slack interactive callbacks could skip configured sender checks in some shared-workspace flowsCVE-2026-32018Mediumopenclaw: OpenClaw's serialize sandbox registry writes to prevent races and delete-rollback corruptionCVE-2026-32001Mediumopenclaw: OpenClaw's Node role device-identity bypass allows unauthorized node.event injectionGHSA-2CH6-X3G4-7759Highopenclaw: OpenClaw's commands.allowFrom sender authorization accepted conversation identifiers via ctx.FromCVE-2026-31995Mediumopenclaw: OpenClaw has Windows Lobster shell fallback command injection in constrained fallback pathGHSA-534W-2VM4-89XRMediumopenclaw: OpenClaw's Zalo group sender allowlist bypass permits unauthorized GROUP dispatchGHSA-CJV3-M589-V3RXMediumopenclaw: OpenClaw has Canvas route hardening for mixed-trust deploymentsCVE-2026-27566Highopenclaw: OpenClaw's exec allowlist wrapper analysis did not unwrap env/shell dispatch chainsCVE-2026-32039Mediumopenclaw: OpenClaw's typed sender-key matching for toolsBySender prevents identity-collision policy bypassCVE-2026-32050Mediumopenclaw: OpenClaw's Signal reaction-only status events could, in limited cases, be enqueued before access checksCVE-2026-27523Highopenclaw: OpenClaw's sandbox bind validation could bypass allowed-root and blocked-path checks via symlink-parent missing-leaf pathsGHSA-JXRQ-8FM4-9P58Highopenclaw: OpenClaw: Zip extraction symlink traversal could write outside destinationCVE-2026-28449Mediumopenclaw: OpenClaw's Nextcloud Talk webhook replay could trigger duplicate inbound processingGHSA-8MF7-VV8W-HJR2Lowopenclaw: OpenClaw's tools.exec.safeBins generic fallback allowed interpreter-style inline payload execution in allowlist modeCVE-2026-31998Mediumopenclaw: OpenClaw's Synology Chat dmPolicy=allowlist failed open on empty allowedUserIds, allowing unauthorized agent dispatchCVE-2026-32897Lowopenclaw: OpenClaw reuses the gateway auth token in the owner ID prompt hashing fallbackGHSA-659F-22XC-98F2Highopenclaw: OpenClaw hook transform path containment missed symlink-resolved escapesCVE-2026-32010Mediumopenclaw: In OpenClaw, manually adding sort to tools.exec.safeBins could bypass allowlist approval via --compress-programCVE-2026-32006Mediumopenclaw: OpenClaw has a BlueBubbles group allowlist mismatch via DM pairing-store fallbackGHSA-GCJ7-R3HG-M7W6Lowopenclaw: OpenClaw's voice-call Twilio replay dedupe now bound to authenticated webhook identityGHSA-W7J5-J98M-W679Highopenclaw: OpenClaw has multiple E2E/test Dockerfiles that run all processes as rootGHSA-796M-2973-WC5QMediumopenclaw: OpenClaw has exec allowlist/safeBins policy-runtime mismatch via env -S wrapper interpretationGHSA-7QF6-H84J-8FQ4Lowopenclaw: OpenClaw: Microsoft Teams media fetch paths bypass shared SSRF guard modelCVE-2026-32025Mediumopenclaw: OpenClaw's browser-origin WebSocket auth hardening gap could enable loopback password brute-force chainsCVE-2026-32029Mediumopenclaw: OpenClaw improperly parses X-Forwarded-For behind trusted proxies allows client IP spoofing in security decisions

Stop the waste.
Protect your environment with Kodem.