Openclaw vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-32007Highopenclaw: OpenClaw: Experimental apply_patch may bypass workspace-only checks in opt-in sandbox mounts (off by default)GHSA-J26J-7QC4-3MRFMediumopenclaw: OpenClaw: MS Teams fileConsent/invoke missing conversation binding allowed cross-conversation pending-upload consumptionGHSA-2HM8-RQRM-XFJQMediumopenclaw: OpenClaw's owner-only gateway tool access checks were incomplete in specific authenticated DM flowsCVE-2026-22217Mediumopenclaw: OpenClaw: shell-env trusted-prefix fallback allowed attacker-controlled binary execution via $SHELLCVE-2026-32896Mediumopenclaw: OpenClaw: BlueBubbles beta plugin webhook auth hardening (remove passwordless fallback)GHSA-2MC2-G238-722JMediumopenclaw: OpenClaw affected by iMessage remote attachment SCP hardening (strict host-key checks and remoteHost validation)CVE-2026-32009Highopenclaw: OpenClaw: safeBins static default trusted dirs allow writable-dir binary hijack (`jq`)GHSA-77HF-7FQF-F227Mediumopenclaw: OpenClaw skills-install-download: tar.bz2 extraction bypassed archive safety parity checks (local DoS)CVE-2026-32035Mediumopenclaw: OpenClaw: Discord voice transcript owner-flag omission could expose owner-only tools in mixed-trust channelsGHSA-474H-PRJG-MMW3Highopenclaw: OpenClaw: Sandboxed sessions_spawn(runtime="acp") bypassed sandbox inheritance and allowed host ACP initializationCVE-2026-32004Highopenclaw: OpenClaw has encoded-path auth bypass in plugin `/api/channels` route classificationCVE-2026-32028Mediumopenclaw: OpenClaw: Discord DM reaction ingress missed dmPolicy/allowFrom checks in restricted setupsCVE-2026-28483Highopenclaw: OpenClaw: ZIP extraction race could write outside destination via parent symlink rebindCVE-2026-22180Mediumopenclaw: OpenClaw: Unified root-bound write hardening for browser output and related path-boundary flowsCVE-2026-22181Mediumopenclaw: OpenClaw's web tools strict URL guard could lose DNS pinning when env proxy is configuredCVE-2026-29608Mediumopenclaw: OpenClaw's Node system.run approval hardening wrapper semantic drift can execute unintended local scriptsGHSA-2858-XG23-26FPMediumopenclaw: OpenClaw: Node camera URL payload host-binding bypass allowed gateway fetch pivotsCVE-2026-32011Mediumopenclaw: OpenClaw has pre-auth webhook body parsing that can enable unauthenticated slow-request DoSCVE-2026-31990Highopenclaw: OpenClaw: stageSandboxMedia destination symlink traversal can overwrite files outside sandbox workspaceCVE-2026-32030Highopenclaw: OpenClaw vulnerable to sensitive file disclosure via stageSandboxMediaCVE-2026-32061Mediumopenclaw: OpenClaw vulnerable to arbitrary file read via $include directiveCVE-2026-28460Mediumopenclaw: OpenClaw's system.run allowlist bypass via shell line-continuation command substitutionCVE-2026-22177Mediumopenclaw: OpenClaw's config env vars allowed startup env injection into service runtimeCVE-2026-32032Highopenclaw: OpenClaw's shell env fallback trusts unvalidated SHELL path from host environmentGHSA-QHRR-GRQP-6X2GMediumopenclaw: OpenClaw's tools.exec.safeBins trusted PATH directories allowed binary shadowing in allowlist mode

Stop the waste.
Protect your environment with Kodem.