Openclaw vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
GHSA-83W9-H5WV-J9XMHighopenclaw: OpenClaw: Node pairing reconnection could confuse approval scope stateGHSA-WV26-J37Q-2G7PMediumopenclaw: OpenClaw's Slack plugin approvals used the exec approver gate for plugin actionsGHSA-P2FH-F5FC-44HRMediumopenclaw: OpenClaw: memory-wiki ingest could read local files with operator.write scopeGHSA-HW9R-H9MR-4JFFHighopenclaw: OpenClaw: Scoped chat.send route inheritance could bypass admin command scope gatesGHSA-MHQ8-78PJ-5J79Highopenclaw: OpenClaw's POSIX node system.run safe-bin allowlist could be widened by shell expansionCVE-2026-35630Highopenclaw: OpenClaw: QQBot native approval buttons did not enforce configured approver identityCVE-2026-53814Highopenclaw: OpenClaw: Hook-triggered CLI runs could receive owner MCP tool authorityCVE-2026-53817Highopenclaw: OpenClaw: Control UI locality spoofing could mint a durable admin device tokenGHSA-RGGC-M335-3WVJHighopenclaw: OpenClaw: Same-host trusted-proxy deployments could accept local forged identity headersCVE-2026-53810Highopenclaw: OpenClaw's marketplace runtime extension metadata could point at unscanned payloadsCVE-2026-53812Mediumopenclaw: OpenClaw's browser act interactions could bypass private-network navigation checksGHSA-2J8V-HWGC-X698HighOpenclaw: OpenClaw: Shell wrapper argv could change between approval and executionGHSA-QH2F-99MV-MRCFMediumopenclaw: OpenClaw: Bundle MCP loopback could miss its exec denylist on session spawnGHSA-XWW8-GQVH-92X9Highopenclaw: OpenClaw: Exec approval display truncation could hide the command being approvedCVE-2026-53815Highopenclaw: OpenClaw: Message read actions could skip channel allowlist checksGHSA-9C3V-684M-579CMediumopenclaw: OpenClaw MCP SSE redirects could forward Authorization headersCVE-2026-53854Mediumopenclaw: OpenClaw: Internal/webchat command auth could inherit ownerAllowFrom wildcard stateCVE-2026-53852Lowopenclaw: OpenClaw: Empty-scope device re-pairing could confuse caller scope containmentCVE-2026-53865Highopenclaw: OpenClaw: Workspace-derived service PATH could influence trash command selectionCVE-2026-53858Highopenclaw: OpenClaw: Workspace .env STATE_DIRECTORY could influence bundled runtime dependency rootsCVE-2026-53849Highopenclaw: OpenClaw: Discord allowFrom could bind to mutable display namesCVE-2026-53850Mediumopenclaw: OpenClaw: Focus command could miss controlScope enforcementCVE-2026-53846Highopenclaw: OpenClaw: Workspace .env npm_execpath could influence bundled runtime dependency installCVE-2026-53853Highopenclaw: OpenClaw: Linux and macOS exec allowlists skipped configured argument patternsCVE-2026-53860Lowopenclaw: OpenClaw: BlueBubbles sender policy could match mutable conversation identifiers

Stop the waste.
Protect your environment with Kodem.