Openclaw vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
GHSA-6G25-PC82-VFWPMediumopenclaw: OpenClaw: macOS beta onboarding exposed PKCE verifier via OAuth stateGHSA-5847-RM3G-23MWMediumopenclaw: OpenClaw has hook auth rate limiter bypass via IPv4-mapped IPv6 client key variantsCVE-2026-32024Mediumopenclaw: OpenClaw's avatar symlink traversal can expose out-of-workspace local filesCVE-2026-32038Mediumopenclaw: OpenClaw has a sandbox network isolation bypass via docker.network=container:<id>CVE-2026-27545Highopenclaw: OpenClaw: Node system.run approval bypass via parent-symlink cwd rebindCVE-2026-27522Highopenclaw: OpenClaw: Message action attachment hydration bypasses local media root checks when sandboxRoot is unsetCVE-2026-32065Mediumopenclaw: OpenClaw: system.run approval identity mismatch could execute a different binary than displayedGHSA-943Q-MWMV-HHVHHighopenclaw: OpenClaw: Gateway /tools/invoke tool escalation + ACP permission auto-approvalCVE-2026-28466Criticalopenclaw: OpenClaw Vulnerable to Remote Code Execution via Node Invoke Approval Bypass in GatewayCVE-2026-28486Mediumopenclaw: OpenClaw vulnerable to path traversal (Zip Slip) in archive extraction during explicit installation commandsCVE-2026-28457Mediumopenclaw: OpenClaw's sandbox skill mirroring path traversal vulnerability could write outside the sandbox workspaceCVE-2026-28464Highopenclaw: OpenClaw has non-constant-time token comparison in hooks authenticationCVE-2026-28475Mediumopenclaw: OpenClaw: Config writes could persist resolved ${VAR} secrets to diskCVE-2026-28453Highopenclaw: OpenClaw has Zip Slip path traversal in tar archive extractionCVE-2026-32013Criticalopenclaw: OpenClaw gateway agents.files symlink escape allowed out-of-workspace file read/writeCVE-2026-32058Lowopenclaw: OpenClaw Node system.run approval context-binding weakness in approval-enabled host=node flowsCVE-2026-32062Highopenclaw: OpenClaw voice-call media stream validated streams after upgrade, which could allow pre-start unauthenticated sockets to increase resource…CVE-2026-32049Highopenclaw: OpenClaw's inbound media downloads could exceed configured byte limits before rejection across multiple channelsGHSA-JQ4X-98M3-GGQ6Highopenclaw: OpenClaw Canvas Path Traversal Information Disclosure VulnerabilityCVE-2026-22175Mediumopenclaw: OpenClaw's exec allow-always can be bypassed via unrecognized multiplexer shell wrappers (busybox/toybox sh -c)GHSA-6X2M-HQFW-HVPJMediumopenclaw: OpenClaw: Node exec approvals could be replayed across nodesCVE-2026-29607Mediumopenclaw: OpenClaw's allow-always wrapper persistence could bypass future approvals and enable command executionCVE-2026-32020Lowopenclaw: OpenClaw's Control UI Static File Handler Follows Symlinks and Allows Out-of-Root File ReadCVE-2026-32054Mediumopenclaw: OpenClaw has browser trace/download path symlink escape in temp output handlingCVE-2026-22178Mediumopenclaw: OpenClaw has ReDoS and regex injection via unescaped Feishu mention metadata in RegExp construction

Stop the waste.
Protect your environment with Kodem.