Openclaw vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-31993Lowopenclaw: OpenClaw macOS companion app (beta): allowlist parsing mismatch for system.run shell chainsCVE-2026-22168Highopenclaw: OpenClaw has Windows system.run approval mismatch on cmd.exe /c trailing argumentsCVE-2026-31991Lowopenclaw: OpenClaw has Signal group allowlist authorization bypass via DM pairing-store leakageCVE-2026-31997Highopenclaw: OpenClaw: system.run approvals did not bind PATH-token executable identity, enabling post-approval executable rebindCVE-2026-31989Highopenclaw: OpenClaw has web_search citation redirect SSRF via private-network-allowing policyGHSA-JR6X-2Q95-FH2GHighopenclaw: OpenClaw's authorization mismatch allowed write-scope agent runs to reach owner-only toolsGHSA-7XMQ-G46G-F8PVHighopenclaw: OpenClaw: Sandbox media TOCTOU could read files outside sandbox rootGHSA-X82F-27X3-Q89CHighopenclaw: OpenClaw's TOCTOU symlink race in writeFileWithinRoot could create or truncate files outside root boundariesCVE-2026-31999Criticalopenclaw: CpenClaw's ACPX Windows wrapper shell fallback allowed cwd injection in specific pathsGHSA-8M9V-XPGF-G99MMediumopenclaw: OpenClaw has an unauthorized sender bypass in its stop triggers and /models command authorizationCVE-2026-32048Mediumopenclaw: OpenClaw's sandboxed sessions_spawn now enforces sandbox inheritance for cross-agent spawnsCVE-2026-32066Mediumopenclaw: OpenClaw has unbounded memory growth in Zalo webhook via query-string key churn (unauthenticated DoS)GHSA-392F-GGF5-FP3CMediumopenclaw: OpenClaw: Unicode canonicalization drift in node metadata policy classification could broaden node allowlistsCVE-2026-32041Highopenclaw: OpenClaw: Browser control startup could continue unauthenticated after auth bootstrap failureCVE-2026-32898Mediumopenclaw: OpenClaw ACP client has permission auto-approval bypass via untrusted tool metadataCVE-2026-4039Mediumopenclaw: OpenClaw: Skill env override host env injection via applySkillConfigEnvOverrides (defense-in-depth)CVE-2026-28363Criticalopenclaw: OpenClaw is vulnerable to validation bypass through GNU long-option abbreviations in allowlist modeCVE-2026-27576Mediumopenclaw: OpenClaw: ACP prompt-size checks missing in local stdio bridge could reduce responsiveness with very large inputsCVE-2026-27488Mediumopenclaw: OpenClaw hardened cron webhook delivery against SSRFCVE-2026-27485Mediumopenclaw: OpenClaw: Reject symlinks in local skill packaging scriptCVE-2026-27484Lowopenclaw: OpenClaw Discord moderation authorization used untrusted sender identity in tool-driven flowsCVE-2026-4040Mediumopenclaw: OpenClaw safeBins file-existence oracle information disclosureCVE-2026-31996Lowopenclaw: OpenClaw safeBins stdin-only bypass via sort output and recursive grep flagsCVE-2026-32060Highopenclaw: OpenClaw has a path traversal in apply_patch could write/delete files outside the workspaceCVE-2026-28479Highopenclaw: OpenClaw replaced a deprecated sandbox hash algorithm

Stop the waste.
Protect your environment with Kodem.