Openclaw vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-28478Highopenclaw: OpenClaw affected by denial of service via unbounded webhook request body bufferingCVE-2026-28452Mediumopenclaw: OpenClaw affected by denial of service through unguarded archive extraction allowing high expansion/resource abuse (ZIP/TAR)CVE-2026-29612Mediumopenclaw: OpenClaw: denial of service through large base64 media files allocating large buffers before limit checksCVE-2026-29609Highopenclaw: OpenClaw affected by denial of service via unbounded URL-backed media fetchCVE-2026-28392Highopenclaw: OpenClaw Slack: dmPolicy=open allowed any DM sender to run privileged slash commandsCVE-2026-28463Highopenclaw: OpenClaw exec approvals: safeBins could bypass stdin-only constraints via shell expansionCVE-2026-26323Highopenclaw: OpenClaw has a command injection in maintainer clawtributors updaterCVE-2026-26329Highopenclaw: OpenClaw has a path traversal in browser upload allows local file readCVE-2026-26328Mediumopenclaw: OpenClaw iMessage group allowlist authorization inherited DM pairing-store identitiesCVE-2026-26327Highopenclaw: OpenClaw allows unauthenticated discovery TXT records to steer routing and TLS pinningGHSA-CHM2-M3W2-WCXMLowopenclaw: OpenClaw Google Chat spoofing access with allowlist authorized mutable email principal despite sender-ID mismatchCVE-2026-26326Mediumopenclaw: OpenClaw skills.status could leak secrets to operator.read clientsCVE-2026-26325Highopenclaw: OpenClaw Node host system.run rawCommand/command mismatch can bypass allowlist/approvalsCVE-2026-26324Highopenclaw: OpenClaw has a SSRF guard bypass via full-form IPv4-mapped IPv6 (loopback / metadata reachable)CVE-2026-26322Highopenclaw: OpenClaw Gateway tool allowed unrestricted gatewayUrl overrideCVE-2026-26321Highopenclaw: OpenClaw has a local file disclosure via sendMediaFeishu in Feishu extensionCVE-2026-26320Highopenclaw: OpenClaw macOS deep link confirmation truncation can conceal executed agent messageCVE-2026-26319Highopenclaw: OpenClaw is Missing Webhook Authentication in Telnyx Provider Allows Unauthenticated RequestsCVE-2026-28447Highopenclaw: OpenClaw has a Path Traversal in Plugin InstallationCVE-2026-28473Highopenclaw: OpenClaw authorization bypass: operator.write can resolve exec approvals via chat.send -> /approveCVE-2026-28481Mediumopenclaw: OpenClaw MS Teams inbound attachment downloader leaks bearer tokens to allowlisted suffix domainsCVE-2026-28448Highopenclaw: OpenClaw Twitch allowFrom is not enforced in optional plugin, unauthorized chat users can trigger agent pipelineCVE-2026-28446Criticalopenclaw: OpenClaw has an inbound allowlist policy bypass in voice-call extension (empty caller ID + suffix matching)CVE-2026-28454Criticalopenclaw: OpenClaw has a potential access-group authorization bypass if channel type lookup failsCVE-2026-28471Mediumopenclaw: OpenClaw has a Matrix allowlist bypass via displayName and cross-homeserver localpart matching

Stop the waste.
Protect your environment with Kodem.