Openclaw vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-41910Mediumopenclaw: OpenClaw: /allowlist omits owner-only enforcement for cross-channel allowlist writesCVE-2026-41916Mediumopenclaw: OpenClaw: resolvedAuth closure becomes stale after config reloadCVE-2026-42431Mediumopenclaw: OpenClaw `node.invoke(browser.proxy)` bypasses `browser.request` persistent profile-mutation guardCVE-2026-42422Mediumopenclaw: OpenClaw `device.token.rotate` mints tokens for unapproved roles, bypassing device role-upgrade pairingCVE-2026-42424Mediumopenclaw: OpenClaw: Shared reply MEDIA - paths are treated as trusted and can trigger cross-channel local file exfiltrationCVE-2026-42423Mediumopenclaw: OpenClaw: strictInlineEval explicit-approval boundary bypassed by approval-timeout fallback on gateway and node exec hostsCVE-2026-42427Highopenclaw: OpenClaw: HGRCPATH, CARGO_BUILD_RUSTC_WRAPPER, RUSTC_WRAPPER, and MAKEFLAGS missing from exec env denylist — RCE via build tool env…GHSA-JF56-MCCX-5F3FHighopenclaw: OpenClaw: Authenticated `/hooks/wake` and mapped `wake` payloads are promoted into the trusted `System:` prompt channelGHSA-GFMX-PPH7-G46XHighopenclaw: OpenClaw: Lower-trust background runtime output is injected into trusted `System:` events, and local async exec completion misses the…CVE-2026-40045Mediumopenclaw: OpenClaw: Android accepted cleartext remote gateway endpoints and sent stored credentials over ws://CVE-2026-41407Mediumopenclaw: OpenClaw: Shared-secret comparison call sites leaked length information through timingCVE-2026-41354Mediumopenclaw: OpenClaw: Zalo replay dedupe keys could suppress messages across chats or sendersCVE-2026-41372Mediumopenclaw: OpenClaw: Trailing-dot localhost CDP hosts could bypass remote loopback protectionsGHSA-W6WX-JQ6J-6MCJMediumopenclaw: OpenClaw: pnpm dlx approvals did not bind local script operandsGHSA-98CH-45WP-CH47Mediumopenclaw: OpenClaw: Windows-compatible env override keys could bypass system.run approval bindingCVE-2026-41339Mediumopenclaw: OpenClaw: Gateway hello snapshots exposed host config and state paths to non-admin clientsCVE-2026-41295Mediumopenclaw: OpenClaw: Untrusted workspace channel shadows could execute during built-in channel setupCVE-2026-41298Mediumopenclaw: OpenClaw: Read-scoped identity-bearing HTTP clients could kill sessions via /sessions/:sessionKey/killCVE-2026-41398Mediumopenclaw: OpenClaw: iOS A2UI bridge trusted generic local-network pages for agent.request dispatchGHSA-846P-HGPV-VPHCMediumopenclaw: OpenClaw: QQ Bot structured payloads could read arbitrary local filesCVE-2026-41383Mediumopenclaw: OpenClaw: OpenShell mirror mode could delete arbitrary remote directories when roots were mis-scopedGHSA-FQRJ-M88P-QF3VLowopenclaw: OpenClaw: Zalo replay dedupe cache could suppress events across authenticated webhook targetsCVE-2026-41346Mediumopenclaw: OpenClaw: Pairing pending-request caps were enforced per channel instead of per accountCVE-2026-41301Mediumopenclaw: OpenClaw: Forged Nostr DMs could create pairing state before signature verificationCVE-2026-41392Mediumopenclaw: OpenClaw: Shell init-file options could satisfy exec allowlist script matching

Stop the waste.
Protect your environment with Kodem.