openclaw vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
GHSA-P73F-W79W-JQR5Highopenclaw: OpenClaw: Native command authorization could skip owner-command enforcementGHSA-J472-GF56-X589Highopenclaw: OpenClaw: PowerShell encoded-command aliases could miss exec allowlist checksGHSA-77Q5-RR5V-X43QHighopenclaw: OpenClaw: Trusted retry endpoint checks could match hostname prefixesGHSA-W5WW-7CHG-MXCQHighopenclaw: OpenClaw: Telegram interactive callbacks could skip commands.allowFromCVE-2026-53811Highopenclaw: OpenClaw: Matrix allowFrom could bind to mutable display namesGHSA-4M3V-Q747-PC6HMediumopenclaw: OpenClaw: Mattermost slash token revocation could lag until monitor refreshCVE-2026-53816Highopenclaw: OpenClaw: Paired nodes could forge exec lifecycle events without system.run provenanceCVE-2026-53806Highopenclaw: OpenClaw: Combined POSIX shell options could confuse exec revalidationCVE-2026-53818Mediumopenclaw: OpenClaw: MCP loopback could skip owner-only tool policy for non-owner callersGHSA-275C-XPVC-JGFWMediumopenclaw: OpenClaw: Slack and Zalo webhook secrets could remain active after secrets.reloadGHSA-3WQP-PRF6-2M72Lowopenclaw: OpenClaw: Feishu dynamic-agent bindings could miss configWrites enforcementGHSA-6C4R-G249-WV3CMediumopenclaw: OpenClaw: Sandboxed session spawn could expose the real workspace path to child promptsCVE-2026-53809Mediumopenclaw: OpenClaw: Embedded runner policy could be confused by provider aliasesCVE-2026-53813Highopenclaw: OpenClaw: Fake package roots could influence memory-core artifact loadingCVE-2026-53819Highopenclaw: OpenClaw: Workspace .env could override Homebrew executable selection for skill install flowsGHSA-77PV-3W4Q-VRJ5Mediumopenclaw: OpenClaw: QQBot pre-dispatch slash commands could skip allowFrom checksGHSA-XR4F-MJXJ-W6W5Highopenclaw: OpenClaw: Non-owner chat senders could issue device-pairing bootstrap codesGHSA-HCM3-8F6R-6XWGMediumopenclaw: OpenClaw: Browser debug/export routes could reuse already-open blocked tabsGHSA-GRC3-2J34-P6GMMediumopenclaw: OpenClaw: message.action forwarding could send Gateway credentials to model-supplied loopback URLsGHSA-W4V6-G3WM-W36CCriticalopenclaw: OpenClaw: QQBot admin commands could skip DM-only and allowFrom policyGHSA-GP79-M99V-GJMHMediumopenclaw: OpenClaw: Mattermost handlers could fall open when channel type was missingGHSA-QJPC-QF9M-XWMRHighopenclaw: OpenClaw: Trusted-proxy Control UI WebSocket accepted client-declared scopes before pairingGHSA-C29C-2Q9C-PC86Highopenclaw: OpenClaw: Slack allowFrom could bind to mutable display namesGHSA-CQWV-9QJX-VXW2Mediumopenclaw: OpenClaw: Skill Workshop apply flow could override pending approvalGHSA-JVM4-4J77-39P6Highopenclaw: OpenClaw: QQBot streaming command could mutate config without explicit allowFrom

Stop the waste.
Protect your environment with Kodem.