openclaw vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
GHSA-JCCR-RRW2-VC8HHighopenclaw: OpenClaw safeBins jq `$ENV` filter bypass allows environment variable disclosureCVE-2026-33581Highopenclaw: OpenClaw's message tool media parameter bypasses tool policy filesystem isolationCVE-2026-41399Mediumopenclaw: OpenClaw: Gateway WebSocket Denial of Service via unbounded pre-auth upgradesCVE-2026-41363Mediumopenclaw: OpenClaw: Feishu extension resolveUploadInput bypasses file-system sandbox and allows arbitrary file reads via upload_imageCVE-2026-41303Highopenclaw: OpenClaw: Discord text `/approve` bypasses `channels.discord.execApprovals.approvers` and allows non-approvers to resolve pending exec…CVE-2026-34503Highopenclaw: OpenClaw's device removal and token revocation do not terminate active WebSocket sessionsCVE-2026-41342Highopenclaw: OpenClaw: CLI Remote Onboarding Persists Unauthenticated Discovery Endpoint and Exfiltrates Gateway CredentialsCVE-2026-33576Mediumopenclaw: OpenClaw: Zalo channel downloads media before sender authorizationCVE-2026-33579Criticalopenclaw: OpenClaw: /pair approve command path omitted caller scope subsetting and reopened device pairing escalationCVE-2026-41395Highopenclaw: OpenClaw: Voice-call Plivo V3 webhook replay key uses unsorted URL, allowing replay via query-parameter reorderingCVE-2026-35620Mediumopenclaw: OpenClaw: Non-owner command-authorized sender can change the owner-only `/send` session delivery policyCVE-2026-35653Highopenclaw: OpenClaw: `browser.request` still allows `POST /reset-profile` through the `operator.write` surfaceGHSA-VQVG-86CC-CG83Mediumopenclaw: OpenClaw: Mutating internal `/allowlist` chat commands missed `operator.admin` scope enforcementCVE-2026-35621Highopenclaw: OpenClaw: Gateway operator.write Can Reach Admin-Class Channel Allowlist Persistence via chat.sendCVE-2026-35641Highopenclaw: OpenClaw has an Arbitrary Malicious Code Execution VulnerabilityCVE-2026-35619Mediumopenclaw: OpenClaw has a Gateway HTTP /v1/models Route Bypasses Operator Read ScopeCVE-2026-35665Mediumopenclaw: OpenClaw has incomplete Fix for CVE-2026-32011: Feishu Webhook Pre-Auth Body Parsing DoS (Slow-Body / Slowloris Variant)CVE-2026-35668Highopenclaw: OpenClaw has Sandbox Media Root Bypass via Unnormalized `mediaUrl` / `fileUrl` Parameter Keys (CWE-22)CVE-2026-35667Mediumopenclaw: OpenClaw has incomplete Fix for CVE-2026-27486: Unvalidated SIGKILL in `!stop` Chat Command via `shell-utils.ts`CVE-2026-35651Mediumopenclaw: OpenClaw has ACP CLI approval prompt ANSI escape sequence injectionCVE-2026-35661Mediumopenclaw: OpenClaw: Telegram DM-Scoped Inline Button Callbacks Bypass DM Pairing and Mutate Session StateCVE-2026-35646Mediumopenclaw: OpenClaw: Synology Chat Webhook Pre-Auth Rate-Limit Bypass Enables Brute-Force Guessing of Webhook TokenCVE-2026-35654Mediumopenclaw: OpenClaw: MS Teams Feedback Invocation Bypasses Sender Allowlists and Records Unauthorized Session FeedbackCVE-2026-35645Mediumopenclaw: OpenClaw: Gateway Plugin Subagent Fallback `deleteSession` Uses Synthetic `operator.admin`CVE-2026-35664Mediumopenclaw: OpenClaw: Feishu Raw Card Send Surface Can Mint Legacy Card Callbacks That Bypass DM Pairing

Stop the waste.
Protect your environment with Kodem.