openclaw vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-35652Mediumopenclaw: OpenClaw: Mattermost callback dispatch allowed non-allowlisted sender actionsGHSA-PPWQ-6V66-5M6JMediumopenclaw: OpenClaw Exposes Credentials Embedded in baseUrl Fields via config.get and channels.statusCVE-2026-35648Lowopenclaw: OpenClaw may have stale policy enforcement for queued node actionsCVE-2026-35650Highopenclaw: OpenClaw has Inconsistent Host Exec Environment Override SanitizationGHSA-48VW-M3QC-WR99Highopenclaw: OpenClaw's Trusted-proxy Control UI sessions retain privileged scopes without device identity on device-less allow pathsCVE-2026-35626Mediumopenclaw: OpenClaw is vulnerable to unauthenticated resource exhaustion through its voice call webhook handlingCVE-2026-35659Mediumopenclaw: OpenClaw: Bonjour/DNS-SD TXT metadata steers CLI routing after failed service resolutionCVE-2026-35633Highopenclaw: OpenClaw: Remote media error responses could trigger unbounded memory allocation before failureCVE-2026-35643Highopenclaw: OpenClaw: Arbitrary code execution via unvalidated WebView JavascriptInterfaceCVE-2026-35666Highopenclaw: OpenClaw's system.run allowlist can be bypassed through an unregistered time dispatch wrapperCVE-2026-35627Highopenclaw: OpenClaw: Nostr inbound DMs could trigger unauthenticated crypto work before sender policy enforcementCVE-2026-35670Mediumopenclaw: OpenClaw: Synology Chat reply delivery could be rebound through username-based user resolution.CVE-2026-34426Mediumopenclaw: OpenClaw: Windows media loaders accepted remote-host file URLs before local path validationCVE-2026-35660Highopenclaw: OpenClaw: Gateway agent /reset exposes admin session reset to operator.write callersCVE-2026-35634Mediumopenclaw: OpenClaw: Gateway Canvas local-direct requests bypass Canvas HTTP and WebSocket authenticationCVE-2026-35618Highopenclaw: OpenClaw: Plivo V2 verified replay identity drifts on query-only variantsCVE-2026-32846Highopenclaw: OpenClaw is vulnerable to Path Traversal through path validation bypassCVE-2026-33572Mediumopenclaw: OpenClaw session transcript files were created without forced user-only permissionsGHSA-G2F6-PWVX-R275Highopenclaw: OpneClaw accepts unsanitized iMessage attachment paths which allowed SCP remote-path command injectionCVE-2026-32980Highopenclaw: OpenClaw Telegram webhook request bodies were read before secret validation, enabling unauthenticated resource exhaustionGHSA-63F5-HHC7-CX6PHighopenclaw: OpenClaw bootstrap setup codes could be replayed to escalate pending pairing scopes before approvalGHSA-XWCJ-HWHF-H378Mediumopenclaw: OpenClaw Telegram media fetch errors exposed bot tokens in logged file URLsCVE-2026-34505Mediumopenclaw: OpenClaw: Zalo webhook rate limiting could be bypassed before secret validationCVE-2026-32974Highopenclaw: OpenClaw: Feishu webhook mode accepted forged events when only `verificationToken` was configuredGHSA-2RQG-GJGV-84JMHighopenclaw: OpenClaw: Gateway `agent` calls could override the workspace boundary

Stop the waste.
Protect your environment with Kodem.