openclaw vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-22172Criticalopenclaw: OpenClaw: WebSocket shared-auth connections could self-declare elevated scopesCVE-2026-32918Highopenclaw: `OpenClaw: session_status` let sandboxed subagents access parent or sibling session stateCVE-2026-32920Highopenclaw: OpenClaw: Workspace plugin auto-discovery allowed code execution from cloned repositoriesGHSA-R7VR-GR74-94P8Highopenclaw: OpenClaw: Command-authorized non-owners could reach owner-only `/config` and `/debug` surfacesGHSA-F8R2-VG7X-GH8MMediumopenclaw: OpenClaw: Exec approval allowlist patterns overmatched on POSIX pathsGHSA-M69H-JM2F-2PV8Mediumopenclaw: OpenClaw: Feishu reaction events could bypass group authorization and mention gatingGHSA-VMHQ-CQM9-6P7QHighopenclaw: OpenClaw: `browser.request` let `operator.write` persist admin-only browser profile changesGHSA-7H7G-X2PX-94HJMediumopenclaw: OpenClaw: Pairing setup codes exposed long-lived shared gateway credentials instead of short-lived bootstrap tokensGHSA-F5MF-3R52-R83WMediumopenclaw: OpenClaw's Zalouser allowlist authorization matched mutable group names by defaultGHSA-9VVH-2768-C8VPMediumopenclaw: OpenClaw: Discord guild reaction ingress could bypass users and roles allowlistsCVE-2026-32970Lowopenclaw: OpenClaw: Unavailable local auth SecretRefs could fall through to remote credentials in local modeGHSA-MJ4P-RC52-M843Highopenclaw: OpenClaw: Sandbox staged writes could escape the verified parent directory before commitGHSA-JF6W-M8JW-JFXCMediumopenclaw: OpenClaw: Write-scoped callers could reach admin-only session reset logic through `agent`CVE-2026-32978Highopenclaw: OpenClaw: Unrecognized script runners could bypass `system.run` approval integrityGHSA-8JHH-JCQG-MJ5PMediumopenclaw: OpenClaw: Channel commands could bypass account-scoped `configWrites` restrictionsCVE-2026-32971Highopenclaw: OpenClaw: Node-host approvals could show misleading shell payloads instead of the executed argvCVE-2026-32979Highopenclaw: OpenClaw: Unbound interpreter and runtime commands could bypass node-host approval integrityGHSA-4W7M-58CG-CMFFHighopenclaw: OpenClaw: Leaf subagents could steer sibling sessions across sandbox boundariesGHSA-4JPW-HJ22-2XMCCriticalopenclaw: OpenClaw: Pairing-scoped device tokens could mint `operator.admin` and reach node RCECVE-2026-32916Criticalopenclaw: OpenClaw: Plugin subagent routes could bypass gateway authorization with synthetic admin scopesCVE-2026-32977Mediumopenclaw: OpenClaw: Sandbox `writeFile` commit could race outside the validated pathCVE-2026-32302Highopenclaw: OpenClaw: Untrusted web origins can obtain authenticated operator.admin access in trusted-proxy modeCVE-2026-32031Mediumopenclaw: OpenClaw: /api/channels gateway-auth boundary bypass via path canonicalization mismatchCVE-2026-32895Mediumopenclaw: OpenClaw: Slack system events bypass sender authorization in member and message subtype handlersGHSA-QCC4-P59M-P54MHighopenclaw: OpenClaw: Sandbox dangling-symlink alias handling could bypass workspace-only write boundary

Stop the waste.
Protect your environment with Kodem.