openclaw vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
GHSA-7FF8-XJH3-MGH6Highopenclaw: OpenClaw's non-default autoAllowSkills setting could bypass on-miss exec promptCVE-2026-32056Highopenclaw: OpenClaw's shell startup env injection bypasses system.run allowlist intent (RCE class)CVE-2026-27524Lowopenclaw: OpenClaw's runtime /debug override path accepted prototype-reserved keysCVE-2026-32033Mediumopenclaw: OpenClaw has a workspace-only sandbox guard mismatch for @-prefixed absolute pathsGHSA-W9CG-V44M-4QV8Highopenclaw: OpenClaw affected by BASH_ENV / ENV startup-file injection into spawned shell commandsGHSA-R294-2894-92J3Mediumopenclaw: OpenClaw has stored XSS in exported session HTML viewer via markdown/raw-HTML renderingGHSA-XMV6-R34M-62P4Highopenclaw: OpenClaw: Sandbox media fallback tmp symlink alias bypass allows host file reads outside sandboxRootCVE-2026-32015Highopenclaw: OpenClaw's `tools.exec.safeBins` PATH-hijack allowed trojan binaries to bypass allowlist checksCVE-2026-32063Highopenclaw: OpenClaw Improperly Neutralizes Line Breaks in systemd Unit Generation Enables Local Command Execution (Linux)CVE-2026-32057Mediumopenclaw: OpenClaw has a Trusted-proxy Control UI pairing bypass which allows unpaired node sessionsCVE-2026-22174Mediumopenclaw: OpenClaw Loopback CDP probe can leak Gateway token to local listenerCVE-2026-22176Highopenclaw: OpenClaw has a Command Injection via unescaped environment assignments in Windows Scheduled Task script generationGHSA-4CQV-H74H-93J4Mediumopenclaw: OpenClaw has a Discord `allowFrom` slug-collision authorization bypassCVE-2026-32034Mediumopenclaw: OpenClaw has an opt-in insecure Control UI auth over plaintext HTTP could allow privileged accessGHSA-H97F-6PQJ-Q452Mediumopenclaw: OpenClaw has a IPv6 multicast SSRF classifier bypassCVE-2026-32017Mediumopenclaw: OpenClaw exec allowlist safeBins short-option bypass could permit arbitrary file writeGHSA-PFV7-RR5M-QMV6Mediumopenclaw: OpenClaw has auth inconsistency on local Browser Extension Relay /extension endpointCVE-2026-32059Highopenclaw: OpenClaw's tools.exec.safeBins sort long-option abbreviation bypass can skip exec approval in allowlist modeCVE-2026-32021Mediumopenclaw: OpenClaw has a Feishu allowFrom authorization bypass via display-name collisionCVE-2026-22179Highopenclaw: OpenClaw has macOS `system.run` allowlist bypass via quoted command substitutionGHSA-5H2C-8V84-QPVRMediumopenclaw: OpenClaw shell-env fallback trusted startup env and could execute attacker-influenced login-shell pathsGHSA-FF98-W8HJ-QRXFMediumopenclaw: OpenClaw plugin runtime command execution is part of trusted plugin boundaryGHSA-553V-F69R-656JMediumopenclaw: OpenClaw unpaired device identity can bypass operator pairing and self-assign operator scopes with shared authCVE-2026-32008Mediumopenclaw: OpenClaw browser navigation guard allowed non-network URL schemes, enabling authenticated browser-tool users to access file:// local filesCVE-2026-31994Highopenclaw: OpenClaw Windows Scheduled Task script generation allowed local command injection via unsafe cmd argument handling

Stop the waste.
Protect your environment with Kodem.