openclaw vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-32899Mediumopenclaw: OpenClaw's Slack reaction/pin sender-policy consistency issue in non-message ingressCVE-2026-32052Mediumopenclaw: OpenClaw's system.run shell-wrapper positional argv carriers could execute hidden commands under misleading approval textCVE-2026-32043Mediumopenclaw: OpenClaw's system.run approval TOCTOU via mutable symlink cwd target on node hostCVE-2026-32064Highopenclaw: OpenClaw's andbox browser noVNC observer lacked VNC authenticationCVE-2026-32027Highopenclaw: OpenClaw DM pairing-store identities could satisfy group allowlist authorizationCVE-2026-32023Mediumopenclaw: OpenClaw's dispatch-wrapper depth-cap mismatch can bypass shell-wrapper approval gating in system.run allowlist modeCVE-2026-32053Mediumopenclaw: OpenClaw's voice-call Twilio webhook replay could bypass manager dedupe because normalized event IDs were randomized per parseCVE-2026-32022Mediumopenclaw: OpenClaw safeBins grep -e File Read Bypass (stdin-only policy bypass)GHSA-H656-5VCF-CM23Mediumopenclaw: OpenClaw: Unauthorized Telegram Senders Trigger Media Download and Disk Write Before Access CheckGHSA-9F72-QCPW-2HXCHighopenclaw: OpenClaw: Native prompt image auto-load did not honor tools.fs.workspaceOnly in sandboxed runsCVE-2026-22169Mediumopenclaw: OpenClaw's non-default safeBins sort configuration can bypass intended allowlist approval constraintsCVE-2026-32036Highopenclaw: OpenClaw has gateway plugin auth bypass via encoded dot-segment traversal in protected /api/channels pathsCVE-2026-32045Mediumopenclaw: OpenClaw's gateway tokenless Tailscale auth applied to HTTP routesCVE-2026-22171Mediumopenclaw: OpenClaw vulnerable to path traversal in Feishu media temp-file naming allows writes outside os.tmpdir()CVE-2026-32040Lowopenclaw: OpenClaw Vulnerable to HTML injection via unvalidated image MIME type in data-URL interpolationCVE-2026-32026Mediumopenclaw: Temporary path handling could write outside OpenClaw temp boundaryCVE-2026-32046Mediumopenclaw: OpenClaw: Chrome --no-sandbox disabled OS-level browser sandbox in sandbox browser containerCVE-2026-32037Highopenclaw: OpenClaw's MSTeams attachment redirect handling could bypass configured media host allowlistsCVE-2026-28393Highopenclaw: OpenClaw's hook transform module path allows traversal and arbitrary JavaScript module loadingCVE-2026-32000Highopenclaw: OpenClaw has command injection via Windows shell fallback in Lobster tool executionGHSA-QJ22-XQJR-V83VHighopenclaw: OpenClaw's Telegram message_reaction authorization bypass allows unauthorized system-event injectionCVE-2026-31992Mediumopenclaw: OpenClaw has allowlist exec-guard bypass via env -SCVE-2026-32016Mediumopenclaw: OpenClaw: macOS optional allowlist basename matching could bypass path-based policyCVE-2026-32003Highopenclaw: OpenClaw has system.run shell-wrapper env injection via SHELLOPTS/PS4 can bypass allowlist intent (RCE)CVE-2026-32014Highopenclaw: OpenClaw: Node reconnect metadata spoofing could bypass platform-based node command policy

Stop the waste.
Protect your environment with Kodem.