openclaw vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-26316Highopenclaw: OpenClaw BlueBubbles webhook auth bypass via loopback proxy trustGHSA-G27F-9QJV-22PMLowopenclaw: OpenClaw log poisoning (indirect prompt injection) via WebSocket headersCVE-2026-28450Mediumopenclaw: OpenClaw's unauthenticated Nostr profile HTTP endpoints allow remote profile/config tamperingCVE-2026-28467Mediumopenclaw: OpenClaw affected by SSRF via attachment/media URL hydrationCVE-2026-25474Highopenclaw: OpenClaw has a Telegram webhook request forgery (missing `channels.telegram.webhookSecret`) → auth bypassCVE-2026-24764Lowopenclaw: OpenClaw Affected by Remote Code Execution via System Prompt Injection in Slack Channel DescriptionsCVE-2026-29613Highopenclaw: OpenClaw has a webhook auth bypass when gateway is behind a reverse proxy (loopback remoteAddress trust)GHSA-56F2-HVWG-5743Highopenclaw: OpenClaw affected by SSRF in Image Tool Remote FetchCVE-2026-28395Mediumopenclaw: OpenClaw's Chrome extension relay binds publicly due to wildcard treated as loopbackCVE-2026-28470Highopenclaw: OpenClaw has an exec allowlist bypass via command substitution/backticks inside double quotesCVE-2026-28458Highopenclaw: OpenClaw's Browser Relay /cdp websocket is missing auth which could allow cross-tab cookie accessCVE-2026-28391Highopenclaw: OpenClaw's Windows cmd.exe parsing may bypass exec allowlist/approval gatingCVE-2026-28459Highopenclaw: OpenClaw has an arbitrary transcript path file write via gateway sessionFileGHSA-HV93-R4J3-Q65FHighopenclaw: OpenClaw Hook Session Key Override Enables Targeted Cross-Session RoutingCVE-2026-28472Criticalopenclaw: OpenClaw's gateway connect could skip device identity checks when auth.token was present but not yet validatedCVE-2026-25593Highopenclaw: OpenClaw vulnerable to Unauthenticated Local RCE via WebSocket config.applyCVE-2026-25475Mediumopenclaw: OpenClaw Vulnerable to Local File Inclusion via MEDIA: Path Extraction

Stop the waste.
Protect your environment with Kodem.