openclaw vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-53844Mediumopenclaw: OpenClaw: memory-wiki shared search could miss session visibility checksCVE-2026-53856Mediumopenclaw: OpenClaw: Config recovery could restore openclaw.json with broad file permissionsCVE-2026-53857Highopenclaw: OpenClaw: Zalo allowFrom could bind to mutable display namesCVE-2026-53845Lowopenclaw: OpenClaw: Skill-command dispatch could skip before-tool-call hooksCVE-2026-53847Mediumopenclaw: OpenClaw: Active Memory write scope could mutate global configCVE-2026-53841Mediumopenclaw: OpenClaw: Exported session HTML could keep unsafe markdown linksCVE-2026-53851Mediumopenclaw: OpenClaw: Slack reaction events could ignore reaction notification settingsCVE-2026-53862Lowopenclaw: OpenClaw: Bootstrap token replay could widen pending pairing scopesCVE-2026-53855Highopenclaw: OpenClaw: Shell positional parameters could weaken strict inline-eval checksCVE-2026-53859Mediumopenclaw: OpenClaw: Hostname checks could treat trailing-dot hosts inconsistentlyCVE-2026-53848Lowopenclaw: OpenClaw: Exec allowlist could miss side effects from transparent command wrappersCVE-2026-53861Mediumopenclaw: OpenClaw: macOS Swift exec allowlist missed combined POSIX inline flagsCVE-2026-53863Mediumopenclaw: OpenClaw: Tool group policy callers could accept unvalidated group IDsCVE-2026-53842Highopenclaw: OpenClaw: Workspace .env CLOUDSDK_PYTHON could influence Gmail setup gcloud executionCVE-2026-53866Highopenclaw: OpenClaw: Shell inline-command parsing could miss an allowlist checkCVE-2026-53843Highopenclaw: OpenClaw: Pairing-scoped device session could restore revoked node token authorityCVE-2026-53864Highopenclaw: OpenClaw: Host environment sanitizer missed two Node.js control variablesCVE-2026-53840Highopenclaw: OpenClaw: MCP Streamable HTTP redirects could forward configured custom headers to another originGHSA-CWJ3-VQPP-PMXRHighopenclaw: OpenClaw's gateway config mutation guard allowed unsafe model-driven config writesCVE-2026-45004Highopenclaw: OpenClaw vulnerable to arbitrary code execution via attacker-controlled setup-api.js loaded from cwd during env-key resolutionCVE-2026-45005Mediumopenclaw: OpenClaw's Webhooks SecretRef route secret remains valid after rotation/reloadCVE-2026-43570Mediumopenclaw: OpenClaw contains a symlink traversal vulnerabilityGHSA-93RG-2XM5-2P9VMediumopenclaw: OpenClaw's Gateway Control UI bootstrap config required Gateway authCVE-2026-44113Mediumopenclaw: OpenClaw: OpenShell FS bridge reads pin and verify the opened file before returning bytesCVE-2026-44112Mediumopenclaw: OpenClaw: OpenShell FS bridge writes stay pinned to the sandbox mount root

Stop the waste.
Protect your environment with Kodem.