openclaw vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
GHSA-X3H8-JRGH-P8JXMediumopenclaw: OpenClaw's exec allowlist analysis rejects shell expansion in unquoted heredocsCVE-2026-44118Highopenclaw: OpenClaw: MCP loopback owner context is derived from server-issued bearer tokensCVE-2026-45003Mediumopenclaw: OpenClaw: Workspace dotenv files cannot override connector endpoint hostsCVE-2026-44997Mediumopenclaw: OpenClaw's ACP child sessions inherit subagent security envelope constraintsCVE-2026-44116Mediumopenclaw: OpenClaw validates Zalo outbound photo URLs through the SSRF guardCVE-2026-41358Lowopenclaw: OpenClaw: Slack thread context could include messages from non-allowlisted sendersGHSA-GFG9-5357-HV4CMediumopenclaw: OpenClaw: Webchat audio embedding could read local files without local-root containmentCVE-2026-44991Mediumopenclaw: OpenClaw: Owner-enforced commands could accept wildcard channel senders as command ownersGHSA-7JM2-G593-4QRCMediumopenclaw: OpenClaw: Agent gateway config mutations could change protected operator settingsGHSA-QRP5-GFW2-GXV4Mediumopenclaw: OpenClaw: Bundled MCP/LSP tools could bypass configured tool policyCVE-2026-44992Mediumopenclaw: OpenClaw: Workspace dotenv MiniMax host override could redirect credentialed requestsGHSA-J4C5-89F5-F3PMLowopenclaw: OpenClaw: Browser CDP profile creation skipped strict-mode SSRF checksGHSA-XRQ9-JM7V-G9H7Lowopenclaw: OpenClaw: Paired-device pairing actions were not limited to the caller deviceCVE-2026-44117Mediumopenclaw: OpenClaw: QQBot direct media upload skipped URL SSRF validationCVE-2026-44995Mediumopenclaw: OpenClaw: MCP stdio server env could load dangerous startup variables from workspace configCVE-2026-44999Lowopenclaw: OpenClaw: Isolated cron awareness events were recorded as trusted system eventsCVE-2026-44114Highopenclaw: OpenClaw: Workspace dotenv could override runtime-control environment variablesGHSA-72Q8-JCMC-97WXMediumopenclaw: OpenClaw: Feishu card actions could misclassify DMs and skip dmPolicyCVE-2026-41908Lowopenclaw: OpenClaw: Assistant media route missed scope enforcement for trusted-proxy authorizationCVE-2026-45002Mediumopenclaw: OpenClaw: Hook mapping templates could bypass hook session-key opt-inGHSA-F934-5RQF-XX47Mediumopenclaw: OpenClaw: QMD memory_get restricts reads to canonical or indexed memory pathsCVE-2026-41389Mediumopenclaw: OpenClaw: Webchat media embedding enforces local-root containment for tool-result filesCVE-2026-44109Criticalopenclaw: OpenClaw: Feishu webhook and card-action validation now fail closedCVE-2026-44110Highopenclaw: OpenClaw: Matrix room control-command authorization no longer trusts DM pairing-store entriesCVE-2026-43585Criticalopenclaw: OpenClaw: Gateway HTTP endpoints re-resolve bearer auth after SecretRef rotation

Stop the waste.
Protect your environment with Kodem.