openclaw vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-43576Mediumopenclaw: OpenClaw: CDP /json/version WebSocket URL could pivot to untrusted second-hop targetsCVE-2026-42438Mediumopenclaw: OpenClaw: Sender policy bypass in host media attachment reads allows unauthorized local file disclosureCVE-2026-43533Highopenclaw: OpenClaw: QQBot media tags could read arbitrary local files through reply textCVE-2026-43530Highopenclaw: OpenClaw: busybox and toybox applet execution weakened exec approval bindingCVE-2026-42433Highopenclaw: OpenClaw: Matrix profile config persistence was reachable from operator.write message toolsCVE-2026-42434Highopenclaw: OpenClaw: Sandboxed agents could escape exec routing via host=node overrideCVE-2026-43580Mediumopenclaw: OpenClaw: Browser press/type interaction routes missed complete navigation guard coverageGHSA-QMWG-QPRG-3J38Mediumopenclaw: OpenClaw: Browser interaction routes could pivot into local CDP and regain file readsCVE-2026-43569Highopenclaw: OpenClaw: Workspace provider auth choices could auto-enable untrusted provider pluginsCVE-2026-43573Mediumopenclaw: OpenClaw: Existing-session browser interaction routes bypassed SSRF policy enforcementCVE-2026-42439Mediumopenclaw: OpenClaw: Browser tabs action select and close routes bypassed SSRF policyGHSA-F3H5-H452-VP3JMediumopenclaw: OpenClaw: Nostr profile mutation routes allowed operator.write config persistenceGHSA-525J-HQQ2-66R4Highopenclaw: OpenClaw: Sandbox browser CDP relay could expose DevTools protocol on 0.0.0.0CVE-2026-43571Highopenclaw: OpenClaw: Channel setup catalog lookups could include untrusted workspace plugin shadowsCVE-2026-43567Mediumopenclaw: OpenClaw: screen_record outPath bypassed workspace-only filesystem guardCVE-2026-43527Mediumopenclaw: OpenClaw: Browser SSRF policy default allowed private-network navigationCVE-2026-43582Mediumopenclaw: OpenClaw: Browser SSRF hostname validation could be bypassed by DNS rebindingCVE-2026-43526Mediumopenclaw: OpenClaw: QQBot reply media URL handling could trigger SSRF and re-upload fetched bytesCVE-2026-43531Mediumopenclaw: OpenClaw: Workspace .env could inject OpenClaw runtime-control variablesCVE-2026-43532Mediumopenclaw: OpenClaw: Discord event cover images bypassed sandbox media normalizationCVE-2026-43574Mediumopenclaw: OpenClaw: Empty approver lists could grant explicit approval authorizationCVE-2026-43534Mediumopenclaw: OpenClaw: Agent hook events could enqueue trusted system events from unsanitized external inputCVE-2026-43584Highopenclaw: OpenClaw: Exec environment denylist missed high-risk interpreter startup variablesCVE-2026-42435Mediumopenclaw: OpenClaw: Shell-wrapper detection missed env-argv assignment injection formsCVE-2026-43568Mediumopenclaw: OpenClaw: Memory dreaming config persistence was reachable from operator.write commands

Stop the waste.
Protect your environment with Kodem.