openclaw vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-43572Lowopenclaw: OpenClaw: Microsoft Teams SSO invoke handler missed sender authorization checksCVE-2026-43583Lowopenclaw: OpenClaw: Delivery queue recovery could lose group tool-policy context for media replayGHSA-G375-H3V6-4873Mediumopenclaw: OpenClaw: Heartbeat owner downgrade missed local async exec completion eventsCVE-2026-42437Highopenclaw: OpenClaw: Voice-call realtime WebSocket accepted oversized framesCVE-2026-43566Mediumopenclaw: OpenClaw: Heartbeat owner downgrade missed untrusted webhook wake eventsCVE-2026-42436Mediumopenclaw: OpenClaw: Browser snapshot and screenshot routes could expose internal page content after navigationCVE-2026-43528Highopenclaw: OpenClaw: config.get redaction bypass through sourceConfig and runtimeConfig aliasesCVE-2026-43535Mediumopenclaw: OpenClaw: Collect-mode queue batches could reuse the last sender authorization contextGHSA-92JP-89MQ-4374Mediumopenclaw: OpenClaw: Sandbox noVNC helper route exposed interactive browser session credentialsCVE-2026-43529Lowopenclaw: OpenClaw: TOCTOU read in exec script preflightCVE-2026-6011Lowopenclaw: OpenClaw vulnerable to SSRF in src/agents/tools/web-fetch.tsCVE-2026-41915Lowopenclaw: OpenClaw: GIT_DIR and related git plumbing env vars missing from exec env denylist (GHSA-m866-6qv5-p2fg variant)CVE-2026-42420Mediumopenclaw: OpenClaw: Multiple Code Paths Missing Base64 Pre-Allocation Size ChecksCVE-2026-42428Mediumopenclaw: OpenClaw B-M3: ClawHub package downloads are not enforced with integrity verificationCVE-2026-40037Highopenclaw: OpenClaw: `fetchWithSsrFGuard` replays unsafe request bodies across cross-origin redirectsGHSA-W9J9-W4CP-6WGRMediumopenclaw: OpenClaw Host-Exec Environment Variable InjectionCVE-2026-42430Mediumopenclaw: OpenClaw: Strict browser SSRF bypass in Playwright redirect handling leaves private targets reachableCVE-2026-42429Lowopenclaw: OpenClaw: Gateway plugin HTTP `auth: gateway` widens identity-bearing `operator.read` requests into runtime `operator.write`CVE-2026-41912Mediumopenclaw: OpenClaw has Browser SSRF Policy Bypass via Interaction-Triggered NavigationCVE-2026-42426Mediumopenclaw: OpenClaw `node.pair.approve` placed in `operator.write` scope instead of `operator.pairing` allows unprivileged pairing approvalCVE-2026-41911Lowopenclaw: OpenClaw: Feishu docx upload_file/upload_image Bypasses Workspace-Only Filesystem Policy (GHSA-qf48-qfv4-jjm9 Incomplete Fix)CVE-2026-41914Mediumopenclaw: OpenClaw QQ Bot Extension missing SSRF Protection on All Media Fetch PathsCVE-2026-42421Mediumopenclaw: OpenClaw: Existing WS sessions survive shared gateway token rotationCVE-2026-41913Lowopenclaw: OpenClaw: Concurrent async auth attempts can bypass the intended shared-secret rate-limit budget on Tailscale-capable pathsCVE-2026-42432Highopenclaw: OpenClaw: Node Pairing Reconnect Command Escalation Bypasses operator.admin Scope Requirement

Stop the waste.
Protect your environment with Kodem.