OsVault/npm/clawdbot
npm

clawdbot

11 known vulnerabilities · 0 critical · 0 high

CVE-2026-28452

OpenClaw affected by denial of service through unguarded archive extraction allowing high expansion/resource abuse (ZIP/TAR)

Published Feb 18, 2026
CVE-2026-29612

OpenClaw: denial of service through large base64 media files allocating large buffers before limit checks

Published Feb 18, 2026
CVE-2026-26317

OpenClaw affected by cross-site request forgery (CSRF) through loopback browser mutation endpoints

Published Feb 18, 2026
CVE-2026-25253

OpenClaw/Clawdbot has 1-Click RCE via Authentication Token Exfiltration From gatewayUrl

Published Feb 2, 2026
CVE-2026-24763

OpenClaw/Clawdbot Docker Execution has Authenticated Command Injection via PATH Environment Variable

Published Feb 2, 2026
CVE-2026-26328

OpenClaw iMessage group allowlist authorization inherited DM pairing-store identities

Published Feb 18, 2026
CVE-2026-28480

OpenClaw Telegram allowlist authorization accepted mutable usernames

Published Feb 18, 2026
CVE-2026-28469

OpenClaw Google Chat shared-path webhook target ambiguity allowed cross-account policy-context misrouting

Published Feb 18, 2026
GHSA-chm2-m3w2-wcxm

OpenClaw Google Chat spoofing access with allowlist authorized mutable email principal despite sender-ID mismatch

Published Feb 17, 2026
CVE-2026-25157

OpenClaw/Clawdbot has OS Command Injection via Project Root Path in sshNodeCommand

Published Feb 2, 2026
GHSA-r2c6-8jc8-g32w

Duplicate Advisory: 1-Click RCE via Authentication Token Exfiltration From gatewayUrl

Published Feb 2, 2026
Check your entire dependency tree at onceRun dependency scan →