OsVault/npm/openclaw
npm

openclaw

581 known vulnerabilities · 0 critical · 2 high

GHSA-2qrv-rc5x-2g2h

OpenClaw: Untrusted workspace channel shadows could execute during built-in channel setup

Published Apr 7, 2026
CVE-2026-32064

OpenClaw's andbox browser noVNC observer lacked VNC authentication

Published Mar 3, 2026
CVE-2026-28452

OpenClaw affected by denial of service through unguarded archive extraction allowing high expansion/resource abuse (ZIP/TAR)

Published Feb 18, 2026
GHSA-25wv-8phj-8p7r

OpenClaw: Concurrent async auth attempts can bypass the intended shared-secret rate-limit budget on Tailscale-capable paths

Published Apr 9, 2026
GHSA-2767-2q9v-9326

OpenClaw: QQBot reply media URL handling could trigger SSRF and re-upload fetched bytes

Published Apr 17, 2026
GHSA-7qf6-h84j-8fq4

OpenClaw: Microsoft Teams media fetch paths bypass shared SSRF guard model

Published Mar 3, 2026
CVE-2026-32061

OpenClaw vulnerable to arbitrary file read via $include directive

Published Mar 3, 2026
GHSA-58q2-7r52-jq62

OpenClaw: Path traversal via inbound channel attachment path in ACP dispatch allows arbitrary file read

Published Apr 3, 2026
GHSA-2ch6-x3g4-7759

OpenClaw's commands.allowFrom sender authorization accepted conversation identifiers via ctx.From

Published Mar 3, 2026
GHSA-2cq5-mf3v-mx44

OpenClaw: busybox and toybox applet execution weakened exec approval binding

Published Apr 17, 2026
CVE-2026-32003

OpenClaw has system.run shell-wrapper env injection via SHELLOPTS/PS4 can bypass allowlist intent (RCE)

Published Mar 3, 2026
GHSA-ccx3-fw7q-rr2r

OpenClaw: Multiple Code Paths Missing Base64 Pre-Allocation Size Checks

Published Apr 9, 2026
GHSA-6pfc-6m7w-m8fx

OpenClaw has a gateway exec allowlist allow-always bypass via unregistered /usr/bin/script wrapper

Published Mar 31, 2026
CVE-2026-27001

OpenClaw: Unsanitized CWD path injection into LLM prompts

Published Feb 18, 2026
GHSA-534w-2vm4-89xr

OpenClaw's Zalo group sender allowlist bypass permits unauthorized GROUP dispatch

Published Mar 3, 2026
GHSA-2rqg-gjgv-84jm

OpenClaw: Gateway `agent` calls could override the workspace boundary

Published Mar 13, 2026
GHSA-3298-56p6-rpw2

OpenClaw has incomplete Fix for CVE-2026-27486: Unvalidated SIGKILL in `!stop` Chat Command via `shell-utils.ts`

Published Mar 30, 2026
GHSA-g87j-gm7p-6vw2

Duplicate Advisory: OpenClaw's Node system.run approval hardening wrapper semantic drift can execute unintended local scripts

Published Mar 19, 2026
GHSA-2w79-r9g8-wmcr

OpenClaw: Voice-call still parses large WebSocket frames before start validation (Incomplete fix for CVE-2026-32062)

Published Apr 3, 2026
GHSA-7jp6-r74r-995q

OpenClaw: Matrix profile config persistence was reachable from operator.write message tools

Published Apr 17, 2026
GHSA-89r3-6x4j-v7wf

OpenClaw: Voice-call Plivo replay mutates in-process callback origin before replay rejection

Published Apr 2, 2026
GHSA-63f5-hhc7-cx6p

OpenClaw bootstrap setup codes could be replayed to escalate pending pairing scopes before approval

Published Mar 16, 2026
GHSA-h97f-6pqj-q452

OpenClaw has a IPv6 multicast SSRF classifier bypass

Published Mar 3, 2026
CVE-2026-22177

OpenClaw's config env vars allowed startup env injection into service runtime

Published Mar 3, 2026
GHSA-939r-rj45-g2rj

OpenClaw: Workspace provider auth choices could auto-enable untrusted provider plugins

Published Apr 17, 2026
GHSA-jjw7-3vjf-fg5j

OpenClaw Nostr privateKey config redaction bypass leaks plaintext signing key via config.get

Published Apr 2, 2026
CVE-2026-32033

OpenClaw has a workspace-only sandbox guard mismatch for @-prefixed absolute paths

Published Mar 3, 2026
GHSA-hf68-49fm-59cq

OpenClaw Gateway: RCE and Privilege Escalation from operator.pairing to operator.admin via device.pair.approve

Published Mar 26, 2026
GHSA-52vj-fvrv-7q82

OpenClaw vulnerable to SSRF in src/agents/tools/web-fetch.ts

Published Apr 10, 2026
CVE-2026-29607

OpenClaw's allow-always wrapper persistence could bypass future approvals and enable command execution

Published Mar 2, 2026
CVE-2026-26316

OpenClaw BlueBubbles webhook auth bypass via loopback proxy trust

Published Feb 17, 2026
GHSA-hv93-r4j3-q65f

OpenClaw Hook Session Key Override Enables Targeted Cross-Session Routing

Published Feb 17, 2026
CVE-2026-22176

OpenClaw has a Command Injection via unescaped environment assignments in Windows Scheduled Task script generation

Published Mar 3, 2026
GHSA-4jpw-hj22-2xmc

OpenClaw: Pairing-scoped device tokens could mint `operator.admin` and reach node RCE

Published Mar 13, 2026
GHSA-fvx6-pj3r-5q4q

OpenClaw's complex interpreter pipelines could skip exec script preflight validation

Published Apr 6, 2026
CVE-2026-28395

OpenClaw's Chrome extension relay binds publicly due to wildcard treated as loopback

Published Feb 17, 2026
GHSA-2858-xg23-26fp

OpenClaw: Node camera URL payload host-binding bypass allowed gateway fetch pivots

Published Mar 3, 2026
GHSA-m866-6qv5-p2fg

OpenClaw host-env blocklist missing `GIT_TEMPLATE_DIR` and `AWS_CONFIG_FILE` allows code execution via env override

Published Mar 31, 2026
GHSA-rf75-g96h-j3rm

Duplicate Advisory: OpenClaw's complex interpreter pipelines could skip exec script preflight validation

Published Apr 2, 2026
GHSA-r849-826x-wgqm

Duplicate Advisory: Signal group allowlist authorization bypass via DM pairing-store leakage

Published Mar 19, 2026
CVE-2026-32055

OpenClaw: workspace path guard bypass on non-existent out-of-root symlink leaf

Published Mar 12, 2026
GHSA-mhr7-2xmv-4c4q

OpenClaw: HTTP operator endpoints lack browser-origin validation in trusted-proxy mode

Published Apr 3, 2026
GHSA-767m-xrhc-fxm7

OpenClaw: Gateway operator.write Can Reach Admin-Class Telegram Config and Cron Persistence via send

Published Apr 7, 2026
CVE-2026-28482

OpenClaw's unsanitized session ID enables path traversal in transcript file operations

Published Feb 18, 2026
GHSA-39pp-xp36-q6mg

OpenClaw has Inconsistent Host Exec Environment Override Sanitization

Published Mar 26, 2026
CVE-2026-28363

OpenClaw's tools.exec.safeBins sort long-option abbreviation bypass can skip exec approval in allowlist mode

Published Mar 3, 2026
CVE-2026-28446

OpenClaw has an inbound allowlist policy bypass in voice-call extension (empty caller ID + suffix matching)

Published Feb 17, 2026
GHSA-rxmx-g7hr-8mx4

OpenClaw: Zalo replay dedupe keys could suppress messages across chats or senders

Published Apr 7, 2026
CVE-2026-28486

OpenClaw vulnerable to path traversal (Zip Slip) in archive extraction during explicit installation commands

Published Mar 2, 2026
CVE-2026-32000

OpenClaw has command injection via Windows shell fallback in Lobster tool execution

Published Mar 3, 2026
GHSA-3fv3-6p2v-gxwj

OpenClaw QQ Bot Extension missing SSRF Protection on All Media Fetch Paths

Published Apr 9, 2026
CVE-2026-26319

OpenClaw is Missing Webhook Authentication in Telnyx Provider Allows Unauthenticated Requests

Published Feb 17, 2026
GHSA-3h2q-j2v4-6w5r

OpenClaw's system.run allowlist approval parsing missed PowerShell encoded-command wrappers

Published Mar 9, 2026
CVE-2026-32053

OpenClaw's voice-call Twilio webhook replay could bypass manager dedupe because normalized event IDs were randomized per parse

Published Mar 3, 2026
CVE-2026-32019

OpenClaw has incomplete IPv4 special-use SSRF blocking in web fetch guard

Published Mar 4, 2026
CVE-2026-28470

OpenClaw has an exec allowlist bypass via command substitution/backticks inside double quotes

Published Feb 17, 2026
GHSA-9gp8-hjxr-6f34

OpenClaw: Host exec environment overrides miss proxy, TLS, Docker, and Git TLS controls

Published Apr 3, 2026
GHSA-9hjh-fr4f-gxc4

OpenClaw: Gateway Backend Reconnect lets Non-Admin Operator Scopes Self-Claim operator.admin

Published Mar 27, 2026
CVE-2026-32052

OpenClaw's system.run shell-wrapper positional argv carriers could execute hidden commands under misleading approval text

Published Mar 3, 2026
GHSA-3jx4-q2m7-r496

OpenClaw: Hardlink alias checks could bypass workspace-only file boundaries in specific configurations

Published Mar 4, 2026
CVE-2026-32046

OpenClaw: Chrome --no-sandbox disabled OS-level browser sandbox in sandbox browser container

Published Mar 3, 2026
GHSA-392f-ggf5-fp3c

OpenClaw: Unicode canonicalization drift in node metadata policy classification could broaden node allowlists

Published Mar 2, 2026
GHSA-9p93-7j67-5pc2

OpenClaw: Gateway HTTP /sessions/:sessionKey/kill Reaches Admin Kill Path Without Caller Scope Binding

Published Mar 27, 2026
GHSA-68v4-hmwv-f43h

OpenClaw: Media download follows cross-origin redirects with Authorization headers intact

Published Apr 3, 2026
CVE-2026-25474

OpenClaw has a Telegram webhook request forgery (missing `channels.telegram.webhookSecret`) → auth bypass

Published Feb 17, 2026
CVE-2026-27002

OpenClaw: Docker container escape via unvalidated bind mount config injection

Published Feb 18, 2026
GHSA-3pm9-5j7m-59vc

OpenClaw: Tlon Startup Migration Rehydrates Empty-Array Revocations From File Config

Published Apr 3, 2026
CVE-2026-28450

OpenClaw's unauthenticated Nostr profile HTTP endpoints allow remote profile/config tampering

Published Feb 17, 2026
GHSA-8883-9w57-vwv6

OpenClaw: Mattermost callback dispatch allowed non-allowlisted sender actions

Published Mar 26, 2026
CVE-2026-27488

OpenClaw hardened cron webhook delivery against SSRF

Published Feb 20, 2026
GHSA-3q42-xmxv-9vfr

OpenClaw: Gateway operator.write Can Reach Admin-Class Talk Voice Config Persistence via chat.send

Published Apr 7, 2026
GHSA-r7vr-gr74-94p8

OpenClaw: Command-authorized non-owners could reach owner-only `/config` and `/debug` surfaces

Published Mar 13, 2026
GHSA-536q-mj95-h29h

OpenClaw: Browser press/type interaction routes missed complete navigation guard coverage

Published Apr 17, 2026
GHSA-53vx-pmqw-863c

OpenClaw: Browser SSRF policy default allowed private-network navigation

Published Apr 17, 2026
CVE-2026-32895

OpenClaw: Slack system events bypass sender authorization in member and message subtype handlers

Published Mar 12, 2026
GHSA-2cwr-f5hx-gg3w

Duplicate Advisory: OpenClaw: stageSandboxMedia destination symlink traversal can overwrite files outside sandbox workspace

Published Mar 19, 2026
GHSA-9f79-7pw8-3fj8

Duplicate Advisory: OpenClaw: workspace path guard bypass on non-existent out-of-root symlink leaf

Published Mar 21, 2026
CVE-2026-29612

OpenClaw: denial of service through large base64 media files allocating large buffers before limit checks

Published Feb 18, 2026
GHSA-9gvx-vj57-vqqx

Duplicate Advisory: OpenClaw: Gateway Canvas local-direct requests bypass Canvas HTTP and WebSocket authentication

Published Apr 10, 2026
GHSA-3vvq-q2qc-7rmp

OpenClaw B-M3: ClawHub package downloads are not enforced with integrity verification

Published Apr 9, 2026
GHSA-3w6x-gv34-mqpf

OpenClaw's mutating internal ACP chat commands missed operator.admin scope enforcement

Published Mar 26, 2026
GHSA-qcj9-wwgw-6gm8

OpenClaw: Workspace `.env` can override the bundled plugin trust root

Published Apr 3, 2026
GHSA-5f7h-p83x-5vc2

Duplicate Advisory: OpenClaw: Nextcloud Talk room allowlist matched colliding room names instead of stable room tokens

Published Apr 10, 2026
GHSA-qj22-xqjr-v83v

OpenClaw's Telegram message_reaction authorization bypass allows unauthorized system-event injection

Published Mar 3, 2026
CVE-2026-29606

OpenClaw Twilio voice-call webhook auth bypass when ngrok loopback compatibility is enabled

Published Feb 18, 2026
CVE-2026-31991

OpenClaw has Signal group allowlist authorization bypass via DM pairing-store leakage

Published Mar 2, 2026
GHSA-wmgj-hrx3-23gj

Duplicate Advisory: OpenClaw: Unbound interpreter and runtime commands could bypass node-host approval integrity

Published Mar 29, 2026
CVE-2026-28471

OpenClaw has a Matrix allowlist bypass via displayName and cross-homeserver localpart matching

Published Feb 17, 2026
CVE-2026-28456

OpenClaw affected by potential code execution via unsafe hook module path handling in Gateway

Published Feb 18, 2026
GHSA-48vw-m3qc-wr99

OpenClaw's Trusted-proxy Control UI sessions retain privileged scopes without device identity on device-less allow paths

Published Mar 26, 2026
CVE-2026-27003

OpenClaw: Telegram bot token exposure via logs

Published Feb 18, 2026
CVE-2026-32039

OpenClaw's typed sender-key matching for toolsBySender prevents identity-collision policy bypass

Published Mar 3, 2026
GHSA-44c9-4rg5-qjgq

Duplicate Advisory: web_search citation redirect SSRF via private-network-allowing policy

Published Mar 19, 2026
CVE-2026-32008

OpenClaw browser navigation guard allowed non-network URL schemes, enabling authenticated browser-tool users to access file:// local files

Published Mar 3, 2026
CVE-2026-28475

OpenClaw: Config writes could persist resolved ${VAR} secrets to disk

Published Mar 2, 2026
GHSA-w7j5-j98m-w679

OpenClaw has multiple E2E/test Dockerfiles that run all processes as root

Published Mar 3, 2026
CVE-2026-28461

OpenClaw has unbounded memory growth in Zalo webhook via query-string key churn (unauthenticated DoS)

Published Mar 2, 2026
GHSA-wr92-6w3g-2hwc

Duplicate Advisory: OpenClaw's sandboxed sessions_spawn now enforces sandbox inheritance for cross-agent spawns

Published Mar 21, 2026
GHSA-f275-5h5c-5wg5

Duplicate Advisory: OpenClaw: /pair approve command path omitted caller scope subsetting and reopened device pairing escalation

Published Mar 31, 2026
CVE-2026-32005

OpenClaw: Slack interactive callbacks could skip configured sender checks in some shared-workspace flows

Published Mar 4, 2026
GHSA-7xr2-q9vf-x4r5

OpenClaw: Symlink Traversal via IDENTITY.md appendFile in agents.create/update (Incomplete Fix for CVE-2026-32013)

Published Mar 26, 2026
GHSA-fqrj-m88p-qf3v

OpenClaw: Zalo replay dedupe cache could suppress events across authenticated webhook targets

Published Apr 7, 2026
GHSA-fqw4-mph7-2vr8

OpenClaw: Silent privilege escalation via gateway shared-auth reconnect

Published Mar 27, 2026
GHSA-4hmj-39m8-jwc7

OpenClaw has ACP CLI approval prompt ANSI escape sequence injection

Published Mar 29, 2026
GHSA-g2hm-779g-vm32

OpenClaw: Heartbeat owner downgrade missed untrusted webhook wake events

Published Apr 17, 2026
GHSA-9wqx-g2cw-vc7r

OpenClaw: Matrix Verification Notices Bypass Matrix DM Policy and Reply to Unpaired DM Peers

Published Mar 27, 2026
CVE-2026-33574

OpenClaw's skills-install-download can be redirected outside the tools root by rebinding the validated base path

Published Mar 12, 2026
CVE-2026-32049

OpenClaw's inbound media downloads could exceed configured byte limits before rejection across multiple channels

Published Mar 2, 2026
GHSA-g374-mggx-p6xc

OpenClaw: Incomplete scope-clearing fix allows operator.admin escalation via trusted-proxy auth mode

Published Apr 3, 2026
GHSA-hhq4-97c2-p447

OpenClaw: Zalo webhook replay cache cross-target messageId scope bypass

Published Apr 2, 2026
CVE-2026-32015

OpenClaw's `tools.exec.safeBins` PATH-hijack allowed trojan binaries to bypass allowlist checks

Published Mar 3, 2026
GHSA-xh9j-mpc9-2m9p

Duplicate Advisory: OpenClaw has a Trusted-proxy Control UI pairing bypass which allows unpaired node sessions

Published Mar 21, 2026
GHSA-8689-gm9g-jgr6

OpenClaw: Voice-call Plivo V3 webhook replay key uses unsorted URL, allowing replay via query-parameter reordering

Published Mar 31, 2026
GHSA-gm9m-x74r-8whg

Duplicate Advisory: OpenClaw's Nextcloud Talk webhook missing rate limiting on shared secret authentication

Published Mar 31, 2026
GHSA-chfm-xgc4-47rj

OpenClaw: MSTeams thread history bypasses sender allowlist via Graph API

Published Apr 2, 2026
GHSA-cxmw-p77q-wchg

OpenClaw: Arbitrary code execution via unvalidated WebView JavascriptInterface

Published Mar 26, 2026
GHSA-jqpf-vj28-9v7r

Duplicate Advisory: Synology Chat dmPolicy=allowlist failed open on empty allowedUserIds, allowing unauthorized agent dispatch

Published Mar 19, 2026
GHSA-hr5v-j9h9-xjhg

OpenClaw has Sandbox Media Root Bypass via Unnormalized `mediaUrl` / `fileUrl` Parameter Keys (CWE-22)

Published Mar 30, 2026
CVE-2026-32065

OpenClaw: system.run approval identity mismatch could execute a different binary than displayed

Published Mar 2, 2026
GHSA-xxj4-96ph-g6j6

Duplicate Advisory: OpenClaw: Sandbox `writeFile` commit could race outside the validated path

Published Mar 31, 2026
GHSA-jj6q-rrrf-h66h

OpenClaw: Shared-secret comparison call sites leaked length information through timing

Published Apr 7, 2026
GHSA-66r7-m7xm-v49h

OpenClaw: QQBot media tags could read arbitrary local files through reply text

Published Apr 17, 2026
GHSA-57gh-m6rq-54cf

OpenClaw: Self-Whitelisting in appendLocalMediaParentRoots Allows Arbitrary File Read & Credential Exfiltration

Published Apr 3, 2026
GHSA-5847-rm3g-23mw

OpenClaw has hook auth rate limiter bypass via IPv4-mapped IPv6 client key variants

Published Mar 3, 2026
GHSA-cqgw-44wg-44rf

OpenClaw: Discord voice manager bypasses channel-level member access allowlist

Published Apr 3, 2026
CVE-2026-27004

OpenClaw session tool visibility hardening and Telegram webhook secret fallback

Published Feb 18, 2026
GHSA-j4c9-w69r-cw33

OpenClaw: Telegram DM-Scoped Inline Button Callbacks Bypass DM Pairing and Mutate Session State

Published Mar 29, 2026
GHSA-mf5g-6r6f-ghhm

OpenClaw: Synology Chat Webhook Pre-Auth Rate-Limit Bypass Enables Brute-Force Guessing of Webhook Token

Published Mar 29, 2026
CVE-2026-32021

OpenClaw has a Feishu allowFrom authorization bypass via display-name collision

Published Mar 3, 2026
GHSA-xgwg-m42c-8q62

Duplicate Advisory: OpenClaw: Slack system events bypass sender authorization in member and message subtype handlers

Published Mar 21, 2026
GHSA-j56c-wpqm-h24x

Duplicate Advisory: OpenClaw: Plivo V2 verified replay identity drifts on query-only variants

Published Apr 10, 2026
GHSA-5r8f-96gm-5j6g

OpenClaw Gateway `operator.write` can reach admin-only session reset via `chat.send` `/reset`

Published Apr 1, 2026
GHSA-mj4p-rc52-m843

OpenClaw: Sandbox staged writes could escape the verified parent directory before commit

Published Mar 13, 2026
CVE-2026-32302

OpenClaw: Untrusted web origins can obtain authenticated operator.admin access in trusted-proxy mode

Published Mar 12, 2026
GHSA-5gjc-grvm-m88j

OpenClaw: Memory dreaming config persistence was reachable from operator.write commands

Published Apr 17, 2026
GHSA-736r-jwj6-4w23

OpenClaw: Sandboxed agents could escape exec routing via host=node override

Published Apr 17, 2026
GHSA-xq3g-m3j8-2vmm

Duplicate Advisory: OpenClaw's inbound media downloads could exceed configured byte limits before rejection across multiple channels

Published Mar 21, 2026
GHSA-m6fx-m8hc-572m

OpenClaw: Telegram audio preflight transcription enables resource consumption by unauthorized senders

Published Apr 3, 2026
GHSA-7g8c-cfr3-vqqr

OpenClaw: Agent hook events could enqueue trusted system events from unsanitized external input

Published Apr 17, 2026
GHSA-h43v-27wg-5mf9

OpenClaw: Forged Nostr DMs could create pairing state before signature verification

Published Apr 7, 2026
CVE-2026-27524

OpenClaw's runtime /debug override path accepted prototype-reserved keys

Published Mar 3, 2026
GHSA-hfpr-jhpq-x4rm

OpenClaw: `operator.write` chat.send could reach admin-only config writes

Published Mar 9, 2026
CVE-2026-32020

OpenClaw's Control UI Static File Handler Follows Symlinks and Allows Out-of-Root File Read

Published Mar 2, 2026
GHSA-5h2w-qmfp-ggp6

OpenClaw: Gateway `operator.write` can reach admin-only persisted `verboseLevel` via `chat.send` `/verbose`

Published Mar 31, 2026
GHSA-5hff-46vh-rxmw

OpenClaw: Read-scoped identity-bearing HTTP clients could kill sessions via /sessions/:sessionKey/kill

Published Apr 7, 2026
CVE-2026-28459

OpenClaw has an arbitrary transcript path file write via gateway sessionFile

Published Feb 17, 2026
CVE-2026-27008

OpenClaw hardened the skill download target directory validation

Published Feb 18, 2026
GHSA-pw7h-9g6p-c378

OpenClaw: Tlon settings empty-allowlist reconciliation bypassed intended revocation

Published Mar 26, 2026
CVE-2026-32896

OpenClaw: BlueBubbles beta plugin webhook auth hardening (remove passwordless fallback)

Published Mar 3, 2026
CVE-2026-32978

OpenClaw: Unrecognized script runners could bypass `system.run` approval integrity

Published Mar 13, 2026
GHSA-qf48-qfv4-jjm9

OpenClaw: Feishu extension resolveUploadInput bypasses file-system sandbox and allows arbitrary file reads via upload_image

Published Mar 31, 2026
GHSA-pg8g-f2hf-x82m

Duplicate Advisory: OpenClaw: `fetchWithSsrFGuard` replays unsafe request bodies across cross-origin redirects

Published Apr 9, 2026
GHSA-3r78-rqg8-95gg

Duplicate Advisory: OpenClaw's voice-call Twilio webhook replay could bypass manager dedupe because normalized event IDs were randomized per parse

Published Mar 21, 2026
GHSA-94pw-c6m8-p9p9

OpenClaw: Gateway operator.write Can Reach Admin-Class Channel Allowlist Persistence via chat.send

Published Mar 30, 2026
CVE-2026-4040

OpenClaw safeBins file-existence oracle information disclosure

Published Feb 19, 2026
CVE-2026-27670

OpenClaw: ZIP extraction race could write outside destination via parent symlink rebind

Published Mar 3, 2026
GHSA-m34q-h93w-vg5x

OpenClaw: OpenShell mirror mode could delete arbitrary remote directories when roots were mis-scoped

Published Apr 7, 2026
GHSA-7wv4-cc7p-jhxc

OpenClaw: Workspace .env could inject OpenClaw runtime-control variables

Published Apr 17, 2026
GHSA-r3v5-2grc-429h

Duplicate Advisory: OpenClaw Gateway: RCE and Privilege Escalation from operator.pairing to operator.admin via device.pair.approve

Published Apr 10, 2026
GHSA-82gw-wqw6-r2cf

Duplicate Advisory: Command Injection via unescaped environment assignments in Windows Scheduled Task script generation

Published Mar 19, 2026
GHSA-82qx-6vj7-p8m2

OpenClaw: Channel setup catalog lookups could include untrusted workspace plugin shadows

Published Apr 17, 2026
CVE-2026-22168

OpenClaw has Windows system.run approval mismatch on cmd.exe /c trailing arguments

Published Mar 2, 2026
CVE-2026-32014

OpenClaw: Node reconnect metadata spoofing could bypass platform-based node command policy

Published Mar 3, 2026
GHSA-mhgq-xpfq-6r66

OpenClaw: Unauthenticated plugin-auth HTTP routes receive operator runtime scopes

Published Apr 2, 2026
GHSA-5wj5-87vq-39xm

OpenClaw: Node Pairing Reconnect Command Escalation Bypasses operator.admin Scope Requirement

Published Apr 9, 2026
GHSA-6336-qqw9-v6x6

OpenClaw: Discord Component Interaction Misclassifies Group DM as Direct Message

Published Apr 3, 2026
CVE-2026-31994

OpenClaw Windows Scheduled Task script generation allowed local command injection via unsafe cmd argument handling

Published Mar 3, 2026
GHSA-q2qc-744p-66r2

OpenClaw: `session_status` sessionId resolution bypasses sandboxed session-tree visibility

Published Mar 29, 2026
GHSA-p6j4-wvmc-vx2h

Duplicate Advisory: OpenClaw: Tlon cite expansion happens before channel and DM authorization is complete

Published Apr 10, 2026
GHSA-8372-7vhw-cm6q

OpenClaw: config.get redaction bypass through sourceConfig and runtimeConfig aliases

Published Apr 17, 2026
CVE-2026-32017

OpenClaw exec allowlist safeBins short-option bypass could permit arbitrary file write

Published Mar 3, 2026
GHSA-67mf-f936-ppxf

OpenClaw `node.pair.approve` placed in `operator.write` scope instead of `operator.pairing` allows unprivileged pairing approval

Published Apr 9, 2026
CVE-2026-32023

OpenClaw's dispatch-wrapper depth-cap mismatch can bypass shell-wrapper approval gating in system.run allowlist mode

Published Mar 3, 2026
GHSA-844j-xrrq-wgh4

OpenClaw: Forwarding header spoofing bypasses gateway.trustedProxies origin detection

Published Mar 26, 2026
GHSA-ch86-pxr9-j9h9

Duplicate Advisory: OpenClaw: Gemini OAuth exposed the PKCE verifier through the OAuth state parameter

Published Apr 3, 2026
CVE-2026-32001

OpenClaw's Node role device-identity bypass allows unauthorized node.event injection

Published Mar 3, 2026
CVE-2026-32024

OpenClaw's avatar symlink traversal can expose out-of-workspace local files

Published Mar 3, 2026
CVE-2026-28472

OpenClaw's gateway connect could skip device identity checks when auth.token was present but not yet validated

Published Feb 17, 2026
CVE-2026-27183

OpenClaw: system.run wrapper-depth boundary could skip shell approval gating

Published Mar 9, 2026
CVE-2026-32913

OpenClaw: fetch-guard forwards custom authorization headers across cross-origin redirects

Published Mar 9, 2026
GHSA-6p8r-6m93-557f

OpenClaw: Fake DeviceToken Bypasses Shared Auth Rate Limiting

Published Apr 3, 2026
GHSA-6q2v-vfwp-pvwh

Duplicate Advisory: OpenClaw's skills-install-download can be redirected outside the tools root by rebinding the validated base path

Published Mar 29, 2026
GHSA-rqp8-q22p-5j9q

OpenClaw Bypasses DM Policy Separation via Synology Chat Webhook Path Collision

Published Mar 26, 2026
GHSA-6rmx-gvvg-vh6j

OpenClaw's hooks count non-POST requests toward auth lockout

Published Mar 9, 2026
CVE-2026-32897

OpenClaw reuses the gateway auth token in the owner ID prompt hashing fallback

Published Mar 3, 2026
GHSA-6xg4-82hv-cp6f

OpenClaw: Gateway chat.send ACP-only provenance guard could be bypassed by client identity spoofing

Published Mar 31, 2026
GHSA-7437-7hg8-frrw

OpenClaw: HGRCPATH, CARGO_BUILD_RUSTC_WRAPPER, RUSTC_WRAPPER, and MAKEFLAGS missing from exec env denylist — RCE via build tool env injection (GHSA-cm8v-2vh9-cxf3 class)

Published Apr 9, 2026
CVE-2026-28467

OpenClaw affected by SSRF via attachment/media URL hydration

Published Feb 17, 2026
GHSA-wv46-v6xc-2qhf

OpenClaw: Synology Chat reply delivery could be rebound through username-based user resolution.

Published Mar 26, 2026
CVE-2026-32050

OpenClaw's Signal reaction-only status events could, in limited cases, be enqueued before access checks

Published Mar 3, 2026
CVE-2026-28451

OpenClaw has two SSRF via sendMediaFeishu and markdown image fetching in Feishu extension

Published Feb 18, 2026
CVE-2026-32037

OpenClaw's MSTeams attachment redirect handling could bypass configured media host allowlists

Published Mar 3, 2026
GHSA-7ff8-xjh3-mgh6

OpenClaw's non-default autoAllowSkills setting could bypass on-miss exec prompt

Published Mar 3, 2026
GHSA-7ggg-pvrf-458v

OpenClaw: PIP_INDEX_URL and UV_INDEX_URL bypass host exec env sanitization and redirect Python package-index traffic

Published Apr 2, 2026
GHSA-xq8g-hgh6-87hv

OpenClaw: BlueBubbles Webhook Missing Rate Limiting Enables Brute-Force Password Guessing

Published Mar 27, 2026
GHSA-wpc6-37g7-8q4w

OpenClaw: Shell init-file options could satisfy exec allowlist script matching

Published Apr 7, 2026
CVE-2026-32898

OpenClaw ACP client has permission auto-approval bypass via untrusted tool metadata

Published Feb 27, 2026
CVE-2026-26320

OpenClaw macOS deep link confirmation truncation can conceal executed agent message

Published Feb 17, 2026
CVE-2026-28457

OpenClaw's sandbox skill mirroring path traversal vulnerability could write outside the sandbox workspace

Published Mar 2, 2026
GHSA-w85g-3h6x-4xh2

OpenClaw: Image pixel-limit guard can fail open on sips and allow decompression-bomb DoS

Published Apr 3, 2026
CVE-2026-28481

OpenClaw MS Teams inbound attachment downloader leaks bearer tokens to allowlisted suffix domains

Published Feb 17, 2026
GHSA-2f7j-rp58-mr42

OpenClaw: Gateway hello snapshots exposed host config and state paths to non-admin clients

Published Apr 7, 2026
GHSA-xrgv-34cc-q765

Duplicate Advisory: OpenClaw's system.run allowlist bypass via shell line-continuation command substitution

Published Mar 19, 2026
GHSA-7xmq-g46g-f8pv

OpenClaw: Sandbox media TOCTOU could read files outside sandbox root

Published Mar 2, 2026
GHSA-2mc2-g238-722j

OpenClaw affected by iMessage remote attachment SCP hardening (strict host-key checks and remoteHost validation)

Published Mar 3, 2026
CVE-2026-32029

OpenClaw improperly parses X-Forwarded-For behind trusted proxies allows client IP spoofing in security decisions

Published Mar 3, 2026
CVE-2026-27007

OpenClaw's sandbox config hash sorted primitive arrays and suppressed needed container recreation

Published Feb 18, 2026
GHSA-943q-mwmv-hhvh

OpenClaw: Gateway /tools/invoke tool escalation + ACP permission auto-approval

Published Mar 2, 2026
CVE-2026-32026

Temporary path handling could write outside OpenClaw temp boundary

Published Mar 3, 2026
GHSA-866c-wwm5-4rj7

Duplicate Advisory: OpenClaw's Nextcloud Talk webhook replay could trigger duplicate inbound processing

Published Mar 19, 2026
GHSA-86jj-29wc-7q2w

Duplicate Advisory: OpenClaw's Signal reaction-only status events could, in limited cases, be enqueued before access checks

Published Mar 21, 2026
GHSA-877v-w3f5-3pcq

OpenClaw: Feishu thread history and quoted messages bypass sender allowlist

Published Apr 2, 2026
CVE-2026-32028

OpenClaw: Discord DM reaction ingress missed dmPolicy/allowFrom checks in restricted setups

Published Mar 3, 2026
GHSA-35cq-wv6v-88xf

Duplicate Advisory: OpenClaw affected by SSRF via unguarded image download in fal provider

Published Mar 31, 2026
GHSA-36cp-mh65-x882

Duplicate Advisory: OpenClaw is vulnerable to unauthenticated resource exhaustion through its voice call webhook handling

Published Apr 10, 2026
GHSA-8cp7-rp8r-mg77

OpenClaw has SSRF guard bypass via IPv6 transition over ISATAP

Published Mar 4, 2026
GHSA-8f9r-gr6r-x63q

Duplicate Advisory: OpenClaw: Feishu webhook reads and parses unauthenticated request bodies before signature validation

Published Apr 10, 2026
GHSA-8rh7-6779-cjqq

OpenClaw has a CWD `.env` environment variable injection which bypasses host-env policy and allows config takeover

Published Apr 1, 2026
GHSA-37v6-fxx8-xjmx

OpenClaw: Telnyx Webhook Replay Detection Bypass via Base64 Signature Re-encoding

Published Apr 3, 2026
GHSA-39mp-545q-w789

OpenClaw: Non-owner command-authorized sender can change the owner-only `/send` session delivery policy

Published Mar 30, 2026
CVE-2026-32034

OpenClaw has an opt-in insecure Control UI auth over plaintext HTTP could allow privileged access

Published Mar 3, 2026
CVE-2026-27487

OpenClaw: Prevent shell injection in macOS keychain credential write

Published Feb 18, 2026
GHSA-3cw3-5vxw-g2h3

OpenClaw: CLI Remote Onboarding Persists Unauthenticated Discovery Endpoint and Exfiltrates Gateway Credentials

Published Mar 31, 2026
CVE-2026-31992

OpenClaw has allowlist exec-guard bypass via env -S

Published Mar 3, 2026
GHSA-c4qm-58hj-j6pj

OpenClaw: Browser snapshot and screenshot routes could expose internal page content after navigation

Published Apr 17, 2026
CVE-2026-26317

OpenClaw affected by cross-site request forgery (CSRF) through loopback browser mutation endpoints

Published Feb 18, 2026
CVE-2026-22178

OpenClaw has ReDoS and regex injection via unescaped Feishu mention metadata in RegExp construction

Published Mar 2, 2026
CVE-2026-26326

OpenClaw skills.status could leak secrets to operator.read clients

Published Feb 17, 2026
GHSA-3p2x-hjxj-c7rv

Duplicate Advisory: OpenClaw's system.run approval TOCTOU via mutable symlink cwd target on node host

Published Mar 21, 2026
GHSA-42mx-vp8m-j7qh

OpenClaw: OpenShell `mirror` mode can convert untrusted sandbox files into explicitly enabled workspace hooks and execute them on the host during gateway startup

Published Apr 7, 2026
GHSA-9528-x887-j2fp

OpenClaw's Nextcloud Talk webhook missing rate limiting on shared secret authentication

Published Mar 31, 2026
CVE-2026-31996

OpenClaw safeBins stdin-only bypass via sort output and recursive grep flags

Published Feb 19, 2026
GHSA-98ch-45wp-ch47

OpenClaw: Windows-compatible env override keys could bypass system.run approval binding

Published Apr 7, 2026
GHSA-98hh-7ghg-x6rq

OpenClaw: Discord text `/approve` bypasses `channels.discord.execApprovals.approvers` and allows non-approvers to resolve pending exec approvals

Published Mar 31, 2026
GHSA-49cg-279w-m73x

OpenClaw: Empty approver lists could grant explicit approval authorization

Published Apr 17, 2026
GHSA-f7fh-qg34-x2xh

OpenClaw: CDP /json/version WebSocket URL could pivot to untrusted second-hop targets

Published Apr 17, 2026
GHSA-f934-5rqf-xx47

OpenClaw: QMD memory_get restricts reads to canonical or indexed memory paths

Published Apr 17, 2026
GHSA-4g5x-2jfc-xm98

OpenClaw: Tlon media downloads can bypass core safety limits and exhaust disk

Published Apr 7, 2026
GHSA-4w7m-58cg-cmff

OpenClaw: Leaf subagents could steer sibling sessions across sandbox boundaries

Published Mar 13, 2026
GHSA-8g75-q649-6pv6

OpenClaw's system.run approvals did not bind mutable script operands across approval and execution

Published Mar 12, 2026
GHSA-fwjq-xwfj-gv75

OpenClaw: `session_status` still bypasses configured `tools.sessions.visibility` for unsandboxed invocations

Published Apr 7, 2026
GHSA-527m-976r-jf79

OpenClaw: Existing-session browser interaction routes bypassed SSRF policy enforcement

Published Apr 17, 2026
GHSA-g375-h3v6-4873

OpenClaw: Heartbeat owner downgrade missed local async exec completion events

Published Apr 17, 2026
GHSA-9mph-4f7v-fmvh

OpenClaw has agent avatar symlink traversal in gateway session metadata

Published Mar 4, 2026
GHSA-99qw-6mr3-36qr

OpenClaw: Workspace plugin auto-discovery allowed code execution from cloned repositories

Published Mar 13, 2026
GHSA-9q8j-chc7-wpgp

Duplicate Advisory: OpenClaw session transcript files were created without forced user-only permissions

Published Mar 29, 2026
GHSA-g8mc-c5f2-mqg7

Duplicate Advisory: OpenClaw Bypasses DM Policy Separation via Synology Chat Webhook Path Collision

Published Apr 10, 2026
GHSA-gj9q-8w99-mp8j

OpenClaw: TOCTOU read in exec script preflight

Published Apr 16, 2026
GHSA-59xc-5v89-r7pr

Duplicate Advisory: OpenClaw: Synology Chat Webhook Pre-Auth Rate-Limit Bypass Enables Brute-Force Guessing of Webhook Token

Published Apr 10, 2026
CVE-2026-31993

OpenClaw macOS companion app (beta): allowlist parsing mismatch for system.run shell chains

Published Mar 2, 2026
GHSA-5fc7-f62m-8983

OpenClaw: Feishu docx upload_file/upload_image Bypasses Workspace-Only Filesystem Policy (GHSA-qf48-qfv4-jjm9 Incomplete Fix)

Published Apr 9, 2026
CVE-2026-31990

OpenClaw: stageSandboxMedia destination symlink traversal can overwrite files outside sandbox workspace

Published Mar 3, 2026
GHSA-9f4w-67g7-mqwv

OpenClaw: Endpoint persists after trust decline, leaking gateway credentials

Published Apr 3, 2026
GHSA-8m9v-xpgf-g99m

OpenClaw has an unauthorized sender bypass in its stop triggers and /models command authorization

Published Mar 2, 2026
GHSA-8mf7-vv8w-hjr2

OpenClaw's tools.exec.safeBins generic fallback allowed interpreter-style inline payload execution in allowlist mode

Published Mar 3, 2026
CVE-2026-32013

OpenClaw gateway agents.files symlink escape allowed out-of-workspace file read/write

Published Mar 2, 2026
GHSA-4cqv-h74h-93j4

OpenClaw has a Discord `allowFrom` slug-collision authorization bypass

Published Mar 3, 2026
GHSA-hgwr-wr8h-rxm7

Duplicate Advisory: OpenClaw: Google Chat app-url webhook auth accepted non-deployment add-on principals

Published Apr 10, 2026
GHSA-4f8g-77mw-3rxc

OpenClaw: Gateway plugin HTTP `auth: gateway` widens identity-bearing `operator.read` requests into runtime `operator.write`

Published Apr 9, 2026
GHSA-cwq8-6f96-g3q4

OpenClaw: Security Scan Failure Does Not Block Plugin Installation (Fail-Open)

Published Apr 2, 2026
GHSA-cxfr-3qp8-hpmw

Duplicate Advisory: OpenClaw: Zalo webhook rate limiting could be bypassed before secret validation

Published Mar 31, 2026
GHSA-j42q-r6qx-xrfp

Duplicate Advisory: OpenClaw: Google Chat Authz Bypass via Group Policy Rebinding with Mutable Space displayName

Published Apr 10, 2026
GHSA-j5qh-5234-4rqp

Duplicate Advisory: OpenClaw: Workspace plugin auto-discovery allowed code execution from cloned repositories

Published Mar 31, 2026
GHSA-j6c7-3h5x-99g9

OpenClaw: Shell-wrapper detection missed env-argv assignment injection forms

Published Apr 17, 2026
GHSA-jccr-rrw2-vc8h

OpenClaw safeBins jq `$ENV` filter bypass allows environment variable disclosure

Published Mar 31, 2026
GHSA-jf25-7968-h2h5

OpenClaw: screen_record outPath bypassed workspace-only filesystem guard

Published Apr 17, 2026
GHSA-9p3r-hh9g-5cmg

OpenClaw: Sandbox escape via TOCTOU race in remote FS bridge readFile

Published Apr 3, 2026
CVE-2026-32032

OpenClaw's shell env fallback trusts unvalidated SHELL path from host environment

Published Mar 3, 2026
GHSA-jhpv-5j76-m56h

OpenClaw: Sender policy bypass in host media attachment reads allows unauthorized local file disclosure

Published Apr 17, 2026
GHSA-9q2p-vc84-2rwm

OpenClaw: system.run allow-always persistence included shell-commented payload tails

Published Mar 9, 2026
GHSA-jjgj-cpp9-cvpv

OpenClaw Vulnerable to Local File Exfiltration via MCP Tool Result MEDIA: Directive Injection

Published Mar 4, 2026
CVE-2026-33578MEDIUM
Risk: 21.5/100

OpenClaw: Google Chat and Zalouser group sender allowlist bypass via policy downgrade

Published Apr 1, 2026
GHSA-9q7v-8mr7-g23p

OpenClaw: SSRF via Unguarded `fetch()` in Marketplace Plugin Download and Ollama Model Discovery

Published Apr 2, 2026
GHSA-74wf-h43j-vvmj

OpenClaw's Conflicting Tool Identity Hints Bypass Dangerous-Tool Prompting

Published Mar 26, 2026
CVE-2026-29610

OpenClaw: Command hijacking via unsafe PATH handling (bootstrapping + node-host PATH overrides)

Published Feb 18, 2026
GHSA-fv94-qvg8-xqpw

OpenClaw: SSH sandbox tar upload follows symlinks, enabling arbitrary file write on remote host

Published Apr 2, 2026
GHSA-jwrq-8g5x-5fhm

OpenClaw: Collect-mode queue batches could reuse the last sender authorization context

Published Apr 17, 2026
GHSA-g27f-9qjv-22pm

OpenClaw log poisoning (indirect prompt injection) via WebSocket headers

Published Feb 17, 2026
GHSA-m5jp-p3r5-mfqp

Duplicate Advisory: OpenClaw: Gateway Plugin Subagent Fallback `deleteSession` Uses Synthetic `operator.admin`

Published Apr 10, 2026
GHSA-j26j-7qc4-3mrf

OpenClaw: MS Teams fileConsent/invoke missing conversation binding allowed cross-conversation pending-upload consumption

Published Mar 3, 2026
CVE-2026-22179

OpenClaw has macOS `system.run` allowlist bypass via quoted command substitution

Published Mar 3, 2026
CVE-2026-26321

OpenClaw has a local file disclosure via sendMediaFeishu in Feishu extension

Published Feb 17, 2026
CVE-2026-32018

OpenClaw's serialize sandbox registry writes to prevent races and delete-rollback corruption

Published Mar 3, 2026
GHSA-mr34-9552-qr95

OpenClaw: Webchat media embedding enforces local-root containment for tool-result files

Published Apr 17, 2026
GHSA-g2f6-pwvx-r275

OpneClaw accepts unsanitized iMessage attachment paths which allowed SCP remote-path command injection

Published Mar 16, 2026
CVE-2026-25593

OpenClaw vulnerable to Unauthenticated Local RCE via WebSocket config.apply

Published Feb 4, 2026
GHSA-g86v-f9qv-rh6m

OpenClaw SSRF guard misses four IPv6 special-use ranges

Published Mar 31, 2026
GHSA-c447-w54g-f55j

Duplicate Advisory: OpenClaw Telegram webhook request bodies were read before secret validation, enabling unauthenticated resource exhaustion

Published Mar 29, 2026
GHSA-p464-m8x6-vhv8

OpenClaw: MS Teams webhook parses body before JWT validation, enabling unauthenticated resource exhaustion

Published Apr 3, 2026
CVE-2026-32048

OpenClaw's sandboxed sessions_spawn now enforces sandbox inheritance for cross-agent spawns

Published Mar 2, 2026
GHSA-f5mf-3r52-r83w

OpenClaw's Zalouser allowlist authorization matched mutable group names by default

Published Mar 13, 2026
CVE-2026-27576

OpenClaw: ACP prompt-size checks missing in local stdio bridge could reduce responsiveness with very large inputs

Published Feb 20, 2026
GHSA-f693-58pc-2gfr

OpenClaw: Telegram legacy allowFrom migration fans default-account trust into all named accounts

Published Apr 3, 2026
GHSA-pmf3-2q63-jmp6

Duplicate Advisory: OpenClaw: Symlink Traversal via IDENTITY.md appendFile in agents.create/update (Incomplete Fix for CVE-2026-32013)

Published Apr 10, 2026
GHSA-ff98-w8hj-qrxf

OpenClaw plugin runtime command execution is part of trusted plugin boundary

Published Mar 3, 2026
GHSA-cfp9-w5v9-3q4h

OpenClaw: Image Tool `tools.fs.workspaceOnly` Bypass via Sandbox Bridge Mounts

Published Mar 26, 2026
GHSA-cg6c-q2hx-69h7

OpenClaw: Plivo V2 verified replay identity drifts on query-only variants

Published Mar 26, 2026
GHSA-cg7q-fg22-4g98

OpenClaw: Host exec environment sanitization misses package, registry, Docker, compiler, and TLS override variables

Published Apr 3, 2026
GHSA-cjq8-m7wj-xmq9

Duplicate Advisory: OpenClaw Node system.run approval context-binding weakness in approval-enabled host=node flows

Published Mar 21, 2026
GHSA-cjv3-m589-v3rx

OpenClaw has Canvas route hardening for mixed-trust deployments

Published Mar 3, 2026
GHSA-cm8v-2vh9-cxf3

OpenClaw: GIT_DIR and related git plumbing env vars missing from exec env denylist (GHSA-m866-6qv5-p2fg variant)

Published Apr 9, 2026
GHSA-f3h5-h452-vp3j

OpenClaw: Nostr profile mutation routes allowed operator.write config persistence

Published Apr 17, 2026
GHSA-gg9v-mgcp-v6m7

OpenClaw: Unbound bootstrap setup codes allow privilege escalation during pairing

Published Apr 3, 2026
GHSA-cwf8-44x6-32c2

OpenClaw: OpenShell Mirror Sync — Sandbox Escape via Unrestricted File Sync + Symlink Traversal

Published Apr 3, 2026
GHSA-qhrr-grqp-6x2g

OpenClaw's tools.exec.safeBins trusted PATH directories allowed binary shadowing in allowlist mode

Published Mar 3, 2026
GHSA-mp66-rf4f-mhh8

OpenClaw: Google Chat app-url webhook auth accepted non-deployment add-on principals

Published Mar 26, 2026
CVE-2026-27522

OpenClaw: Message action attachment hydration bypasses local media root checks when sandboxRoot is unset

Published Mar 2, 2026
GHSA-qmwg-qprg-3j38

OpenClaw: Browser interaction routes could pivot into local CDP and regain file reads

Published Apr 17, 2026
CVE-2026-28454

OpenClaw has a potential access-group authorization bypass if channel type lookup fails

Published Feb 17, 2026
GHSA-qqq7-4hxc-x63c

OpenClaw: Shared reply MEDIA - paths are treated as trusted and can trigger cross-channel local file exfiltration

Published Apr 9, 2026
GHSA-qvr7-g57c-mrc7

OpenClaw: Unavailable local auth SecretRefs could fall through to remote credentials in local mode

Published Mar 13, 2026
GHSA-r4c2-gq3j-7rpj

Duplicate Advisory: OpenClaw: Telegram Webhook Missing Guess Rate Limiting Enables Brute-Force Guessing of Weak Webhook Secret

Published Apr 10, 2026
GHSA-f6h3-846h-2r8w

OpenClaw's elevated allowFrom accepted broader identity signals than specified within sender-scoped authorization

Published Mar 4, 2026
GHSA-r77c-2cmr-7p47

OpenClaw: Delivery queue recovery could lose group tool-policy context for media replay

Published Apr 17, 2026
GHSA-rc8f-r29c-chr6

Duplicate Advisory: OpenClaw: BlueBubbles Webhook Missing Rate Limiting Enables Brute-Force Password Guessing

Published Apr 10, 2026
GHSA-rj2p-j66c-mgqh

OpenClaw: Browser tabs action select and close routes bypassed SSRF policy

Published Apr 17, 2026
GHSA-f6pf-4gjx-c94r

OpenClaw: Media Parsing Path Traversal Leads to Arbitrary File Read

Published Apr 3, 2026
GHSA-q94v-v6m9-jhq9

Duplicate Advisory: OpenClaw has an improper sandbox configuration vulnerability

Published Mar 21, 2026
CVE-2026-33576MEDIUM
Risk: 32.51/100

OpenClaw: Zalo channel downloads media before sender authorization

Published Mar 31, 2026
CVE-2026-27545

OpenClaw: Node system.run approval bypass via parent-symlink cwd rebind

Published Mar 2, 2026
GHSA-7h7g-x2px-94hj

OpenClaw: Pairing setup codes exposed long-lived shared gateway credentials instead of short-lived bootstrap tokens

Published Mar 13, 2026
GHSA-vvjh-f6p9-5vcf

OpenClaw Canvas Authentication Bypass Vulnerability

Published Mar 4, 2026
GHSA-ffr4-mrhv-vfr2

Duplicate Advisory: OpenClaw has browser trace/download path symlink escape in temp output handling

Published Mar 21, 2026
GHSA-vw3h-q6xq-jjm5

OpenClaw: Voice-call realtime WebSocket accepted oversized frames

Published Apr 17, 2026
GHSA-w8rf-7qf8-65ww

Duplicate Advisory: OpenClaw: Node-host approvals could show misleading shell payloads instead of the executed argv

Published Mar 31, 2026
CVE-2026-28479

OpenClaw replaced a deprecated sandbox hash algorithm

Published Feb 19, 2026
GHSA-g5cg-8x5w-7jpm

OpenClaw: Heartbeat context inheritance bypasses sandbox via senderIsOwner escalation

Published Apr 2, 2026
CVE-2026-28393

OpenClaw's hook transform module path allows traversal and arbitrary JavaScript module loading

Published Mar 3, 2026
GHSA-8288-jpqp-95fx

Duplicate Advisory: OpenClaw has Bypass in Webhook Rate Limiting via Pre-Authentication Secret Validation

Published Mar 31, 2026
CVE-2026-4039

OpenClaw: Skill env override host env injection via applySkillConfigEnvOverrides (defense-in-depth)

Published Feb 27, 2026
GHSA-g839-vp47-wgh8

Duplicate Advisory: OpenClaw's Slack reaction/pin sender-policy consistency issue in non-message ingress

Published Mar 21, 2026
CVE-2026-26325

OpenClaw Node host system.run rawCommand/command mismatch can bypass allowlist/approvals

Published Feb 17, 2026
GHSA-x2cm-hg9c-mf5w

OpenClaw leaf subagents can bypass controlScope restrictions to send messages to child sessions

Published Mar 26, 2026
GHSA-8h8f-7cxm-m38j

Duplicate Advisory: OpenClaw: Windows media loaders accepted remote-host file URLs before local path validation

Published Apr 2, 2026
CVE-2026-32031

OpenClaw: /api/channels gateway-auth boundary bypass via path canonicalization mismatch

Published Mar 12, 2026
CVE-2026-26322

OpenClaw Gateway tool allowed unrestricted gatewayUrl override

Published Feb 17, 2026
CVE-2026-22181

OpenClaw's web tools strict URL guard could lose DNS pinning when env proxy is configured

Published Mar 3, 2026
GHSA-4qwc-c7g9-4xcw

OpenClaw: Remote media error responses could trigger unbounded memory allocation before failure

Published Mar 26, 2026
GHSA-g8xp-qx39-9jq9

OpenClaw: Incomplete host-env-security-policy allows untrusted model to substitute compiler binaries via env overrides

Published Apr 3, 2026
GHSA-92jp-89mq-4374

OpenClaw: Sandbox noVNC helper route exposed interactive browser session credentials

Published Apr 17, 2026
GHSA-gfmx-pph7-g46x

OpenClaw: Lower-trust background runtime output is injected into trusted `System:` events, and local async exec completion misses the intended `exec-event` downgrade

Published Apr 9, 2026
CVE-2026-28473

OpenClaw authorization bypass: operator.write can resolve exec approvals via chat.send -> /approve

Published Feb 17, 2026
GHSA-ggm6-h3mx-cmmp

Duplicate Advisory: safeBins stdin-only bypass via sort output and recursive grep flags

Published Mar 19, 2026
GHSA-gjm7-hw8f-73rq

OpenClaw: Paired node escalates to gateway RCE via unrestricted node.event agent dispatch

Published Apr 3, 2026
CVE-2026-31998

OpenClaw's Synology Chat dmPolicy=allowlist failed open on empty allowedUserIds, allowing unauthorized agent dispatch

Published Mar 3, 2026
GHSA-gp3q-wpq4-5c5h

OpenClaw: LINE group allowlist scope mismatch with DM pairing-store entries

Published Mar 12, 2026
CVE-2026-32036

OpenClaw has gateway plugin auth bypass via encoded dot-segment traversal in protected /api/channels paths

Published Mar 3, 2026
GHSA-9f72-qcpw-2hxc

OpenClaw: Native prompt image auto-load did not honor tools.fs.workspaceOnly in sandboxed runs

Published Mar 3, 2026
CVE-2026-28453

OpenClaw has Zip Slip path traversal in tar archive extraction

Published Mar 2, 2026
CVE-2026-29608

OpenClaw's Node system.run approval hardening wrapper semantic drift can execute unintended local scripts

Published Mar 3, 2026
GHSA-9jpj-g8vv-j5mf

OpenClaw: Gemini OAuth exposed the PKCE verifier through the OAuth state parameter

Published Apr 4, 2026
CVE-2026-28462

OpenClaw has a path traversal in browser trace/download output paths may allow arbitrary file writes

Published Feb 18, 2026
CVE-2026-27646

OpenClaw: Sandboxed /acp spawn requests could initialize host ACP sessions

Published Mar 9, 2026
GHSA-c9h3-5p7r-mrjh

OpenClaw: Discord event cover images bypassed sandbox media normalization

Published Apr 17, 2026
CVE-2026-29609

OpenClaw affected by denial of service via unbounded URL-backed media fetch

Published Feb 18, 2026
CVE-2026-26329

OpenClaw has a path traversal in browser upload allows local file read

Published Feb 18, 2026
GHSA-pfv5-rpcw-x34x

Duplicate Advisory: OpenClaw's allow-always wrapper persistence could bypass future approvals and enable command execution

Published Mar 19, 2026
GHSA-h4jx-hjr3-fhgc

OpenClaw: Gateway Plugin Subagent Fallback `deleteSession` Uses Synthetic `operator.admin`

Published Mar 29, 2026
GHSA-h656-5vcf-cm23

OpenClaw: Unauthorized Telegram Senders Trigger Media Download and Disk Write Before Access Check

Published Mar 3, 2026
CVE-2026-31995

OpenClaw has Windows Lobster shell fallback command injection in constrained fallback path

Published Mar 3, 2026
CVE-2026-32027

OpenClaw DM pairing-store identities could satisfy group allowlist authorization

Published Mar 3, 2026
GHSA-hc5h-pmr3-3497

OpenClaw: /pair approve command path omitted caller scope subsetting and reopened device pairing escalation

Published Mar 31, 2026
CVE-2026-26328

OpenClaw iMessage group allowlist authorization inherited DM pairing-store identities

Published Feb 18, 2026
CVE-2026-31989

OpenClaw has web_search citation redirect SSRF via private-network-allowing policy

Published Mar 2, 2026
GHSA-gc9r-867r-j85f

OpenClaw: Microsoft Teams SSO invoke handler missed sender authorization checks

Published Apr 17, 2026
CVE-2026-32045

OpenClaw's gateway tokenless Tailscale auth applied to HTTP routes

Published Mar 3, 2026
CVE-2026-32846

OpenClaw is vulnerable to Path Traversal through path validation bypass

Published Mar 26, 2026
GHSA-hhff-fj5f-qg48

OpenClaw runs Discord audio preflight transcription before member authorization

Published Apr 3, 2026
CVE-2026-32058

OpenClaw Node system.run approval context-binding weakness in approval-enabled host=node flows

Published Mar 2, 2026
CVE-2026-26323

OpenClaw has a command injection in maintainer clawtributors updater

Published Feb 18, 2026
CVE-2026-22175

OpenClaw's exec allow-always can be bypassed via unrecognized multiplexer shell wrappers (busybox/toybox sh -c)

Published Mar 2, 2026
GHSA-h3x4-hc5v-v2gm

OpenClaw: Windows media loaders accepted remote-host file URLs before local path validation

Published Mar 26, 2026
GHSA-h5hg-h7rr-gpf3

OpenClaw: Node browser proxy `allowProfiles` bypass through persistent profile mutation and runtime profile selection

Published Apr 3, 2026
CVE-2026-32016

OpenClaw: macOS optional allowlist basename matching could bypass path-based policy

Published Mar 3, 2026
GHSA-j425-whc4-4jgc

OpenClaw's `system.run` env override filtering allowed dangerous helper-command pivots

Published Mar 9, 2026
GHSA-j9pv-rrcj-6pfx

OpenClaw: SSH-based sandbox backends pass unsanitized process.env to child processes

Published Apr 2, 2026
GHSA-jf56-mccx-5f3f

OpenClaw: Authenticated `/hooks/wake` and mapped `wake` payloads are promoted into the trusted `System:` prompt channel

Published Apr 9, 2026
GHSA-jf6w-m8jw-jfxc

OpenClaw: Write-scoped callers could reach admin-only session reset logic through `agent`

Published Mar 13, 2026
GHSA-mw7w-g3mg-xqm7

OpenClaw: BlueBubbles Group Reactions Bypass requireMention and Still Enqueue Agent-Visible System Events

Published Mar 27, 2026
CVE-2026-27486

OpenClaw: Process Safety - Unvalidated PID Kill via SIGKILL in Process Cleanup

Published Feb 18, 2026
CVE-2026-28480

OpenClaw Telegram allowlist authorization accepted mutable usernames

Published Feb 18, 2026
GHSA-52q4-3xjc-6778

OpenClaw: Google Chat Authz Bypass via Group Policy Rebinding with Mutable Space displayName

Published Mar 29, 2026
GHSA-mxmg-3p7m-2ghr

Duplicate Advisory: OpenClaw: system.run approval identity mismatch could execute a different binary than displayed

Published Mar 21, 2026
GHSA-pjvx-rx66-r3fg

OpenClaw: Cross-account sender authorization expansion in `/allowlist ... --store` account scoping

Published Mar 9, 2026
CVE-2026-27485

OpenClaw: Reject symlinks in local skill packaging script

Published Feb 20, 2026
GHSA-rcx4-77x4-hjx5

Duplicate Advisory: OpenClaw ACP client has permission auto-approval bypass via untrusted tool metadata

Published Mar 21, 2026
CVE-2026-28464

OpenClaw has non-constant-time token comparison in hooks authentication

Published Mar 2, 2026
CVE-2026-32025

OpenClaw's browser-origin WebSocket auth hardening gap could enable loopback password brute-force chains

Published Mar 3, 2026
CVE-2026-26327

OpenClaw allows unauthenticated discovery TXT records to steer routing and TLS pinning

Published Feb 18, 2026
GHSA-rvqr-hrcc-j9vv

OpenClaw: Bonjour/DNS-SD TXT metadata steers CLI routing after failed service resolution

Published Mar 26, 2026
GHSA-rw39-5899-8mxp

OpenClaw: Node-host approvals could show misleading shell payloads instead of the executed argv

Published Mar 13, 2026
CVE-2026-32060

OpenClaw has a path traversal in apply_patch could write/delete files outside the workspace

Published Feb 19, 2026
CVE-2026-32030

OpenClaw vulnerable to sensitive file disclosure via stageSandboxMedia

Published Mar 3, 2026
CVE-2026-28392

OpenClaw Slack: dmPolicy=open allowed any DM sender to run privileged slash commands

Published Feb 18, 2026
CVE-2026-26324

OpenClaw has a SSRF guard bypass via full-form IPv4-mapped IPv6 (loopback / metadata reachable)

Published Feb 17, 2026
CVE-2026-28447

OpenClaw has a Path Traversal in Plugin Installation

Published Feb 17, 2026
GHSA-qwmf-95r9-gx9x

Duplicate Advisory: OpenClaw's gateway tokenless Tailscale auth applied to HTTP routes

Published Mar 21, 2026
GHSA-v3qc-wrwx-j3pw

OpenClaw: Agentic Consent Bypass — LLM Agent Can Silently Disable Exec Approval via `config.patch`

Published Apr 3, 2026
GHSA-vcx4-4qxg-mfp4

OpenClaw: Telegram Webhook Missing Guess Rate Limiting Enables Brute-Force Guessing of Weak Webhook Secret

Published Mar 27, 2026
CVE-2026-32002

OpenClaw's image tool bypasses tools.fs.workspaceOnly on sandbox mount paths and exfiltrates out-of-workspace images

Published Mar 4, 2026
GHSA-jxrq-8fm4-9p58

OpenClaw: Zip extraction symlink traversal could write outside destination

Published Mar 3, 2026
CVE-2026-32063

OpenClaw Improperly Neutralizes Line Breaks in systemd Unit Generation Enables Local Command Execution (Linux)

Published Mar 3, 2026
CVE-2026-33581MEDIUM
Risk: 32.51/100

OpenClaw's message tool media parameter bypasses tool policy filesystem isolation

Published Mar 31, 2026
GHSA-q9w8-cf67-r238

OpenClaw: macOS Tailnet DNS Spoofing & Credential Exfiltration

Published Apr 3, 2026
GHSA-qm9x-v7cx-7rq4

OpenClaw's system.run allowlist can be bypassed through an unregistered time dispatch wrapper

Published Mar 26, 2026
GHSA-vfw7-6rhc-6xxg

OpenClaw Has Incomplete Fix for CVE-2026-4039: CLI Backend Environment Variable Injection via Workspace Config

Published Apr 7, 2026
GHSA-vh4c-j2xv-9pv9

Duplicate Advisory: OpenClaw: BlueBubbles beta plugin webhook auth hardening (remove passwordless fallback)

Published Mar 21, 2026
GHSA-qx8j-g322-qj6m

OpenClaw: `fetchWithSsrFGuard` replays unsafe request bodies across cross-origin redirects

Published Apr 9, 2026
CVE-2026-32057

OpenClaw has a Trusted-proxy Control UI pairing bypass which allows unpaired node sessions

Published Mar 3, 2026
GHSA-5h2c-8v84-qpvr

OpenClaw shell-env fallback trusted startup env and could execute attacker-influenced login-shell paths

Published Mar 3, 2026
CVE-2026-32899

OpenClaw's Slack reaction/pin sender-policy consistency issue in non-message ingress

Published Mar 3, 2026
GHSA-rm5c-4rmf-vvhw

OpenClaw: Sandbox file operations use check-then-act, bypassing fd-based TOCTOU defenses

Published Apr 3, 2026
CVE-2026-31999

CpenClaw's ACPX Windows wrapper shell fallback allowed cwd injection in specific paths

Published Mar 2, 2026
GHSA-6x2m-hqfw-hvpj

OpenClaw: Node exec approvals could be replayed across nodes

Published Mar 2, 2026
GHSA-vfg3-pqpq-93m4

OpenClaw: Tlon cite expansion happens before channel and DM authorization is complete

Published Mar 26, 2026
GHSA-7977-c43c-xpwj

OpenClaw is vulnerable to validation bypass through GNU long-option abbreviations in allowlist mode

Published Feb 27, 2026
GHSA-vfp4-8x56-j7c5

OpenClaw: Exec environment denylist missed high-risk interpreter startup variables

Published Apr 17, 2026
CVE-2026-32062

OpenClaw voice-call media stream validated streams after upgrade, which could allow pre-start unauthenticated sockets to increase resource pressure

Published Mar 2, 2026
GHSA-83f3-hh45-vfw9

OpenClaw: Android accepted cleartext remote gateway endpoints and sent stored credentials over ws://

Published Apr 7, 2026
GHSA-vr5g-mmx7-h897

OpenClaw has Browser SSRF Policy Bypass via Interaction-Triggered Navigation

Published Apr 9, 2026
GHSA-whf9-3hcx-gq54

OpenClaw `device.token.rotate` mints tokens for unapproved roles, bypassing device role-upgrade pairing

Published Apr 9, 2026
GHSA-9vvh-2768-c8vp

OpenClaw: Discord guild reaction ingress could bypass users and roles allowlists

Published Mar 13, 2026
CVE-2026-32035

OpenClaw: Discord voice transcript owner-flag omission could expose owner-only tools in mixed-trust channels

Published Mar 3, 2026
CVE-2026-32918

`OpenClaw: session_status` let sandboxed subagents access parent or sibling session state

Published Mar 13, 2026
GHSA-w9cg-v44m-4qv8

OpenClaw affected by BASH_ENV / ENV startup-file injection into spawned shell commands

Published Mar 3, 2026
CVE-2026-32043

OpenClaw's system.run approval TOCTOU via mutable symlink cwd target on node host

Published Mar 3, 2026
GHSA-pfv7-rr5m-qmv6

OpenClaw has auth inconsistency on local Browser Extension Relay /extension endpoint

Published Mar 3, 2026
GHSA-xmv6-r34m-62p4

OpenClaw: Sandbox media fallback tmp symlink alias bypass allows host file reads outside sandboxRoot

Published Mar 3, 2026
GHSA-phgf-3849-rgjq

Duplicate Advisory: OpenClaw: Plugin subagent routes could bypass gateway authorization with synthetic admin scopes

Published Mar 31, 2026
GHSA-h36m-2vh5-x699

Duplicate Advisory: ACPX Windows wrapper shell fallback allowed cwd injection in specific paths

Published Mar 19, 2026
GHSA-56f2-hvwg-5743

OpenClaw affected by SSRF in Image Tool Remote Fetch

Published Feb 17, 2026
GHSA-5h3f-885m-v22w

OpenClaw: Existing WS sessions survive shared gateway token rotation

Published Apr 9, 2026
GHSA-xh72-v6v9-mwhc

OpenClaw: Feishu webhook and card-action validation now fail closed

Published Apr 17, 2026
GHSA-xhq5-45pm-2gjr

OpenClaw: Nextcloud Talk room allowlist matched colliding room names instead of stable room tokens

Published Mar 26, 2026
CVE-2026-28469

OpenClaw Google Chat shared-path webhook target ambiguity allowed cross-account policy-context misrouting

Published Feb 18, 2026
CVE-2026-22174

OpenClaw Loopback CDP probe can leak Gateway token to local listener

Published Mar 3, 2026
GHSA-vjqw-w5jr-g9w5

Duplicate Advisory: OpenClaw: Feishu webhook mode accepted forged events when only `verificationToken` was configured

Published Mar 29, 2026
GHSA-vjx8-8p7h-82gr

OpenClaw: Marketplace Plugin Download Follows Redirects Without SSRF Protection

Published Apr 7, 2026
GHSA-68x5-xx89-w9mm

OpenClaw: resolvedAuth closure becomes stale after config reload

Published Apr 9, 2026
GHSA-vqvg-86cc-cg83

OpenClaw: Mutating internal `/allowlist` chat commands missed `operator.admin` scope enforcement

Published Mar 30, 2026
GHSA-77w2-crqv-cmv3

OpenClaw: Feishu Raw Card Send Surface Can Mint Legacy Card Callbacks That Bypass DM Pairing

Published Mar 29, 2026
GHSA-w6f4-3v35-qjhj

Duplicate Advisory: OpenClaw's system.run shell-wrapper positional argv carriers could execute hidden commands under misleading approval text

Published Mar 21, 2026
GHSA-3h52-cx59-c456

OpenClaw: Feishu webhook reads and parses unauthenticated request bodies before signature validation

Published Mar 29, 2026
GHSA-xq94-r468-qwgj

OpenClaw: Browser SSRF hostname validation could be bypassed by DNS rebinding

Published Apr 17, 2026
CVE-2026-32040

OpenClaw Vulnerable to HTML injection via unvalidated image MIME type in data-URL interpolation

Published Mar 3, 2026
GHSA-cmfr-9m2r-xwhq

OpenClaw `node.invoke(browser.proxy)` bypasses `browser.request` persistent profile-mutation guard

Published Apr 9, 2026
GHSA-wwrj-437c-ppq4

Duplicate Advisory: OpenClaw's system.run approvals did not bind mutable script operands across approval and execution

Published Mar 31, 2026
GHSA-525j-hqq2-66r4

OpenClaw: Sandbox browser CDP relay could expose DevTools protocol on 0.0.0.0

Published Apr 17, 2026
CVE-2026-27009

OpenClaw affected by Stored XSS in Control UI via unsanitized assistant name/avatar in inline script injection

Published Feb 18, 2026
GHSA-3846-mfvc-xwpf

Duplicate Advisory: Exec allowlist wrapper analysis did not unwrap env/shell dispatch chains

Published Mar 19, 2026
CVE-2026-29613

OpenClaw has a webhook auth bypass when gateway is behind a reverse proxy (loopback remoteAddress trust)

Published Feb 17, 2026
GHSA-xwcj-hwhf-h378

OpenClaw Telegram media fetch errors exposed bot tokens in logged file URLs

Published Mar 16, 2026
GHSA-f8r2-vg7x-gh8m

OpenClaw: Exec approval allowlist patterns overmatched on POSIX paths

Published Mar 13, 2026
GHSA-3qpv-xf3v-mm45

OpenClaw: Workspace `.env` can override the bundled hooks root and load attacker hook code

Published Apr 2, 2026
GHSA-wq58-2pvg-5h4f

OpenClaw: Gateway agent /reset exposes admin session reset to operator.write callers

Published Mar 26, 2026
GHSA-fh32-73r9-rgh5

OpenClaw: Trailing-dot localhost CDP hosts could bypass remote loopback protections

Published Apr 7, 2026
CVE-2026-32009

OpenClaw: safeBins static default trusted dirs allow writable-dir binary hijack (`jq`)

Published Mar 3, 2026
CVE-2026-32974

OpenClaw: Feishu webhook mode accepted forged events when only `verificationToken` was configured

Published Mar 13, 2026
GHSA-5jvj-hxmh-6h6j

OpenClaw: Gateway HTTP Session History Route Bypasses Operator Read Scope

Published Mar 29, 2026
CVE-2026-24764

OpenClaw Affected by Remote Code Execution via System Prompt Injection in Slack Channel Descriptions

Published Feb 17, 2026
GHSA-5m9r-p9g7-679c

OpenClaw: Zalo webhook rate limiting could be bypassed before secret validation

Published Mar 13, 2026
GHSA-5rp4-cwgh-gvwq

Duplicate Advisory: OpenClaw: WebSocket shared-auth connections could self-declare elevated scopes

Published Mar 19, 2026
GHSA-659f-22xc-98f2

OpenClaw hook transform path containment missed symlink-resolved escapes

Published Mar 3, 2026
GHSA-8j7f-g9gv-7jhc

Duplicate Advisory: OpenClaw: SSRF via Unguarded Configured Base URLs in Multiple Channel Extensions (Incomplete Fix for CVE-2026-28476)

Published Apr 10, 2026
GHSA-8jhh-jcqg-mj5p

OpenClaw: Channel commands could bypass account-scoped `configWrites` restrictions

Published Mar 13, 2026
GHSA-89hr-6x2p-8xjv

Duplicate Advisory: OpenClaw's device removal and token revocation do not terminate active WebSocket sessions

Published Mar 31, 2026
GHSA-chm2-m3w2-wcxm

OpenClaw Google Chat spoofing access with allowlist authorized mutable email principal despite sender-ID mismatch

Published Feb 17, 2026
GHSA-8px5-2gfr-7ph6

Duplicate Advisory: OpenClaw has Windows Lobster shell fallback command injection in constrained fallback path

Published Mar 19, 2026
CVE-2026-28460

OpenClaw's system.run allowlist bypass via shell line-continuation command substitution

Published Mar 3, 2026
CVE-2026-28466

OpenClaw Vulnerable to Remote Code Execution via Node Invoke Approval Bypass in Gateway

Published Mar 2, 2026
GHSA-jr6x-2q95-fh2g

OpenClaw's authorization mismatch allowed write-scope agent runs to reach owner-only tools

Published Mar 2, 2026
GHSA-hr8g-2q7x-3f4w

OpenClaw Has a Gateway Control Interface Information Disclosure Vulnerability

Published Apr 3, 2026
GHSA-jp4j-q5fc-58gv

OpenClaw's Discord component interaction ingress skips guild/channel policy enforcement

Published Mar 31, 2026
GHSA-f44p-c7w9-7xr7

OpenClaw: Gateway WebSocket Denial of Service via unbounded pre-auth upgrades

Published Mar 31, 2026
GHSA-gcj7-r3hg-m7w6

OpenClaw's voice-call Twilio replay dedupe now bound to authenticated webhook identity

Published Mar 3, 2026
GHSA-m3mh-3mpg-37hw

OpenClaw has an Arbitrary Malicious Code Execution Vulnerability

Published Mar 30, 2026
CVE-2026-32007

OpenClaw: Experimental apply_patch may bypass workspace-only checks in opt-in sandbox mounts (off by default)

Published Mar 3, 2026
GHSA-hh43-q692-2xmq

Duplicate Advisory: `OpenClaw: session_status` let sandboxed subagents access parent or sibling session state

Published Mar 29, 2026
GHSA-hm63-vwj4-mj2q

Duplicate Advisory: OpenClaw: Remote media error responses could trigger unbounded memory allocation before failure

Published Apr 10, 2026
GHSA-j7p2-qcwm-94v4

OpenClaw's incomplete host env sanitization blocklist allows supply-chain redirection via package-manager env overrides

Published Mar 31, 2026
CVE-2026-27566

OpenClaw's exec allowlist wrapper analysis did not unwrap env/shell dispatch chains

Published Mar 3, 2026
CVE-2026-32980

OpenClaw Telegram webhook request bodies were read before secret validation, enabling unauthenticated resource exhaustion

Published Mar 16, 2026
GHSA-jq4x-98m3-ggq6

OpenClaw Canvas Path Traversal Information Disclosure Vulnerability

Published Mar 2, 2026
CVE-2026-31997

OpenClaw: system.run approvals did not bind PATH-token executable identity, enabling post-approval executable rebind

Published Mar 2, 2026
CVE-2026-22170

OpenClaw: BlueBubbles (optional plugin) pairing/allowlist mismatch when allowFrom is empty

Published Mar 4, 2026
GHSA-q86m-697p-h7fh

Duplicate Advisory: OpenClaw: system.run approvals did not bind PATH-token executable identity, enabling post-approval executable rebind

Published Mar 19, 2026
GHSA-qcc3-jqwp-5vh2

OpenClaw: LINE webhook handler lacks shared pre-auth concurrency budget before signature verification

Published Apr 2, 2026
CVE-2026-28458

OpenClaw's Browser Relay /cdp websocket is missing auth which could allow cross-tab cookie access

Published Feb 17, 2026
CVE-2026-22171

OpenClaw vulnerable to path traversal in Feishu media temp-file naming allows writes outside os.tmpdir()

Published Mar 3, 2026
CVE-2026-32041

OpenClaw: Browser control startup could continue unauthenticated after auth bootstrap failure

Published Mar 2, 2026
CVE-2026-32006

OpenClaw has a BlueBubbles group allowlist mismatch via DM pairing-store fallback

Published Mar 3, 2026
CVE-2026-32038

OpenClaw has a sandbox network isolation bypass via docker.network=container:<id>

Published Mar 2, 2026
CVE-2026-32054

OpenClaw has browser trace/download path symlink escape in temp output handling

Published Mar 2, 2026
GHSA-xw77-45gv-p728

OpenClaw: Plugin subagent routes could bypass gateway authorization with synthetic admin scopes

Published Mar 13, 2026
GHSA-8mr2-f9wf-hcfq

Duplicate Advisory: OpenClaw reuses the gateway auth token in the owner ID prompt hashing fallback

Published Mar 21, 2026
CVE-2026-32010

In OpenClaw, manually adding sort to tools.exec.safeBins could bypass allowlist approval via --compress-program

Published Mar 3, 2026
GHSA-rhfg-j8jq-7v2h

OpenClaw: SSRF via Unguarded Configured Base URLs in Multiple Channel Extensions (Incomplete Fix for CVE-2026-28476)

Published Mar 29, 2026
GHSA-5326-6f73-m96w

Duplicate Advisory: OpenClaw macOS companion app (beta): allowlist parsing mismatch for system.run shell chains

Published Mar 19, 2026
CVE-2026-32042

OpenClaw unpaired device identity can bypass operator pairing and self-assign operator scopes with shared auth

Published Mar 3, 2026
GHSA-5gqg-mqh5-2v39

Duplicate Advisory: OpenClaw Windows Scheduled Task script generation allowed local command injection via unsafe cmd argument handling

Published Mar 19, 2026
CVE-2026-28476

OpenClaw affected by SSRF in optional Tlon (Urbit) extension authentication

Published Feb 18, 2026
GHSA-w5c7-9qqw-6645

OpenClaw inter-session prompts could be treated as direct user instructions

Published Feb 18, 2026
GHSA-w8g9-x8gx-crmm

OpenClaw: Strict browser SSRF bypass in Playwright redirect handling leaves private targets reachable

Published Apr 9, 2026
GHSA-q2gc-xjqw-qp89

OpenClaw: strictInlineEval explicit-approval boundary bypassed by approval-timeout fallback on gateway and node exec hosts

Published Apr 9, 2026
CVE-2026-32067

OpenClaw has cross-account DM pairing authorization bypass via unscoped pairing store access

Published Mar 4, 2026
GHSA-x2m8-53h4-6hch

OpenClaw: Discord voice ingress authorization can be bypassed via channel, name, and stale-role validation gaps

Published Apr 3, 2026
CVE-2026-28391

OpenClaw's Windows cmd.exe parsing may bypass exec allowlist/approval gating

Published Feb 17, 2026
GHSA-qm2m-28pf-hgjw

OpenClaw: Gateway Plugin HTTP Auth Grants Unrestricted operator.admin Runtime Scope to All Callers

Published Mar 27, 2026
GHSA-cxcw-jm67-3wwp

Duplicate Advisory: OpenClaw's andbox browser noVNC observer lacked VNC authentication

Published Mar 21, 2026
GHSA-g7cr-9h7q-4qxq

OpenClaw's MS Teams sender allowlist bypass when route allowlist is configured and sender allowlist is empty

Published Mar 12, 2026
GHSA-w6wx-jq6j-6mcj

OpenClaw: pnpm dlx approvals did not bind local script operands

Published Apr 7, 2026
CVE-2026-28449

OpenClaw's Nextcloud Talk webhook replay could trigger duplicate inbound processing

Published Mar 3, 2026
GHSA-rf6h-5gpw-qrgq

OpenClaw: MS Teams Feedback Invocation Bypasses Sender Allowlists and Records Unauthorized Session Feedback

Published Mar 29, 2026
GHSA-rj39-33v7-9xrq

Duplicate Advisory: OpenClaw's shell startup env injection bypasses system.run allowlist intent (RCE class)

Published Mar 21, 2026
GHSA-rm59-992w-x2mv

OpenClaw is vulnerable to unauthenticated resource exhaustion through its voice call webhook handling

Published Mar 26, 2026
GHSA-m69h-jm2f-2pv8

OpenClaw: Feishu reaction events could bypass group authorization and mention gating

Published Mar 13, 2026
CVE-2026-27523

OpenClaw's sandbox bind validation could bypass allowed-root and blocked-path checks via symlink-parent missing-leaf paths

Published Mar 3, 2026
CVE-2026-22217

OpenClaw: shell-env trusted-prefix fallback allowed attacker-controlled binary execution via $SHELL

Published Mar 3, 2026
GHSA-p4x4-2r7f-wjxg

OpenClaw gateway exec allow-always over-trusts positional carrier executables

Published Apr 1, 2026
GHSA-w6m8-cqvj-pg5v

OpenClaw has incomplete Fix for CVE-2026-32011: Feishu Webhook Pre-Auth Body Parsing DoS (Slow-Body / Slowloris Variant)

Published Mar 30, 2026
GHSA-w9j9-w4cp-6wgr

OpenClaw Host-Exec Environment Variable Injection

Published Apr 9, 2026
GHSA-wgx8-r9vw-2w4h

Duplicate Advisory: OpenClaw: Skill env override host env injection via applySkillConfigEnvOverrides (defense-in-depth)

Published Mar 12, 2026
CVE-2026-32011

OpenClaw has pre-auth webhook body parsing that can enable unauthenticated slow-request DoS

Published Mar 3, 2026
CVE-2026-32979

OpenClaw: Unbound interpreter and runtime commands could bypass node-host approval integrity

Published Mar 13, 2026
GHSA-r294-2894-92j3

OpenClaw has stored XSS in exported session HTML viewer via markdown/raw-HTML rendering

Published Mar 3, 2026
CVE-2026-32056

OpenClaw's shell startup env injection bypasses system.run allowlist intent (RCE class)

Published Mar 3, 2026
GHSA-rchv-x836-w7xp

OpenClaw's dashboard leaked gateway auth material via browser URL/query and localStorage

Published Mar 9, 2026
GHSA-rvvf-6vh3-9j43

OpenClaw: Discord Slash Commands Bypass Group DM Channel Allowlist

Published Apr 3, 2026
GHSA-rwwx-25m7-ww73

Duplicate Advisory: OpenClaw: Unrecognized script runners could bypass `system.run` approval integrity

Published Mar 29, 2026
GHSA-xp9r-prpg-373r

OpenClaw: `browser.request` still allows `POST /reset-profile` through the `operator.write` surface

Published Mar 30, 2026
CVE-2026-32004

OpenClaw has encoded-path auth bypass in plugin `/api/channels` route classification

Published Mar 3, 2026
GHSA-vc32-h5mq-453v

OpenClaw: /allowlist omits owner-only enforcement for cross-channel allowlist writes

Published Apr 9, 2026
GHSA-vmhq-cqm9-6p7q

OpenClaw: `browser.request` let `operator.write` persist admin-only browser profile changes

Published Mar 13, 2026
CVE-2026-27484

OpenClaw Discord moderation authorization used untrusted sender identity in tool-driven flows

Published Feb 20, 2026
GHSA-wwfp-w96m-c6x8

OpenClaw: Pairing pending-request caps were enforced per channel instead of per account

Published Apr 7, 2026
GHSA-x49q-fhhm-r9jf

Duplicate Advisory: OpenClaw: WebSocket shared-auth connections could self-declare elevated scopes

Published Mar 20, 2026
GHSA-xjj9-2w6f-jg55

Duplicate Advisory: OpenClaw safeBins file-existence oracle information disclosure

Published Mar 12, 2026
GHSA-xmxx-7p24-h892

OpenClaw: Gateway HTTP endpoints re-resolve bearer auth after SecretRef rotation

Published Apr 17, 2026
GHSA-xvx8-77m6-gwg6

OpenClaw: Sandbox `writeFile` commit could race outside the validated path

Published Mar 13, 2026
CVE-2026-26972

OpenClaw has a Path Traversal in Browser Download Functionality

Published Feb 18, 2026
CVE-2026-32022

OpenClaw safeBins grep -e File Read Bypass (stdin-only policy bypass)

Published Mar 3, 2026
GHSA-6mqc-jqh6-x8fc

OpenClaw: Gateway Canvas local-direct requests bypass Canvas HTTP and WebSocket authentication

Published Mar 26, 2026
CVE-2026-28463

OpenClaw exec approvals: safeBins could bypass stdin-only constraints via shell expansion

Published Feb 18, 2026
GHSA-ppwq-6v66-5m6j

OpenClaw Exposes Credentials Embedded in baseUrl Fields via config.get and channels.status

Published Mar 26, 2026
GHSA-2hm8-rqrm-xfjq

OpenClaw's owner-only gateway tool access checks were incomplete in specific authenticated DM flows

Published Mar 3, 2026
GHSA-2j53-2c28-g9v2

Duplicate Advisory: OpenClaw: Nostr inbound DMs could trigger unauthenticated crypto work before sender policy enforcement

Published Apr 10, 2026
CVE-2026-34503HIGH
Risk: 40.51/100

OpenClaw's device removal and token revocation do not terminate active WebSocket sessions

Published Mar 31, 2026
CVE-2026-33577HIGH
Risk: 40.5/100

OpenClaw: node.pair.approve missing callerScopes validation allows low-privilege operator to approve malicious nodes

Published Apr 1, 2026
CVE-2026-28448

OpenClaw Twitch allowFrom is not enforced in optional plugin, unauthorized chat users can trigger agent pipeline

Published Feb 17, 2026
GHSA-3gr8-2752-h46q

Duplicate Advisory: OpenClaw's message tool media parameter bypasses tool policy filesystem isolation

Published Mar 31, 2026
CVE-2026-22180

OpenClaw: Unified root-bound write hardening for browser output and related path-boundary flows

Published Mar 3, 2026
GHSA-3xv9-89fm-7h4r

OpenClaw: diffs viewer misclassifies proxied remote requests as loopback when `allowRemoteViewer` is disabled

Published Apr 3, 2026
GHSA-474h-prjg-mmw3

OpenClaw: Sandboxed sessions_spawn(runtime="acp") bypassed sandbox inheritance and allowed host ACP initialization

Published Mar 3, 2026
GHSA-68f8-9mhj-h2mp

OpenClaw has a Gateway HTTP /v1/models Route Bypasses Operator Read Scope

Published Mar 30, 2026
GHSA-6g25-pc82-vfwp

OpenClaw: macOS beta onboarding exposed PKCE verifier via OAuth state

Published Mar 3, 2026
CVE-2026-32044

OpenClaw skills-install-download: tar.bz2 extraction bypassed archive safety parity checks (local DoS)

Published Mar 3, 2026
GHSA-796m-2973-wc5q

OpenClaw has exec allowlist/safeBins policy-runtime mismatch via env -S wrapper interpretation

Published Mar 3, 2026
CVE-2026-28477

OpenClaw Chutes manual OAuth state validation bypass can cause credential substitution

Published Feb 18, 2026
GHSA-846p-hgpv-vphc

OpenClaw: QQ Bot structured payloads could read arbitrary local files

Published Apr 7, 2026
GHSA-h2v7-xc88-xx8c

OpenClaw: `/phone arm`/`/phone disarm` Bypasses `operator.admin` Scope Check for External Channels

Published Apr 7, 2026
GHSA-qcc4-p59m-p54m

OpenClaw: Sandbox dangling-symlink alias handling could bypass workspace-only write boundary

Published Mar 12, 2026
GHSA-qxgf-hmcj-3xw3

OpenClaw affected by SSRF via unguarded image download in fal provider

Published Apr 1, 2026
GHSA-rfqg-qgf8-xr9x

OpenClaw: Gateway `device.token.rotate` does not terminate active WebSocket sessions after credential rotation

Published Apr 3, 2026
GHSA-rg8m-3943-vm6q

OpenClaw: Matrix thread root and reply context bypass sender allowlist

Published Apr 2, 2026
GHSA-4p4f-fc8q-84m3

OpenClaw: iOS A2UI bridge trusted generic local-network pages for agent.request dispatch

Published Apr 7, 2026
CVE-2026-22169

OpenClaw's non-default safeBins sort configuration can bypass intended allowlist approval constraints

Published Mar 3, 2026
GHSA-wj55-88gf-x564

OpenClaw may have stale policy enforcement for queued node actions

Published Mar 26, 2026
GHSA-x742-88jj-7hv9

Duplicate Advisory: allowlist exec-guard bypass via env -S

Published Mar 19, 2026
GHSA-x82f-27x3-q89c

OpenClaw's TOCTOU symlink race in writeFileWithinRoot could create or truncate files outside root boundaries

Published Mar 2, 2026
GHSA-65h8-27jh-q8wv

OpenClaw: Nostr inbound DMs could trigger unauthenticated crypto work before sender policy enforcement

Published Mar 26, 2026
GHSA-xj9w-5r6q-x6v4

OpenClaw: Device-Paired Node Skips Node Scope Gate → Host RCE.md

Published Apr 3, 2026
CVE-2026-33572

OpenClaw session transcript files were created without forced user-only permissions

Published Mar 16, 2026
GHSA-xg59-f45v-9r9j

Duplicate Advisory: OpenClaw's MS Teams sender allowlist bypass when route allowlist is configured and sender allowlist is empty

Published Mar 31, 2026
GHSA-7853-gqqm-vcwx

openclaw-claude-bridge: sandbox is not effective - `--allowed-tools ""` does not restrict available tools

Published Apr 8, 2026
CVE-2026-28465

OpenClaw optional voice-call plugin: webhook verification may be bypassed behind certain proxy configurations

Published Feb 17, 2026
CVE-2026-25253

OpenClaw/Clawdbot has 1-Click RCE via Authentication Token Exfiltration From gatewayUrl

Published Feb 2, 2026
MAL-2026-1151

Malicious code in openclaw-droid (npm)

Published Mar 3, 2026
CVE-2026-24763

OpenClaw/Clawdbot Docker Execution has Authenticated Command Injection via PATH Environment Variable

Published Feb 2, 2026
CVE-2026-25157

OpenClaw/Clawdbot has OS Command Injection via Project Root Path in sshNodeCommand

Published Feb 2, 2026
MAL-2026-1321

Malicious code in @openclaw-ai/openclawai (npm)

Published Mar 10, 2026
GHSA-vm29-7mq3-9jrg

Duplicate Advisory: OpenClaw: Unavailable local auth SecretRefs could fall through to remote credentials in local mode

Published Mar 31, 2026
Check your entire dependency tree at onceRun dependency scan →