openclaw
npm218 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting openclawpage 1 of 5
- CVE-2026-22177MEDIUMCVSS 6.1EG 6.1✓ Fixed in 2026.2.212026-03-18
OpenClaw versions prior to 2026.2.21 fail to filter dangerous process-control environment variables from config env.vars, allowing startup-time code execution. Attackers can inject variables like NODE_OPTIONS or LD_* through configuration …
- CVE-2026-22217MEDIUMCVSS 6.1EG 6.1✓ Fixed in 2026.2.232026-03-18
OpenClaw version 2026.2.22 prior to 2026.2.23 contains an arbitrary code execution vulnerability in shell-env that allows attackers to execute attacker-controlled binaries by exploiting trusted-prefix fallback logic for the $SHELL variable…
- CVE-2026-28395MEDIUMCVSS 6.5EG 6.5✓ Fixed in 2026.2.122026-03-05
OpenClaw version 2026.1.14-1 prior to 2026.2.12 contains an improper network binding vulnerability in the Chrome extension (must be installed and enabled) relay server that treats wildcard hosts as loopback addresses, allowing the relay HT…
- CVE-2026-28463HIGHCVSS 8.4EG 8.4✓ Fixed in 2026.2.142026-03-05
OpenClaw versions prior to 2026.2.14 contain an arbitrary file read vulnerability in the exec-approvals allowlist validation that checks pre-expansion argv tokens but executes using real shell expansion. Attackers with authorization or thr…
- CVE-2026-28476HIGHCVSS 8.3EG 8.3✓ Fixed in 2026.2.142026-03-05
OpenClaw versions prior to 2026.2.14 contain a server-side request forgery vulnerability in the optional Tlon Urbit extension that accepts user-provided base URLs for authentication without proper validation. Attackers who can influence th…
- CVE-2026-28481MEDIUMCVSS 6.5EG 6.5✓ Fixed in 2026.2.12026-03-05
OpenClaw versions 2026.1.30 and earlier, contain an information disclosure vulnerability, patched in 2026.2.1, in the MS Teams attachment downloader (optional extension must be enabled) that leaks bearer tokens to allowlisted suffix domain…
- CVE-2026-29611HIGHCVSS 7.5EG 7.5✓ Fixed in 2026.2.142026-03-05
OpenClaw versions prior to 2026.2.14 contain a local file inclusion vulnerability in BlueBubbles extension (must be installed and enabled) media path handling that allows attackers to read arbitrary files from the local filesystem. The sen…
- CVE-2026-32018LOWCVSS 3.6EG 3.6✓ Fixed in 2026.2.192026-03-19
OpenClaw versions prior to 2026.2.19 contain a race condition vulnerability in concurrent updateRegistry and removeRegistryEntry operations for sandbox containers and browsers. Attackers can exploit unsynchronized read-modify-write operati…
- CVE-2026-32019HIGHCVSS 7.4EG 7.4✓ Fixed in 2026.2.222026-03-19
OpenClaw versions prior to 2026.2.22 contain incomplete IPv4 special-use range validation in the isPrivateIpv4() function, allowing requests to RFC-reserved ranges to bypass SSRF policy checks. Attackers with network reachability to specia…
- CVE-2026-32022MEDIUMCVSS 6.5EG 6.5✓ Fixed in 2026.2.212026-03-19
OpenClaw versions prior to 2026.2.21 contain a stdin-only policy bypass vulnerability in the grep tool within tools.exec.safeBins that allows attackers to read arbitrary files by supplying a pattern via the -e flag parameter. Attackers can…
- CVE-2026-32035MEDIUMCVSS 5.9EG 5.9✓ Fixed in 2026.3.22026-03-19
OpenClaw versions prior to 2026.3.2 fail to pass the senderIsOwner flag when processing Discord voice transcripts in agentCommand, causing the flag to default to true. Non-owner voice participants can exploit this omission to access owner-…
- CVE-2026-32062HIGHCVSS 7.5EG 7.5✓ Fixed in 2026.2.222026-03-11
OpenClaw versions 2026.2.21-2 up to, but not including, 2026.2.22, and @openclaw/voice-call versions 2026.2.21 up to, but not including, 2026.2.22 accept media-stream WebSocket upgrades before stream validation, allowing unauthenticated cl…
- CVE-2026-32846HIGHCVSS 8.7EG 7.5✓ Fixed in 2026.03.282026-03-26
OpenClaw before 2026.3.28 contains a path traversal vulnerability in media parsing that allows attackers to read arbitrary files by bypassing path validation in the isLikelyLocalPath() and isValidMedia() functions. Attackers can exploit in…
- CVE-2026-32896MEDIUMCVSS 4.8EG 4.8✓ Fixed in 2026.2.212026-03-21
The BlueBubbles webhook handler in OpenClaw versions prior to 2026.2.21 contains a passwordless fallback authentication path that allows unauthenticated webhook events in certain reverse-proxy or local routing configurations. Attackers can…
- CVE-2026-32916CRITICALCVSS 9.4EG 9.4✓ Fixed in 2026.3.112026-03-31
OpenClaw versions 2026.3.7 before 2026.3.11 contain an authorization bypass vulnerability where plugin subagent routes execute gateway methods through a synthetic operator client with broad administrative scopes. Remote unauthenticated req…
- CVE-2026-32920HIGHCVSS 8.4EG 8.4✓ Fixed in 2026.3.122026-03-31
OpenClaw before 2026.3.12 automatically discovers and loads plugins from .OpenClaw/extensions/ without explicit trust verification, allowing arbitrary code execution. Attackers can execute malicious code by including crafted workspace plug…
- CVE-2026-32921MEDIUMCVSS 6.3EG 6.3✓ Fixed in 2026.3.82026-03-31
OpenClaw before 2026.3.8 contains an approval bypass vulnerability in system.run where mutable script operands are not bound across approval and execution phases. Attackers can obtain approval for script execution, modify the approved scri…
- CVE-2026-32970LOWCVSS 2.5EG 2.5✓ Fixed in 2026.3.112026-03-31
OpenClaw before 2026.3.11 contains a credential fallback vulnerability where unavailable local gateway.auth.token and gateway.auth.password SecretRefs are treated as unset, allowing fallback to remote credentials in local mode. Attackers c…
- CVE-2026-32971HIGHCVSS 7.1EG 7.1✓ Fixed in 2026.3.112026-03-31
OpenClaw before 2026.3.11 contains an approval-integrity vulnerability in node-host system.run approvals that displays extracted shell payloads instead of the executed argv. Attackers can place wrapper binaries and induce wrapper-shaped co…
- CVE-2026-32977MEDIUMCVSS 6.3EG 6.3✓ Fixed in 2026.3.112026-03-31
OpenClaw before 2026.3.11 contains a sandbox boundary bypass vulnerability in the fs-bridge writeFile commit step that uses an unanchored container path during the final move operation. An attacker can exploit a time-of-check-time-of-use r…
- CVE-2026-33579CRITICALCVSS 9.9EG 9.9✓ Fixed in 2026.3.282026-03-31
OpenClaw before 2026.3.28 contains a privilege escalation vulnerability in the /pair approve command path that fails to forward caller scopes into the core approval check. A caller with pairing privileges but without admin privileges can a…
- CVE-2026-34425MEDIUMCVSS 5.4EG 5.4✓ Fixed in 2026.4.22026-04-02
OpenClaw versions prior to commit 8aceaf5 contain a preflight validation bypass vulnerability in shell-bleed protection that allows attackers to execute blocked script content by using piped or complex command forms that the parser fails t…
- CVE-2026-34426HIGHCVSS 7.6EG 7.6✓ Fixed in 2026.3.222026-04-02
OpenClaw versions prior to commit b57b680 contain an approval bypass vulnerability due to inconsistent environment variable normalization between approval and execution paths, allowing attackers to inject attacker-controlled environment v…
- CVE-2026-34503HIGHCVSS 8.1EG 8.1✓ Fixed in 2026.3.282026-03-31
OpenClaw before 2026.3.28 fails to disconnect active WebSocket sessions when devices are removed or tokens are revoked. Attackers with revoked credentials can maintain unauthorized access through existing live sessions until forced reconne…
- CVE-2026-34504HIGHCVSS 8.3EG 8.3✓ Fixed in 2026.3.282026-03-31
OpenClaw before 2026.3.28 contains a server-side request forgery vulnerability in the fal provider image-generation-provider.ts component that allows attackers to fetch internal URLs. A malicious or compromised fal relay can exploit unguar…
- CVE-2026-34505MEDIUMCVSS 6.5EG 6.5✓ Fixed in 2026.3.122026-03-31
OpenClaw before 2026.3.12 applies rate limiting only after successful webhook authentication, allowing attackers to bypass rate limits and brute-force webhook secrets. Attackers can submit repeated authentication requests with invalid secr…
- CVE-2026-34511MEDIUMCVSS 5.3EG 5.3✓ Fixed in 2026.4.22026-04-03
OpenClaw before 2026.4.2 reuses the PKCE verifier as the OAuth state parameter in the Gemini OAuth flow, exposing it through the redirect URL. Attackers who capture the redirect URL can obtain both the authorization code and PKCE verifier,…
- CVE-2026-35617MEDIUMCVSS 4.2EG 4.2✓ Fixed in 2026.3.282026-04-09
OpenClaw before 2026.3.25 contains an authorization bypass vulnerability in Google Chat group policy enforcement that relies on mutable space display names. Attackers can rebind group policies by changing or colliding space display names t…
- CVE-2026-35618MEDIUMCVSS 6.5EG 6.5✓ Fixed in 2026.3.232026-04-09
OpenClaw before 2026.3.23 contains a replay identity vulnerability in Plivo V2 signature verification that allows attackers to bypass replay protection by modifying query parameters. The verification path derives replay keys from the full …
- CVE-2026-35619MEDIUMCVSS 4.3EG 4.3✓ Fixed in 2026.3.242026-04-10
OpenClaw before 2026.3.24 contains an authorization bypass vulnerability in the HTTP /v1/models endpoint that fails to enforce operator read scope requirements. Attackers with only operator.approvals scope can enumerate gateway model metad…
- CVE-2026-35620MEDIUMCVSS 5.4EG 5.4✓ Fixed in 2026.3.242026-04-10
OpenClaw before 2026.3.24 contains missing authorization vulnerabilities in the /send and /allowlist chat command handlers. The /send command allows non-owner command-authorized senders to change owner-only session delivery policy settings…
- CVE-2026-35621MEDIUMCVSS 6.5EG 6.5✓ Fixed in 2026.3.242026-04-10
OpenClaw before 2026.3.24 contains a privilege escalation vulnerability where the /allowlist command fails to re-validate gateway client scopes for internal callers, allowing operator.write-scoped clients to mutate channel authorization po…
- CVE-2026-35622MEDIUMCVSS 5.9EG 5.9✓ Fixed in 2026.3.222026-04-09
OpenClaw before 2026.3.22 contains an improper authentication verification vulnerability in Google Chat app-url webhook handling that accepts add-on principals outside intended deployment bindings. Attackers can bypass webhook authenticati…
- CVE-2026-35623MEDIUMCVSS 4.8EG 4.82026-04-09
OpenClaw before 2026.3.25 contains a missing rate limiting vulnerability in webhook authentication that allows attackers to brute-force weak webhook passwords without throttling. Remote attackers can repeatedly submit incorrect password gu…
- CVE-2026-35624MEDIUMCVSS 4.2EG 4.2✓ Fixed in 2026.3.222026-04-09
OpenClaw before 2026.3.22 contains a policy confusion vulnerability in room authorization that matches colliding room names instead of stable room tokens. Attackers can exploit similarly named rooms to bypass allowlist policies and gain un…
- CVE-2026-35626MEDIUMCVSS 5.3EG 5.3✓ Fixed in 2026.3.222026-04-09
OpenClaw before 2026.3.22 contains an unauthenticated resource exhaustion vulnerability in voice call webhook handling that buffers request bodies before provider signature checks. Attackers can send large or malicious webhook requests to …
- CVE-2026-35627MEDIUMCVSS 6.5EG 6.5✓ Fixed in 2026.3.222026-04-09
OpenClaw before 2026.3.22 performs cryptographic and dispatch operations on inbound Nostr direct messages before enforcing sender and pairing policy validation. Attackers can trigger unauthorized pre-authentication computation by sending c…
- CVE-2026-35628MEDIUMCVSS 4.8EG 4.82026-04-09
OpenClaw before 2026.3.25 contains a missing rate limiting vulnerability in Telegram webhook authentication that allows attackers to brute-force weak webhook secrets. The vulnerability enables repeated authentication guesses without thrott…
- CVE-2026-35629HIGHCVSS 7.4EG 7.4✓ Fixed in 2026.3.282026-04-09
OpenClaw before 2026.3.25 contains a server-side request forgery vulnerability in multiple channel extensions that fail to properly guard configured base URLs against SSRF attacks. Attackers can exploit unprotected fetch() calls against co…
- CVE-2026-35632HIGHCVSS 7.1EG 7.12026-04-09
OpenClaw through 2026.2.22 contains a symlink traversal vulnerability in agents.create and agents.update handlers that use fs.appendFile on IDENTITY.md without symlink containment checks. Attackers with workspace access can plant symlinks …
- CVE-2026-35633MEDIUMCVSS 5.3EG 5.3✓ Fixed in 2026.3.222026-04-09
OpenClaw before 2026.3.22 contains an unbounded memory allocation vulnerability in remote media HTTP error handling that allows attackers to trigger excessive memory consumption. Attackers can send crafted HTTP error responses with large b…
- CVE-2026-35634MEDIUMCVSS 5.1EG 5.1✓ Fixed in 2026.3.232026-04-09
OpenClaw before 2026.3.23 contains an authentication bypass vulnerability in the Canvas gateway where authorizeCanvasRequest() unconditionally allows local-direct requests without validating bearer tokens or canvas capabilities. Attackers …
- CVE-2026-35635MEDIUMCVSS 4.8EG 4.8✓ Fixed in 2026.3.222026-04-09
OpenClaw before 2026.3.22 contains a webhook path route replacement vulnerability in the Synology Chat extension that allows attackers to collapse multi-account configurations onto shared webhook paths. Attackers can exploit inherited or d…
- CVE-2026-35637HIGHCVSS 7.3EG 7.3✓ Fixed in 2026.3.222026-04-09
OpenClaw before 2026.3.22 performs cite expansion before completing channel and DM authorization checks, allowing cite work and content handling prior to final auth decisions. Attackers can exploit this timing vulnerability to access or ma…
- CVE-2026-35639HIGHCVSS 8.8EG 8.8✓ Fixed in 2026.3.222026-04-09
OpenClaw before 2026.3.22 contains a privilege escalation vulnerability in the device.pair.approve method that allows an operator.pairing approver to approve pending device requests with broader operator scopes than the approver actually h…
- CVE-2026-35640MEDIUMCVSS 5.3EG 5.3✓ Fixed in 2026.3.282026-04-09
OpenClaw before 2026.3.25 parses JSON request bodies before validating webhook signatures, allowing unauthenticated attackers to force resource-intensive parsing operations. Remote attackers can send malicious webhook requests to trigger d…
- CVE-2026-35641HIGHCVSS 7.8EG 7.8✓ Fixed in 2026.3.242026-04-10
OpenClaw before 2026.3.24 contains an arbitrary code execution vulnerability in local plugin and hook installation that allows attackers to execute malicious code by crafting a .npmrc file with a git executable override. During npm install…
- CVE-2026-35643HIGHCVSS 8.8EG 8.8✓ Fixed in 2026.3.222026-04-10
OpenClaw before 2026.3.22 contains an unvalidated WebView JavascriptInterface vulnerability allowing attackers to inject arbitrary instructions. Untrusted pages can invoke the canvas bridge to execute malicious code within the Android appl…
- CVE-2026-35645HIGHCVSS 8.1EG 8.1✓ Fixed in 2026.3.282026-04-09
OpenClaw before 2026.3.25 contains a privilege escalation vulnerability in the gateway plugin subagent fallback deleteSession function that uses a synthetic operator.admin runtime scope. Attackers can exploit this by triggering session del…
- CVE-2026-35646MEDIUMCVSS 4.8EG 4.8✓ Fixed in 2026.3.282026-04-09
OpenClaw before 2026.3.25 contains a pre-authentication rate-limit bypass vulnerability in webhook token validation that allows attackers to brute-force weak webhook secrets. The vulnerability exists because invalid webhook tokens are reje…
Check whether openclaw is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for openclaw CVEs against the assets you own.
Start Free Scan →