openclaw
npm530 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting openclawpage 1 of 11
- CVE-2026-22168MEDIUMCVSS 6.5EG 6.5✓ Fixed in 2026.2.212026-03-18
OpenClaw versions prior to 2026.2.21 contain an approval-integrity mismatch vulnerability in system.run that allows authenticated operators to execute arbitrary trailing arguments after cmd.exe /c while approval text reflects only a benign…
- CVE-2026-22169MEDIUMCVSS 6.7EG 6.7✓ Fixed in 2026.2.222026-03-18
OpenClaw versions prior to 2026.2.22 contain an allowlist bypass vulnerability in the safeBins configuration that allows attackers to invoke external helpers through the compress-program option. When sort is explicitly added to tools.exec.…
- CVE-2026-22170MEDIUMCVSS 6.5EG 6.5✓ Fixed in 2026.2.222026-03-18
OpenClaw versions prior to 2026.2.22 with the optional BlueBubbles plugin contain an access control bypass vulnerability where empty allowFrom configuration causes dmPolicy pairing and allowlist restrictions to be ineffective. Remote attac…
- CVE-2026-22171HIGHCVSS 8.2EG 8.2✓ Fixed in 2026.2.192026-03-18
OpenClaw versions prior to 2026.2.19 contain a path traversal vulnerability in the Feishu media download flow where untrusted media keys are interpolated directly into temporary file paths in extensions/feishu/src/media.ts. An attacker who…
- CVE-2026-22172CRITICALCVSS 9.9EG 9.9✓ Fixed in 2026.3.122026-03-20
OpenClaw versions prior to 2026.3.12 contain an authorization bypass vulnerability in the WebSocket connect path that allows shared-token or password-authenticated connections to self-declare elevated scopes without server-side binding. At…
- CVE-2026-22174MEDIUMCVSS 6.8EG 6.8✓ Fixed in 2026.2.222026-03-18
OpenClaw versions prior to 2026.2.22 inject the x-OpenClaw-relay-token header into Chrome CDP probe traffic on loopback interfaces, allowing local processes to capture the Gateway authentication token. An attacker controlling a loopback po…
- CVE-2026-22175HIGHCVSS 7.1EG 7.1✓ Fixed in 2026.2.232026-03-18
OpenClaw versions prior to 2026.2.23 contain an exec approval bypass vulnerability in allowlist mode where allow-always grants could be circumvented through unrecognized multiplexer shell wrappers like busybox and toybox sh -c commands. At…
- CVE-2026-22176MEDIUMCVSS 6.1EG 6.1✓ Fixed in 2026.2.192026-03-19
OpenClaw versions prior to 2026.2.19 contain a command injection vulnerability in Windows Scheduled Task script generation where environment variables are written to gateway.cmd using unquoted set KEY=VALUE assignments, allowing shell meta…
- CVE-2026-22177HIGHCVSS 8.8EG 8.8✓ Fixed in 2026.2.212026-03-18
OpenClaw versions prior to 2026.2.21 fail to filter dangerous process-control environment variables from config env.vars, allowing startup-time code execution. Attackers can inject variables like NODE_OPTIONS or LD_* through configuration …
- CVE-2026-22178MEDIUMCVSS 6.5EG 6.5✓ Fixed in 2026.2.192026-03-18
OpenClaw versions prior to 2026.2.19 construct RegExp objects directly from unescaped Feishu mention metadata in the stripBotMention function, allowing regex injection and denial of service. Attackers can craft nested-quantifier patterns o…
- CVE-2026-22179HIGHCVSS 7.2EG 7.2✓ Fixed in 2026.2.222026-03-18
OpenClaw versions prior to 2026.2.22 in macOS node-host system.run contain an allowlist bypass vulnerability that allows remote attackers to execute non-allowlisted commands by exploiting improper parsing of command substitution tokens. At…
- CVE-2026-22180MEDIUMCVSS 5.3EG 5.3✓ Fixed in 2026.3.22026-03-18
OpenClaw versions prior to 2026.3.2 contain a path-confinement bypass vulnerability in browser output handling that allows writes outside intended root directories. Attackers can exploit insufficient canonical path-boundary validation in f…
- CVE-2026-22181HIGHCVSS 7.6EG 7.6✓ Fixed in 2026.3.22026-03-18
OpenClaw versions prior to 2026.3.2 contain a DNS pinning bypass vulnerability in strict URL fetch paths that allows attackers to circumvent SSRF guards when environment proxy variables are configured. When HTTP_PROXY, HTTPS_PROXY, or ALL_…
- CVE-2026-22217MEDIUMCVSS 6.1EG 6.1✓ Fixed in 2026.2.232026-03-18
OpenClaw version 2026.2.22 prior to 2026.2.23 contains an arbitrary code execution vulnerability in shell-env that allows attackers to execute attacker-controlled binaries by exploiting trusted-prefix fallback logic for the $SHELL variable…
- CVE-2026-24764LOWCVSS 3.7EG 3.7✓ Fixed in 2026.2.32026-02-19
OpenClaw (formerly Clawdbot) is a personal AI assistant users run on their own devices. In versions 2026.2.2 and below, when the Slack integration is enabled, channel metadata (topic/description) can be incorporated into the model's system…
- CVE-2026-25474HIGHCVSS 7.5EG 7.5✓ Fixed in 2026.2.12026-02-19
OpenClaw is a personal AI assistant. In versions 2026.1.30 and below, if channels.telegram.webhookSecret is not set when in Telegram webhook mode, OpenClaw may accept webhook HTTP requests without verifying Telegram’s secret token header…
- CVE-2026-25475MEDIUMCVSS 6.5EG 6.5✓ Fixed in 2026.1.302026-02-04
OpenClaw is a personal AI assistant. Prior to version 2026.1.30, the isValidMedia() function in src/media/parse.ts allows arbitrary file paths including absolute paths, home directory paths, and directory traversal sequences. An agent can …
- CVE-2026-25593HIGHCVSS 8.4EG 8.4✓ Fixed in 2026.1.202026-02-06
OpenClaw is a personal AI assistant. Prior to 2026.1.20, an unauthenticated local client could use the Gateway WebSocket API to write config via config.apply and set unsafe cliPath values that were later used for command discovery, enablin…
- CVE-2026-26316HIGHCVSS 7.5EG 7.5✓ Fixed in 2026.2.132026-02-19
OpenClaw is a personal AI assistant. Prior to 2026.2.13, the optional BlueBubbles iMessage channel plugin could accept webhook requests as authenticated based only on the TCP peer address being loopback (`127.0.0.1`, `::1`, `::ffff:127.0.0…
- CVE-2026-26317HIGHCVSS 7.1EG 7.1✓ Fixed in 2026.2.142026-02-19
OpenClaw is a personal AI assistant. Prior to 2026.2.14, browser-facing localhost mutation routes accepted cross-origin browser requests without explicit Origin/Referer validation. Loopback binding reduces remote exposure but does not prev…
- CVE-2026-26319HIGHCVSS 7.5EG 7.5✓ Fixed in 2026.2.142026-02-19
OpenClaw is a personal AI assistant. Versions 2026.2.13 and below allow the optional @openclaw/voice-call plugin Telnyx webhook handler to accept unsigned inbound webhook requests when telnyx.publicKey is not configured, enabling unauthent…
- CVE-2026-26320MEDIUMCVSS 6.5EG 6.5✓ Fixed in 2026.2.142026-02-19
OpenClaw is a personal AI assistant. OpenClaw macOS desktop client registers the `openclaw://` URL scheme. For `openclaw://agent` deep links without an unattended `key`, the app shows a confirmation dialog that previously displayed only th…
- CVE-2026-26321HIGHCVSS 7.5EG 7.5✓ Fixed in 2026.2.142026-02-19
OpenClaw is a personal AI assistant. Prior to OpenClaw version 2026.2.14, the Feishu extension previously allowed `sendMediaFeishu` to treat attacker-controlled `mediaUrl` values as local filesystem paths and read them directly. If an atta…
- CVE-2026-26322HIGHCVSS 7.6EG 7.6✓ Fixed in 2026.2.142026-02-19
OpenClaw is a personal AI assistant. Prior to OpenClaw version 2026.2.14, the Gateway tool accepted a tool-supplied `gatewayUrl` without sufficient restrictions, which could cause the OpenClaw host to attempt outbound WebSocket connections…
- CVE-2026-26323HIGHCVSS 8.8EG 8.8✓ Fixed in 2026.2.142026-02-19
OpenClaw is a personal AI assistant. Versions 2026.1.8 through 2026.2.13 have a command injection in the maintainer/dev script `scripts/update-clawtributors.ts`. The issue affects contributors/maintainers (or CI) who run `bun scripts/updat…
- CVE-2026-26324HIGHCVSS 7.5EG 7.5✓ Fixed in 2026.2.142026-02-19
OpenClaw is a personal AI assistant. Prior to version 2026.2.14, OpenClaw's SSRF protection could be bypassed using full-form IPv4-mapped IPv6 literals such as `0:0:0:0:0:ffff:7f00:1` (which is `127.0.0.1`). This could allow requests that …
- CVE-2026-26325HIGHCVSS 7.2EG 7.2✓ Fixed in 2026.2.142026-02-19
OpenClaw is a personal AI assistant. Prior to version 2026.2.14, a mismatch between `rawCommand` and `command[]` in the node host `system.run` handler could cause allowlist/approval evaluation to be performed on one command while executing…
- CVE-2026-26326MEDIUMCVSS 4.3EG 4.3✓ Fixed in 2026.2.142026-02-19
OpenClaw is a personal AI assistant. Prior to version 2026.2.14, `skills.status` could disclose secrets to `operator.read` clients by returning raw resolved config values in `configChecks` for skill `requires.config` paths. Version 2026.2.…
- CVE-2026-26327MEDIUMCVSS 6.5EG 6.5✓ Fixed in 2026.2.142026-02-19
OpenClaw is a personal AI assistant. Discovery beacons (Bonjour/mDNS and DNS-SD) include TXT records such as `lanHost`, `tailnetDns`, `gatewayPort`, and `gatewayTlsSha256`. TXT records are unauthenticated. Prior to version 2026.2.14, some …
- CVE-2026-26328MEDIUMCVSS 6.5EG 6.5✓ Fixed in 2026.2.142026-02-20
OpenClaw is a personal AI assistant. Prior to version 2026.2.14, under iMessage `groupPolicy=allowlist`, group authorization could be satisfied by sender identities coming from the DM pairing store, broadening DM trust into group contexts.…
- CVE-2026-26329MEDIUMCVSS 6.5EG 6.5✓ Fixed in 2026.2.142026-02-20
OpenClaw is a personal AI assistant. Prior to version 2026.2.14, authenticated attackers can read arbitrary files from the Gateway host by supplying absolute paths or path traversal sequences to the browser tool's `upload` action. The serv…
- CVE-2026-26972MEDIUMCVSS 6.7EG 6.7✓ Fixed in 2026.2.132026-02-20
OpenClaw is a personal AI assistant. In versions 2026.1.12 through 2026.2.12, OpenClaw browser download helpers accepted an unsanitized output path. When invoked via the browser control gateway routes, this allowed path traversal to write …
- CVE-2026-27001HIGHCVSS 7.8EG 7.8✓ Fixed in 2026.2.152026-02-20
OpenClaw is a personal AI assistant. Prior to version 2026.2.15, OpenClaw embedded the current working directory (workspace path) into the agent system prompt without sanitization. If an attacker can cause OpenClaw to run inside a director…
- CVE-2026-27002CRITICALCVSS 9.8EG 9.8✓ Fixed in 2026.2.152026-02-20
OpenClaw is a personal AI assistant. Prior to version 2026.2.15, a configuration injection issue in the Docker tool sandbox could allow dangerous Docker options (bind mounts, host networking, unconfined profiles) to be applied, enabling co…
- CVE-2026-27003MEDIUMCVSS 5.5EG 5.5✓ Fixed in 2026.2.152026-02-20
OpenClaw is a personal AI assistant. Telegram bot tokens can appear in error messages and stack traces (for example, when request URLs include `https://api.telegram.org/bot<token>/...`). Prior to version 2026.2.15, OpenClaw logged these st…
- CVE-2026-27004MEDIUMCVSS 5.5EG 5.5✓ Fixed in 2026.2.152026-02-20
OpenClaw is a personal AI assistant. Prior to version 2026.2.15, in some shared-agent deployments, OpenClaw session tools (`sessions_list`, `sessions_history`, `sessions_send`) allowed broader session targeting than some operators intended…
- CVE-2026-27007LOWCVSS 3.3EG 3.3✓ Fixed in 2026.2.152026-02-20
OpenClaw is a personal AI assistant. Prior to version 2026.2.15, `normalizeForHash` in `src/agents/sandbox/config-hash.ts` recursively sorted arrays that contained only primitive values. This made order-sensitive sandbox configuration arra…
- CVE-2026-27008MEDIUMCVSS 6.7EG 6.7✓ Fixed in 2026.2.152026-02-20
OpenClaw is a personal AI assistant. Prior to version 2026.2.15, a bug in `download` skill installation allowed `targetDir` values from skill frontmatter to resolve outside the per-skill tools directory if not strictly validated. In the ad…
- CVE-2026-27009MEDIUMCVSS 5.8EG 5.8✓ Fixed in 2026.2.152026-02-20
OpenClaw is a personal AI assistant. Prior to version 2026.2.15, a atored XSS issue in the OpenClaw Control UI when rendering assistant identity (name/avatar) into an inline `<script>` tag without script-context-safe escaping. A crafted va…
- CVE-2026-27183MEDIUMCVSS 5.3EG 5.3✓ Fixed in 2026.3.72026-03-23
OpenClaw versions prior to 2026.3.7 contain a shell approval gating bypass vulnerability in system.run dispatch-wrapper handling that allows attackers to skip shell wrapper approval requirements. The approval classifier and execution plann…
- CVE-2026-27484MEDIUMCVSS 4.3EG 4.3✓ Fixed in 2026.2.182026-02-21
OpenClaw is a personal AI assistant. In versions 2026.2.17 and below, the Discord moderation action handling (timeout, kick, ban) uses sender identity from request parameters in tool-driven flows, instead of trusted runtime sender context.…
- CVE-2026-27485MEDIUMCVSS 4.4EG 4.4✓ Fixed in 2026.2.192026-02-21
OpenClaw is a personal AI assistant. In versions 2026.2.17 and below, skills/skill-creator/scripts/package_skill.py (a local helper script used when authors package skills) previously followed symlinks while building .skill archives. If an…
- CVE-2026-27486MEDIUMCVSS 5.3EG 5.3✓ Fixed in 2026.2.142026-02-21
OpenClaw is a personal AI assistant. In versions 2026.2.13 and below of the OpenClaw CLI, the process cleanup uses system-wide process enumeration and pattern matching to terminate processes without verifying if they are owned by the curre…
- CVE-2026-27487HIGHCVSS 8.0EG 8.0✓ Fixed in 2026.2.142026-02-21
OpenClaw is a personal AI assistant. In versions 2026.2.13 and below, when using macOS, the Claude CLI keychain credential refresh path constructed a shell command to write the updated JSON blob into Keychain via security add-generic-passw…
- CVE-2026-27488HIGHCVSS 7.3EG 7.3✓ Fixed in 2026.2.192026-02-21
OpenClaw is a personal AI assistant. In versions 2026.2.17 and below, Cron webhook delivery in src/gateway/server-cron.ts uses fetch() directly, so webhook targets can reach private/metadata/internal endpoints without SSRF policy checks. T…
- CVE-2026-27522MEDIUMCVSS 6.5EG 6.5✓ Fixed in 2026.2.242026-03-18
OpenClaw versions prior to 2026.2.24 contain a local media root bypass vulnerability in sendAttachment and setGroupIcon message actions when sandboxRoot is unset. Attackers can hydrate media from local absolute paths to read arbitrary host…
- CVE-2026-27523MEDIUMCVSS 6.1EG 6.1✓ Fixed in 2026.2.242026-03-18
OpenClaw versions prior to 2026.2.24 contain a sandbox bind validation vulnerability allowing attackers to bypass allowed-root and blocked-path checks via symlinked parent directories with non-existent leaf paths. Attackers can craft bind …
- CVE-2026-27524MEDIUMCVSS 4.3EG 4.3✓ Fixed in 2026.2.212026-03-18
OpenClaw versions prior to 2026.2.21 accept prototype-reserved keys in runtime /debug set override object values, allowing prototype pollution attacks. Authorized /debug set callers can inject __proto__, constructor, or prototype keys to m…
- CVE-2026-27545MEDIUMCVSS 6.1EG 6.1✓ Fixed in 2026.2.262026-03-18
OpenClaw versions prior to 2026.2.26 contain an approval bypass vulnerability in system.run execution that allows attackers to execute commands from unintended filesystem locations by rebinding writable parent symlinks in the current worki…
- CVE-2026-27566HIGHCVSS 7.1EG 7.1✓ Fixed in 2026.2.222026-03-19
OpenClaw versions prior to 2026.2.22 contain an allowlist bypass vulnerability in system.run exec analysis that fails to unwrap env and shell-dispatch wrapper chains. Attackers can route execution through wrapper binaries like env bash to …
Check whether openclaw is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for openclaw CVEs against the assets you own.
Start Free Scan →