openclaw
npm530 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting openclawpage 1 of 11
- CVE-2026-22168MEDIUMCVSS 6.5EG 6.5fixed in 2026.2.212026-03-18
OpenClaw versions prior to 2026.2.21 contain an approval-integrity mismatch vulnerability in system.run that allows authenticated operators to execute arbitrary trailing arguments after cmd.exe /c while approval text reflects only a benign…
- CVE-2026-22169MEDIUMCVSS 6.7EG 6.7fixed in 2026.2.222026-03-18
OpenClaw versions prior to 2026.2.22 contain an allowlist bypass vulnerability in the safeBins configuration that allows attackers to invoke external helpers through the compress-program option. When sort is explicitly added to tools.exec.…
- CVE-2026-22170MEDIUMCVSS 6.5EG 6.5fixed in 2026.2.222026-03-18
OpenClaw versions prior to 2026.2.22 with the optional BlueBubbles plugin contain an access control bypass vulnerability where empty allowFrom configuration causes dmPolicy pairing and allowlist restrictions to be ineffective. Remote attac…
- CVE-2026-22171HIGHCVSS 8.2EG 8.2fixed in 2026.2.192026-03-18
OpenClaw versions prior to 2026.2.19 contain a path traversal vulnerability in the Feishu media download flow where untrusted media keys are interpolated directly into temporary file paths in extensions/feishu/src/media.ts. An attacker who…
- CVE-2026-22172CRITICALCVSS 9.9EG 9.9fixed in 2026.3.122026-03-20
OpenClaw versions prior to 2026.3.12 contain an authorization bypass vulnerability in the WebSocket connect path that allows shared-token or password-authenticated connections to self-declare elevated scopes without server-side binding. At…
- CVE-2026-22174MEDIUMCVSS 6.8EG 6.8fixed in 2026.2.222026-03-18
OpenClaw versions prior to 2026.2.22 inject the x-OpenClaw-relay-token header into Chrome CDP probe traffic on loopback interfaces, allowing local processes to capture the Gateway authentication token. An attacker controlling a loopback po…
- CVE-2026-22175HIGHCVSS 7.1EG 7.1fixed in 2026.2.232026-03-18
OpenClaw versions prior to 2026.2.23 contain an exec approval bypass vulnerability in allowlist mode where allow-always grants could be circumvented through unrecognized multiplexer shell wrappers like busybox and toybox sh -c commands. At…
- CVE-2026-22176MEDIUMCVSS 6.1EG 6.1fixed in 2026.2.192026-03-19
OpenClaw versions prior to 2026.2.19 contain a command injection vulnerability in Windows Scheduled Task script generation where environment variables are written to gateway.cmd using unquoted set KEY=VALUE assignments, allowing shell meta…
- CVE-2026-22177HIGHCVSS 8.8EG 8.8fixed in 2026.2.212026-03-18
OpenClaw versions prior to 2026.2.21 fail to filter dangerous process-control environment variables from config env.vars, allowing startup-time code execution. Attackers can inject variables like NODE_OPTIONS or LD_* through configuration …
- CVE-2026-22178MEDIUMCVSS 6.5EG 6.5fixed in 2026.2.192026-03-18
OpenClaw versions prior to 2026.2.19 construct RegExp objects directly from unescaped Feishu mention metadata in the stripBotMention function, allowing regex injection and denial of service. Attackers can craft nested-quantifier patterns o…
- CVE-2026-22179HIGHCVSS 7.2EG 7.2fixed in 2026.2.222026-03-18
OpenClaw versions prior to 2026.2.22 in macOS node-host system.run contain an allowlist bypass vulnerability that allows remote attackers to execute non-allowlisted commands by exploiting improper parsing of command substitution tokens. At…
- CVE-2026-22180MEDIUMCVSS 5.3EG 5.3fixed in 2026.3.22026-03-18
OpenClaw versions prior to 2026.3.2 contain a path-confinement bypass vulnerability in browser output handling that allows writes outside intended root directories. Attackers can exploit insufficient canonical path-boundary validation in f…
- CVE-2026-22181HIGHCVSS 7.6EG 7.6fixed in 2026.3.22026-03-18
OpenClaw versions prior to 2026.3.2 contain a DNS pinning bypass vulnerability in strict URL fetch paths that allows attackers to circumvent SSRF guards when environment proxy variables are configured. When HTTP_PROXY, HTTPS_PROXY, or ALL_…
- CVE-2026-22217MEDIUMCVSS 6.1EG 6.1fixed in 2026.2.232026-03-18
OpenClaw version 2026.2.22 prior to 2026.2.23 contains an arbitrary code execution vulnerability in shell-env that allows attackers to execute attacker-controlled binaries by exploiting trusted-prefix fallback logic for the $SHELL variable…
- CVE-2026-24764LOWCVSS 3.7EG 3.7fixed in 2026.2.32026-02-19
OpenClaw (formerly Clawdbot) is a personal AI assistant users run on their own devices. In versions 2026.2.2 and below, when the Slack integration is enabled, channel metadata (topic/description) can be incorporated into the model's system…
- CVE-2026-25474HIGHCVSS 7.5EG 7.5fixed in 2026.2.12026-02-19
OpenClaw is a personal AI assistant. In versions 2026.1.30 and below, if channels.telegram.webhookSecret is not set when in Telegram webhook mode, OpenClaw may accept webhook HTTP requests without verifying Telegram’s secret token header…
- CVE-2026-25475MEDIUMCVSS 6.5EG 6.5fixed in 2026.1.302026-02-04
OpenClaw is a personal AI assistant. Prior to version 2026.1.30, the isValidMedia() function in src/media/parse.ts allows arbitrary file paths including absolute paths, home directory paths, and directory traversal sequences. An agent can …
- CVE-2026-25593HIGHCVSS 8.4EG 8.4fixed in 2026.1.202026-02-06
OpenClaw is a personal AI assistant. Prior to 2026.1.20, an unauthenticated local client could use the Gateway WebSocket API to write config via config.apply and set unsafe cliPath values that were later used for command discovery, enablin…
- CVE-2026-26316HIGHCVSS 7.5EG 7.5fixed in 2026.2.132026-02-19
OpenClaw is a personal AI assistant. Prior to 2026.2.13, the optional BlueBubbles iMessage channel plugin could accept webhook requests as authenticated based only on the TCP peer address being loopback (`127.0.0.1`, `::1`, `::ffff:127.0.0…
- CVE-2026-26317HIGHCVSS 7.1EG 7.1fixed in 2026.2.142026-02-19
OpenClaw is a personal AI assistant. Prior to 2026.2.14, browser-facing localhost mutation routes accepted cross-origin browser requests without explicit Origin/Referer validation. Loopback binding reduces remote exposure but does not prev…
- CVE-2026-26319HIGHCVSS 7.5EG 7.5fixed in 2026.2.142026-02-19
OpenClaw is a personal AI assistant. Versions 2026.2.13 and below allow the optional @openclaw/voice-call plugin Telnyx webhook handler to accept unsigned inbound webhook requests when telnyx.publicKey is not configured, enabling unauthent…
- CVE-2026-26320MEDIUMCVSS 6.5EG 6.5fixed in 2026.2.142026-02-19
OpenClaw is a personal AI assistant. OpenClaw macOS desktop client registers the `openclaw://` URL scheme. For `openclaw://agent` deep links without an unattended `key`, the app shows a confirmation dialog that previously displayed only th…
- CVE-2026-26321HIGHCVSS 7.5EG 7.5fixed in 2026.2.142026-02-19
OpenClaw is a personal AI assistant. Prior to OpenClaw version 2026.2.14, the Feishu extension previously allowed `sendMediaFeishu` to treat attacker-controlled `mediaUrl` values as local filesystem paths and read them directly. If an atta…
- CVE-2026-26322HIGHCVSS 7.6EG 7.6fixed in 2026.2.142026-02-19
OpenClaw is a personal AI assistant. Prior to OpenClaw version 2026.2.14, the Gateway tool accepted a tool-supplied `gatewayUrl` without sufficient restrictions, which could cause the OpenClaw host to attempt outbound WebSocket connections…
- CVE-2026-26323HIGHCVSS 8.8EG 8.8fixed in 2026.2.142026-02-19
OpenClaw is a personal AI assistant. Versions 2026.1.8 through 2026.2.13 have a command injection in the maintainer/dev script `scripts/update-clawtributors.ts`. The issue affects contributors/maintainers (or CI) who run `bun scripts/updat…
- CVE-2026-26324HIGHCVSS 7.5EG 7.5fixed in 2026.2.142026-02-19
OpenClaw is a personal AI assistant. Prior to version 2026.2.14, OpenClaw's SSRF protection could be bypassed using full-form IPv4-mapped IPv6 literals such as `0:0:0:0:0:ffff:7f00:1` (which is `127.0.0.1`). This could allow requests that …
- CVE-2026-26325HIGHCVSS 7.2EG 7.2fixed in 2026.2.142026-02-19
OpenClaw is a personal AI assistant. Prior to version 2026.2.14, a mismatch between `rawCommand` and `command[]` in the node host `system.run` handler could cause allowlist/approval evaluation to be performed on one command while executing…
- CVE-2026-26326MEDIUMCVSS 4.3EG 4.3fixed in 2026.2.142026-02-19
OpenClaw is a personal AI assistant. Prior to version 2026.2.14, `skills.status` could disclose secrets to `operator.read` clients by returning raw resolved config values in `configChecks` for skill `requires.config` paths. Version 2026.2.…
- CVE-2026-26327MEDIUMCVSS 6.5EG 6.5fixed in 2026.2.142026-02-19
OpenClaw is a personal AI assistant. Discovery beacons (Bonjour/mDNS and DNS-SD) include TXT records such as `lanHost`, `tailnetDns`, `gatewayPort`, and `gatewayTlsSha256`. TXT records are unauthenticated. Prior to version 2026.2.14, some …
- CVE-2026-26328MEDIUMCVSS 6.5EG 6.5fixed in 2026.2.142026-02-20
OpenClaw is a personal AI assistant. Prior to version 2026.2.14, under iMessage `groupPolicy=allowlist`, group authorization could be satisfied by sender identities coming from the DM pairing store, broadening DM trust into group contexts.…
- CVE-2026-26329MEDIUMCVSS 6.5EG 6.5fixed in 2026.2.142026-02-20
OpenClaw is a personal AI assistant. Prior to version 2026.2.14, authenticated attackers can read arbitrary files from the Gateway host by supplying absolute paths or path traversal sequences to the browser tool's `upload` action. The serv…
- CVE-2026-26972MEDIUMCVSS 6.7EG 6.7fixed in 2026.2.132026-02-20
OpenClaw is a personal AI assistant. In versions 2026.1.12 through 2026.2.12, OpenClaw browser download helpers accepted an unsanitized output path. When invoked via the browser control gateway routes, this allowed path traversal to write …
- CVE-2026-27001HIGHCVSS 7.8EG 7.8fixed in 2026.2.152026-02-20
OpenClaw is a personal AI assistant. Prior to version 2026.2.15, OpenClaw embedded the current working directory (workspace path) into the agent system prompt without sanitization. If an attacker can cause OpenClaw to run inside a director…
- CVE-2026-27002CRITICALCVSS 9.8EG 9.8fixed in 2026.2.152026-02-20
OpenClaw is a personal AI assistant. Prior to version 2026.2.15, a configuration injection issue in the Docker tool sandbox could allow dangerous Docker options (bind mounts, host networking, unconfined profiles) to be applied, enabling co…
- CVE-2026-27003MEDIUMCVSS 5.5EG 5.5fixed in 2026.2.152026-02-20
OpenClaw is a personal AI assistant. Telegram bot tokens can appear in error messages and stack traces (for example, when request URLs include `https://api.telegram.org/bot<token>/...`). Prior to version 2026.2.15, OpenClaw logged these st…
- CVE-2026-27004MEDIUMCVSS 5.5EG 5.5fixed in 2026.2.152026-02-20
OpenClaw is a personal AI assistant. Prior to version 2026.2.15, in some shared-agent deployments, OpenClaw session tools (`sessions_list`, `sessions_history`, `sessions_send`) allowed broader session targeting than some operators intended…
- CVE-2026-27007LOWCVSS 3.3EG 3.3fixed in 2026.2.152026-02-20
OpenClaw is a personal AI assistant. Prior to version 2026.2.15, `normalizeForHash` in `src/agents/sandbox/config-hash.ts` recursively sorted arrays that contained only primitive values. This made order-sensitive sandbox configuration arra…
- CVE-2026-27008MEDIUMCVSS 6.7EG 6.7fixed in 2026.2.152026-02-20
OpenClaw is a personal AI assistant. Prior to version 2026.2.15, a bug in `download` skill installation allowed `targetDir` values from skill frontmatter to resolve outside the per-skill tools directory if not strictly validated. In the ad…
- CVE-2026-27009MEDIUMCVSS 5.8EG 5.8fixed in 2026.2.152026-02-20
OpenClaw is a personal AI assistant. Prior to version 2026.2.15, a atored XSS issue in the OpenClaw Control UI when rendering assistant identity (name/avatar) into an inline `<script>` tag without script-context-safe escaping. A crafted va…
- CVE-2026-27183MEDIUMCVSS 5.3EG 5.3fixed in 2026.3.72026-03-23
OpenClaw versions prior to 2026.3.7 contain a shell approval gating bypass vulnerability in system.run dispatch-wrapper handling that allows attackers to skip shell wrapper approval requirements. The approval classifier and execution plann…
- CVE-2026-27484MEDIUMCVSS 4.3EG 4.3fixed in 2026.2.182026-02-21
OpenClaw is a personal AI assistant. In versions 2026.2.17 and below, the Discord moderation action handling (timeout, kick, ban) uses sender identity from request parameters in tool-driven flows, instead of trusted runtime sender context.…
- CVE-2026-27485MEDIUMCVSS 4.4EG 4.4fixed in 2026.2.192026-02-21
OpenClaw is a personal AI assistant. In versions 2026.2.17 and below, skills/skill-creator/scripts/package_skill.py (a local helper script used when authors package skills) previously followed symlinks while building .skill archives. If an…
- CVE-2026-27486MEDIUMCVSS 5.3EG 5.3fixed in 2026.2.142026-02-21
OpenClaw is a personal AI assistant. In versions 2026.2.13 and below of the OpenClaw CLI, the process cleanup uses system-wide process enumeration and pattern matching to terminate processes without verifying if they are owned by the curre…
- CVE-2026-27487HIGHCVSS 8.0EG 8.0fixed in 2026.2.142026-02-21
OpenClaw is a personal AI assistant. In versions 2026.2.13 and below, when using macOS, the Claude CLI keychain credential refresh path constructed a shell command to write the updated JSON blob into Keychain via security add-generic-passw…
- CVE-2026-27488HIGHCVSS 7.3EG 7.3fixed in 2026.2.192026-02-21
OpenClaw is a personal AI assistant. In versions 2026.2.17 and below, Cron webhook delivery in src/gateway/server-cron.ts uses fetch() directly, so webhook targets can reach private/metadata/internal endpoints without SSRF policy checks. T…
- CVE-2026-27522MEDIUMCVSS 6.5EG 6.5fixed in 2026.2.242026-03-18
OpenClaw versions prior to 2026.2.24 contain a local media root bypass vulnerability in sendAttachment and setGroupIcon message actions when sandboxRoot is unset. Attackers can hydrate media from local absolute paths to read arbitrary host…
- CVE-2026-27523MEDIUMCVSS 6.1EG 6.1fixed in 2026.2.242026-03-18
OpenClaw versions prior to 2026.2.24 contain a sandbox bind validation vulnerability allowing attackers to bypass allowed-root and blocked-path checks via symlinked parent directories with non-existent leaf paths. Attackers can craft bind …
- CVE-2026-27524MEDIUMCVSS 4.3EG 4.3fixed in 2026.2.212026-03-18
OpenClaw versions prior to 2026.2.21 accept prototype-reserved keys in runtime /debug set override object values, allowing prototype pollution attacks. Authorized /debug set callers can inject __proto__, constructor, or prototype keys to m…
- CVE-2026-27545MEDIUMCVSS 6.1EG 6.1fixed in 2026.2.262026-03-18
OpenClaw versions prior to 2026.2.26 contain an approval bypass vulnerability in system.run execution that allows attackers to execute commands from unintended filesystem locations by rebinding writable parent symlinks in the current worki…
- CVE-2026-27566HIGHCVSS 7.1EG 7.1fixed in 2026.2.222026-03-19
OpenClaw versions prior to 2026.2.22 contain an allowlist bypass vulnerability in system.run exec analysis that fails to unwrap env and shell-dispatch wrapper chains. Attackers can route execution through wrapper binaries like env bash to …
Check whether openclaw is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for openclaw CVEs against the assets you own.
Book a Demo →