openclaw
npm530 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting openclawpage 10 of 11
- CVE-2026-44117MEDIUMCVSS 5.8EG 5.8✓ Fixed in 2026.4.202026-05-06
OpenClaw before 2026.4.20 contains a server-side request forgery vulnerability in QQBot direct media upload that skips URL validation. Attackers can bypass SSRF protections by sending crafted image URLs to uploadC2CMedia and uploadGroupMed…
- CVE-2026-44118HIGHCVSS 7.8EG 7.8✓ Fixed in 2026.4.222026-05-06
OpenClaw before 2026.4.22 derives loopback MCP owner context from spoofable server-issued bearer tokens in request headers. Non-owner loopback clients can present themselves as owner to bypass owner-gated operations by manipulating the sen…
- CVE-2026-44991MEDIUMCVSS 4.2EG 4.2✓ Fixed in 2026.4.212026-05-11
OpenClaw before 2026.4.21 contains an authorization bypass vulnerability in command-auth.ts that allows non-owner senders to execute owner-enforced slash commands when wildcard inbound senders are configured without explicit owner allowFro…
- CVE-2026-44992MEDIUMCVSS 5.0EG 5.0✓ Fixed in 2026.4.202026-05-11
OpenClaw versions 2026.4.5 before 2026.4.20 contain an environment variable injection vulnerability allowing workspace dotenv to override MINIMAX_API_HOST. Attackers can redirect credentialed MiniMax API requests to attacker-controlled ori…
- CVE-2026-44993MEDIUMCVSS 5.4EG 5.4✓ Fixed in 2026.4.202026-05-11
OpenClaw before 2026.4.20 contains a message classification vulnerability in Feishu card-action callbacks that misclassifies direct messages as group conversations. Attackers can bypass dmPolicy enforcement by triggering card-action flows …
- CVE-2026-44994MEDIUMCVSS 5.3EG 5.3✓ Fixed in 2026.4.222026-05-11
OpenClaw before 2026.4.22 contains an authentication bypass vulnerability in the Control UI bootstrap config endpoint that allows unauthenticated attackers to read sensitive configuration fields. Attackers can access the bootstrap config r…
- CVE-2026-44995HIGHCVSS 7.3EG 7.3✓ Fixed in 2026.4.202026-05-11
OpenClaw before 2026.4.20 contains an improper environment variable validation vulnerability in MCP stdio server configuration that allows attackers to execute arbitrary code. Malicious workspace configurations can pass dangerous startup v…
- CVE-2026-44996LOWCVSS 3.7EG 3.7✓ Fixed in 2026.4.152026-05-11
OpenClaw before 2026.4.15 contains an arbitrary local file read vulnerability in the webchat audio embedding helper that fails to apply local media root containment checks. Attackers can influence agent or tool-produced ReplyPayload.mediaU…
- CVE-2026-44997MEDIUMCVSS 4.3EG 4.3✓ Fixed in 2026.4.222026-05-11
OpenClaw before 2026.4.22 contains a security envelope constraint bypass vulnerability allowing restricted subagents to spawn ACP child sessions that fail to inherit depth, child-count limits, control scope, or target-agent restrictions. A…
- CVE-2026-44998MEDIUMCVSS 5.4EG 5.4✓ Fixed in 2026.4.202026-05-11
OpenClaw before 2026.4.20 contains a tool policy bypass vulnerability allowing bundled MCP and LSP tools to circumvent configured tool restrictions. Attackers with local agent access can append restricted tools to the effective tool set af…
- CVE-2026-44999MEDIUMCVSS 5.3EG 5.3✓ Fixed in 2026.4.202026-05-11
OpenClaw before 2026.4.20 fails to properly preserve untrusted labels for isolated cron awareness events, allowing webhook-triggered cron agent output to be recorded as trusted system events. Attackers can exploit this trust-labeling issue…
- CVE-2026-45000MEDIUMCVSS 5.0EG 5.0✓ Fixed in 2026.4.202026-05-11
OpenClaw before 2026.4.20 contains a server-side request forgery vulnerability in browser CDP profile creation that skips strict-mode SSRF policy checks. Attackers can create stored profiles pointing to private-network or metadata endpoint…
- CVE-2026-45001HIGHCVSS 7.1EG 7.1✓ Fixed in 2026.4.202026-05-11
OpenClaw before 2026.4.20 contains a guard bypass vulnerability in the agent-facing gateway config.patch and config.apply endpoints that fails to protect operator-trusted settings including sandbox policy, plugin enablement, gateway auth/T…
- CVE-2026-45002MEDIUMCVSS 5.3EG 5.3✓ Fixed in 2026.4.202026-05-11
OpenClaw before 2026.4.20 contains a hook session-key bypass vulnerability that allows attackers to circumvent the hooks.allowRequestSessionKey opt-in restriction. Attackers can render externally influenced session keys through templated h…
- CVE-2026-45003MEDIUMCVSS 5.0EG 5.0✓ Fixed in 2026.4.222026-05-11
OpenClaw before 2026.4.22 allows workspace dotenv files to override connector endpoint hosts for Matrix, Mattermost, IRC, and Synology connectors. Attackers with workspace access can redirect runtime traffic to malicious endpoints by setti…
- CVE-2026-45004HIGHCVSS 7.8EG 7.8✓ Fixed in 2026.4.232026-05-11
OpenClaw before 2026.4.23 contains an arbitrary code execution vulnerability in the bundled plugin setup resolver that loads setup-api.js from process.cwd() during provider setup metadata resolution. Attackers can execute arbitrary JavaScr…
- CVE-2026-45005MEDIUMCVSS 6.0EG 6.0✓ Fixed in 2026.4.232026-05-11
OpenClaw before 2026.4.23 caches resolved webhook route secrets backed by SecretRef values, allowing stale secrets to remain valid after rotation and reload. Attackers with previously valid webhook route secrets can continue authenticating…
- CVE-2026-45006HIGHCVSS 8.8EG 8.8✓ Fixed in 2026.4.232026-05-11
OpenClaw before 2026.4.23 contains an improper access control vulnerability in the gateway tool's config.apply and config.patch operations that allows compromised models to write unsafe configuration changes by bypassing an incomplete deny…
- CVE-2026-53806HIGHCVSS 8.8EG 8.8✓ Fixed in 2026.5.122026-06-11
OpenClaw before 2026.5.12 contains a shell option parsing vulnerability that allows combined POSIX shell flags to bypass exec revalidation checks. Attackers can exploit this by using combined shell options to execute inline shell content w…
- CVE-2026-53807HIGHCVSS 8.8EG 8.8✓ Fixed in 2026.5.62026-06-11
OpenClaw before 2026.5.6 contains an authorization bypass vulnerability in Telegram interactive callbacks that allows authenticated users to skip commands.allowFrom validation. Attackers can invoke affected callbacks to mark themselves as …
- CVE-2026-53808MEDIUMCVSS 6.5EG 6.5✓ Fixed in 2026.5.62026-06-11
OpenClaw before 2026.5.6 contains an approval policy bypass vulnerability in the Skill Workshop apply flow that allows agent tool calls to set apply: true despite approvalPolicy: pending configuration. Attackers can exploit this by reachin…
- CVE-2026-53809LOWCVSS 3.8EG 3.8✓ Fixed in 2026.4.252026-06-11
OpenClaw before 2026.4.25 contains a policy bypass vulnerability in embedded runner policy that allows requests using provider aliases to compare against aliases instead of canonical provider identities. Attackers can exploit this confusio…
- CVE-2026-53810HIGHCVSS 8.8EG 8.8✓ Fixed in 2026.5.182026-06-11
OpenClaw before 2026.5.18 contains a code execution vulnerability where marketplace runtime extension metadata can redirect loading toward unscanned package payloads. Attackers with trusted operator access can manipulate extension metadata…
- CVE-2026-53811HIGHCVSS 8.8EG 8.8✓ Fixed in 2026.5.72026-06-11
OpenClaw before 2026.5.7 contains a privilege escalation vulnerability in the Matrix allowFrom feature that allows authenticated accounts to match policy entries through mutable display name metadata. Attackers with the ability to change d…
- CVE-2026-53812HIGHCVSS 7.7EG 7.7✓ Fixed in 2026.5.182026-06-11
OpenClaw before 2026.5.18 contains a server-side request forgery vulnerability in browser control that allows authenticated users to bypass private-network navigation checks through Playwright act interactions. Attackers can trigger naviga…
- CVE-2026-53813HIGHCVSS 7.8EG 7.8✓ Fixed in 2026.4.252026-06-11
OpenClaw before 2026.4.25 contains a path traversal vulnerability in memory-core artifact loading where workspace state influences local package root resolution. Attackers with access to affected workspaces can load memory-core artifacts f…
- CVE-2026-53814HIGHCVSS 8.3EG 8.3✓ Fixed in 2026.5.202026-06-11
OpenClaw before 2026.5.20 contains a privilege escalation vulnerability where hook-triggered agent runs incorrectly receive owner-scoped MCP loopback authority instead of hook-appropriate scope. Attackers with a valid hook token can exploi…
- CVE-2026-53815MEDIUMCVSS 6.5EG 6.5✓ Fixed in 2026.5.192026-06-11
OpenClaw before 2026.5.19 contains an authorization bypass vulnerability in message read actions that skips channel allowlist checks. Lower-trust callers can request messages from channels not intended for them by exploiting insufficient v…
- CVE-2026-53816HIGHCVSS 7.2EG 7.2✓ Fixed in 2026.5.182026-06-11
OpenClaw before 2026.5.18 contains an insufficient provenance validation vulnerability in node event handling that allows paired nodes to forge exec lifecycle events without system.run authorization. A malicious or compromised paired node …
- CVE-2026-53817HIGHCVSS 8.8EG 8.8✓ Fixed in 2026.5.222026-06-11
OpenClaw before 2026.5.22 contains a locality validation vulnerability in Control UI pairing that allows attackers with network access to spoof locality information and obtain durable admin-capable device tokens. Attackers can exploit insu…
- CVE-2026-53818MEDIUMCVSS 6.6EG 6.6✓ Fixed in 2026.4.242026-06-11
OpenClaw before 2026.4.24 contains an authorization bypass vulnerability in the MCP loopback feature that allows non-owner callers to skip owner-only tool policies and before-tool-call hooks. Attackers can invoke owner-only behavior throug…
- CVE-2026-53819HIGHCVSS 8.8EG 8.8✓ Fixed in 2026.5.272026-06-11
OpenClaw before 2026.5.27 contains an arbitrary code execution vulnerability in skill install flows where workspace .env files can override the Homebrew executable selection. Attackers with access to trusted operator workspaces can execute…
- CVE-2026-53820MEDIUMCVSS 6.6EG 6.6✓ Fixed in 2026.5.122026-06-12
OpenClaw before 2026.5.12 contains an exec denylist bypass vulnerability in the bundle MCP loopback session-spawn path that allows authenticated callers to bypass intended command restrictions. Attackers can reach the affected bundled MCP …
- CVE-2026-53821HIGHCVSS 8.8EG 8.8✓ Fixed in 2026.5.182026-06-12
OpenClaw before 2026.5.18 accepts WebSocket client-declared operator scopes before binding to server-approved pairing or trusted-proxy authorization baseline. Unpaired or restricted trusted-proxy Control UI clients can obtain cached operat…
- CVE-2026-53823HIGHCVSS 8.1EG 8.1✓ Fixed in 2026.5.32026-06-12
OpenClaw before 2026.5.3 contains a privilege escalation vulnerability in the allowFrom feature that binds to mutable Slack display names. Attackers with Slack account access can change display name metadata to match policy entries, potent…
- CVE-2026-53824MEDIUMCVSS 6.5EG 6.5✓ Fixed in 2026.4.242026-06-12
OpenClaw before 2026.4.24 contains a token revocation vulnerability allowing callers with revoked slash tokens to continue executing commands during monitor refresh windows. Attackers can exploit stale token acceptance to invoke slash comm…
- CVE-2026-53825MEDIUMCVSS 6.5EG 6.5✓ Fixed in 2026.5.122026-06-12
OpenClaw before 2026.4.7 contains an arbitrary file read vulnerability in the memory-wiki ingest feature that allows authenticated Gateway operators with operator.write scope to read local files outside intended ingest sources. Attackers w…
- CVE-2026-53826MEDIUMCVSS 4.3EG 4.3✓ Fixed in 2026.4.262026-06-12
OpenClaw before 2026.4.26 contains an information disclosure vulnerability in sandboxed session spawning that exposes the real workspace path to child prompts. Attackers can exploit this by spawning child sessions from sandboxed parents to…
- CVE-2026-53827MEDIUMCVSS 6.5EG 6.5✓ Fixed in 2026.5.22026-06-12
OpenClaw before 2026.5.2 contains a credential exposure vulnerability in message.action forwarding that allows model-controlled metadata to forward action payloads with Gateway credentials to attacker-supplied loopback URLs. Remote attacke…
- CVE-2026-53828HIGHCVSS 8.8EG 8.8✓ Fixed in 2026.5.62026-06-12
OpenClaw before 2026.5.6 contains an authorization bypass vulnerability in native command handling that allows authenticated senders to execute owner-only commands without proper policy enforcement. Attackers can trigger native command han…
- CVE-2026-53829HIGHCVSS 8.0EG 8.0✓ Fixed in 2026.5.182026-06-12
OpenClaw before 2026.5.18 contains an approval display truncation vulnerability allowing authenticated users to hide command suffixes from approvers. Attackers can submit oversized exec commands with benign prefixes and malicious suffixes …
- CVE-2026-53830MEDIUMCVSS 6.5EG 6.5✓ Fixed in 2026.4.222026-06-12
OpenClaw before 2026.4.22 contains a webhook secret revocation bypass vulnerability allowing callers with old Slack and Zalo webhook secrets to remain active after secrets.reload. Attackers can exploit the stale-secret window to deliver we…
- CVE-2026-53831HIGHCVSS 8.1EG 8.3✓ Fixed in 2026.5.182026-06-12
OpenClaw before 2026.5.18 contains a policy enforcement vulnerability in system.run safe-bin allowlist validation that allows shell expansion to modify command interpretation on POSIX nodes. Authenticated operators can exploit shell metach…
- CVE-2026-53832HIGHCVSS 7.1EG 7.7✓ Fixed in 2026.5.182026-06-12
OpenClaw before 2026.5.18 contains an identity header validation vulnerability allowing local same-host callers to forge trusted-proxy identity headers. Attackers with access to the proxy-facing Gateway port can supply forged identity head…
- CVE-2026-53833HIGHCVSS 6.5EG 7.7✓ Fixed in 2026.4.292026-06-12
OpenClaw before 2026.4.29 contains an authorization bypass vulnerability in the QQBot streaming command that allows authenticated senders to mutate configuration without explicit allowFrom restrictions. Attackers can modify QQBot streaming…
- CVE-2026-53834HIGHCVSS 6.5EG 7.5✓ Fixed in 2026.4.272026-06-12
OpenClaw before 2026.4.27 contains an authorization bypass vulnerability in QQBot pre-dispatch slash commands that allows authenticated senders to skip allowFrom policy checks. Attackers can invoke slash commands before configured access c…
- CVE-2026-53835MEDIUMCVSS 4.3EG 4.3✓ Fixed in 2026.5.62026-06-12
OpenClaw before 2026.5.6 contains a configuration enforcement bypass vulnerability in Feishu dynamic-agent bindings that allows authenticated senders to create or update bindings without honoring configured config-write controls. Attackers…
- CVE-2026-53836HIGHCVSS 8.8EG 8.8✓ Fixed in 2026.5.122026-06-12
OpenClaw before 2026.5.12 contains an allowlist bypass vulnerability in PowerShell encoded-command handling that allows attackers to execute encoded commands using abbreviated flag aliases not recognized by the allowlist parser. Remote aut…
- CVE-2026-53837MEDIUMCVSS 5.3EG 5.3✓ Fixed in 2026.5.62026-06-12
OpenClaw before 2026.5.6 contains an improper access control vulnerability in Mattermost event handlers that fails to validate channel type metadata. Attackers can bypass intended DM policy decisions by sending crafted Mattermost events mi…
- CVE-2026-53838CRITICALCVSS 9.8EG 9.8✓ Fixed in 2026.5.272026-06-12
OpenClaw before 2026.5.27 contains a state mutation vulnerability in node pairing reconnection that allows paired nodes to confuse approval scope decisions. Attackers can exploit reconnection logic to restore or present broader node author…
Check whether openclaw is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for openclaw CVEs against the assets you own.
Start Free Scan →