openclaw
npm530 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting openclawpage 2 of 11
- CVE-2026-27576MEDIUMCVSS 4.0EG 4.0✓ Fixed in 2026.2.192026-02-21
OpenClaw is a personal AI assistant. In versions 2026.2.17 and below, the ACP bridge accepts very large prompt text blocks and can assemble oversized prompt payloads before forwarding them to chat.send. Because ACP runs over local stdio, t…
- CVE-2026-27646MEDIUMCVSS 6.1EG 6.1✓ Fixed in 2026.3.72026-03-23
OpenClaw versions prior to 2026.3.7 contain a sandbox escape vulnerability in the /acp spawn command that allows authorized sandboxed sessions to initialize host-side ACP runtime. Attackers can bypass sandbox restrictions by invoking the /…
- CVE-2026-27670MEDIUMCVSS 5.3EG 5.3✓ Fixed in 2026.3.22026-03-19
OpenClaw versions prior to 2026.3.2 contain a race condition vulnerability in ZIP extraction that allows local attackers to write files outside the intended destination directory. Attackers can exploit a time-of-check-time-of-use race betw…
- CVE-2026-28363HIGHCVSS 8.8EG 8.8✓ Fixed in 2026.2.232026-02-27
In OpenClaw before 2026.2.23, tools.exec.safeBins validation for sort could be bypassed via GNU long-option abbreviations (such as --compress-prog) in allowlist mode, leading to approval-free execution paths that were intended to require a…
- CVE-2026-28391CRITICALCVSS 9.8EG 9.8✓ Fixed in 2026.2.22026-03-05
OpenClaw versions prior to 2026.2.2 fail to properly validate Windows cmd.exe metacharacters in allowlist-gated exec requests (non-default configuration), allowing attackers to bypass command approval restrictions. Remote attackers can cra…
- CVE-2026-28392CRITICALCVSS 9.8EG 9.8✓ Fixed in 2026.2.142026-03-05
OpenClaw versions prior to 2026.2.14 contain a privilege escalation vulnerability in the Slack slash-command handler that incorrectly authorizes any direct message sender when dmPolicy is set to open (must be configured). Attackers can exe…
- CVE-2026-28393CRITICALCVSS 9.8EG 9.8✓ Fixed in 2026.2.142026-03-05
OpenClaw versions 2.0.0-beta3 prior to 2026.2.14 contain a path traversal vulnerability in hook transform module loading that allows arbitrary JavaScript execution. The hooks.mappings[].transform.module parameter accepts absolute paths and…
- CVE-2026-28394MEDIUMCVSS 6.5EG 6.5✓ Fixed in 2026.2.152026-03-05
OpenClaw versions prior to 2026.2.15 contain a denial of service vulnerability in the web_fetch tool that allows attackers to crash the Gateway process through memory exhaustion by parsing oversized or deeply nested HTML responses. Remote …
- CVE-2026-28395CRITICALCVSS 9.1EG 9.1✓ Fixed in 2026.2.122026-03-05
OpenClaw version 2026.1.14-1 prior to 2026.2.12 contains an improper network binding vulnerability in the Chrome extension (must be installed and enabled) relay server that treats wildcard hosts as loopback addresses, allowing the relay HT…
- CVE-2026-28446CRITICALCVSS 9.8EG 9.8✓ Fixed in 2026.2.22026-03-05
OpenClaw versions prior to 2026.2.1 with the voice-call extension installed and enabled contain an authentication bypass vulnerability in inbound allowlist policy validation that accepts empty caller IDs and uses suffix-based matching inst…
- CVE-2026-28447MEDIUMCVSS 6.5EG 6.5✓ Fixed in 2026.2.12026-03-05
OpenClaw versions 2026.1.29-beta.1 prior to 2026.2.1 contain a path traversal vulnerability in plugin installation that allows malicious plugin package names to escape the extensions directory. Attackers can craft scoped package names cont…
- CVE-2026-28448CRITICALCVSS 9.4EG 9.4✓ Fixed in 2026.2.12026-03-05
OpenClaw versions 2026.1.29 prior to 2026.2.1 contain a vulnerability in the Twitch plugin (must be installed and enabled) in which it fails to enforce the allowFrom allowlist when allowedRoles is unset or empty, allowing unauthorized Twit…
- CVE-2026-28449MEDIUMCVSS 6.5EG 6.5✓ Fixed in 2026.2.252026-03-19
OpenClaw versions prior to 2026.2.25 lack durable replay state for Nextcloud Talk webhook events, allowing valid signed webhook requests to be replayed without suppression. Attackers can capture and replay previously valid signed webhook r…
- CVE-2026-28450HIGHCVSS 8.2EG 8.2✓ Fixed in 2026.2.122026-03-05
OpenClaw versions prior to 2026.2.12 with the optional Nostr plugin enabled expose unauthenticated HTTP endpoints at /api/channels/nostr/:accountId/profile and /api/channels/nostr/:accountId/profile/import that allow reading and modifying …
- CVE-2026-28451CRITICALCVSS 9.3EG 9.3✓ Fixed in 2026.2.142026-03-05
OpenClaw versions prior to 2026.2.14 contain server-side request forgery vulnerabilities in the Feishu extension that allow attackers to fetch attacker-controlled remote URLs without SSRF protections via sendMediaFeishu function and markdo…
- CVE-2026-28452MEDIUMCVSS 6.5EG 6.5✓ Fixed in 2026.2.142026-03-05
OpenClaw versions prior to 2026.2.14 contain a denial of service vulnerability in the extractArchive function within src/infra/archive.ts that allows attackers to consume excessive CPU, memory, and disk resources through high-expansion ZIP…
- CVE-2026-28453CRITICALCVSS 9.8EG 9.8✓ Fixed in 2026.2.142026-03-05
OpenClaw versions prior to 2026.2.14 fail to validate TAR archive entry paths during extraction, allowing path traversal sequences to write files outside the intended directory. Attackers can craft malicious archives with traversal sequenc…
- CVE-2026-28454CRITICALCVSS 9.8EG 9.8✓ Fixed in 2026.2.12026-03-05
OpenClaw versions prior to 2026.2.2 fail to validate webhook secrets in Telegram webhook mode (must be enabled), allowing unauthenticated HTTP POST requests to the webhook endpoint that trust attacker-controlled JSON payloads. Remote attac…
- CVE-2026-28456HIGHCVSS 7.2EG 7.2✓ Fixed in 2026.2.142026-03-05
OpenClaw versions 2026.1.5 prior to 2026.2.14 contain a vulnerability in the Gateway in which it does not sufficiently constrain configured hook module paths before passing them to dynamic import(), allowing code execution. An attacker wit…
- CVE-2026-28457HIGHCVSS 7.9EG 7.9✓ Fixed in 2026.2.142026-03-05
OpenClaw versions prior to 2026.2.14 contain a path traversal vulnerability in sandbox skill mirroring (must be enabled) that uses the skill frontmatter name parameter unsanitized when copying skills into the sandbox workspace. Attackers w…
- CVE-2026-28458MEDIUMCVSS 5.4EG 5.4✓ Fixed in 2026.2.12026-03-05
OpenClaw version 2026.1.20 prior to 2026.2.1 contains a vulnerability in the Browser Relay (extension must be installed and enabled) /cdp WebSocket endpoint in which it does not require authentication tokens, allowing websites to connect v…
- CVE-2026-28459HIGHCVSS 8.1EG 8.1✓ Fixed in 2026.2.122026-03-05
OpenClaw versions prior to 2026.2.12 fail to validate the sessionFile path parameter, allowing authenticated gateway clients to write transcript data to arbitrary locations on the host filesystem. Attackers can supply a sessionFile path ou…
- CVE-2026-28460HIGHCVSS 7.1EG 7.1✓ Fixed in 2026.2.222026-03-19
OpenClaw versions prior to 2026.2.22 contain an allowlist bypass vulnerability in system.run that allows attackers to execute non-allowlisted commands by splitting command substitution using shell line-continuation characters. Attackers ca…
- CVE-2026-28461HIGHCVSS 7.5EG 7.5✓ Fixed in 2026.3.12026-03-19
OpenClaw versions prior to 2026.3.1 contain an unbounded memory growth vulnerability in the Zalo webhook endpoint that allows unauthenticated attackers to trigger in-memory key accumulation by varying query strings. Remote attackers can ex…
- CVE-2026-28462CRITICALCVSS 9.1EG 9.1✓ Fixed in 2026.2.132026-03-05
OpenClaw versions prior to 2026.2.13 contain a vulnerability in the browser control API in which it accepts user-supplied output paths for trace and download files without consistently constraining writes to temporary directories. Attacker…
- CVE-2026-28463MEDIUMCVSS 5.5EG 5.5✓ Fixed in 2026.2.142026-03-05
OpenClaw versions prior to 2026.2.14 contain an arbitrary file read vulnerability in the exec-approvals allowlist validation that checks pre-expansion argv tokens but executes using real shell expansion. Attackers with authorization or thr…
- CVE-2026-28464HIGHCVSS 7.5EG 7.5✓ Fixed in 2026.2.122026-03-05
OpenClaw versions prior to 2026.2.12 use non-constant-time string comparison for hook token validation, allowing attackers to infer tokens through timing measurements. Remote attackers with network access to the hooks endpoint can exploit …
- CVE-2026-28466CRITICALCVSS 9.9EG 9.9✓ Fixed in 2026.2.142026-03-05
OpenClaw versions prior to 2026.2.14 contain a vulnerability in the gateway in which it fails to sanitize internal approval fields in node.invoke parameters, allowing authenticated clients to bypass exec approval gating for system.run comm…
- CVE-2026-28467HIGHCVSS 8.6EG 8.6✓ Fixed in 2026.2.22026-03-05
OpenClaw versions prior to 2026.2.2 contain a server-side request forgery vulnerability in attachment and media URL hydration that allows remote attackers to fetch arbitrary HTTP(S) URLs. Attackers who can influence media URLs through mode…
- CVE-2026-28468HIGHCVSS 7.7EG 7.7✓ Fixed in 2026.2.142026-03-05
OpenClaw versions 2026.1.29-beta.1 prior to 2026.2.14 contain a vulnerability in the sandbox browser bridge server in which it accepts requests without requiring gateway authentication, allowing local attackers to access browser control en…
- CVE-2026-28469HIGHCVSS 7.5EG 7.5✓ Fixed in 2026.2.142026-03-05
OpenClaw versions prior to 2026.2.14 contain a webhook routing vulnerability in the Google Chat monitor component that allows cross-account policy context misrouting when multiple webhook targets share the same HTTP path. Attackers can exp…
- CVE-2026-28470CRITICALCVSS 9.8EG 9.8✓ Fixed in 2026.2.22026-03-05
OpenClaw versions prior to 2026.2.2 contain an exec approvals (must be enabled) allowlist bypass vulnerability that allows attackers to execute arbitrary commands by injecting command substitution syntax. Attackers can bypass the allowlist…
- CVE-2026-28471MEDIUMCVSS 5.3EG 5.3✓ Fixed in 2026.2.22026-03-05
OpenClaw version 2026.1.14-1 prior to 2026.2.2, with the Matrix plugin installed and enabled, contain a vulnerability in which DM allowlist matching could be bypassed by exact-matching against sender display names and localparts without ho…
- CVE-2026-28472CRITICALCVSS 9.8EG 9.8✓ Fixed in 2026.2.22026-03-05
OpenClaw versions prior to 2026.2.2 contain a vulnerability in the gateway WebSocket connect handshake in which it allows skipping device identity checks when auth.token is present but not validated. Attackers can connect to the gateway wi…
- CVE-2026-28473HIGHCVSS 8.1EG 8.1✓ Fixed in 2026.2.22026-03-05
OpenClaw versions prior to 2026.2.2 contain an authorization bypass vulnerability where clients with operator.write scope can approve or deny exec approval requests by sending the /approve chat command. The /approve command path invokes ex…
- CVE-2026-28475LOWCVSS 3.7EG 3.7✓ Fixed in 2026.2.132026-03-05
OpenClaw versions prior to 2026.2.13 use non-constant-time string comparison for hook token validation, allowing attackers to infer tokens through timing measurements. Remote attackers with network access to the hooks endpoint can exploit …
- CVE-2026-28476MEDIUMCVSS 5.8EG 5.8✓ Fixed in 2026.2.142026-03-05
OpenClaw versions prior to 2026.2.14 contain a server-side request forgery vulnerability in the optional Tlon Urbit extension that accepts user-provided base URLs for authentication without proper validation. Attackers who can influence th…
- CVE-2026-28477HIGHCVSS 7.1EG 7.1✓ Fixed in 2026.2.142026-03-05
OpenClaw versions prior to 2026.2.14 contain an oauth state validation bypass vulnerability in the manual Chutes login flow that allows attackers to bypass CSRF protection. An attacker can convince a user to paste attacker-controlled OAuth…
- CVE-2026-28478HIGHCVSS 7.5EG 7.5✓ Fixed in 2026.2.132026-03-05
OpenClaw versions prior to 2026.2.13 contain a denial of service vulnerability in webhook handlers that buffer request bodies without strict byte or time limits. Remote unauthenticated attackers can send oversized JSON payloads or slow upl…
- CVE-2026-28479CRITICALCVSS 9.1EG 9.1✓ Fixed in 2026.2.152026-03-05
OpenClaw versions prior to 2026.2.15 use SHA-1 to hash sandbox identifier cache keys for Docker and browser sandbox configurations, which is deprecated and vulnerable to collision attacks. An attacker can exploit SHA-1 collisions to cause …
- CVE-2026-28480MEDIUMCVSS 6.5EG 6.5✓ Fixed in 2026.2.142026-03-05
OpenClaw versions prior to 2026.2.14 contain an authorization bypass vulnerability where Telegram allowlist matching accepts mutable usernames instead of immutable numeric sender IDs. Attackers can spoof identity by obtaining recycled user…
- CVE-2026-28481HIGHCVSS 7.5EG 7.5✓ Fixed in 2026.2.12026-03-05
OpenClaw versions 2026.1.30 and earlier, contain an information disclosure vulnerability, patched in 2026.2.1, in the MS Teams attachment downloader (optional extension must be enabled) that leaks bearer tokens to allowlisted suffix domain…
- CVE-2026-28482HIGHCVSS 7.1EG 7.1✓ Fixed in 2026.2.122026-03-05
OpenClaw versions prior to 2026.2.12 construct transcript file paths using unsanitized sessionId parameters and sessionFile paths without enforcing directory containment. Authenticated attackers can exploit path traversal sequences like ..…
- CVE-2026-28486MEDIUMCVSS 5.5EG 5.5✓ Fixed in 2026.2.142026-03-05
OpenClaw versions 2026.1.16-2 prior to 2026.2.14 contain a path traversal vulnerability in archive extraction during installation commands that allows arbitrary file writes outside the intended directory. Attackers can craft malicious arch…
- CVE-2026-29606MEDIUMCVSS 6.5EG 6.5✓ Fixed in 2026.2.142026-03-05
OpenClaw versions prior to 2026.2.14 contain a webhook signature-verification bypass in the voice-call extension that allows unauthenticated requests when the tunnel.allowNgrokFreeTierLoopbackBypass option is explicitly enabled. An externa…
- CVE-2026-29607MEDIUMCVSS 6.8EG 6.8✓ Fixed in 2026.2.222026-03-19
OpenClaw versions prior to 2026.2.22 contain an authorization bypass vulnerability in allow-always wrapper persistence that allows attackers to bypass approval checks by persisting wrapper-level allowlist entries instead of validating inne…
- CVE-2026-29608MEDIUMCVSS 6.7EG 6.7✓ Fixed in 2026.3.22026-03-19
vulnerable: 2026.3.1
OpenClaw 2026.3.1 contains an approval integrity vulnerability in system.run node-host execution where argv rewriting changes command semantics. Attackers can place malicious local scripts in the working directory to execute unintended cod…
- CVE-2026-29609HIGHCVSS 7.5EG 7.5✓ Fixed in 2026.2.142026-03-05
OpenClaw versions prior to 2026.2.14 contain a denial of service vulnerability in the fetchWithGuard function that allocates entire response payloads in memory before enforcing maxBytes limits. Remote attackers can trigger memory exhaustio…
- CVE-2026-29610HIGHCVSS 8.8EG 8.8✓ Fixed in 2026.2.142026-03-05
OpenClaw versions prior to 2026.2.14 contain a command hijacking vulnerability that allows attackers to execute unintended binaries by manipulating PATH environment variables through node-host execution or project-local bootstrapping. Atta…
- CVE-2026-29611HIGHCVSS 7.5EG 7.5✓ Fixed in 2026.2.142026-03-05
OpenClaw versions prior to 2026.2.14 contain a local file inclusion vulnerability in BlueBubbles extension (must be installed and enabled) media path handling that allows attackers to read arbitrary files from the local filesystem. The sen…
Check whether openclaw is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for openclaw CVEs against the assets you own.
Start Free Scan →