openclaw
npm530 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting openclawpage 3 of 11
- CVE-2026-29612HIGHCVSS 7.5EG 7.5✓ Fixed in 2026.2.142026-03-05
OpenClaw versions prior to 2026.2.14 decode base64-backed media inputs into buffers before enforcing decoded-size budget limits, allowing attackers to trigger large memory allocations. Remote attackers can supply oversized base64 payloads …
- CVE-2026-29613MEDIUMCVSS 5.9EG 5.9✓ Fixed in 2026.2.122026-03-05
OpenClaw versions prior to 2026.2.12 contain a vulnerability in the BlueBubbles (optional plugin) webhook handler in which it authenticates requests based solely on loopback remoteAddress without validating forwarding headers, allowing byp…
- CVE-2026-31989HIGHCVSS 7.4EG 7.4✓ Fixed in 2026.3.12026-03-19
OpenClaw versions prior to 2026.3.1 contain a server-side request forgery vulnerability in web_search citation redirect resolution that uses a private-network-allowing SSRF policy. An attacker who can influence citation redirect targets ca…
- CVE-2026-31990MEDIUMCVSS 6.1EG 6.1✓ Fixed in 2026.3.22026-03-19
OpenClaw versions prior to 2026.3.2 contain a vulnerability in the stageSandboxMedia function in which it fails to validate destination symlinks during media staging, allowing writes to follow symlinks outside the sandbox workspace. Attack…
- CVE-2026-31991LOWCVSS 3.7EG 3.7✓ Fixed in 2026.2.262026-03-19
OpenClaw versions prior to 2026.2.26 contain an authorization bypass vulnerability where Signal group allowlist policy incorrectly accepts sender identities from DM pairing-store approvals. Attackers can exploit this boundary weakness by o…
- CVE-2026-31992HIGHCVSS 7.1EG 7.1✓ Fixed in 2026.2.232026-03-19
OpenClaw versions prior to 2026.2.23 contain an allowlist bypass vulnerability in system.run guardrails that allows authenticated operators to execute unintended commands. When /usr/bin/env is allowlisted, attackers can use env -S to bypas…
- CVE-2026-31993MEDIUMCVSS 4.8EG 4.8✓ Fixed in 2026.2.222026-03-19
OpenClaw versions prior to 2026.2.22 contain an allowlist parsing mismatch vulnerability in the macOS companion app that allows authenticated operators to bypass exec approval checks. Attackers with operator.write privileges and a paired m…
- CVE-2026-31994HIGHCVSS 7.1EG 7.1✓ Fixed in 2026.2.192026-03-19
OpenClaw versions prior to 2026.2.19 contain a local command injection vulnerability in Windows scheduled task script generation due to unsafe handling of cmd metacharacters and expansion-sensitive characters in gateway.cmd files. Local at…
- CVE-2026-31995MEDIUMCVSS 5.3EG 5.3✓ Fixed in 2026.2.192026-03-19
OpenClaw versions 2026.1.21 prior to 2026.2.19 contain a command injection vulnerability in the Lobster extension's Windows shell fallback mechanism that allows attackers to inject arbitrary commands through tool-provided arguments. When s…
- CVE-2026-31996MEDIUMCVSS 4.4EG 4.4✓ Fixed in 2026.2.192026-03-19
OpenClaw versions prior to 2026.2.19 tools.exec.safeBins contains an input validation bypass vulnerability that allows attackers to execute unintended filesystem operations through sort output flags or recursive grep flags. Attackers with …
- CVE-2026-31997MEDIUMCVSS 6.0EG 6.0✓ Fixed in 2026.3.12026-03-19
OpenClaw versions prior to 2026.3.1 fail to pin executable identity for non-path-like argv[0] tokens in system.run approvals, allowing post-approval executable rebind attacks. Attackers can modify PATH resolution after approval to execute …
- CVE-2026-31998HIGHCVSS 8.6EG 8.6✓ Fixed in 2026.2.242026-03-19
OpenClaw versions 2026.2.22 and 2026.2.23 contain an authorization bypass vulnerability in the synology-chat channel plugin where dmPolicy set to allowlist with empty allowedUserIds fails open. Attackers with Synology sender access can byp…
- CVE-2026-31999MEDIUMCVSS 6.3EG 6.3✓ Fixed in 2026.3.12026-03-19
OpenClaw versions 2026.2.26 prior to 2026.3.1 on Windows contain a current working directory injection vulnerability in wrapper resolution for .cmd/.bat files that allows attackers to influence execution behavior through cwd manipulation. …
- CVE-2026-32000HIGHCVSS 7.1EG 7.1✓ Fixed in 2026.2.192026-03-19
OpenClaw versions prior to 2026.2.19 contain a command injection vulnerability in the Lobster extension tool execution that uses Windows shell fallback with shell: true after spawn failures. Attackers can inject shell metacharacters in com…
- CVE-2026-32001MEDIUMCVSS 5.4EG 5.4✓ Fixed in 2026.2.222026-03-19
OpenClaw versions prior to 2026.2.22 contain an authentication bypass vulnerability that allows clients authenticated with a shared gateway token to connect as role=node without device identity verification. Attackers can exploit this by c…
- CVE-2026-32002MEDIUMCVSS 5.3EG 5.3✓ Fixed in 2026.2.232026-03-19
OpenClaw versions prior to 2026.2.23 contain a sandbox bypass vulnerability in the sandboxed image tool that fails to enforce tools.fs.workspaceOnly restrictions on mounted sandbox paths, allowing attackers to read out-of-workspace files. …
- CVE-2026-32003MEDIUMCVSS 6.6EG 6.6✓ Fixed in 2026.2.222026-03-19
OpenClaw versions prior to 2026.2.22 contain an environment variable injection vulnerability in the system.run function that allows attackers to bypass command allowlist restrictions via SHELLOPTS and PS4 environment variables. An attacker…
- CVE-2026-32004MEDIUMCVSS 6.5EG 6.5✓ Fixed in 2026.3.22026-03-19
OpenClaw versions prior to 2026.3.2 contain an authentication bypass vulnerability in the /api/channels route classification due to canonicalization depth mismatch between auth-path classification and route-path canonicalization. Attackers…
- CVE-2026-32005MEDIUMCVSS 6.8EG 6.8✓ Fixed in 2026.2.252026-03-19
OpenClaw versions prior to 2026.2.25 fail to enforce sender authorization checks for interactive callbacks including block_action, view_submission, and view_closed in shared workspace deployments. Unauthorized workspace members can bypass …
- CVE-2026-32006LOWCVSS 3.1EG 3.1✓ Fixed in 2026.2.262026-03-19
OpenClaw versions prior to 2026.2.26 contain an authorization bypass vulnerability where DM pairing-store identities are incorrectly treated as group allowlist identities when dmPolicy=pairing and groupPolicy=allowlist. Remote attackers ca…
- CVE-2026-32007MEDIUMCVSS 6.8EG 6.8✓ Fixed in 2026.2.232026-03-19
OpenClaw versions prior to 2026.2.23 contain a path traversal vulnerability in the experimental apply_patch tool that allows attackers with sandbox access to modify files outside the workspace directory by exploiting inconsistent enforceme…
- CVE-2026-32008MEDIUMCVSS 6.5EG 6.5✓ Fixed in 2026.2.212026-03-19
OpenClaw versions prior to 2026.2.21 contain an improper URL scheme validation vulnerability in the assertBrowserNavigationAllowed() function that allows authenticated users with browser-tool access to navigate to file:// URLs. Attackers c…
- CVE-2026-32009MEDIUMCVSS 5.7EG 5.7✓ Fixed in 2026.2.242026-03-19
OpenClaw versions prior to 2026.2.24 contain a policy bypass vulnerability in the safeBins allowlist evaluation that trusts static default directories including writable package-manager paths like /opt/homebrew/bin and /usr/local/bin. An a…
- CVE-2026-32010MEDIUMCVSS 6.3EG 6.3✓ Fixed in 2026.2.222026-03-19
OpenClaw versions prior to 2026.2.22 contain an allowlist bypass vulnerability in the safe-bin configuration when sort is manually added to tools.exec.safeBins. Attackers can invoke sort with the --compress-program flag to execute arbitrar…
- CVE-2026-32011HIGHCVSS 7.5EG 7.5✓ Fixed in 2026.3.22026-03-19
OpenClaw versions prior to 2026.3.2 contain a denial of service vulnerability in webhook handlers for BlueBubbles and Google Chat that parse request bodies before performing authentication and signature validation. Unauthenticated attacker…
- CVE-2026-32013HIGHCVSS 8.8EG 8.8✓ Fixed in 2026.2.252026-03-19
OpenClaw versions prior to 2026.2.25 contain a symlink traversal vulnerability in the agents.files.get and agents.files.set methods that allows reading and writing files outside the agent workspace. Attackers can exploit symlinked allowlis…
- CVE-2026-32014HIGHCVSS 8.0EG 8.0✓ Fixed in 2026.2.262026-03-19
OpenClaw versions prior to 2026.2.26 contain a metadata spoofing vulnerability where reconnect platform and deviceFamily fields are accepted from the client without being bound into the device-auth signature. An attacker with a paired node…
- CVE-2026-32015HIGHCVSS 7.8EG 7.8✓ Fixed in 2026.2.192026-03-19
OpenClaw versions 2026.1.21 prior to 2026.2.19 contain a path hijacking vulnerability in tools.exec.safeBins that allows attackers to bypass allowlist checks by controlling process PATH resolution. Attackers who can influence the gateway p…
- CVE-2026-32016HIGHCVSS 7.8EG 7.8✓ Fixed in 2026.2.222026-03-19
OpenClaw versions prior to 2026.2.22 on macOS contain a path validation bypass vulnerability in the exec-approval allowlist mode that allows local attackers to execute unauthorized binaries by exploiting basename-only allowlist entries. At…
- CVE-2026-32017HIGHCVSS 7.1EG 7.1✓ Fixed in 2026.2.192026-03-19
OpenClaw versions prior to 2026.2.19 contain an allowlist bypass vulnerability in the exec safeBins policy that allows attackers to write arbitrary files using short-option payloads. Attackers can bypass argument validation by attaching sh…
- CVE-2026-32018LOWCVSS 3.6EG 3.6✓ Fixed in 2026.2.192026-03-19
OpenClaw versions prior to 2026.2.19 contain a race condition vulnerability in concurrent updateRegistry and removeRegistryEntry operations for sandbox containers and browsers. Attackers can exploit unsynchronized read-modify-write operati…
- CVE-2026-32019HIGHCVSS 7.4EG 7.4✓ Fixed in 2026.2.222026-03-19
OpenClaw versions prior to 2026.2.22 contain incomplete IPv4 special-use range validation in the isPrivateIpv4() function, allowing requests to RFC-reserved ranges to bypass SSRF policy checks. Attackers with network reachability to specia…
- CVE-2026-32020LOWCVSS 3.3EG 3.3✓ Fixed in 2026.2.222026-03-19
OpenClaw versions prior to 2026.2.22 contain a path traversal vulnerability in the static file handler that follows symbolic links, allowing out-of-root file reads. Attackers can place symlinks under the Control UI root directory to bypass…
- CVE-2026-32021MEDIUMCVSS 6.5EG 6.5✓ Fixed in 2026.2.222026-03-19
OpenClaw versions prior to 2026.2.22 contain an authorization bypass vulnerability in the Feishu allowFrom allowlist implementation that accepts mutable sender display names instead of enforcing ID-only matching. An attacker can set a disp…
- CVE-2026-32022MEDIUMCVSS 6.5EG 6.5✓ Fixed in 2026.2.212026-03-19
OpenClaw versions prior to 2026.2.21 contain a stdin-only policy bypass vulnerability in the grep tool within tools.exec.safeBins that allows attackers to read arbitrary files by supplying a pattern via the -e flag parameter. Attackers can…
- CVE-2026-32023HIGHCVSS 7.1EG 7.1✓ Fixed in 2026.2.242026-03-19
OpenClaw versions prior to 2026.2.24 contain an approval gating bypass vulnerability in system.run allowlist mode where nested transparent dispatch wrappers can suppress shell-wrapper detection. Attackers can exploit this by chaining multi…
- CVE-2026-32024MEDIUMCVSS 5.5EG 5.5✓ Fixed in 2026.2.222026-03-19
OpenClaw versions prior to 2026.2.22 contain a symlink traversal vulnerability in avatar handling that allows attackers to read arbitrary files outside the configured workspace boundary. Remote attackers can exploit this by requesting avat…
- CVE-2026-32025HIGHCVSS 7.5EG 7.5✓ Fixed in 2026.2.252026-03-19
OpenClaw versions prior to 2026.2.25 contain an authentication hardening gap in browser-origin WebSocket clients that allows attackers to bypass origin checks and auth throttling on loopback deployments. An attacker can trick a user into o…
- CVE-2026-32026MEDIUMCVSS 6.5EG 6.5✓ Fixed in 2026.2.242026-03-19
OpenClaw versions prior to 2026.2.24 contain an improper path validation vulnerability in sandbox media handling that allows absolute paths under the host temporary directory outside the active sandbox root. Attackers can exploit this by p…
- CVE-2026-32027MEDIUMCVSS 6.5EG 6.5✓ Fixed in 2026.2.262026-03-19
OpenClaw versions prior to 2026.2.26 contain an authorization bypass vulnerability where DM pairing-store identities are incorrectly eligible for group allowlist authorization checks. Attackers can exploit this cross-context authorization …
- CVE-2026-32028MEDIUMCVSS 5.3EG 5.3✓ Fixed in 2026.2.252026-03-19
OpenClaw versions prior to 2026.2.25 fail to enforce dmPolicy and allowFrom authorization checks on Discord direct-message reaction notifications, allowing non-allowlisted users to enqueue reaction-derived system events. Attackers can expl…
- CVE-2026-32029MEDIUMCVSS 5.3EG 5.3✓ Fixed in 2026.2.212026-03-19
OpenClaw versions prior to 2026.2.21 improperly parse the left-most X-Forwarded-For header value when requests originate from configured trusted proxies, allowing attackers to spoof client IP addresses. In proxy chains that append or prese…
- CVE-2026-32030HIGHCVSS 7.5EG 7.5✓ Fixed in 2026.2.192026-03-19
OpenClaw versions prior to 2026.2.19 contain a path traversal vulnerability in the stageSandboxMedia function that accepts arbitrary absolute paths when iMessage remote attachment fetching is enabled. An attacker who can tamper with attach…
- CVE-2026-32031MEDIUMCVSS 4.8EG 4.8✓ Fixed in 2026.2.262026-03-19
OpenClaw versions prior to 2026.2.26 server-http contains an authentication bypass vulnerability in gateway authentication for plugin channel endpoints due to path canonicalization mismatch between the gateway guard and plugin handler rout…
- CVE-2026-32032HIGHCVSS 7.8EG 7.8✓ Fixed in 2026.2.222026-03-19
OpenClaw versions prior to 2026.2.22 contain an arbitrary shell execution vulnerability in shell environment fallback that trusts the unvalidated SHELL path from the host environment. An attacker with local environment access can inject a …
- CVE-2026-32033MEDIUMCVSS 6.5EG 6.5✓ Fixed in 2026.2.242026-03-19
OpenClaw versions prior to 2026.2.24 contain a path traversal vulnerability where @-prefixed absolute paths bypass workspace-only file-system boundary validation due to canonicalization mismatch. Attackers can exploit this by crafting @-pr…
- CVE-2026-32034HIGHCVSS 8.1EG 8.1✓ Fixed in 2026.2.212026-03-19
OpenClaw versions prior to 2026.2.21 contain an authentication bypass vulnerability in the Control UI when allowInsecureAuth is explicitly enabled and the gateway is exposed over plaintext HTTP, allowing attackers to bypass device identity…
- CVE-2026-32035MEDIUMCVSS 5.9EG 5.9✓ Fixed in 2026.3.22026-03-19
OpenClaw versions prior to 2026.3.2 fail to pass the senderIsOwner flag when processing Discord voice transcripts in agentCommand, causing the flag to default to true. Non-owner voice participants can exploit this omission to access owner-…
- CVE-2026-32036MEDIUMCVSS 6.5EG 6.5✓ Fixed in 2026.2.262026-03-19
OpenClaw gateway plugin versions prior to 2026.2.26 contain a path traversal vulnerability that allows remote attackers to bypass route authentication checks by manipulating /api/channels paths with encoded dot-segment traversal sequences.…
- CVE-2026-32037MEDIUMCVSS 6.0EG 6.0✓ Fixed in 2026.2.222026-03-19
OpenClaw versions prior to 2026.2.22 fail to consistently validate redirect chains against configured mediaAllowHosts allowlists during MSTeams media downloads. Attackers can supply or influence attachment URLs to force redirects to non-al…
Check whether openclaw is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for openclaw CVEs against the assets you own.
Start Free Scan →