openclaw
npm530 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting openclawpage 4 of 11
- CVE-2026-32038CRITICALCVSS 9.8EG 9.8✓ Fixed in 2026.2.242026-03-19
OpenClaw before 2026.2.24 contains a sandbox network isolation bypass vulnerability that allows trusted operators to join another container's network namespace. Attackers can configure the docker.network parameter with container:<id> value…
- CVE-2026-32039MEDIUMCVSS 5.9EG 5.9✓ Fixed in 2026.2.222026-03-19
OpenClaw versions prior to 2026.2.22 contain an authorization bypass vulnerability in the toolsBySender group policy matching that allows attackers to inherit elevated tool permissions through identifier collision attacks. Attackers can ex…
- CVE-2026-32040MEDIUMCVSS 4.6EG 4.6✓ Fixed in 2026.2.232026-03-19
OpenClaw versions prior to 2026.2.23 contain an html injection vulnerability in the HTML session exporter that allows attackers to execute arbitrary javascript by injecting malicious mimeType values in image content blocks. Attackers can c…
- CVE-2026-32041MEDIUMCVSS 6.9EG 6.9✓ Fixed in 2026.3.12026-03-19
OpenClaw versions prior to 2026.3.1 fail to properly handle authentication bootstrap errors during startup, allowing browser-control routes to remain accessible without authentication. Local processes or loopback-reachable SSRF paths can e…
- CVE-2026-32042HIGHCVSS 8.8EG 8.8✓ Fixed in 2026.2.252026-03-21
OpenClaw versions 2026.2.22 prior to 2026.2.25 contain a privilege escalation vulnerability allowing unpaired device identities to bypass operator pairing requirements and self-assign elevated operator scopes including operator.admin. Atta…
- CVE-2026-32043MEDIUMCVSS 6.5EG 6.5✓ Fixed in 2026.2.252026-03-21
OpenClaw versions prior to 2026.2.25 contain a time-of-check-time-of-use vulnerability in approval-bound system.run execution where the cwd parameter is validated at approval time but resolved at execution time. Attackers can retarget a sy…
- CVE-2026-32044MEDIUMCVSS 5.5EG 5.5✓ Fixed in 2026.3.22026-03-21
OpenClaw versions prior to 2026.3.2 contain an archive extraction vulnerability in the tar.bz2 installer path that bypasses safety checks enforced on other archive formats. Attackers can craft malicious tar.bz2 skill archives to bypass spe…
- CVE-2026-32045MEDIUMCVSS 5.9EG 5.9✓ Fixed in 2026.2.212026-03-21
OpenClaw versions prior to 2026.2.21 incorrectly apply tokenless Tailscale header authentication to HTTP gateway routes, allowing bypass of token and password requirements. Attackers on trusted networks can exploit this misconfiguration to…
- CVE-2026-32046MEDIUMCVSS 5.3EG 5.3✓ Fixed in 2026.2.212026-03-21
OpenClaw versions prior to 2026.2.21 contain an improper sandbox configuration vulnerability that allows attackers to execute arbitrary code by exploiting renderer-side vulnerabilities without requiring a sandbox escape. Attackers can leve…
- CVE-2026-32048HIGHCVSS 7.5EG 7.5✓ Fixed in 2026.3.12026-03-21
OpenClaw versions prior to 2026.3.1 fail to enforce sandbox inheritance during cross-agent sessions_spawn operations, allowing sandboxed sessions to create child processes under unsandboxed agents. An attacker with a sandboxed session can …
- CVE-2026-32049HIGHCVSS 7.5EG 7.5✓ Fixed in 2026.2.222026-03-21
OpenClaw versions prior to 2026.2.22 fail to consistently enforce configured inbound media byte limits before buffering remote media across multiple channel ingestion paths. Remote attackers can send oversized media payloads to trigger ele…
- CVE-2026-32050LOWCVSS 3.7EG 3.7✓ Fixed in 2026.2.252026-03-21
OpenClaw versions prior to 2026.2.25 contain an access control vulnerability in signal reaction notification handling that allows unauthorized senders to enqueue status events before authorization checks are applied. Attackers can exploit …
- CVE-2026-32051HIGHCVSS 8.8EG 8.8✓ Fixed in 2026.3.12026-03-21
OpenClaw versions prior to 2026.3.1 contain an authorization mismatch vulnerability that allows authenticated callers with operator.write scope to invoke owner-only tool surfaces including gateway and cron through agent runs in scoped-toke…
- CVE-2026-32052MEDIUMCVSS 6.4EG 6.4✓ Fixed in 2026.2.242026-03-21
OpenClaw versions prior to 2026.2.24 contain a command injection vulnerability in the system.run shell-wrapper that allows attackers to execute hidden commands by injecting positional argv carriers after inline shell payloads. Attackers ca…
- CVE-2026-32053MEDIUMCVSS 6.5EG 6.5✓ Fixed in 2026.2.232026-03-21
OpenClaw versions prior to 2026.2.23 contain a vulnerability in Twilio webhook event deduplication where normalized event IDs are randomized per parse, allowing replay events to bypass manager dedupe checks. Attackers can replay Twilio web…
- CVE-2026-32054MEDIUMCVSS 6.5EG 6.5✓ Fixed in 2026.2.252026-03-21
OpenClaw versions prior to 2026.2.25 contain a symlink traversal vulnerability in browser trace and download output path handling that allows local attackers to escape the managed temp root directory. An attacker with local access can crea…
- CVE-2026-32055HIGHCVSS 7.6EG 7.6✓ Fixed in 2026.2.262026-03-21
OpenClaw versions prior to 2026.2.26 contain a path traversal vulnerability in workspace boundary validation that allows attackers to write files outside the workspace through in-workspace symlinks pointing to non-existent out-of-root targ…
- CVE-2026-32056HIGHCVSS 7.5EG 7.5✓ Fixed in 2026.2.222026-03-21
OpenClaw versions prior to 2026.2.22 fail to sanitize shell startup environment variables HOME and ZDOTDIR in the system.run function, allowing attackers to bypass command allowlist protections. Remote attackers can inject malicious startu…
- CVE-2026-32057HIGHCVSS 7.1EG 7.1✓ Fixed in 2026.2.252026-03-21
OpenClaw versions prior to 2026.2.25 contain an authentication bypass vulnerability in the trusted-proxy Control UI pairing mechanism that accepts client.id=control-ui without proper device identity verification. An authenticated node role…
- CVE-2026-32058LOWCVSS 2.6EG 2.6✓ Fixed in 2026.2.262026-03-21
OpenClaw versions prior to 2026.2.26 contain an approval context-binding weakness in system.run execution flows with host=node that allows reuse of previously approved requests with modified environment variables. Attackers with access to …
- CVE-2026-32059HIGHCVSS 8.8EG 8.8✓ Fixed in 2026.2.232026-03-11
OpenClaw version 2026.2.22-2 prior to 2026.2.23 tools.exec.safeBins validation for sort command fails to properly validate GNU long-option abbreviations, allowing attackers to bypass denied-flag checks via abbreviated options. Remote attac…
- CVE-2026-32060HIGHCVSS 8.8EG 8.8✓ Fixed in 2026.2.142026-03-11
OpenClaw versions prior to 2026.2.14 contain a path traversal vulnerability in apply_patch that allows attackers to write or delete files outside the configured workspace directory. When apply_patch is enabled without filesystem sandbox co…
- CVE-2026-32061MEDIUMCVSS 4.4EG 4.4✓ Fixed in 2026.2.172026-03-11
OpenClaw versions prior to 2026.2.17 contain a path traversal vulnerability in the $include directive resolution that allows reading arbitrary local files outside the config directory boundary. Attackers with config modification capabiliti…
- CVE-2026-32062HIGHCVSS 7.5EG 7.5✓ Fixed in 2026.2.222026-03-11
OpenClaw versions 2026.2.21-2 up to, but not including, 2026.2.22, and @openclaw/voice-call versions 2026.2.21 up to, but not including, 2026.2.22 accept media-stream WebSocket upgrades before stream validation, allowing unauthenticated cl…
- CVE-2026-32063HIGHCVSS 7.8EG 7.8✓ Fixed in 2026.2.212026-03-11
OpenClaw version 2026.2.19-2 prior to 2026.2.21 contains a command injection vulnerability in systemd unit file generation where attacker-controlled environment values are not validated for CR/LF characters, allowing newline injection to b…
- CVE-2026-32064HIGHCVSS 7.7EG 7.7✓ Fixed in 2026.2.212026-03-21
OpenClaw versions prior to 2026.2.21 sandbox browser entrypoint launches x11vnc without authentication for noVNC observer sessions, allowing unauthenticated access to the VNC interface. Remote attackers on the host loopback interface can c…
- CVE-2026-32065MEDIUMCVSS 4.8EG 4.8✓ Fixed in 2026.2.252026-03-21
OpenClaw versions prior to 2026.2.25 contain an approval-integrity bypass vulnerability in system.run where rendered command text is used as approval identity while trimming argv token whitespace, but runtime execution uses raw argv. An at…
- CVE-2026-32067LOWCVSS 3.7EG 3.7✓ Fixed in 2026.2.262026-03-21
OpenClaw versions prior to 2026.2.26 contain an authorization bypass vulnerability in the pairing-store access control for direct message pairing policy that allows attackers to reuse pairing approvals across multiple accounts. An attacker…
- CVE-2026-32302HIGHCVSS 8.1EG 8.1✓ Fixed in 2026.3.112026-03-13
OpenClaw is a personal AI assistant. Prior to 2026.3.11, browser-originated WebSocket connections could bypass origin validation when gateway.auth.mode was set to trusted-proxy and the request arrived with proxy headers. A page served from…
- CVE-2026-32846HIGHCVSS 8.7EG 8.7✓ Fixed in 2026.03.282026-03-26
OpenClaw before 2026.3.28 contains a path traversal vulnerability in media parsing that allows attackers to read arbitrary files by bypassing path validation in the isLikelyLocalPath() and isValidMedia() functions. Attackers can exploit in…
- CVE-2026-32895MEDIUMCVSS 5.4EG 5.4✓ Fixed in 2026.2.262026-03-21
OpenClaw versions prior to 2026.2.26 fail to enforce sender authorization in member and message subtype system event handlers, allowing unauthorized events to be enqueued. Attackers can bypass Slack DM allowlists and per-channel user allow…
- CVE-2026-32896MEDIUMCVSS 4.8EG 4.8✓ Fixed in 2026.2.212026-03-21
The BlueBubbles webhook handler in OpenClaw versions prior to 2026.2.21 contains a passwordless fallback authentication path that allows unauthenticated webhook events in certain reverse-proxy or local routing configurations. Attackers can…
- CVE-2026-32897LOWCVSS 3.7EG 3.7✓ Fixed in 2026.2.222026-03-21
OpenClaw versions prior to 2026.2.22 reuse gateway.auth.token as a fallback hash secret for owner-ID prompt obfuscation when commands.ownerDisplay is set to hash and commands.ownerDisplaySecret is unset, creating dual-use of authentication…
- CVE-2026-32898MEDIUMCVSS 5.4EG 5.4✓ Fixed in 2026.2.232026-03-21
OpenClaw versions prior to 2026.2.23 contain an authorization bypass vulnerability in the ACP client that auto-approves tool calls based on untrusted toolCall.kind metadata and permissive name heuristics. Attackers can bypass interactive a…
- CVE-2026-32899MEDIUMCVSS 4.3EG 4.3✓ Fixed in 2026.2.252026-03-21
OpenClaw versions prior to 2026.2.25 fail to consistently apply sender-policy checks to reaction_* and pin_* non-message events before adding them to system-event context. Attackers can bypass configured DM policies and channel user allowl…
- CVE-2026-32905HIGHCVSS 8.3EG 8.3✓ Fixed in 2026.5.42026-05-29
OpenClaw before 2026.5.4 contains an authorization bypass vulnerability in the bundled device-pair plugin that allows non-owner authorized chat senders to issue device-pairing bootstrap codes without proper scope validation. Attackers with…
- CVE-2026-32906MEDIUMCVSS 4.3EG 4.3✓ Fixed in 2026.5.122026-05-29
OpenClaw before 2026.5.12 contains a privilege escalation vulnerability in Slack plugin approvals that allows exec-authorized users to resolve plugin approvals through the exec approver gate. Attackers with limited exec approval permission…
- CVE-2026-32913CRITICALCVSS 9.3EG 9.3✓ Fixed in 2026.3.72026-03-23
OpenClaw before 2026.3.7 contains an improper header validation vulnerability in fetchWithSsrFGuard that forwards custom authorization headers across cross-origin redirects. Attackers can trigger redirects to different origins to intercept…
- CVE-2026-32914HIGHCVSS 8.8EG 8.8✓ Fixed in 2026.3.122026-03-29
OpenClaw before 2026.3.12 contains an insufficient access control vulnerability in the /config and /debug command handlers that allows command-authorized non-owners to access owner-only surfaces. Attackers with command authorization can re…
- CVE-2026-32915HIGHCVSS 8.8EG 8.8✓ Fixed in 2026.3.112026-03-29
OpenClaw before 2026.3.11 contains a sandbox boundary bypass vulnerability allowing leaf subagents to access the subagents control surface and resolve against parent requester scope instead of their own session tree. A low-privilege sandbo…
- CVE-2026-32916CRITICALCVSS 9.8EG 9.8✓ Fixed in 2026.3.112026-03-31
OpenClaw versions 2026.3.7 before 2026.3.11 contain an authorization bypass vulnerability where plugin subagent routes execute gateway methods through a synthetic operator client with broad administrative scopes. Remote unauthenticated req…
- CVE-2026-32917CRITICALCVSS 9.8EG 9.8✓ Fixed in 2026.3.132026-03-31
OpenClaw before 2026.3.13 contains a remote command injection vulnerability in the iMessage attachment staging flow that allows attackers to execute arbitrary commands on configured remote hosts. The vulnerability exists because unsanitize…
- CVE-2026-32918HIGHCVSS 8.4EG 8.4✓ Fixed in 2026.3.112026-03-29
OpenClaw before 2026.3.11 contains a session sandbox escape vulnerability in the session_status tool that allows sandboxed subagents to access parent or sibling session state. Attackers can supply arbitrary sessionKey values to read or mod…
- CVE-2026-32919MEDIUMCVSS 6.1EG 6.1✓ Fixed in 2026.3.112026-03-29
OpenClaw before 2026.3.11 contains an authorization bypass vulnerability allowing write-scoped callers to reach admin-only session reset logic. Attackers with operator.write scope can issue agent requests containing /new or /reset slash co…
- CVE-2026-32920HIGHCVSS 8.8EG 8.8✓ Fixed in 2026.3.122026-03-31
OpenClaw before 2026.3.12 automatically discovers and loads plugins from .OpenClaw/extensions/ without explicit trust verification, allowing arbitrary code execution. Attackers can execute malicious code by including crafted workspace plug…
- CVE-2026-32921MEDIUMCVSS 5.0EG 5.0✓ Fixed in 2026.3.82026-03-31
OpenClaw before 2026.3.8 contains an approval bypass vulnerability in system.run where mutable script operands are not bound across approval and execution phases. Attackers can obtain approval for script execution, modify the approved scri…
- CVE-2026-32922CRITICALCVSS 9.9EG 9.9✓ Fixed in 2026.3.112026-03-29
OpenClaw before 2026.3.11 contains a privilege escalation vulnerability in device.token.rotate that allows callers with operator.pairing scope to mint tokens with broader scopes by failing to constrain newly minted scopes to the caller's c…
- CVE-2026-32923MEDIUMCVSS 5.4EG 5.4✓ Fixed in 2026.3.112026-03-29
OpenClaw before 2026.3.11 contains an authorization bypass vulnerability in Discord guild reaction ingestion that fails to enforce member users and roles allowlist checks. Non-allowlisted guild members can trigger reaction events accepted …
- CVE-2026-32924CRITICALCVSS 9.8EG 9.8✓ Fixed in 2026.3.122026-03-29
OpenClaw before 2026.3.12 contains an authorization bypass vulnerability where Feishu reaction events with omitted chat_type are misclassified as p2p conversations instead of group chats. Attackers can exploit this misclassification to byp…
- CVE-2026-32970LOWCVSS 3.3EG 3.3✓ Fixed in 2026.3.112026-03-31
OpenClaw before 2026.3.11 contains a credential fallback vulnerability where unavailable local gateway.auth.token and gateway.auth.password SecretRefs are treated as unset, allowing fallback to remote credentials in local mode. Attackers c…
Check whether openclaw is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for openclaw CVEs against the assets you own.
Start Free Scan →