openclaw
npm530 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting openclawpage 5 of 11
- CVE-2026-32971HIGHCVSS 8.0EG 8.0✓ Fixed in 2026.3.112026-03-31
OpenClaw before 2026.3.11 contains an approval-integrity vulnerability in node-host system.run approvals that displays extracted shell payloads instead of the executed argv. Attackers can place wrapper binaries and induce wrapper-shaped co…
- CVE-2026-32972HIGHCVSS 7.1EG 7.1✓ Fixed in 2026.3.112026-03-29
OpenClaw before 2026.3.11 contains an authorization bypass vulnerability allowing authenticated operators with only operator.write permission to access admin-only browser profile management routes through browser.request. Attackers can cre…
- CVE-2026-32973CRITICALCVSS 9.8EG 9.8✓ Fixed in 2026.3.112026-03-29
OpenClaw before 2026.3.11 contains an exec allowlist bypass vulnerability where matchesExecAllowlistPattern improperly normalizes patterns with lowercasing and glob matching that overmatches on POSIX paths. Attackers can exploit the ? wild…
- CVE-2026-32974HIGHCVSS 8.6EG 8.6✓ Fixed in 2026.3.122026-03-29
OpenClaw before 2026.3.12 contains an authentication bypass vulnerability in Feishu webhook mode when only verificationToken is configured without encryptKey, allowing acceptance of forged events. Unauthenticated network attackers can inje…
- CVE-2026-32975CRITICALCVSS 9.8EG 9.8✓ Fixed in 2026.3.122026-03-29
OpenClaw before 2026.3.12 contains a weak authorization vulnerability in Zalouser allowlist mode that matches mutable group display names instead of stable group identifiers. Attackers can create groups with identical names to allowlisted …
- CVE-2026-32976MEDIUMCVSS 6.5EG 6.5✓ Fixed in 2026.3.112026-03-31
OpenClaw before 2026.3.11 contains an authorization bypass vulnerability allowing channel commands to mutate protected sibling-account configuration despite configWrites restrictions. Attackers with authorized access on one account can exe…
- CVE-2026-32977MEDIUMCVSS 6.3EG 6.3✓ Fixed in 2026.3.112026-03-31
OpenClaw before 2026.3.11 contains a sandbox boundary bypass vulnerability in the fs-bridge writeFile commit step that uses an unanchored container path during the final move operation. An attacker can exploit a time-of-check-time-of-use r…
- CVE-2026-32978HIGHCVSS 8.0EG 8.0✓ Fixed in 2026.3.112026-03-29
OpenClaw before 2026.3.11 contains an approval integrity vulnerability where system.run approvals fail to bind mutable file operands for certain script runners like tsx and jiti. Attackers can obtain approval for benign script commands, re…
- CVE-2026-32979HIGHCVSS 7.3EG 7.3✓ Fixed in 2026.3.112026-03-29
OpenClaw before 2026.3.11 contains an approval integrity vulnerability allowing attackers to execute rewritten local code by modifying scripts between approval and execution when exact file binding cannot occur. Remote attackers can change…
- CVE-2026-32980HIGHCVSS 7.5EG 7.5✓ Fixed in 2026.3.132026-03-29
OpenClaw before 2026.3.13 reads and buffers Telegram webhook request bodies before validating the x-telegram-bot-api-secret-token header, allowing unauthenticated attackers to exhaust server resources. Attackers can send POST requests to t…
- CVE-2026-32982HIGHCVSS 7.5EG 7.5✓ Fixed in 2026.3.132026-03-31
OpenClaw before 2026.3.13 contains an information disclosure vulnerability in the fetchRemoteMedia function that exposes Telegram bot tokens in error messages. When media downloads fail, the original Telegram file URLs containing bot token…
- CVE-2026-32987CRITICALCVSS 9.8EG 9.8✓ Fixed in 2026.3.132026-03-29
OpenClaw before 2026.3.13 allows bootstrap setup codes to be replayed during device pairing verification in src/infra/device-bootstrap.ts. Attackers can verify a valid bootstrap code multiple times before approval to escalate pending pairi…
- CVE-2026-32988HIGHCVSS 7.5EG 7.5✓ Fixed in 2026.3.112026-03-31
OpenClaw before 2026.3.11 contains a sandbox boundary bypass vulnerability in fs-bridge staged writes where temporary file creation and population are not pinned to a verified parent directory. Attackers can exploit a race condition in par…
- CVE-2026-33572HIGHCVSS 8.4EG 8.4✓ Fixed in 2026.2.172026-03-29
OpenClaw before 2026.2.17 creates session transcript JSONL files with overly broad default permissions, allowing local users to read transcript contents. Attackers with local access can read transcript files to extract sensitive informatio…
- CVE-2026-33573HIGHCVSS 8.8EG 8.8✓ Fixed in 2026.3.112026-03-29
OpenClaw before 2026.3.11 contains an authorization bypass vulnerability in the gateway agent RPC that allows authenticated operators with operator.write permission to override workspace boundaries by supplying attacker-controlled spawnedB…
- CVE-2026-33574MEDIUMCVSS 6.2EG 6.2✓ Fixed in 2026.3.82026-03-29
OpenClaw before 2026.3.8 contains a path traversal vulnerability in the skills download installer that validates the tools root lexically but reuses the mutable path during archive download and copy operations. A local attacker can rebind …
- CVE-2026-33575HIGHCVSS 7.5EG 7.5✓ Fixed in 2026.3.122026-03-29
OpenClaw before 2026.3.12 embeds long-lived shared gateway credentials directly in pairing setup codes generated by /pair endpoint and OpenClaw qr command. Attackers with access to leaked setup codes from chat history, logs, or screenshots…
- CVE-2026-33576MEDIUMCVSS 6.5EG 6.5✓ Fixed in 2026.3.282026-03-31
OpenClaw before 2026.3.28 downloads and stores inbound media from Zalo channels before validating sender authorization. Unauthorized senders can force network fetches and disk writes to the media store by sending messages that are subseque…
- CVE-2026-33577HIGHCVSS 8.1EG 8.1✓ Fixed in 2026.3.282026-03-31
OpenClaw before 2026.3.28 contains an insufficient scope validation vulnerability in the node pairing approval path that allows low-privilege operators to approve nodes with broader scopes. Attackers can exploit missing callerScopes valida…
- CVE-2026-33578MEDIUMCVSS 4.3EG 4.3✓ Fixed in 2026.3.282026-03-31
OpenClaw before 2026.3.28 contains a sender policy bypass vulnerability in the Google Chat and Zalouser extensions where route-level group allowlist policies silently downgrade to open policy. Attackers can exploit this policy resolution f…
- CVE-2026-33579CRITICALCVSS 9.9EG 9.9✓ Fixed in 2026.3.282026-03-31
OpenClaw before 2026.3.28 contains a privilege escalation vulnerability in the /pair approve command path that fails to forward caller scopes into the core approval check. A caller with pairing privileges but without admin privileges can a…
- CVE-2026-33580MEDIUMCVSS 6.5EG 6.5✓ Fixed in 2026.3.282026-03-31
OpenClaw before 2026.3.28 contains a missing rate limiting vulnerability in the Nextcloud Talk webhook authentication that allows attackers to brute-force weak shared secrets. Attackers who can reach the webhook endpoint can exploit this t…
- CVE-2026-33581HIGHCVSS 8.6EG 8.6✓ Fixed in 2026.3.242026-03-31
OpenClaw before 2026.3.24 contains a sandbox bypass vulnerability in the message tool that allows attackers to read arbitrary local files by using mediaUrl and fileUrl alias parameters that bypass localRoots validation. Remote attackers ca…
- CVE-2026-34425MEDIUMCVSS 4.3EG 4.3✓ Fixed in 2026.4.22026-04-02
OpenClaw versions prior to commit 8aceaf5 contain a preflight validation bypass vulnerability in shell-bleed protection that allows attackers to execute blocked script content by using piped or complex command forms that the parser fails t…
- CVE-2026-34426HIGHCVSS 7.3EG 7.3✓ Fixed in 2026.3.222026-04-02
OpenClaw versions prior to commit b57b680 contain an approval bypass vulnerability due to inconsistent environment variable normalization between approval and execution paths, allowing attackers to inject attacker-controlled environment v…
- CVE-2026-34503HIGHCVSS 8.1EG 8.1✓ Fixed in 2026.3.282026-03-31
OpenClaw before 2026.3.28 fails to disconnect active WebSocket sessions when devices are removed or tokens are revoked. Attackers with revoked credentials can maintain unauthorized access through existing live sessions until forced reconne…
- CVE-2026-34504HIGHCVSS 8.3EG 8.3✓ Fixed in 2026.3.282026-03-31
OpenClaw before 2026.3.28 contains a server-side request forgery vulnerability in the fal provider image-generation-provider.ts component that allows attackers to fetch internal URLs. A malicious or compromised fal relay can exploit unguar…
- CVE-2026-34505MEDIUMCVSS 6.5EG 6.5✓ Fixed in 2026.3.122026-03-31
OpenClaw before 2026.3.12 applies rate limiting only after successful webhook authentication, allowing attackers to bypass rate limits and brute-force webhook secrets. Attackers can submit repeated authentication requests with invalid secr…
- CVE-2026-34506MEDIUMCVSS 4.3EG 4.3✓ Fixed in 2026.3.82026-03-31
OpenClaw before 2026.3.8 contains a sender allowlist bypass vulnerability in its Microsoft Teams plugin that allows unauthorized senders to bypass intended authorization checks. When a team/channel route allowlist is configured with an emp…
- CVE-2026-34507MEDIUMCVSS 5.4EG 5.4✓ Fixed in 2026.4.292026-05-29
OpenClaw before 2026.4.29 contains a policy bypass vulnerability in QQBot admin commands that allows authenticated senders to skip DM-only and allowFrom policy checks. Attackers can route admin commands from unauthorized senders or context…
- CVE-2026-34510MEDIUMCVSS 5.3EG 5.3✓ Fixed in 2026.3.222026-04-01
OpenClaw before 2026.3.22 contains a path traversal vulnerability in Windows media loaders that accepts remote-host file URLs and UNC-style paths before local-path validation. Attackers can exploit this by providing network-hosted file tar…
- CVE-2026-34511MEDIUMCVSS 5.9EG 5.9✓ Fixed in 2026.4.22026-04-03
OpenClaw before 2026.4.2 reuses the PKCE verifier as the OAuth state parameter in the Gemini OAuth flow, exposing it through the redirect URL. Attackers who capture the redirect URL can obtain both the authorization code and PKCE verifier,…
- CVE-2026-34512HIGHCVSS 8.1EG 8.12026-04-09
OpenClaw before 2026.3.25 contains an improper access control vulnerability in the HTTP /sessions/:sessionKey/kill route that allows any bearer-authenticated user to invoke admin-level session termination functions without proper scope val…
- CVE-2026-35617MEDIUMCVSS 4.2EG 4.2✓ Fixed in 2026.3.282026-04-09
OpenClaw before 2026.3.25 contains an authorization bypass vulnerability in Google Chat group policy enforcement that relies on mutable space display names. Attackers can rebind group policies by changing or colliding space display names t…
- CVE-2026-35618MEDIUMCVSS 6.5EG 6.5✓ Fixed in 2026.3.232026-04-09
OpenClaw before 2026.3.23 contains a replay identity vulnerability in Plivo V2 signature verification that allows attackers to bypass replay protection by modifying query parameters. The verification path derives replay keys from the full …
- CVE-2026-35619MEDIUMCVSS 4.3EG 4.3✓ Fixed in 2026.3.242026-04-10
OpenClaw before 2026.3.24 contains an authorization bypass vulnerability in the HTTP /v1/models endpoint that fails to enforce operator read scope requirements. Attackers with only operator.approvals scope can enumerate gateway model metad…
- CVE-2026-35620MEDIUMCVSS 5.4EG 5.4✓ Fixed in 2026.3.242026-04-10
OpenClaw before 2026.3.24 contains missing authorization vulnerabilities in the /send and /allowlist chat command handlers. The /send command allows non-owner command-authorized senders to change owner-only session delivery policy settings…
- CVE-2026-35621MEDIUMCVSS 6.5EG 6.5✓ Fixed in 2026.3.242026-04-10
OpenClaw before 2026.3.24 contains a privilege escalation vulnerability where the /allowlist command fails to re-validate gateway client scopes for internal callers, allowing operator.write-scoped clients to mutate channel authorization po…
- CVE-2026-35622MEDIUMCVSS 5.9EG 5.9✓ Fixed in 2026.3.222026-04-09
OpenClaw before 2026.3.22 contains an improper authentication verification vulnerability in Google Chat app-url webhook handling that accepts add-on principals outside intended deployment bindings. Attackers can bypass webhook authenticati…
- CVE-2026-35623MEDIUMCVSS 4.8EG 4.82026-04-09
OpenClaw before 2026.3.25 contains a missing rate limiting vulnerability in webhook authentication that allows attackers to brute-force weak webhook passwords without throttling. Remote attackers can repeatedly submit incorrect password gu…
- CVE-2026-35624MEDIUMCVSS 4.2EG 4.2✓ Fixed in 2026.3.222026-04-09
OpenClaw before 2026.3.22 contains a policy confusion vulnerability in room authorization that matches colliding room names instead of stable room tokens. Attackers can exploit similarly named rooms to bypass allowlist policies and gain un…
- CVE-2026-35625HIGHCVSS 7.8EG 7.82026-04-09
OpenClaw before 2026.3.25 contains a privilege escalation vulnerability where silent local shared-auth reconnects auto-approve scope-upgrade requests, widening paired device permissions from operator.read to operator.admin. Attackers can e…
- CVE-2026-35626MEDIUMCVSS 5.3EG 5.3✓ Fixed in 2026.3.222026-04-09
OpenClaw before 2026.3.22 contains an unauthenticated resource exhaustion vulnerability in voice call webhook handling that buffers request bodies before provider signature checks. Attackers can send large or malicious webhook requests to …
- CVE-2026-35627MEDIUMCVSS 6.5EG 6.5✓ Fixed in 2026.3.222026-04-09
OpenClaw before 2026.3.22 performs cryptographic and dispatch operations on inbound Nostr direct messages before enforcing sender and pairing policy validation. Attackers can trigger unauthorized pre-authentication computation by sending c…
- CVE-2026-35628MEDIUMCVSS 4.8EG 4.82026-04-09
OpenClaw before 2026.3.25 contains a missing rate limiting vulnerability in Telegram webhook authentication that allows attackers to brute-force weak webhook secrets. The vulnerability enables repeated authentication guesses without thrott…
- CVE-2026-35629HIGHCVSS 7.4EG 7.4✓ Fixed in 2026.3.282026-04-09
OpenClaw before 2026.3.25 contains a server-side request forgery vulnerability in multiple channel extensions that fail to properly guard configured base URLs against SSRF attacks. Attackers can exploit unprotected fetch() calls against co…
- CVE-2026-35630HIGHCVSS 8.0EG 8.0✓ Fixed in 2026.5.182026-05-29
OpenClaw before 2026.5.18 contains an authorization bypass vulnerability in QQBot native approval buttons that fails to enforce configured approver identity. Non-approver users can click approval buttons to resolve pending exec or plugin a…
- CVE-2026-35631MEDIUMCVSS 6.5EG 6.5✓ Fixed in 2026.3.222026-04-09
OpenClaw before 2026.3.22 fails to enforce operator.admin scope on mutating internal ACP chat commands, allowing unauthorized modifications. Attackers without admin privileges can execute mutating control-plane actions by directly invoking…
- CVE-2026-35632HIGHCVSS 7.1EG 7.12026-04-09
OpenClaw through 2026.2.22 contains a symlink traversal vulnerability in agents.create and agents.update handlers that use fs.appendFile on IDENTITY.md without symlink containment checks. Attackers with workspace access can plant symlinks …
- CVE-2026-35633MEDIUMCVSS 5.3EG 5.3✓ Fixed in 2026.3.222026-04-09
OpenClaw before 2026.3.22 contains an unbounded memory allocation vulnerability in remote media HTTP error handling that allows attackers to trigger excessive memory consumption. Attackers can send crafted HTTP error responses with large b…
Check whether openclaw is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for openclaw CVEs against the assets you own.
Start Free Scan →