Openclaw
105 CVEsCVE IDSeverityProduct / summaryPublished
CVE-2026-62201
MEDIUM 4.9
Openclaw — OpenClaw versions before 2026.6.6 contain a network policy bypass vulnerability in the sandbox exec-server tha…
2026-07-17
CVE-2026-62202
HIGH 7.7
Openclaw — OpenClaw versions 2026.6.1 before 2026.6.9 contain a privilege escalation vulnerability in isolated cron jobs …
2026-07-17
CVE-2026-62203
HIGH 7.7
Openclaw — OpenClaw versions before 2026.6.6 contain an environment variable filtering vulnerability in host exec that fa…
2026-07-17
CVE-2026-62205
MEDIUM 6
Openclaw — OpenClaw versions 2026.4.12-beta.1 before 2026.6.6 contain a missing-authorization vulnerability in the MS Tea…
2026-07-17
CVE-2026-62206
MEDIUM 6
Openclaw — OpenClaw versions before 2026.6.9 contain a missing authorization vulnerability in Discord moderation actions.…
2026-07-17
CVE-2026-62207
HIGH 7.7
Openclaw — OpenClaw versions before 2026.6.5 contain an authentication bypass vulnerability that allows lower-trust calle…
2026-07-17
CVE-2026-62208
MEDIUM 6
Openclaw — OpenClaw before 2026.6.5 could forward Authorization headers during MCP SSE redirects. When the affected featu…
2026-07-17
CVE-2026-62209
HIGH 7.6
Openclaw — OpenClaw versions 2026.5.10-beta.1 before 2026.6.5 contain an authorization bypass in the ClickClack agent-mod…
2026-07-17
CVE-2026-62210
MEDIUM 6
Openclaw — OpenClaw versions before 2026.6.1 contain a denial of service vulnerability where remote media URLs can trigge…
2026-07-17
CVE-2026-62211
MEDIUM 4.1
Openclaw — OpenClaw versions before 2026.6.1 contain a credential redaction bypass vulnerability in the trajectory export…
2026-07-17
CVE-2026-62212
MEDIUM 5.1
Openclaw — OpenClaw before 2026.5.28 contains a race condition in the MS Teams safeFetch DNS rebinding check. When the af…
2026-07-17
CVE-2026-62213
MEDIUM 6
Msteams — OpenClaw versions before 2026.5.27 contain a token leakage vulnerability in MS Teams outbound requests that al…
2026-07-17
CVE-2026-62214
MEDIUM 6
Msteams — OpenClaw versions before 2026.5.28 Bot Framework contains an improper input validation vulnerability that allo…
2026-07-17
CVE-2026-62215
MEDIUM 5.1
Openclaw — OpenClaw versions before 2026.6.5 contain an authentication bypass vulnerability in HTTP Canvas responses that…
2026-07-17
CVE-2026-62216
LOW 2.3
Openclaw — OpenClaw 2026.4.20 before 2026.5.28 contain a policy bypass in the QQBot media upload feature. A lower-trust c…
2026-07-17
CVE-2026-62217
HIGH 7.7
Openclaw — OpenClaw 2026.5.14-beta.1 before 2026.5.27 contain an authorization flaw in the QQBot exec approvals feature. …
2026-07-17
CVE-2026-62218
HIGH 8.7
Openclaw — OpenClaw 2026.1.20 before 2026.5.27 contain an authorization bypass vulnerability in the device.pair.approve f…
2026-07-17
CVE-2026-62219
MEDIUM 6
Openclaw — OpenClaw 2026.2.12 before 2026.5.26 contain an authorization bypass vulnerability in the hooks allowedAgentIds…
2026-07-17
CVE-2026-62220
MEDIUM 6.3
Openclaw — OpenClaw 2026.2.25 before 2026.5.26 allow a lower-trust caller or configured input path to bypass non-browser …
2026-07-17
CVE-2026-62221
LOW 2.3
Openclaw — OpenClaw 2026.5.12 before 2026.5.26 contain an incorrect authorization vulnerability in the ClickClack allowFr…
2026-07-17
CVE-2026-62222
HIGH 7.1
Openclaw — OpenClaw before 2026.5.22 contain a vulnerability in setup-mode discovery that allows loading of untrusted wor…
2026-07-17
CVE-2026-62223
HIGH 7.7
Openclaw — OpenClaw before 2026.5.18 contain an authorization bypass vulnerability in the device-pair approval feature th…
2026-07-17
CVE-2026-62224
LOW 2.3
Msteams — OpenClaw MS Teams before 2026.5.12 contain an authorization bypass vulnerability where the allowFrom feature b…
2026-07-17
CVE-2026-62225
LOW 2.3
Openclaw — OpenClaw versions before 2026.5.18 contain an authorization bypass vulnerability in skill command dispatch tha…
2026-07-17
CVE-2026-62226
MEDIUM 5.1
Openclaw — OpenClaw 2026.3.28 before 2026.5.19 contain an authorization bypass vulnerability in the browser act route tha…
2026-07-17
CVE-2026-62227
MEDIUM 4.9
Openclaw — OpenClaw 2026.4.14 before 2026.5.26 contain a server-side request forgery vulnerability in browser snapshot ro…
2026-07-17
CVE-2026-62228
HIGH 7.7
Openclaw — OpenClaw before 2026.6.5 contain an authorization bypass vulnerability in node exec approvals that allows lowe…
2026-07-17
CVE-2026-62229
HIGH 7.7
Openclaw — OpenClaw before 2026.5.18 contain an authorization bypass vulnerability in exec allowlist glob matching that a…
2026-07-17
CVE-2026-62186
HIGH 7.2
Openclaw — OpenClaw versions before 2026.6.8 contain an authorization bypass vulnerability in OpenAI-compatible HTTP mode…
2026-07-13
CVE-2026-62187
HIGH 8.6
Feishu — OpenClaw Feishu tools (npm package @openclaw/feishu) in versions <= 2026.6.6 could ignore per-account disablem…
2026-07-13
CVE-2026-62188
HIGH 8.6
Feishu — OpenClaw @openclaw/feishu versions 2026.6.6 and earlier contain an incorrect authorization vulnerability in wh…
2026-07-13
CVE-2026-62189
HIGH 7.6
Openclaw — OpenClaw versions before 2026.6.9 contain a symlink following vulnerability in the mirror sync feature that al…
2026-07-13
CVE-2026-62190
HIGH 8.7
Openclaw — OpenClaw versions before 2026.6.9 contain an authorization bypass vulnerability in the flock wrapper that allo…
2026-07-13
CVE-2026-62191
HIGH 7.1
Openclaw — OpenClaw versions 2026.6.6 before 2026.6.9 contain an authorization bypass vulnerability in message mutation h…
2026-07-13
CVE-2026-62192
HIGH 7.2
Openclaw — OpenClaw versions 2026.6.6 before 2026.6.9 contain an authorization bypass vulnerability in Discord guild acti…
2026-07-13
CVE-2026-62193
MEDIUM 6.9
Openclaw — OpenClaw versions 2026.6.5 before 2026.6.9 contain a vulnerability in the plugin install wrappers that could s…
2026-07-13
CVE-2026-62194
HIGH 8.7
Openclaw — OpenClaw versions 2026.5.20 before 2026.6.9 contain a privilege escalation vulnerability in plugin install com…
2026-07-13
CVE-2026-62195
HIGH 8.7
Openclaw — OpenClaw versions 2026.5.20 before 2026.6.6 contain an authorization bypass vulnerability in the MCP loopback …
2026-07-13
CVE-2026-62196
HIGH 8.7
Openclaw — OpenClaw versions 2026.3.22 before 2026.6.6 contain an authorization bypass vulnerability where WhatsApp group…
2026-07-13
CVE-2026-62197
MEDIUM 6.3
Openclaw — OpenClaw before 2026.6.6 contains a policy bypass vulnerability in browser CDP discovery that accepts blocked …
2026-07-13
CVE-2026-62198
MEDIUM 5.3
Openclaw — OpenClaw versions 2026.5.28 before 2026.6.6 contain an authorization bypass vulnerability in native web search…
2026-07-13
CVE-2026-62199
HIGH 8.7
Openclaw — OpenClaw versions before 2026.6.6 contain a flaw in host exec environment filtering that can miss interpreter …
2026-07-13
CVE-2026-62200
HIGH 8.7
Openclaw — OpenClaw versions before 2026.6.6 contain a flaw in host exec environment filtering that could allow Git ext t…
2026-07-13
CVE-2026-59261
HIGH 8.4
Openclaw — OpenClaw before 2026.5.28 contains a credential exposure vulnerability where workspace dotenv files can overri…
2026-07-08
CVE-2026-53840
MEDIUM 6
Openclaw — OpenClaw before 2026.5.12 contains an information disclosure vulnerability in streamable-http MCP servers that…
2026-06-16
CVE-2026-53841
LOW 2.1
Openclaw — OpenClaw before 2026.5.12 contains a cross-site scripting vulnerability in exported session HTML that preserve…
2026-06-16
CVE-2026-53842
HIGH 7
Openclaw — OpenClaw before 2026.5.2 contains an environment variable injection vulnerability allowing workspace .env file…
2026-06-16
CVE-2026-53843
HIGH 8.7
Openclaw — OpenClaw before 2026.5.26 contains an authorization bypass vulnerability where a surviving pairing-scoped devi…
2026-06-16
CVE-2026-53844
MEDIUM 6
Openclaw — OpenClaw before 2026.4.29 contains a session visibility check bypass vulnerability in shared memory search tha…
2026-06-16
CVE-2026-53845
LOW 2.3
Openclaw — OpenClaw before 2026.5.6 contains a hook bypass vulnerability where skill commands routed through the affected…
2026-06-16
CVE-2026-53846
HIGH 7
Openclaw — OpenClaw before 2026.4.29 contains a path traversal vulnerability in the install helper that allows workspace …
2026-06-16
CVE-2026-53847
MEDIUM 5.3
Openclaw — OpenClaw before 2026.5.6 contains a privilege escalation vulnerability in the Active Memory write scope that a…
2026-06-16
CVE-2026-53848
LOW 2.3
Openclaw — OpenClaw before 2026.5.26 contains an exec allowlist bypass vulnerability allowing authenticated operators to …
2026-06-16
CVE-2026-53849
HIGH 8.6
Openclaw — OpenClaw before 2026.5.7 contains a privilege escalation vulnerability where the allowFrom feature improperly …
2026-06-16
CVE-2026-53850
MEDIUM 6.8
Openclaw — OpenClaw before 2026.4.25 contains a control scope enforcement bypass vulnerability in the focus command that …
2026-06-16
CVE-2026-53851
MEDIUM 6.3
Openclaw — OpenClaw before 2026.5.12 contains a notification bypass vulnerability allowing Slack reaction events to enter…
2026-06-16
CVE-2026-53852
LOW 2.3
Openclaw — OpenClaw before 2026.4.25 contains a scope containment bypass vulnerability in device re-pairing that allows a…
2026-06-16
CVE-2026-53853
HIGH 7.6
Openclaw — OpenClaw before 2026.5.12 contains an argument pattern validation bypass in the exec allowlist that allows att…
2026-06-16
CVE-2026-53854
MEDIUM 6
Openclaw — OpenClaw before 2026.4.25 contains a privilege escalation vulnerability in internal and webchat command authen…
2026-06-16
CVE-2026-53855
HIGH 7.6
Openclaw — OpenClaw before 2026.4.2 contains an inline-eval bypass vulnerability allowing authenticated operators to weak…
2026-06-16
CVE-2026-53856
MEDIUM 5.7
Openclaw — OpenClaw 2026.4.23 before 2026.4.24 contains an insecure file permissions vulnerability in config recovery tha…
2026-06-16
CVE-2026-53857
HIGH 8.6
Openclaw — OpenClaw before 2026.5.3 contains a policy enforcement vulnerability where Zalo contacts with mutable display …
2026-06-16
CVE-2026-53858
HIGH 7
Openclaw — OpenClaw before 2026.5.2 contains an environment variable injection vulnerability where workspace .env STATE_D…
2026-06-16
CVE-2026-53859
MEDIUM 6
Openclaw — OpenClaw before 2026.5.26 contains a hostname validation vulnerability allowing attackers to bypass blocklist …
2026-06-16
CVE-2026-53860
LOW 2.3
Openclaw — OpenClaw before 2026.5.7 contains a sender policy bypass vulnerability in BlueBubbles that allows participants…
2026-06-16
CVE-2026-53861
MEDIUM 5.3
Openclaw — OpenClaw before 2026.5.6 contains an allowlist bypass vulnerability in the macOS Swift exec feature that misse…
2026-06-16
CVE-2026-53862
LOW 2.3
Openclaw — OpenClaw before 2026.5.12 contains a bootstrap token replay vulnerability allowing callers with pending token …
2026-06-16
CVE-2026-53863
MEDIUM 6
Openclaw — OpenClaw before 2026.4.25 contains an input validation vulnerability in tool group policy callers that accept …
2026-06-16
CVE-2026-53864
HIGH 7.6
Openclaw — OpenClaw before 2026.5.26 contains an insufficient sanitization vulnerability in the host environment sanitize…
2026-06-16
CVE-2026-53865
HIGH 7.2
Openclaw — OpenClaw before 2026.5.2 contains a path traversal vulnerability in maintenance task execution that allows wor…
2026-06-16
CVE-2026-53866
HIGH 7.6
Openclaw — OpenClaw before 2026.5.12 contains an allowlist bypass vulnerability in shell inline-command parsing that allo…
2026-06-16
CVE-2026-53820
MEDIUM 6.9
Openclaw — OpenClaw before 2026.5.12 contains an exec denylist bypass vulnerability in the bundle MCP loopback session-sp…
2026-06-12
CVE-2026-53821
HIGH 8.7
Openclaw — OpenClaw before 2026.5.18 accepts WebSocket client-declared operator scopes before binding to server-approved …
2026-06-12
CVE-2026-53822
HIGH 8.7
Openclaw — OpenClaw before 2026.5.18 contains a command injection vulnerability where shell wrapper argv could change bet…
2026-06-12
CVE-2026-53823
HIGH 8.6
Openclaw — OpenClaw before 2026.5.3 contains a privilege escalation vulnerability in the allowFrom feature that binds to …
2026-06-12
CVE-2026-53824
MEDIUM 6
Openclaw — OpenClaw before 2026.4.24 contains a token revocation vulnerability allowing callers with revoked slash tokens…
2026-06-12
CVE-2026-53825
HIGH 7.1
Openclaw — OpenClaw before 2026.4.7 contains an arbitrary file read vulnerability in the memory-wiki ingest feature that …
2026-06-12
CVE-2026-53826
LOW 2.3
Openclaw — OpenClaw before 2026.4.26 contains an information disclosure vulnerability in sandboxed session spawning that …
2026-06-12
CVE-2026-53827
MEDIUM 6
Openclaw — OpenClaw before 2026.5.2 contains a credential exposure vulnerability in message.action forwarding that allows…
2026-06-12
CVE-2026-53828
HIGH 7.7
Openclaw — OpenClaw before 2026.5.6 contains an authorization bypass vulnerability in native command handling that allows…
2026-06-12
CVE-2026-53829
HIGH 8.5
Openclaw — OpenClaw before 2026.5.18 contains an approval display truncation vulnerability allowing authenticated users t…
2026-06-12
CVE-2026-53830
MEDIUM 6
Openclaw — OpenClaw before 2026.4.22 contains a webhook secret revocation bypass vulnerability allowing callers with old …
2026-06-12
CVE-2026-53831
HIGH 7.6
Openclaw — OpenClaw before 2026.5.18 contains a policy enforcement vulnerability in system.run safe-bin allowlist validat…
2026-06-12
CVE-2026-53832
HIGH 7.4
Openclaw — OpenClaw before 2026.5.18 contains an identity header validation vulnerability allowing local same-host caller…
2026-06-12
CVE-2026-53833
HIGH 7.4
Openclaw — OpenClaw before 2026.4.29 contains an authorization bypass vulnerability in the QQBot streaming command that a…
2026-06-12
CVE-2026-53834
HIGH 8.2
Openclaw — OpenClaw before 2026.4.27 contains an authorization bypass vulnerability in QQBot pre-dispatch slash commands …
2026-06-12
CVE-2026-53835
LOW 2.3
Openclaw — OpenClaw before 2026.5.6 contains a configuration enforcement bypass vulnerability in Feishu dynamic-agent bin…
2026-06-12
CVE-2026-53836
HIGH 8.7
Openclaw — OpenClaw before 2026.5.12 contains an allowlist bypass vulnerability in PowerShell encoded-command handling th…
2026-06-12
CVE-2026-53837
MEDIUM 6.3
Openclaw — OpenClaw before 2026.5.6 contains an improper access control vulnerability in Mattermost event handlers that f…
2026-06-12
CVE-2026-53838
MEDIUM 6
Openclaw — OpenClaw before 2026.5.27 contains a state mutation vulnerability in node pairing reconnection that allows pai…
2026-06-12
CVE-2026-53839
MEDIUM 6
Openclaw — OpenClaw before 2026.5.7 contains a hostname validation vulnerability in retry endpoint checks that allows mat…
2026-06-12
CVE-2026-53806
HIGH 7.7
Openclaw — OpenClaw before 2026.5.12 contains a shell option parsing vulnerability that allows combined POSIX shell flags…
2026-06-11
CVE-2026-53807
HIGH 7.7
Openclaw — OpenClaw before 2026.5.6 contains an authorization bypass vulnerability in Telegram interactive callbacks that…
2026-06-11
CVE-2026-53808
MEDIUM 6
Openclaw — OpenClaw before 2026.5.6 contains an approval policy bypass vulnerability in the Skill Workshop apply flow tha…
2026-06-11
CVE-2026-53809
MEDIUM 4.8
Openclaw — OpenClaw before 2026.4.25 contains a policy bypass vulnerability in embedded runner policy that allows request…
2026-06-11
CVE-2026-53810
HIGH 7.7
Openclaw — OpenClaw before 2026.5.18 contains a code execution vulnerability where marketplace runtime extension metadata…
2026-06-11
CVE-2026-53811
HIGH 7.7
Openclaw — OpenClaw before 2026.5.7 contains a privilege escalation vulnerability in the Matrix allowFrom feature that al…
2026-06-11
CVE-2026-53812
MEDIUM 4.9
Openclaw — OpenClaw before 2026.5.18 contains a server-side request forgery vulnerability in browser control that allows …
2026-06-11
CVE-2026-53813
HIGH 7.3
Openclaw — OpenClaw before 2026.4.25 contains a path traversal vulnerability in memory-core artifact loading where worksp…
2026-06-11
CVE-2026-53814
HIGH 8.7
Openclaw — OpenClaw before 2026.5.20 contains a privilege escalation vulnerability where hook-triggered agent runs incorr…
2026-06-11
CVE-2026-53815
HIGH 7.1
Openclaw — OpenClaw before 2026.5.19 contains an authorization bypass vulnerability in message read actions that skips ch…
2026-06-11
CVE-2026-53816
HIGH 8.6
Openclaw — OpenClaw before 2026.5.18 contains an insufficient provenance validation vulnerability in node event handling …
2026-06-11
CVE-2026-53817
HIGH 8.7
Openclaw — OpenClaw before 2026.5.22 contains a locality validation vulnerability in Control UI pairing that allows attac…
2026-06-11
CVE-2026-53818
MEDIUM 6.9
Openclaw — OpenClaw before 2026.4.24 contains an authorization bypass vulnerability in the MCP loopback feature that allo…
2026-06-11
CVE-2026-53819
HIGH 8.7
Openclaw — OpenClaw before 2026.5.27 contains an arbitrary code execution vulnerability in skill install flows where work…
2026-06-11