← Browse

Openclaw

105 CVEs
CVE IDSeverityProduct / summaryPublished
CVE-2026-62201 MEDIUM 4.9 Openclaw — OpenClaw versions before 2026.6.6 contain a network policy bypass vulnerability in the sandbox exec-server tha… 2026-07-17 CVE-2026-62202 HIGH 7.7 Openclaw — OpenClaw versions 2026.6.1 before 2026.6.9 contain a privilege escalation vulnerability in isolated cron jobs … 2026-07-17 CVE-2026-62203 HIGH 7.7 Openclaw — OpenClaw versions before 2026.6.6 contain an environment variable filtering vulnerability in host exec that fa… 2026-07-17 CVE-2026-62205 MEDIUM 6 Openclaw — OpenClaw versions 2026.4.12-beta.1 before 2026.6.6 contain a missing-authorization vulnerability in the MS Tea… 2026-07-17 CVE-2026-62206 MEDIUM 6 Openclaw — OpenClaw versions before 2026.6.9 contain a missing authorization vulnerability in Discord moderation actions.… 2026-07-17 CVE-2026-62207 HIGH 7.7 Openclaw — OpenClaw versions before 2026.6.5 contain an authentication bypass vulnerability that allows lower-trust calle… 2026-07-17 CVE-2026-62208 MEDIUM 6 Openclaw — OpenClaw before 2026.6.5 could forward Authorization headers during MCP SSE redirects. When the affected featu… 2026-07-17 CVE-2026-62209 HIGH 7.6 Openclaw — OpenClaw versions 2026.5.10-beta.1 before 2026.6.5 contain an authorization bypass in the ClickClack agent-mod… 2026-07-17 CVE-2026-62210 MEDIUM 6 Openclaw — OpenClaw versions before 2026.6.1 contain a denial of service vulnerability where remote media URLs can trigge… 2026-07-17 CVE-2026-62211 MEDIUM 4.1 Openclaw — OpenClaw versions before 2026.6.1 contain a credential redaction bypass vulnerability in the trajectory export… 2026-07-17 CVE-2026-62212 MEDIUM 5.1 Openclaw — OpenClaw before 2026.5.28 contains a race condition in the MS Teams safeFetch DNS rebinding check. When the af… 2026-07-17 CVE-2026-62213 MEDIUM 6 Msteams — OpenClaw versions before 2026.5.27 contain a token leakage vulnerability in MS Teams outbound requests that al… 2026-07-17 CVE-2026-62214 MEDIUM 6 Msteams — OpenClaw versions before 2026.5.28 Bot Framework contains an improper input validation vulnerability that allo… 2026-07-17 CVE-2026-62215 MEDIUM 5.1 Openclaw — OpenClaw versions before 2026.6.5 contain an authentication bypass vulnerability in HTTP Canvas responses that… 2026-07-17 CVE-2026-62216 LOW 2.3 Openclaw — OpenClaw 2026.4.20 before 2026.5.28 contain a policy bypass in the QQBot media upload feature. A lower-trust c… 2026-07-17 CVE-2026-62217 HIGH 7.7 Openclaw — OpenClaw 2026.5.14-beta.1 before 2026.5.27 contain an authorization flaw in the QQBot exec approvals feature. … 2026-07-17 CVE-2026-62218 HIGH 8.7 Openclaw — OpenClaw 2026.1.20 before 2026.5.27 contain an authorization bypass vulnerability in the device.pair.approve f… 2026-07-17 CVE-2026-62219 MEDIUM 6 Openclaw — OpenClaw 2026.2.12 before 2026.5.26 contain an authorization bypass vulnerability in the hooks allowedAgentIds… 2026-07-17 CVE-2026-62220 MEDIUM 6.3 Openclaw — OpenClaw 2026.2.25 before 2026.5.26 allow a lower-trust caller or configured input path to bypass non-browser … 2026-07-17 CVE-2026-62221 LOW 2.3 Openclaw — OpenClaw 2026.5.12 before 2026.5.26 contain an incorrect authorization vulnerability in the ClickClack allowFr… 2026-07-17 CVE-2026-62222 HIGH 7.1 Openclaw — OpenClaw before 2026.5.22 contain a vulnerability in setup-mode discovery that allows loading of untrusted wor… 2026-07-17 CVE-2026-62223 HIGH 7.7 Openclaw — OpenClaw before 2026.5.18 contain an authorization bypass vulnerability in the device-pair approval feature th… 2026-07-17 CVE-2026-62224 LOW 2.3 Msteams — OpenClaw MS Teams before 2026.5.12 contain an authorization bypass vulnerability where the allowFrom feature b… 2026-07-17 CVE-2026-62225 LOW 2.3 Openclaw — OpenClaw versions before 2026.5.18 contain an authorization bypass vulnerability in skill command dispatch tha… 2026-07-17 CVE-2026-62226 MEDIUM 5.1 Openclaw — OpenClaw 2026.3.28 before 2026.5.19 contain an authorization bypass vulnerability in the browser act route tha… 2026-07-17 CVE-2026-62227 MEDIUM 4.9 Openclaw — OpenClaw 2026.4.14 before 2026.5.26 contain a server-side request forgery vulnerability in browser snapshot ro… 2026-07-17 CVE-2026-62228 HIGH 7.7 Openclaw — OpenClaw before 2026.6.5 contain an authorization bypass vulnerability in node exec approvals that allows lowe… 2026-07-17 CVE-2026-62229 HIGH 7.7 Openclaw — OpenClaw before 2026.5.18 contain an authorization bypass vulnerability in exec allowlist glob matching that a… 2026-07-17 CVE-2026-62186 HIGH 7.2 Openclaw — OpenClaw versions before 2026.6.8 contain an authorization bypass vulnerability in OpenAI-compatible HTTP mode… 2026-07-13 CVE-2026-62187 HIGH 8.6 Feishu — OpenClaw Feishu tools (npm package @openclaw/feishu) in versions <= 2026.6.6 could ignore per-account disablem… 2026-07-13 CVE-2026-62188 HIGH 8.6 Feishu — OpenClaw @openclaw/feishu versions 2026.6.6 and earlier contain an incorrect authorization vulnerability in wh… 2026-07-13 CVE-2026-62189 HIGH 7.6 Openclaw — OpenClaw versions before 2026.6.9 contain a symlink following vulnerability in the mirror sync feature that al… 2026-07-13 CVE-2026-62190 HIGH 8.7 Openclaw — OpenClaw versions before 2026.6.9 contain an authorization bypass vulnerability in the flock wrapper that allo… 2026-07-13 CVE-2026-62191 HIGH 7.1 Openclaw — OpenClaw versions 2026.6.6 before 2026.6.9 contain an authorization bypass vulnerability in message mutation h… 2026-07-13 CVE-2026-62192 HIGH 7.2 Openclaw — OpenClaw versions 2026.6.6 before 2026.6.9 contain an authorization bypass vulnerability in Discord guild acti… 2026-07-13 CVE-2026-62193 MEDIUM 6.9 Openclaw — OpenClaw versions 2026.6.5 before 2026.6.9 contain a vulnerability in the plugin install wrappers that could s… 2026-07-13 CVE-2026-62194 HIGH 8.7 Openclaw — OpenClaw versions 2026.5.20 before 2026.6.9 contain a privilege escalation vulnerability in plugin install com… 2026-07-13 CVE-2026-62195 HIGH 8.7 Openclaw — OpenClaw versions 2026.5.20 before 2026.6.6 contain an authorization bypass vulnerability in the MCP loopback … 2026-07-13 CVE-2026-62196 HIGH 8.7 Openclaw — OpenClaw versions 2026.3.22 before 2026.6.6 contain an authorization bypass vulnerability where WhatsApp group… 2026-07-13 CVE-2026-62197 MEDIUM 6.3 Openclaw — OpenClaw before 2026.6.6 contains a policy bypass vulnerability in browser CDP discovery that accepts blocked … 2026-07-13 CVE-2026-62198 MEDIUM 5.3 Openclaw — OpenClaw versions 2026.5.28 before 2026.6.6 contain an authorization bypass vulnerability in native web search… 2026-07-13 CVE-2026-62199 HIGH 8.7 Openclaw — OpenClaw versions before 2026.6.6 contain a flaw in host exec environment filtering that can miss interpreter … 2026-07-13 CVE-2026-62200 HIGH 8.7 Openclaw — OpenClaw versions before 2026.6.6 contain a flaw in host exec environment filtering that could allow Git ext t… 2026-07-13 CVE-2026-59261 HIGH 8.4 Openclaw — OpenClaw before 2026.5.28 contains a credential exposure vulnerability where workspace dotenv files can overri… 2026-07-08 CVE-2026-53840 MEDIUM 6 Openclaw — OpenClaw before 2026.5.12 contains an information disclosure vulnerability in streamable-http MCP servers that… 2026-06-16 CVE-2026-53841 LOW 2.1 Openclaw — OpenClaw before 2026.5.12 contains a cross-site scripting vulnerability in exported session HTML that preserve… 2026-06-16 CVE-2026-53842 HIGH 7 Openclaw — OpenClaw before 2026.5.2 contains an environment variable injection vulnerability allowing workspace .env file… 2026-06-16 CVE-2026-53843 HIGH 8.7 Openclaw — OpenClaw before 2026.5.26 contains an authorization bypass vulnerability where a surviving pairing-scoped devi… 2026-06-16 CVE-2026-53844 MEDIUM 6 Openclaw — OpenClaw before 2026.4.29 contains a session visibility check bypass vulnerability in shared memory search tha… 2026-06-16 CVE-2026-53845 LOW 2.3 Openclaw — OpenClaw before 2026.5.6 contains a hook bypass vulnerability where skill commands routed through the affected… 2026-06-16 CVE-2026-53846 HIGH 7 Openclaw — OpenClaw before 2026.4.29 contains a path traversal vulnerability in the install helper that allows workspace … 2026-06-16 CVE-2026-53847 MEDIUM 5.3 Openclaw — OpenClaw before 2026.5.6 contains a privilege escalation vulnerability in the Active Memory write scope that a… 2026-06-16 CVE-2026-53848 LOW 2.3 Openclaw — OpenClaw before 2026.5.26 contains an exec allowlist bypass vulnerability allowing authenticated operators to … 2026-06-16 CVE-2026-53849 HIGH 8.6 Openclaw — OpenClaw before 2026.5.7 contains a privilege escalation vulnerability where the allowFrom feature improperly … 2026-06-16 CVE-2026-53850 MEDIUM 6.8 Openclaw — OpenClaw before 2026.4.25 contains a control scope enforcement bypass vulnerability in the focus command that … 2026-06-16 CVE-2026-53851 MEDIUM 6.3 Openclaw — OpenClaw before 2026.5.12 contains a notification bypass vulnerability allowing Slack reaction events to enter… 2026-06-16 CVE-2026-53852 LOW 2.3 Openclaw — OpenClaw before 2026.4.25 contains a scope containment bypass vulnerability in device re-pairing that allows a… 2026-06-16 CVE-2026-53853 HIGH 7.6 Openclaw — OpenClaw before 2026.5.12 contains an argument pattern validation bypass in the exec allowlist that allows att… 2026-06-16 CVE-2026-53854 MEDIUM 6 Openclaw — OpenClaw before 2026.4.25 contains a privilege escalation vulnerability in internal and webchat command authen… 2026-06-16 CVE-2026-53855 HIGH 7.6 Openclaw — OpenClaw before 2026.4.2 contains an inline-eval bypass vulnerability allowing authenticated operators to weak… 2026-06-16 CVE-2026-53856 MEDIUM 5.7 Openclaw — OpenClaw 2026.4.23 before 2026.4.24 contains an insecure file permissions vulnerability in config recovery tha… 2026-06-16 CVE-2026-53857 HIGH 8.6 Openclaw — OpenClaw before 2026.5.3 contains a policy enforcement vulnerability where Zalo contacts with mutable display … 2026-06-16 CVE-2026-53858 HIGH 7 Openclaw — OpenClaw before 2026.5.2 contains an environment variable injection vulnerability where workspace .env STATE_D… 2026-06-16 CVE-2026-53859 MEDIUM 6 Openclaw — OpenClaw before 2026.5.26 contains a hostname validation vulnerability allowing attackers to bypass blocklist … 2026-06-16 CVE-2026-53860 LOW 2.3 Openclaw — OpenClaw before 2026.5.7 contains a sender policy bypass vulnerability in BlueBubbles that allows participants… 2026-06-16 CVE-2026-53861 MEDIUM 5.3 Openclaw — OpenClaw before 2026.5.6 contains an allowlist bypass vulnerability in the macOS Swift exec feature that misse… 2026-06-16 CVE-2026-53862 LOW 2.3 Openclaw — OpenClaw before 2026.5.12 contains a bootstrap token replay vulnerability allowing callers with pending token … 2026-06-16 CVE-2026-53863 MEDIUM 6 Openclaw — OpenClaw before 2026.4.25 contains an input validation vulnerability in tool group policy callers that accept … 2026-06-16 CVE-2026-53864 HIGH 7.6 Openclaw — OpenClaw before 2026.5.26 contains an insufficient sanitization vulnerability in the host environment sanitize… 2026-06-16 CVE-2026-53865 HIGH 7.2 Openclaw — OpenClaw before 2026.5.2 contains a path traversal vulnerability in maintenance task execution that allows wor… 2026-06-16 CVE-2026-53866 HIGH 7.6 Openclaw — OpenClaw before 2026.5.12 contains an allowlist bypass vulnerability in shell inline-command parsing that allo… 2026-06-16 CVE-2026-53820 MEDIUM 6.9 Openclaw — OpenClaw before 2026.5.12 contains an exec denylist bypass vulnerability in the bundle MCP loopback session-sp… 2026-06-12 CVE-2026-53821 HIGH 8.7 Openclaw — OpenClaw before 2026.5.18 accepts WebSocket client-declared operator scopes before binding to server-approved … 2026-06-12 CVE-2026-53822 HIGH 8.7 Openclaw — OpenClaw before 2026.5.18 contains a command injection vulnerability where shell wrapper argv could change bet… 2026-06-12 CVE-2026-53823 HIGH 8.6 Openclaw — OpenClaw before 2026.5.3 contains a privilege escalation vulnerability in the allowFrom feature that binds to … 2026-06-12 CVE-2026-53824 MEDIUM 6 Openclaw — OpenClaw before 2026.4.24 contains a token revocation vulnerability allowing callers with revoked slash tokens… 2026-06-12 CVE-2026-53825 HIGH 7.1 Openclaw — OpenClaw before 2026.4.7 contains an arbitrary file read vulnerability in the memory-wiki ingest feature that … 2026-06-12 CVE-2026-53826 LOW 2.3 Openclaw — OpenClaw before 2026.4.26 contains an information disclosure vulnerability in sandboxed session spawning that … 2026-06-12 CVE-2026-53827 MEDIUM 6 Openclaw — OpenClaw before 2026.5.2 contains a credential exposure vulnerability in message.action forwarding that allows… 2026-06-12 CVE-2026-53828 HIGH 7.7 Openclaw — OpenClaw before 2026.5.6 contains an authorization bypass vulnerability in native command handling that allows… 2026-06-12 CVE-2026-53829 HIGH 8.5 Openclaw — OpenClaw before 2026.5.18 contains an approval display truncation vulnerability allowing authenticated users t… 2026-06-12 CVE-2026-53830 MEDIUM 6 Openclaw — OpenClaw before 2026.4.22 contains a webhook secret revocation bypass vulnerability allowing callers with old … 2026-06-12 CVE-2026-53831 HIGH 7.6 Openclaw — OpenClaw before 2026.5.18 contains a policy enforcement vulnerability in system.run safe-bin allowlist validat… 2026-06-12 CVE-2026-53832 HIGH 7.4 Openclaw — OpenClaw before 2026.5.18 contains an identity header validation vulnerability allowing local same-host caller… 2026-06-12 CVE-2026-53833 HIGH 7.4 Openclaw — OpenClaw before 2026.4.29 contains an authorization bypass vulnerability in the QQBot streaming command that a… 2026-06-12 CVE-2026-53834 HIGH 8.2 Openclaw — OpenClaw before 2026.4.27 contains an authorization bypass vulnerability in QQBot pre-dispatch slash commands … 2026-06-12 CVE-2026-53835 LOW 2.3 Openclaw — OpenClaw before 2026.5.6 contains a configuration enforcement bypass vulnerability in Feishu dynamic-agent bin… 2026-06-12 CVE-2026-53836 HIGH 8.7 Openclaw — OpenClaw before 2026.5.12 contains an allowlist bypass vulnerability in PowerShell encoded-command handling th… 2026-06-12 CVE-2026-53837 MEDIUM 6.3 Openclaw — OpenClaw before 2026.5.6 contains an improper access control vulnerability in Mattermost event handlers that f… 2026-06-12 CVE-2026-53838 MEDIUM 6 Openclaw — OpenClaw before 2026.5.27 contains a state mutation vulnerability in node pairing reconnection that allows pai… 2026-06-12 CVE-2026-53839 MEDIUM 6 Openclaw — OpenClaw before 2026.5.7 contains a hostname validation vulnerability in retry endpoint checks that allows mat… 2026-06-12 CVE-2026-53806 HIGH 7.7 Openclaw — OpenClaw before 2026.5.12 contains a shell option parsing vulnerability that allows combined POSIX shell flags… 2026-06-11 CVE-2026-53807 HIGH 7.7 Openclaw — OpenClaw before 2026.5.6 contains an authorization bypass vulnerability in Telegram interactive callbacks that… 2026-06-11 CVE-2026-53808 MEDIUM 6 Openclaw — OpenClaw before 2026.5.6 contains an approval policy bypass vulnerability in the Skill Workshop apply flow tha… 2026-06-11 CVE-2026-53809 MEDIUM 4.8 Openclaw — OpenClaw before 2026.4.25 contains a policy bypass vulnerability in embedded runner policy that allows request… 2026-06-11 CVE-2026-53810 HIGH 7.7 Openclaw — OpenClaw before 2026.5.18 contains a code execution vulnerability where marketplace runtime extension metadata… 2026-06-11 CVE-2026-53811 HIGH 7.7 Openclaw — OpenClaw before 2026.5.7 contains a privilege escalation vulnerability in the Matrix allowFrom feature that al… 2026-06-11 CVE-2026-53812 MEDIUM 4.9 Openclaw — OpenClaw before 2026.5.18 contains a server-side request forgery vulnerability in browser control that allows … 2026-06-11 CVE-2026-53813 HIGH 7.3 Openclaw — OpenClaw before 2026.4.25 contains a path traversal vulnerability in memory-core artifact loading where worksp… 2026-06-11 CVE-2026-53814 HIGH 8.7 Openclaw — OpenClaw before 2026.5.20 contains a privilege escalation vulnerability where hook-triggered agent runs incorr… 2026-06-11 CVE-2026-53815 HIGH 7.1 Openclaw — OpenClaw before 2026.5.19 contains an authorization bypass vulnerability in message read actions that skips ch… 2026-06-11 CVE-2026-53816 HIGH 8.6 Openclaw — OpenClaw before 2026.5.18 contains an insufficient provenance validation vulnerability in node event handling … 2026-06-11 CVE-2026-53817 HIGH 8.7 Openclaw — OpenClaw before 2026.5.22 contains a locality validation vulnerability in Control UI pairing that allows attac… 2026-06-11 CVE-2026-53818 MEDIUM 6.9 Openclaw — OpenClaw before 2026.4.24 contains an authorization bypass vulnerability in the MCP loopback feature that allo… 2026-06-11 CVE-2026-53819 HIGH 8.7 Openclaw — OpenClaw before 2026.5.27 contains an arbitrary code execution vulnerability in skill install flows where work… 2026-06-11