openclaw
npm449 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting openclawpage 3 of 9
- CVE-2026-32062HIGHCVSS 7.5EG 7.5✓ Fixed in 2026.2.222026-03-11
OpenClaw versions 2026.2.21-2 up to, but not including, 2026.2.22, and @openclaw/voice-call versions 2026.2.21 up to, but not including, 2026.2.22 accept media-stream WebSocket upgrades before stream validation, allowing unauthenticated cl…
- CVE-2026-32064HIGHCVSS 7.7EG 7.7✓ Fixed in 2026.2.212026-03-21
OpenClaw versions prior to 2026.2.21 sandbox browser entrypoint launches x11vnc without authentication for noVNC observer sessions, allowing unauthenticated access to the VNC interface. Remote attackers on the host loopback interface can c…
- CVE-2026-32065MEDIUMCVSS 4.8EG 4.8✓ Fixed in 2026.2.252026-03-21
OpenClaw versions prior to 2026.2.25 contain an approval-integrity bypass vulnerability in system.run where rendered command text is used as approval identity while trimming argv token whitespace, but runtime execution uses raw argv. An at…
- CVE-2026-32067LOWCVSS 3.7EG 3.7✓ Fixed in 2026.2.262026-03-21
OpenClaw versions prior to 2026.2.26 contain an authorization bypass vulnerability in the pairing-store access control for direct message pairing policy that allows attackers to reuse pairing approvals across multiple accounts. An attacker…
- CVE-2026-32846HIGHCVSS 8.7EG 8.7✓ Fixed in 2026.03.282026-03-26
OpenClaw before 2026.3.28 contains a path traversal vulnerability in media parsing that allows attackers to read arbitrary files by bypassing path validation in the isLikelyLocalPath() and isValidMedia() functions. Attackers can exploit in…
- CVE-2026-32895MEDIUMCVSS 5.4EG 5.4✓ Fixed in 2026.2.262026-03-21
OpenClaw versions prior to 2026.2.26 fail to enforce sender authorization in member and message subtype system event handlers, allowing unauthorized events to be enqueued. Attackers can bypass Slack DM allowlists and per-channel user allow…
- CVE-2026-32896MEDIUMCVSS 4.8EG 4.8✓ Fixed in 2026.2.212026-03-21
The BlueBubbles webhook handler in OpenClaw versions prior to 2026.2.21 contains a passwordless fallback authentication path that allows unauthenticated webhook events in certain reverse-proxy or local routing configurations. Attackers can…
- CVE-2026-32897LOWCVSS 3.7EG 3.7✓ Fixed in 2026.2.222026-03-21
OpenClaw versions prior to 2026.2.22 reuse gateway.auth.token as a fallback hash secret for owner-ID prompt obfuscation when commands.ownerDisplay is set to hash and commands.ownerDisplaySecret is unset, creating dual-use of authentication…
- CVE-2026-32898MEDIUMCVSS 5.4EG 5.4✓ Fixed in 2026.2.232026-03-21
OpenClaw versions prior to 2026.2.23 contain an authorization bypass vulnerability in the ACP client that auto-approves tool calls based on untrusted toolCall.kind metadata and permissive name heuristics. Attackers can bypass interactive a…
- CVE-2026-32899MEDIUMCVSS 4.3EG 4.3✓ Fixed in 2026.2.252026-03-21
OpenClaw versions prior to 2026.2.25 fail to consistently apply sender-policy checks to reaction_* and pin_* non-message events before adding them to system-event context. Attackers can bypass configured DM policies and channel user allowl…
- CVE-2026-32905HIGHCVSS 8.3EG 8.3✓ Fixed in 2026.5.42026-05-29
OpenClaw before 2026.5.4 contains an authorization bypass vulnerability in the bundled device-pair plugin that allows non-owner authorized chat senders to issue device-pairing bootstrap codes without proper scope validation. Attackers with…
- CVE-2026-32906MEDIUMCVSS 4.3EG 4.3✓ Fixed in 2026.5.122026-05-29
OpenClaw before 2026.5.12 contains a privilege escalation vulnerability in Slack plugin approvals that allows exec-authorized users to resolve plugin approvals through the exec approver gate. Attackers with limited exec approval permission…
- CVE-2026-32913CRITICALCVSS 9.3EG 9.3✓ Fixed in 2026.3.72026-03-23
OpenClaw before 2026.3.7 contains an improper header validation vulnerability in fetchWithSsrFGuard that forwards custom authorization headers across cross-origin redirects. Attackers can trigger redirects to different origins to intercept…
- CVE-2026-32914HIGHCVSS 8.8EG 8.8✓ Fixed in 2026.3.122026-03-29
OpenClaw before 2026.3.12 contains an insufficient access control vulnerability in the /config and /debug command handlers that allows command-authorized non-owners to access owner-only surfaces. Attackers with command authorization can re…
- CVE-2026-32915HIGHCVSS 8.8EG 8.8✓ Fixed in 2026.3.112026-03-29
OpenClaw before 2026.3.11 contains a sandbox boundary bypass vulnerability allowing leaf subagents to access the subagents control surface and resolve against parent requester scope instead of their own session tree. A low-privilege sandbo…
- CVE-2026-32916CRITICALCVSS 9.4EG 9.4✓ Fixed in 2026.3.112026-03-31
OpenClaw versions 2026.3.7 before 2026.3.11 contain an authorization bypass vulnerability where plugin subagent routes execute gateway methods through a synthetic operator client with broad administrative scopes. Remote unauthenticated req…
- CVE-2026-32917CRITICALCVSS 9.8EG 9.8✓ Fixed in 2026.3.132026-03-31
OpenClaw before 2026.3.13 contains a remote command injection vulnerability in the iMessage attachment staging flow that allows attackers to execute arbitrary commands on configured remote hosts. The vulnerability exists because unsanitize…
- CVE-2026-32918HIGHCVSS 8.4EG 8.4✓ Fixed in 2026.3.112026-03-29
OpenClaw before 2026.3.11 contains a session sandbox escape vulnerability in the session_status tool that allows sandboxed subagents to access parent or sibling session state. Attackers can supply arbitrary sessionKey values to read or mod…
- CVE-2026-32919MEDIUMCVSS 6.1EG 6.1✓ Fixed in 2026.3.112026-03-29
OpenClaw before 2026.3.11 contains an authorization bypass vulnerability allowing write-scoped callers to reach admin-only session reset logic. Attackers with operator.write scope can issue agent requests containing /new or /reset slash co…
- CVE-2026-32920HIGHCVSS 8.4EG 8.4✓ Fixed in 2026.3.122026-03-31
OpenClaw before 2026.3.12 automatically discovers and loads plugins from .OpenClaw/extensions/ without explicit trust verification, allowing arbitrary code execution. Attackers can execute malicious code by including crafted workspace plug…
- CVE-2026-32921MEDIUMCVSS 6.3EG 6.3✓ Fixed in 2026.3.82026-03-31
OpenClaw before 2026.3.8 contains an approval bypass vulnerability in system.run where mutable script operands are not bound across approval and execution phases. Attackers can obtain approval for script execution, modify the approved scri…
- CVE-2026-32922CRITICALCVSS 9.9EG 9.9✓ Fixed in 2026.3.112026-03-29
OpenClaw before 2026.3.11 contains a privilege escalation vulnerability in device.token.rotate that allows callers with operator.pairing scope to mint tokens with broader scopes by failing to constrain newly minted scopes to the caller's c…
- CVE-2026-32923MEDIUMCVSS 5.4EG 5.4✓ Fixed in 2026.3.112026-03-29
OpenClaw before 2026.3.11 contains an authorization bypass vulnerability in Discord guild reaction ingestion that fails to enforce member users and roles allowlist checks. Non-allowlisted guild members can trigger reaction events accepted …
- CVE-2026-32924CRITICALCVSS 9.8EG 9.8✓ Fixed in 2026.3.122026-03-29
OpenClaw before 2026.3.12 contains an authorization bypass vulnerability where Feishu reaction events with omitted chat_type are misclassified as p2p conversations instead of group chats. Attackers can exploit this misclassification to byp…
- CVE-2026-32970LOWCVSS 2.5EG 2.5✓ Fixed in 2026.3.112026-03-31
OpenClaw before 2026.3.11 contains a credential fallback vulnerability where unavailable local gateway.auth.token and gateway.auth.password SecretRefs are treated as unset, allowing fallback to remote credentials in local mode. Attackers c…
- CVE-2026-32971HIGHCVSS 7.1EG 7.1✓ Fixed in 2026.3.112026-03-31
OpenClaw before 2026.3.11 contains an approval-integrity vulnerability in node-host system.run approvals that displays extracted shell payloads instead of the executed argv. Attackers can place wrapper binaries and induce wrapper-shaped co…
- CVE-2026-32972HIGHCVSS 7.1EG 7.1✓ Fixed in 2026.3.112026-03-29
OpenClaw before 2026.3.11 contains an authorization bypass vulnerability allowing authenticated operators with only operator.write permission to access admin-only browser profile management routes through browser.request. Attackers can cre…
- CVE-2026-32973CRITICALCVSS 9.8EG 9.8✓ Fixed in 2026.3.112026-03-29
OpenClaw before 2026.3.11 contains an exec allowlist bypass vulnerability where matchesExecAllowlistPattern improperly normalizes patterns with lowercasing and glob matching that overmatches on POSIX paths. Attackers can exploit the ? wild…
- CVE-2026-32974HIGHCVSS 8.6EG 8.6✓ Fixed in 2026.3.122026-03-29
OpenClaw before 2026.3.12 contains an authentication bypass vulnerability in Feishu webhook mode when only verificationToken is configured without encryptKey, allowing acceptance of forged events. Unauthenticated network attackers can inje…
- CVE-2026-32975CRITICALCVSS 9.8EG 9.8✓ Fixed in 2026.3.122026-03-29
OpenClaw before 2026.3.12 contains a weak authorization vulnerability in Zalouser allowlist mode that matches mutable group display names instead of stable group identifiers. Attackers can create groups with identical names to allowlisted …
- CVE-2026-32976MEDIUMCVSS 6.5EG 6.5✓ Fixed in 2026.3.112026-03-31
OpenClaw before 2026.3.11 contains an authorization bypass vulnerability allowing channel commands to mutate protected sibling-account configuration despite configWrites restrictions. Attackers with authorized access on one account can exe…
- CVE-2026-32977MEDIUMCVSS 6.3EG 6.3✓ Fixed in 2026.3.112026-03-31
OpenClaw before 2026.3.11 contains a sandbox boundary bypass vulnerability in the fs-bridge writeFile commit step that uses an unanchored container path during the final move operation. An attacker can exploit a time-of-check-time-of-use r…
- CVE-2026-32978HIGHCVSS 8.0EG 8.0✓ Fixed in 2026.3.112026-03-29
OpenClaw before 2026.3.11 contains an approval integrity vulnerability where system.run approvals fail to bind mutable file operands for certain script runners like tsx and jiti. Attackers can obtain approval for benign script commands, re…
- CVE-2026-32979HIGHCVSS 7.3EG 7.3✓ Fixed in 2026.3.112026-03-29
OpenClaw before 2026.3.11 contains an approval integrity vulnerability allowing attackers to execute rewritten local code by modifying scripts between approval and execution when exact file binding cannot occur. Remote attackers can change…
- CVE-2026-32980HIGHCVSS 7.5EG 7.5✓ Fixed in 2026.3.132026-03-29
OpenClaw before 2026.3.13 reads and buffers Telegram webhook request bodies before validating the x-telegram-bot-api-secret-token header, allowing unauthenticated attackers to exhaust server resources. Attackers can send POST requests to t…
- CVE-2026-32982HIGHCVSS 7.5EG 7.5✓ Fixed in 2026.3.132026-03-31
OpenClaw before 2026.3.13 contains an information disclosure vulnerability in the fetchRemoteMedia function that exposes Telegram bot tokens in error messages. When media downloads fail, the original Telegram file URLs containing bot token…
- CVE-2026-32987CRITICALCVSS 9.8EG 9.8✓ Fixed in 2026.3.132026-03-29
OpenClaw before 2026.3.13 allows bootstrap setup codes to be replayed during device pairing verification in src/infra/device-bootstrap.ts. Attackers can verify a valid bootstrap code multiple times before approval to escalate pending pairi…
- CVE-2026-32988HIGHCVSS 7.5EG 7.5✓ Fixed in 2026.3.112026-03-31
OpenClaw before 2026.3.11 contains a sandbox boundary bypass vulnerability in fs-bridge staged writes where temporary file creation and population are not pinned to a verified parent directory. Attackers can exploit a race condition in par…
- CVE-2026-33572HIGHCVSS 8.4EG 8.4✓ Fixed in 2026.2.172026-03-29
OpenClaw before 2026.2.17 creates session transcript JSONL files with overly broad default permissions, allowing local users to read transcript contents. Attackers with local access can read transcript files to extract sensitive informatio…
- CVE-2026-33573HIGHCVSS 8.8EG 8.8✓ Fixed in 2026.3.112026-03-29
OpenClaw before 2026.3.11 contains an authorization bypass vulnerability in the gateway agent RPC that allows authenticated operators with operator.write permission to override workspace boundaries by supplying attacker-controlled spawnedB…
- CVE-2026-33574MEDIUMCVSS 6.2EG 6.2✓ Fixed in 2026.3.82026-03-29
OpenClaw before 2026.3.8 contains a path traversal vulnerability in the skills download installer that validates the tools root lexically but reuses the mutable path during archive download and copy operations. A local attacker can rebind …
- CVE-2026-33575HIGHCVSS 7.5EG 7.5✓ Fixed in 2026.3.122026-03-29
OpenClaw before 2026.3.12 embeds long-lived shared gateway credentials directly in pairing setup codes generated by /pair endpoint and OpenClaw qr command. Attackers with access to leaked setup codes from chat history, logs, or screenshots…
- CVE-2026-33576MEDIUMCVSS 6.5EG 6.5✓ Fixed in 2026.3.282026-03-31
OpenClaw before 2026.3.28 downloads and stores inbound media from Zalo channels before validating sender authorization. Unauthorized senders can force network fetches and disk writes to the media store by sending messages that are subseque…
- CVE-2026-33577HIGHCVSS 8.1EG 8.1✓ Fixed in 2026.3.282026-03-31
OpenClaw before 2026.3.28 contains an insufficient scope validation vulnerability in the node pairing approval path that allows low-privilege operators to approve nodes with broader scopes. Attackers can exploit missing callerScopes valida…
- CVE-2026-33578MEDIUMCVSS 4.3EG 4.3✓ Fixed in 2026.3.282026-03-31
OpenClaw before 2026.3.28 contains a sender policy bypass vulnerability in the Google Chat and Zalouser extensions where route-level group allowlist policies silently downgrade to open policy. Attackers can exploit this policy resolution f…
- CVE-2026-33579CRITICALCVSS 9.9EG 9.9✓ Fixed in 2026.3.282026-03-31
OpenClaw before 2026.3.28 contains a privilege escalation vulnerability in the /pair approve command path that fails to forward caller scopes into the core approval check. A caller with pairing privileges but without admin privileges can a…
- CVE-2026-33580MEDIUMCVSS 6.5EG 6.5✓ Fixed in 2026.3.282026-03-31
OpenClaw before 2026.3.28 contains a missing rate limiting vulnerability in the Nextcloud Talk webhook authentication that allows attackers to brute-force weak shared secrets. Attackers who can reach the webhook endpoint can exploit this t…
- CVE-2026-33581MEDIUMCVSS 6.5EG 6.5✓ Fixed in 2026.3.242026-03-31
OpenClaw before 2026.3.24 contains a sandbox bypass vulnerability in the message tool that allows attackers to read arbitrary local files by using mediaUrl and fileUrl alias parameters that bypass localRoots validation. Remote attackers ca…
- CVE-2026-34425MEDIUMCVSS 5.4EG 5.4✓ Fixed in 2026.4.22026-04-02
OpenClaw versions prior to commit 8aceaf5 contain a preflight validation bypass vulnerability in shell-bleed protection that allows attackers to execute blocked script content by using piped or complex command forms that the parser fails t…
- CVE-2026-34426HIGHCVSS 7.6EG 7.6✓ Fixed in 2026.3.222026-04-02
OpenClaw versions prior to commit b57b680 contain an approval bypass vulnerability due to inconsistent environment variable normalization between approval and execution paths, allowing attackers to inject attacker-controlled environment v…
Check whether openclaw is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for openclaw CVEs against the assets you own.
Start Free Scan →