openclaw
npm455 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting openclawpage 6 of 10
- CVE-2026-41348MEDIUMCVSS 5.4EG 5.4✓ Fixed in 2026.3.312026-04-23
OpenClaw before 2026.3.31 contains an authorization bypass vulnerability in Discord slash command and autocomplete paths that fail to enforce group DM channel allowlist restrictions. Authorized Discord users can bypass channel restrictions…
- CVE-2026-41349HIGHCVSS 8.8EG 8.8✓ Fixed in 2026.3.282026-04-23
OpenClaw before 2026.3.28 contains an agentic consent bypass vulnerability allowing LLM agents to silently disable execution approval via config.patch parameter. Remote attackers can exploit this to bypass security controls and execute una…
- CVE-2026-41350MEDIUMCVSS 4.3EG 4.3✓ Fixed in 2026.3.312026-04-23
OpenClaw before 2026.3.31 contains a session visibility bypass vulnerability where the session_status function fails to enforce configured tools.sessions.visibility restrictions for unsandboxed invocations. Attackers can invoke session_sta…
- CVE-2026-41351MEDIUMCVSS 5.3EG 5.3✓ Fixed in 2026.3.312026-04-23
OpenClaw before 2026.3.31 contains a replay detection bypass vulnerability in webhook signature handling that treats Base64 and Base64URL encoded signatures as distinct requests. Attackers can re-encode Telnyx webhook signatures to bypass …
- CVE-2026-41352HIGHCVSS 8.8EG 8.8✓ Fixed in 2026.3.312026-04-23
OpenClaw before 2026.3.31 contains a remote code execution vulnerability where a device-paired node can bypass the node scope gate authentication mechanism. Attackers with device pairing credentials can execute arbitrary node commands on t…
- CVE-2026-41353HIGHCVSS 8.1EG 8.1✓ Fixed in 2026.3.222026-04-23
OpenClaw before 2026.3.22 contains an access control bypass vulnerability in the allowProfiles feature that allows attackers to circumvent profile restrictions through persistent profile mutation and runtime profile selection. Remote attac…
- CVE-2026-41354LOWCVSS 3.7EG 3.7✓ Fixed in 2026.4.22026-04-23
OpenClaw before 2026.4.2 contains an insufficient scope vulnerability in Zalo webhook replay dedupe keys that allows legitimate events from different conversations or senders to collide. Attackers can exploit weak deduplication scoping to …
- CVE-2026-41355HIGHCVSS 7.3EG 7.3✓ Fixed in 2026.3.282026-04-23
OpenClaw before 2026.3.28 contains an arbitrary code execution vulnerability in mirror mode that converts untrusted sandbox files into workspace hooks. Attackers with mirror mode access can execute arbitrary code on the host during gateway…
- CVE-2026-41356MEDIUMCVSS 5.4EG 5.4✓ Fixed in 2026.3.312026-04-23
OpenClaw before 2026.3.31 fails to terminate active WebSocket sessions when rotating device tokens. Attackers with previously compromised credentials can maintain unauthorized access through existing WebSocket connections after token rotat…
- CVE-2026-41357LOWCVSS 3.3EG 3.3✓ Fixed in 2026.3.312026-04-23
OpenClaw before 2026.3.31 contains an environment variable leakage vulnerability in SSH-based sandbox backends that pass unsanitized process.env to child processes. Attackers can exploit this by leveraging non-default SSH environment forwa…
- CVE-2026-41358MEDIUMCVSS 5.4EG 5.4✓ Fixed in 2026.4.22026-04-23
OpenClaw before 2026.4.2 fails to filter Slack thread context by sender allowlist, allowing non-allowlisted messages to enter agent context. Attackers can inject unauthorized thread messages through allowlisted user replies to bypass sende…
- CVE-2026-41359HIGHCVSS 7.1EG 7.1✓ Fixed in 2026.3.282026-04-23
OpenClaw before 2026.3.28 contains a privilege escalation vulnerability allowing authenticated operators with write permissions to access admin-class Telegram configuration and cron persistence settings via the send endpoint. Attackers wit…
- CVE-2026-41360MEDIUMCVSS 6.7EG 6.7✓ Fixed in 2026.4.22026-04-23
OpenClaw before 2026.4.2 contains an approval integrity vulnerability in pnpm dlx that fails to bind local script operands consistently with pnpm exec flows. Attackers can replace approved local scripts before execution without invalidatin…
- CVE-2026-41361HIGHCVSS 7.1EG 7.1✓ Fixed in 2026.3.282026-04-23
OpenClaw before 2026.3.28 contains an SSRF guard bypass vulnerability that fails to block four IPv6 special-use ranges. Attackers can exploit this by crafting URLs targeting internal or non-routable IPv6 addresses to bypass SSRF protection…
- CVE-2026-41362MEDIUMCVSS 4.3EG 4.3✓ Fixed in 2026.3.312026-04-28
OpenClaw versions 2026.2.19 before 2026.3.31 contain an improper cache isolation vulnerability in the Zalo webhook replay-dedupe mechanism that is shared across authenticated webhook targets. Attackers controlling one authenticated Zalo we…
- CVE-2026-41363MEDIUMCVSS 5.3EG 5.3✓ Fixed in 2026.3.282026-04-28
OpenClaw versions 2026.2.6 through 2026.3.24 contain a path traversal vulnerability in the Feishu extension resolveUploadInput function that bypasses file-system sandbox restrictions. Attackers can exploit improper path resolution during u…
- CVE-2026-41364HIGHCVSS 8.1EG 8.1✓ Fixed in 2026.3.312026-04-28
OpenClaw before 2026.3.31 contains a symlink following vulnerability in SSH sandbox tar upload that allows remote attackers to write arbitrary files. Attackers can exploit this by uploading tar archives containing symlinks to escape the sa…
- CVE-2026-41365MEDIUMCVSS 5.4EG 5.4✓ Fixed in 2026.3.312026-04-28
OpenClaw before 2026.3.31 contains a sender allowlist bypass vulnerability in MS Teams thread history fetched via Graph API. Attackers can retrieve thread messages that should be filtered by sender allowlists, bypassing message filtering r…
- CVE-2026-41366MEDIUMCVSS 5.5EG 5.5✓ Fixed in 2026.3.312026-04-28
OpenClaw before 2026.3.31 contains a local roots self-whitelisting vulnerability in appendLocalMediaParentRoots that allows model-initiated arbitrary host file read. Attackers can exploit improper media parent directory validation to exfil…
- CVE-2026-41367MEDIUMCVSS 5.0EG 5.0✓ Fixed in 2026.3.282026-04-28
OpenClaw versions 2026.2.14 through 2026.3.24 fail to consistently apply guild and channel policy gates to Discord button and component interactions. Attackers can trigger privileged component actions from blocked contexts by bypassing cha…
- CVE-2026-41368MEDIUMCVSS 6.5EG 6.5✓ Fixed in 2026.3.282026-04-28
OpenClaw before 2026.3.28 contains an environment variable disclosure vulnerability in the jq safe-bin policy that fails to block the $ENV filter. Attackers can bypass safe-bin restrictions by using $ENV in jq programs to access sensitive …
- CVE-2026-41369MEDIUMCVSS 6.5EG 6.5✓ Fixed in 2026.3.312026-04-28
OpenClaw before 2026.3.31 contains insufficient environment variable sanitization in host exec operations, failing to filter package, registry, Docker, compiler, and TLS override variables. Attackers can exploit this by injecting malicious…
- CVE-2026-41370MEDIUMCVSS 6.5EG 6.5✓ Fixed in 2026.3.312026-04-28
OpenClaw before 2026.3.31 contains a path traversal vulnerability in ACP dispatch that allows attackers to read arbitrary files by manipulating inbound channel attachment paths. Remote attackers can bypass attachment-cache and root directo…
- CVE-2026-41371HIGHCVSS 8.5EG 8.5✓ Fixed in 2026.3.282026-04-28
OpenClaw before 2026.3.28 contains a privilege escalation vulnerability in chat.send that allows write-scoped gateway callers to trigger admin-only session reset operations. Attackers can rotate target sessions, archive prior transcript st…
- CVE-2026-41372MEDIUMCVSS 5.8EG 5.8✓ Fixed in 2026.4.22026-04-28
OpenClaw before 2026.4.2 fails to normalize trailing-dot localhost hosts in remote CDP discovery responses, allowing bypass of loopback protections. Attackers can craft hostile discovery responses returning localhost. to retarget authentic…
- CVE-2026-41373MEDIUMCVSS 6.1EG 6.1✓ Fixed in 2026.3.312026-04-28
OpenClaw before 2026.3.31 contains an incomplete host-env-security-policy.json that fails to restrict compiler binary environment variables, allowing untrusted models to substitute CC, CXX, CARGO_BUILD_RUSTC, and CMAKE_C_COMPILER via envir…
- CVE-2026-41374MEDIUMCVSS 5.3EG 5.3✓ Fixed in 2026.3.312026-04-28
OpenClaw before 2026.3.31 performs Discord audio preflight transcription before validating member authorization, allowing unauthenticated attackers to consume resources. Remote attackers can trigger audio preflight processing without membe…
- CVE-2026-41375MEDIUMCVSS 6.5EG 6.5✓ Fixed in 2026.3.282026-04-28
OpenClaw before 2026.3.28 contains an authorization bypass vulnerability in the /phone arm and /phone disarm endpoints that fails to properly enforce operator.admin scope checks for external channels. Attackers can bypass authentication re…
- CVE-2026-41376MEDIUMCVSS 5.4EG 5.4✓ Fixed in 2026.3.312026-04-28
OpenClaw before 2026.3.31 contains an allowlist bypass vulnerability in Matrix thread root and reply context handling that fails to properly validate message senders. Attackers can fetch thread-root and reply context messages that should b…
- CVE-2026-41377MEDIUMCVSS 4.6EG 4.6✓ Fixed in 2026.3.312026-04-28
OpenClaw before 2026.3.31 contains a fail-open vulnerability in the plugin installation flow where security scan failures do not block installation. Attackers can exploit scan failures to install untrusted plugins when operators proceed de…
- CVE-2026-41378HIGHCVSS 8.8EG 8.8✓ Fixed in 2026.3.312026-04-28
OpenClaw before 2026.3.31 contains a privilege escalation vulnerability allowing paired nodes with role=node to dispatch node.event agent requests with unrestricted gateway-side tool access. Attackers with trusted paired node credentials c…
- CVE-2026-41379HIGHCVSS 7.1EG 7.1✓ Fixed in 2026.3.282026-04-28
OpenClaw before 2026.3.28 contains a privilege escalation vulnerability allowing authenticated operators with write permissions to access admin-class Talk Voice configuration persistence. Attackers with operator.write privileges can exploi…
- CVE-2026-41380HIGHCVSS 7.3EG 7.3✓ Fixed in 2026.3.282026-04-28
OpenClaw before 2026.3.28 contains an execution approval vulnerability in exec-approvals-allowlist.ts that allows allow-always persistence to trust wrapper carrier executables instead of invoked targets. Attackers can exploit positional ca…
- CVE-2026-41381MEDIUMCVSS 5.4EG 5.4✓ Fixed in 2026.3.312026-04-28
OpenClaw before 2026.3.31 contains an access control bypass vulnerability in the Discord voice manager that allows attackers to bypass channel-level member access allowlist restrictions. Attackers can send Discord voice ingress requests be…
- CVE-2026-41382MEDIUMCVSS 5.4EG 5.4✓ Fixed in 2026.3.312026-04-28
OpenClaw before 2026.3.31 contains an authorization bypass vulnerability in Discord voice ingress that allows attackers to bypass channel and member allowlist restrictions. Attackers can exploit stale-role validation gaps and improper chan…
- CVE-2026-41383HIGHCVSS 8.1EG 8.1✓ Fixed in 2026.4.22026-04-28
OpenClaw before 2026.4.2 contains an arbitrary directory deletion vulnerability in mirror mode that allows attackers to delete remote directories by influencing remoteWorkspaceDir and remoteAgentWorkspaceDir configuration values. Attackers…
- CVE-2026-41384HIGHCVSS 7.8EG 7.8✓ Fixed in 2026.3.242026-04-28
OpenClaw before 2026.3.24 contains an environment variable injection vulnerability in the CLI backend runner that allows attackers to inject malicious environment variables through workspace configuration. Attackers can craft malicious wor…
- CVE-2026-41385MEDIUMCVSS 6.5EG 6.5✓ Fixed in 2026.3.312026-04-28
OpenClaw before 2026.3.31 stores Nostr privateKey as plaintext in configuration, allowing exposure through config.get method calls that bypass redaction mechanisms. Attackers can retrieve unredacted configuration data to obtain plaintext s…
- CVE-2026-41386CRITICALCVSS 9.1EG 9.1✓ Fixed in 2026.3.222026-04-28
OpenClaw before 2026.3.22 contains a privilege escalation vulnerability where bootstrap setup codes are not bound to intended device roles and scopes during pairing. Attackers can exploit this during first-use device pairing to escalate pr…
- CVE-2026-41387HIGHCVSS 7.8EG 7.8✓ Fixed in 2026.3.222026-04-28
OpenClaw before 2026.3.22 contains an incomplete host environment variable sanitization vulnerability in host-env-security-policy.json and host-env-security.ts that allows package-manager environment overrides. Attackers can exploit approv…
- CVE-2026-41388MEDIUMCVSS 6.5EG 6.5✓ Fixed in 2026.3.312026-04-28
OpenClaw before 2026.3.31 contains a configuration management vulnerability where startup migration treats empty-array settings as missing values. Attackers can restart the application to rehydrate revoked Tlon configuration from file stat…
- CVE-2026-41389MEDIUMCVSS 5.8EG 5.8✓ Fixed in 2026.4.152026-04-20
OpenClaw versions 2026.4.7 before 2026.4.15 fail to enforce local-root containment on tool-result media paths, allowing arbitrary local and UNC file access. Attackers can craft malicious tool-result media references to trigger host-side fi…
- CVE-2026-41390HIGHCVSS 7.3EG 7.3✓ Fixed in 2026.3.282026-04-28
OpenClaw before 2026.3.28 contains an exec allowlist bypass vulnerability where allow-always persistence fails to unwrap /usr/bin/script and similar wrappers before storing trust decisions. Attackers can obtain user approval for one wrappe…
- CVE-2026-41391MEDIUMCVSS 5.3EG 5.3✓ Fixed in 2026.3.312026-04-28
OpenClaw before 2026.3.31 fails to properly sanitize PIP_INDEX_URL and UV_INDEX_URL environment variables in host execution contexts, allowing attackers to redirect Python package-index traffic. Attackers can exploit this bypass to interce…
- CVE-2026-41392MEDIUMCVSS 6.7EG 6.7✓ Fixed in 2026.3.312026-04-28
OpenClaw before 2026.3.31 contains an exec allowlist bypass vulnerability allowing attackers to inherit allowlist trust via shell init-file wrapper invocations. Attackers can exploit shell options like --rcfile, --init-file, and --startup-…
- CVE-2026-41393MEDIUMCVSS 4.8EG 4.8✓ Fixed in 2026.3.312026-04-28
OpenClaw before 2026.3.31 contains a wide-area discovery vulnerability allowing arbitrary tailnet peers to be accepted as DNS authorities. Attackers with same-tailnet position and CA-trusted endpoint access can exfiltrate operator credenti…
- CVE-2026-41394HIGHCVSS 8.2EG 8.2✓ Fixed in 2026.3.312026-04-28
OpenClaw before 2026.3.31 contains an authentication bypass vulnerability where unauthenticated plugin-auth HTTP routes receive operator runtime write scopes. Attackers can access these routes without authentication to perform privileged r…
- CVE-2026-41395HIGHCVSS 7.5EG 7.5✓ Fixed in 2026.3.282026-04-28
OpenClaw before 2026.3.28 contains a webhook replay vulnerability in Plivo V3 signature verification that canonicalizes query ordering for signatures but hashes raw URLs for replay detection. Attackers can reorder query parameters to bypas…
- CVE-2026-41396HIGHCVSS 7.8EG 7.8✓ Fixed in 2026.3.312026-04-28
OpenClaw before 2026.3.31 allows workspace .env files to override the OPENCLAW_BUNDLED_PLUGINS_DIR environment variable, compromising plugin trust verification. Attackers with control over workspace configuration can inject malicious plugi…
- CVE-2026-41397MEDIUMCVSS 6.8EG 6.8✓ Fixed in 2026.3.312026-04-28
OpenClaw before 2026.3.31 contains a sandbox escape vulnerability allowing attackers to traverse directory boundaries through symlink exploitation during file synchronization operations. Remote attackers can bypass sandbox restrictions by …
Check whether openclaw is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for openclaw CVEs against the assets you own.
Start Free Scan →