openclaw
npm455 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting openclawpage 8 of 10
- CVE-2026-43568MEDIUMCVSS 6.5EG 6.5✓ Fixed in 2026.4.102026-05-05
OpenClaw versions 2026.4.5 before 2026.4.10 contain a privilege escalation vulnerability allowing write-scoped operators to modify persistent memory dreaming settings. Attackers with write-scoped gateway access can toggle admin-class confi…
- CVE-2026-43569HIGHCVSS 8.8EG 8.8✓ Fixed in 2026.4.92026-05-05
OpenClaw before 2026.4.9 contains an authentication bypass vulnerability allowing untrusted workspace plugins to be auto-enabled during non-interactive onboarding when provider auth choices are shadowed. Attackers can exploit this by craft…
- CVE-2026-43570MEDIUMCVSS 6.5EG 6.5✓ Fixed in 2026.4.52026-05-05
OpenClaw versions 2026.3.22 before 2026.4.5 contain a symlink traversal vulnerability in remote marketplace repository path handling that allows attackers to escape the expected repository root. Attackers can exploit this by providing craf…
- CVE-2026-43571HIGHCVSS 8.8EG 8.8✓ Fixed in 2026.4.102026-05-05
OpenClaw before 2026.4.10 contains a plugin trust bypass vulnerability that allows channel setup catalog lookups to resolve workspace plugin shadows before bundled channel plugins. Attackers can exploit this by crafting malicious workspace…
- CVE-2026-43572MEDIUMCVSS 5.3EG 5.3✓ Fixed in 2026.4.142026-05-05
OpenClaw versions 2026.4.10 before 2026.4.14 contain a missing authorization vulnerability in the Microsoft Teams SSO invoke handler that fails to apply sender allowlist checks. Attackers can bypass sender authorization by sending SSO invo…
- CVE-2026-43573HIGHCVSS 7.7EG 7.7✓ Fixed in 2026.4.102026-05-05
OpenClaw before 2026.4.10 contains a server-side request forgery policy bypass vulnerability in existing-session browser interaction routes. Attackers can bypass SSRF navigation guards to interact with or navigate to unauthorized targets w…
- CVE-2026-43574MEDIUMCVSS 6.5EG 6.5✓ Fixed in 2026.4.122026-05-05
OpenClaw before 2026.4.12 contains an improper authorization vulnerability in helper-backed channels where empty resolved approver lists are interpreted as explicit approval authorization. Attackers can resolve pending approvals without pr…
- CVE-2026-43575CRITICALCVSS 9.8EG 9.8✓ Fixed in 2026.4.102026-05-06
OpenClaw versions 2026.2.21 before 2026.4.10 contain an authentication bypass vulnerability in the sandbox noVNC helper route that exposes interactive browser session credentials. Attackers can access the noVNC helper route without bridge …
- CVE-2026-43576HIGHCVSS 7.7EG 7.7✓ Fixed in 2026.4.52026-05-06
OpenClaw before 2026.4.5 contains a server-side request forgery vulnerability in the CDP /json/version WebSocket endpoint that allows attackers to pivot to untrusted second-hop targets. The webSocketDebuggerUrl response field is not proper…
- CVE-2026-43577MEDIUMCVSS 6.5EG 6.5✓ Fixed in 2026.4.92026-05-06
OpenClaw before 2026.4.9 contains a file read vulnerability allowing attackers to bypass navigation guards through browser act/evaluate interactions. Attackers can pivot into the local CDP origin and create or read disallowed file:// pages…
- CVE-2026-43578CRITICALCVSS 9.1EG 9.1✓ Fixed in 2026.4.102026-05-06
OpenClaw versions 2026.3.31 before 2026.4.10 contain a privilege escalation vulnerability where heartbeat owner downgrade detection misses local background async exec completion events. Attackers can exploit this by providing untrusted com…
- CVE-2026-43579MEDIUMCVSS 6.5EG 6.5✓ Fixed in 2026.4.102026-05-06
OpenClaw before 2026.4.10 contains an insufficient access control vulnerability in Nostr plugin HTTP profile routes that allows operators with write permissions to persist profile configuration without requiring admin authority. Attackers …
- CVE-2026-43580HIGHCVSS 7.7EG 7.7✓ Fixed in 2026.4.102026-05-06
OpenClaw before 2026.4.10 contains an incomplete navigation guard vulnerability that allows attackers to trigger navigation without complete SSRF policy enforcement. Browser press/type style interactions, including pressKey and type submit…
- CVE-2026-43581CRITICALCVSS 9.6EG 9.6✓ Fixed in 2026.4.102026-05-06
OpenClaw before 2026.4.10 contains an improper network binding vulnerability in the sandbox browser CDP relay that exposes Chrome DevTools Protocol on 0.0.0.0. Attackers can access the DevTools protocol outside intended local sandbox bound…
- CVE-2026-43582MEDIUMCVSS 6.3EG 6.3✓ Fixed in 2026.4.102026-05-06
OpenClaw before 2026.4.10 contains a server-side request forgery vulnerability in browser navigation policy that allows attackers to bypass hostname validation through DNS rebinding attacks. Attackers can exploit inconsistent hostname reso…
- CVE-2026-43583MEDIUMCVSS 5.3EG 5.3✓ Fixed in 2026.4.142026-05-06
OpenClaw versions 2026.4.10 before 2026.4.14 fail to persist session context during delivery queue recovery for media replay. Attackers can exploit recovered queued outbound media to bypass group tool policy enforcement and weaken channel …
- CVE-2026-43584HIGHCVSS 8.8EG 8.8✓ Fixed in 2026.4.102026-05-06
OpenClaw before 2026.4.10 contains an insufficient environment variable denylist vulnerability in its exec environment policy that allows operator-supplied overrides of high-risk interpreter startup variables including VIMINIT, EXINIT, LUA…
- CVE-2026-43585HIGHCVSS 8.1EG 8.1✓ Fixed in 2026.4.152026-05-06
OpenClaw before 2026.4.15 captures resolved bearer-auth configuration at startup, allowing revoked tokens to remain valid after SecretRef rotation. Gateway HTTP and WebSocket handlers fail to re-resolve authentication per-request, enabling…
- CVE-2026-44109CRITICALCVSS 9.8EG 9.8✓ Fixed in 2026.4.152026-05-06
OpenClaw before 2026.4.15 contains an authentication bypass vulnerability in Feishu webhook and card-action validation that allows unauthenticated requests to reach command dispatch. Missing encryptKey configuration and blank callback toke…
- CVE-2026-44111MEDIUMCVSS 4.3EG 4.3✓ Fixed in 2026.4.152026-05-06
OpenClaw before 2026.4.15 contains an arbitrary file read vulnerability in the QMD backend memory_get function that allows callers to read any Markdown files within the workspace root. Attackers with access to the memory tool can bypass pa…
- CVE-2026-44112CRITICALCVSS 9.6EG 9.6✓ Fixed in 2026.4.222026-05-06
OpenClaw before 2026.4.22 contains a time-of-check/time-of-use race condition in OpenShell sandbox filesystem writes that allows attackers to redirect writes outside the intended mount root. Attackers can exploit symlink swaps during files…
- CVE-2026-44113HIGHCVSS 7.7EG 7.7✓ Fixed in 2026.4.222026-05-06
OpenClaw before 2026.4.22 contains a time-of-check/time-of-use race condition in the OpenShell filesystem bridge that allows attackers to read files outside the intended mount root. Attackers can exploit symlink swaps during filesystem ope…
- CVE-2026-44114HIGHCVSS 7.8EG 7.8✓ Fixed in 2026.4.202026-05-06
OpenClaw before 2026.4.20 fails to properly reserve the OPENCLAW_ runtime-control environment namespace in workspace dotenv files, allowing attackers to override critical runtime variables. Malicious workspaces can set variables like OPENC…
- CVE-2026-44115HIGHCVSS 8.8EG 8.8✓ Fixed in 2026.4.222026-05-06
OpenClaw before 2026.4.22 contains an exec allowlist analysis vulnerability allowing shell expansion hiding in unquoted heredoc bodies. Attackers can bypass allowlist validation by embedding shell expansion tokens in heredoc bodies to exec…
- CVE-2026-44116HIGHCVSS 8.6EG 8.6✓ Fixed in 2026.4.222026-05-06
OpenClaw before 2026.4.22 contains a server-side request forgery vulnerability in the Zalo plugin's sendPhoto function that fails to validate outbound photo URLs through the SSRF guard. Attackers can bypass SSRF protection by providing mal…
- CVE-2026-44117MEDIUMCVSS 5.8EG 5.8✓ Fixed in 2026.4.202026-05-06
OpenClaw before 2026.4.20 contains a server-side request forgery vulnerability in QQBot direct media upload that skips URL validation. Attackers can bypass SSRF protections by sending crafted image URLs to uploadC2CMedia and uploadGroupMed…
- CVE-2026-44118HIGHCVSS 7.8EG 7.8✓ Fixed in 2026.4.222026-05-06
OpenClaw before 2026.4.22 derives loopback MCP owner context from spoofable server-issued bearer tokens in request headers. Non-owner loopback clients can present themselves as owner to bypass owner-gated operations by manipulating the sen…
- CVE-2026-44991MEDIUMCVSS 4.2EG 4.2✓ Fixed in 2026.4.212026-05-11
OpenClaw before 2026.4.21 contains an authorization bypass vulnerability in command-auth.ts that allows non-owner senders to execute owner-enforced slash commands when wildcard inbound senders are configured without explicit owner allowFro…
- CVE-2026-44992MEDIUMCVSS 5.0EG 5.0✓ Fixed in 2026.4.202026-05-11
OpenClaw versions 2026.4.5 before 2026.4.20 contain an environment variable injection vulnerability allowing workspace dotenv to override MINIMAX_API_HOST. Attackers can redirect credentialed MiniMax API requests to attacker-controlled ori…
- CVE-2026-44993MEDIUMCVSS 5.4EG 5.4✓ Fixed in 2026.4.202026-05-11
OpenClaw before 2026.4.20 contains a message classification vulnerability in Feishu card-action callbacks that misclassifies direct messages as group conversations. Attackers can bypass dmPolicy enforcement by triggering card-action flows …
- CVE-2026-44994MEDIUMCVSS 5.3EG 5.3✓ Fixed in 2026.4.222026-05-11
OpenClaw before 2026.4.22 contains an authentication bypass vulnerability in the Control UI bootstrap config endpoint that allows unauthenticated attackers to read sensitive configuration fields. Attackers can access the bootstrap config r…
- CVE-2026-44995HIGHCVSS 7.3EG 7.3✓ Fixed in 2026.4.202026-05-11
OpenClaw before 2026.4.20 contains an improper environment variable validation vulnerability in MCP stdio server configuration that allows attackers to execute arbitrary code. Malicious workspace configurations can pass dangerous startup v…
- CVE-2026-44996LOWCVSS 3.7EG 3.7✓ Fixed in 2026.4.152026-05-11
OpenClaw before 2026.4.15 contains an arbitrary local file read vulnerability in the webchat audio embedding helper that fails to apply local media root containment checks. Attackers can influence agent or tool-produced ReplyPayload.mediaU…
- CVE-2026-44997MEDIUMCVSS 4.3EG 4.3✓ Fixed in 2026.4.222026-05-11
OpenClaw before 2026.4.22 contains a security envelope constraint bypass vulnerability allowing restricted subagents to spawn ACP child sessions that fail to inherit depth, child-count limits, control scope, or target-agent restrictions. A…
- CVE-2026-44998MEDIUMCVSS 5.4EG 5.4✓ Fixed in 2026.4.202026-05-11
OpenClaw before 2026.4.20 contains a tool policy bypass vulnerability allowing bundled MCP and LSP tools to circumvent configured tool restrictions. Attackers with local agent access can append restricted tools to the effective tool set af…
- CVE-2026-44999MEDIUMCVSS 5.3EG 5.3✓ Fixed in 2026.4.202026-05-11
OpenClaw before 2026.4.20 fails to properly preserve untrusted labels for isolated cron awareness events, allowing webhook-triggered cron agent output to be recorded as trusted system events. Attackers can exploit this trust-labeling issue…
- CVE-2026-45000MEDIUMCVSS 5.0EG 5.0✓ Fixed in 2026.4.202026-05-11
OpenClaw before 2026.4.20 contains a server-side request forgery vulnerability in browser CDP profile creation that skips strict-mode SSRF policy checks. Attackers can create stored profiles pointing to private-network or metadata endpoint…
- CVE-2026-45001HIGHCVSS 7.1EG 7.1✓ Fixed in 2026.4.202026-05-11
OpenClaw before 2026.4.20 contains a guard bypass vulnerability in the agent-facing gateway config.patch and config.apply endpoints that fails to protect operator-trusted settings including sandbox policy, plugin enablement, gateway auth/T…
- CVE-2026-45002MEDIUMCVSS 5.3EG 5.3✓ Fixed in 2026.4.202026-05-11
OpenClaw before 2026.4.20 contains a hook session-key bypass vulnerability that allows attackers to circumvent the hooks.allowRequestSessionKey opt-in restriction. Attackers can render externally influenced session keys through templated h…
- CVE-2026-45003MEDIUMCVSS 5.0EG 5.0✓ Fixed in 2026.4.222026-05-11
OpenClaw before 2026.4.22 allows workspace dotenv files to override connector endpoint hosts for Matrix, Mattermost, IRC, and Synology connectors. Attackers with workspace access can redirect runtime traffic to malicious endpoints by setti…
- CVE-2026-45004HIGHCVSS 7.8EG 7.8✓ Fixed in 2026.4.232026-05-11
OpenClaw before 2026.4.23 contains an arbitrary code execution vulnerability in the bundled plugin setup resolver that loads setup-api.js from process.cwd() during provider setup metadata resolution. Attackers can execute arbitrary JavaScr…
- CVE-2026-45005MEDIUMCVSS 6.0EG 6.0✓ Fixed in 2026.4.232026-05-11
OpenClaw before 2026.4.23 caches resolved webhook route secrets backed by SecretRef values, allowing stale secrets to remain valid after rotation and reload. Attackers with previously valid webhook route secrets can continue authenticating…
- CVE-2026-45006HIGHCVSS 8.8EG 8.8✓ Fixed in 2026.4.232026-05-11
OpenClaw before 2026.4.23 contains an improper access control vulnerability in the gateway tool's config.apply and config.patch operations that allows compromised models to write unsafe configuration changes by bypassing an incomplete deny…
- CVE-2026-53806HIGHCVSS 8.8EG 8.8✓ Fixed in 2026.5.122026-06-11
OpenClaw before 2026.5.12 contains a shell option parsing vulnerability that allows combined POSIX shell flags to bypass exec revalidation checks. Attackers can exploit this by using combined shell options to execute inline shell content w…
- CVE-2026-53807HIGHCVSS 8.8EG 8.8✓ Fixed in 2026.5.62026-06-11
OpenClaw before 2026.5.6 contains an authorization bypass vulnerability in Telegram interactive callbacks that allows authenticated users to skip commands.allowFrom validation. Attackers can invoke affected callbacks to mark themselves as …
- CVE-2026-53808MEDIUMCVSS 6.5EG 6.5✓ Fixed in 2026.5.62026-06-11
OpenClaw before 2026.5.6 contains an approval policy bypass vulnerability in the Skill Workshop apply flow that allows agent tool calls to set apply: true despite approvalPolicy: pending configuration. Attackers can exploit this by reachin…
- CVE-2026-53809LOWCVSS 3.8EG 3.8✓ Fixed in 2026.4.252026-06-11
OpenClaw before 2026.4.25 contains a policy bypass vulnerability in embedded runner policy that allows requests using provider aliases to compare against aliases instead of canonical provider identities. Attackers can exploit this confusio…
- CVE-2026-53810HIGHCVSS 8.8EG 8.8✓ Fixed in 2026.5.182026-06-11
OpenClaw before 2026.5.18 contains a code execution vulnerability where marketplace runtime extension metadata can redirect loading toward unscanned package payloads. Attackers with trusted operator access can manipulate extension metadata…
- CVE-2026-53811HIGHCVSS 8.8EG 8.8✓ Fixed in 2026.5.72026-06-11
OpenClaw before 2026.5.7 contains a privilege escalation vulnerability in the Matrix allowFrom feature that allows authenticated accounts to match policy entries through mutable display name metadata. Attackers with the ability to change d…
- CVE-2026-53812HIGHCVSS 7.7EG 7.7✓ Fixed in 2026.5.182026-06-11
OpenClaw before 2026.5.18 contains a server-side request forgery vulnerability in browser control that allows authenticated users to bypass private-network navigation checks through Playwright act interactions. Attackers can trigger naviga…
Check whether openclaw is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for openclaw CVEs against the assets you own.
Start Free Scan →