Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
54367
Total
4306
Critical
16164
High
15850
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-100587 | HIGH | 8.8 | OpenClaw versions before 2026.7.1 fail to properly validate owner authorization in the Codex computer-use installation command. Non-owner channel senders can install arbitrary plugins and execute … | Sep 26, 2026 |
| CVE-2026-100586 | HIGH | 8.8 | OpenClaw Codex before 2026.7.1 fails to properly enforce owner authorization when creating native conversation bindings. Non-owner channel senders with command access can create bindings to … | Sep 26, 2026 |
| CVE-2026-100585 | HIGH | 8.0 | OpenClaw (npm package `openclaw`) before 2026.7.1 fails to enforce the owner-only authorization requirement for Claude Code permission prompts delivered through the MCP channel bridge. An … | Sep 26, 2026 |
| CVE-2026-100584 | MEDIUM | 6.7 | OpenClaw is an npm-distributed agent runtime. In versions >= 2026.2.26 and < 2026.7.1, PowerShell command analysis on Windows hosts running in exec allowlist mode could … | Sep 26, 2026 |
| CVE-2026-100583 | MEDIUM | 4.3 | OpenClaw Discord versions before 2026.7.1 contain an authorization bypass vulnerability in guild metadata read actions that allows lower-trust senders to retrieve information excluded by channel … | Sep 26, 2026 |
| CVE-2026-100582 | MEDIUM | 6.5 | OpenClaw channel plugins (@openclaw/msteams, @openclaw/feishu, @openclaw/matrix, and @openclaw/googlechat) before 2026.8.1 do not enforce the configured channel read allowlist for caller-supplied explicit read targets in message, … | Sep 26, 2026 |
| CVE-2026-100581 | MEDIUM | 5.5 | OpenClaw for iOS before 2026.8.11 stores Gateway credentials as cleartext JSON in App Group UserDefaults instead of the device Keychain. Attackers with access to unencrypted … | Sep 26, 2026 |
| CVE-2026-100580 | HIGH | 8.8 | OpenClaw (npm package 'openclaw') before 2026.7.1 improperly handles case sensitivity in the model-facing cron tool: a mixed-case payload kind can pass the agent-facing shell-execution guard … | Sep 26, 2026 |
| CVE-2026-100579 | HIGH | 7.6 | OpenClaw (npm package 'openclaw') before 2026.7.1 incorrectly trusts requester provenance in message.action. In identity-bearing Gateway deployments (authentication modes that honor caller identity and narrower operator … | Sep 26, 2026 |
| CVE-2026-100578 | HIGH | 7.6 | OpenClaw (npm package `openclaw`) before 2026.7.1 fails to restrict owner-only infrastructure tools exposed through the chat.send endpoint. In Gateway deployments using authentication modes that honor … | Sep 26, 2026 |
| CVE-2026-100577 | MEDIUM | 6.3 | OpenClaw versions before 2026.8.1 fail to validate video asset URLs returned by providers, allowing server-side requests to private destinations. A malicious or compromised provider can … | Sep 26, 2026 |
| CVE-2026-100576 | MEDIUM | 5.4 | OpenClaw versions before 2026.8.1 contain a server-side request forgery vulnerability in browser wait predicates that allows attackers to bypass SSRF protections by reaching blocked destinations. … | Sep 26, 2026 |
| CVE-2026-100575 | HIGH | 8.8 | OpenClaw Slack versions before 2026.8.1 fail to properly enforce sender allowlists in multi-person direct messages. Disallowed participants can trigger Slack agents and access tools and … | Sep 26, 2026 |
| CVE-2026-100574 | MEDIUM | 5.9 | OpenClaw (npm package 'openclaw') before 2026.8.1 contains a server-side request forgery vulnerability in its trusted-host DNS checks. For fetches that use the trusted-host DNS recheck, … | Sep 26, 2026 |
| CVE-2026-100573 | LOW | 3.3 | OpenClaw versions before 2026.8.1 contain a sandbox policy bypass vulnerability in the MCP loopback component that allows sandboxed coding-agent sessions to invoke tools explicitly denied … | Sep 26, 2026 |
| CVE-2026-100572 | MEDIUM | 5.3 | OpenClaw versions >= 2026.3.25 and < 2026.8.1 apply invalid-token rate limiting for Synology Chat webhooks before authentication and key the limit on the raw proxy … | Sep 26, 2026 |
| CVE-2026-100571 | MEDIUM | 5.3 | OpenClaw (npm package 'openclaw') versions >= 2026.6.6 and < 2026.8.1 apply the SMS webhook invalid-request rate limit before Twilio signature verification and identify clients only … | Sep 26, 2026 |
| CVE-2026-100570 | HIGH | 7.8 | OpenClaw (npm package 'openclaw') versions >= 2026.3.28 and < 2026.8.1 allow an untrusted workspace .env file to set the CLOUDSDK_PYTHON_ARGS environment variable. When an operator … | Sep 26, 2026 |
| CVE-2026-100569 | MEDIUM | 5.5 | OpenClaw is an npm-distributed application. In versions >= 2026.4.25 and < 2026.8.1, the workspace environment-variable filter did not block variables ending in `_ENDPOINT`, so an … | Sep 26, 2026 |
| CVE-2026-100568 | HIGH | 8.3 | OpenClaw versions before 2026.8.1 fail to properly restrict access to operator command cron jobs, allowing model-visible agent callers to read and execute ownerless command jobs. … | Sep 26, 2026 |
| CVE-2026-100567 | HIGH | 8.2 | OpenClaw is an agent gateway distributed as the npm package 'openclaw'. In versions >= 2026.4.5 and < 2026.8.1, the Gateway validated a single DNS resolution … | Sep 26, 2026 |
| CVE-2026-100566 | MEDIUM | 6.5 | OpenClaw LINE versions before 2026.8.1 contain an access control vulnerability where group allowlist mode silently inherits DM allowFrom values when groupAllowFrom is not explicitly configured. … | Sep 26, 2026 |
| CVE-2026-100564 | MEDIUM | 5.4 | OpenClaw versions before 2026.8.1 fail to neutralize spreadsheet formula characters in participant display names within attendance CSV exports. Attackers can inject formula-like cells that execute … | Sep 26, 2026 |
| CVE-2026-100563 | MEDIUM | 5.4 | OpenClaw (npm package `openclaw`) before 2026.8.1 does not neutralize leading characters that spreadsheet applications interpret as formulas when the Control UI exports session data to … | Sep 26, 2026 |
| CVE-2026-100562 | MEDIUM | 5.4 | OpenClaw versions before 2026.8.1 contain an authorization bypass vulnerability in the sessions.create endpoint that allows operator.write callers to modify session configurations reserved for operator.admin scope. … | Sep 26, 2026 |