Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
54367
Total
4306
Critical
16164
High
15850
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-100561 | HIGH | 8.0 | OpenClaw (npm package 'openclaw') versions >= 2026.3.22 and < 2026.8.1 contain an approval-bypass flaw in the exec approval policy: the policy could trust a command-running … | Sep 26, 2026 |
| CVE-2026-100560 | HIGH | 7.5 | OpenClaw versions before 2026.8.1 contain an authorization bypass vulnerability where Allow Always approvals for exact commands persist as path-only grants on macOS and Linux. Attackers … | Sep 26, 2026 |
| CVE-2026-100559 | HIGH | 8.0 | OpenClaw versions before 2026.8.1 contain a command parser vulnerability where escaped newlines confuse exec allowlist parsing, allowing hidden commands to execute. Attackers can craft input … | Sep 26, 2026 |
| CVE-2026-100558 | HIGH | 7.5 | OpenClaw versions before 2026.8.1 contain a resource exhaustion vulnerability in the Gateway listener that allows unauthenticated clients to retain response sockets by sending WebSocket upgrade … | Sep 26, 2026 |
| CVE-2026-100557 | HIGH | 8.3 | OpenClaw versions before 2026.8.1 contain an authorization bypass vulnerability in skill tool dispatch that fails to carry the sender's owner status. Non-owner senders authorized to … | Sep 26, 2026 |
| CVE-2026-100556 | MEDIUM | 6.3 | OpenClaw (npm package openclaw) versions >= 2026.5.2 and < 2026.8.1 contain an incorrect authorization vulnerability in WhatsApp group handling. A group sender who is admitted … | Sep 26, 2026 |
| CVE-2026-100555 | HIGH | 7.1 | OpenClaw is an npm-distributed gateway application. In versions >= 2026.7.1 and < 2026.8.1, Synology Chat attachment delivery could lose DNS pinning: the Gateway validated a … | Sep 26, 2026 |
| CVE-2026-100554 | MEDIUM | 4.2 | OpenClaw (npm package 'openclaw') versions >= 2026.5.12 and < 2026.8.1 do not immediately invalidate Canvas HTTP authorization when a paired node is revoked. Node revocation … | Sep 26, 2026 |
| CVE-2026-100553 | MEDIUM | 4.3 | OpenClaw versions >= 2026.6.9 and < 2026.8.1 do not declare the native chatId parameter as a delivery target in the Feishu unpin feature, so unpin … | Sep 26, 2026 |
| CVE-2026-100552 | HIGH | 8.8 | OpenClaw (npm package 'openclaw') before 2026.8.1 does not correctly enforce per-chat tool policies for Codex app-server runtime tools. A conversation-level tools.allow rule filtered OpenClaw tools … | Sep 26, 2026 |
| CVE-2026-100551 | HIGH | 8.3 | OpenClaw for iOS versions >= 2026.7.1 and < 2026.8.11 do not enforce saved Gateway TLS pins in the Control UI. While native connections enforced the … | Sep 26, 2026 |
| CVE-2026-100550 | MEDIUM | 5.4 | OpenClaw (npm package 'openclaw') before 2026.8.1 contains an access-control bypass in the Microsoft Teams integration. When groupPolicy is set to allowlist, a missing or unsupported … | Sep 26, 2026 |
| CVE-2026-100549 | MEDIUM | 5.4 | OpenClaw versions before 2026.8.1 contain a path traversal vulnerability in QQBot voice attachment handling where filenames are decoded twice, allowing encoded traversal segments to reappear … | Sep 26, 2026 |
| CVE-2026-100548 | MEDIUM | 5.3 | OpenClaw (npm package 'openclaw') versions >= 2026.3.28 and < 2026.8.1 contain a credential exposure issue in memory embedding failover. When remote embedding fallback is configured … | Sep 26, 2026 |
| CVE-2026-100547 | MEDIUM | 5.5 | OpenClaw is a coding agent distributed as the npm package `openclaw`. In affected versions (2026.7.1 through 2026.7.2), alternate but valid `file:` URL spellings supplied over … | Sep 26, 2026 |
| CVE-2026-100546 | MEDIUM | 6.4 | OpenClaw (npm package `openclaw`) versions >= 2026.7.2 and < 2026.9.2 contain a race condition in the Discord realtime voice transcript path. Concurrent control-classified voice transcripts … | Sep 26, 2026 |
| CVE-2026-100545 | MEDIUM | 5.3 | OpenClaw (npm package `openclaw`) before 2026.8.1 incorrectly enforces sender tool policies during session-memory filename generation. In affected versions, filename generation created an embedded helper that … | Sep 26, 2026 |
| CVE-2026-100544 | HIGH | 8.8 | openclaw's @openclaw/voice-call package before 2026.8.1 launches the configured agent for classic inbound voice calls without propagating the caller's identity or non-owner status. As a result, … | Sep 26, 2026 |
| CVE-2026-100543 | HIGH | 7.5 | OpenClaw (npm package openclaw) before 2026.8.1 could include deterministic hashes computed over the original, unredacted configuration in redacted configuration responses. When the Gateway password had … | Sep 26, 2026 |
| CVE-2026-100542 | LOW | 3.1 | OpenClaw (npm package 'openclaw') versions >= 2026.5.28 and < 2026.8.1 mishandle archive listings in the tar.bz2 skill installer: bounded command-output suffixes were treated as complete … | Sep 26, 2026 |
| CVE-2026-100541 | HIGH | 7.5 | OpenClaw's Matrix integration (npm package @openclaw/matrix) versions >= 2026.2.2 and < 2026.8.1 lowercase complete Matrix user IDs — including historical localparts and the case-sensitive server-name … | Sep 26, 2026 |
| CVE-2026-100540 | MEDIUM | 6.8 | OpenClaw Feishu before 2026.8.1 fails to validate whether a configured default account is disabled before selecting it for model tool operations. Attackers can exploit multi-account … | Sep 26, 2026 |
| CVE-2026-100539 | LOW | 2.6 | OpenClaw (npm package 'openclaw') before 2026.8.1 fails to revoke memory tool access when an operator hot-disables memory configuration. Existing memory_search and memory_get tool instances retain … | Sep 26, 2026 |
| CVE-2026-100538 | MEDIUM | 6.5 | OpenClaw (npm package 'openclaw') before 2026.8.1 does not apply the originating sender's global or per-agent toolsBySender policy when handling outbound attachments. A sender that has … | Sep 26, 2026 |
| CVE-2026-100537 | LOW | 3.1 | OpenClaw (npm package 'openclaw') before 2026.8.1 fails to apply the originating requester's effective tool policy during Active Memory automatic recall. In deployments that use Active … | Sep 26, 2026 |