Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

54449
Total
4308
Critical
16178
High
15893
Medium
CVE ID Severity Score Description Published
CVE-2026-100543 HIGH 7.5 OpenClaw (npm package openclaw) before 2026.8.1 could include deterministic hashes computed over the original, unredacted configuration in redacted configuration responses. When the Gateway password had … Sep 26, 2026
CVE-2026-100542 LOW 3.1 OpenClaw (npm package 'openclaw') versions >= 2026.5.28 and < 2026.8.1 mishandle archive listings in the tar.bz2 skill installer: bounded command-output suffixes were treated as complete … Sep 26, 2026
CVE-2026-100541 HIGH 7.5 OpenClaw's Matrix integration (npm package @openclaw/matrix) versions >= 2026.2.2 and < 2026.8.1 lowercase complete Matrix user IDs — including historical localparts and the case-sensitive server-name … Sep 26, 2026
CVE-2026-100540 MEDIUM 6.8 OpenClaw Feishu before 2026.8.1 fails to validate whether a configured default account is disabled before selecting it for model tool operations. Attackers can exploit multi-account … Sep 26, 2026
CVE-2026-100539 LOW 2.6 OpenClaw (npm package 'openclaw') before 2026.8.1 fails to revoke memory tool access when an operator hot-disables memory configuration. Existing memory_search and memory_get tool instances retain … Sep 26, 2026
CVE-2026-100538 MEDIUM 6.5 OpenClaw (npm package 'openclaw') before 2026.8.1 does not apply the originating sender's global or per-agent toolsBySender policy when handling outbound attachments. A sender that has … Sep 26, 2026
CVE-2026-100537 LOW 3.1 OpenClaw (npm package 'openclaw') before 2026.8.1 fails to apply the originating requester's effective tool policy during Active Memory automatic recall. In deployments that use Active … Sep 26, 2026
CVE-2026-100536 MEDIUM 6.5 OpenClaw versions before 2026.8.1 fail to validate all source fields in structured message attachments, allowing attackers to hide unvalidated host paths behind allowed attachment sources. … Sep 26, 2026
CVE-2026-100535 HIGH 7.5 OpenClaw (npm package 'openclaw') versions >= 2026.4.5 and < 2026.8.1 can lose the originating requester's restrictions and untrusted provenance when session-derived text is persisted to … Sep 26, 2026
CVE-2026-100534 LOW 3.1 OpenClaw versions before 2026.8.1 contain an authorization bypass vulnerability in webhook TaskFlow cancellation that allows attackers to cancel unrelated sessions. An attacker with a webhook … Sep 26, 2026
CVE-2026-100533 MEDIUM 5.3 OpenClaw versions before 2026.8.1 contain a path traversal vulnerability in the tools.fs.workspaceOnly feature where Unicode filename fallback can normalize validated parent directory components. Admitted requesters … Sep 26, 2026
CVE-2026-100532 HIGH 8.1 @openclaw/whatsapp (npm) before 2026.8.1 exposes the WhatsApp login tool through the generic channel-tool path without preserving the originating sender's owner status, so the owner-only tool … Sep 26, 2026
CVE-2026-100531 MEDIUM 6.5 The @openclaw/slack npm package before 2026.8.1 contains an authorization flaw in its Slack download-file handler: when a file lacks the share metadata used to prove … Sep 26, 2026
CVE-2026-100530 HIGH 7.3 OpenClaw versions before 2026.8.1 fail to bind working directory context to reusable exec approvals, allowing approved commands to execute in different directories. Attackers with an … Sep 26, 2026
CVE-2026-100529 MEDIUM 6.4 OpenClaw versions before 2026.8.1 contain an authorization scope widening vulnerability in file-transfer allow-always approvals that allows attackers to reuse standing grants for unreviewed paths. Attackers … Sep 26, 2026
CVE-2026-100528 MEDIUM 5.4 OpenClaw (npm package 'openclaw') before 2026.8.1 could send third-party provider credentials to the wrong endpoint. In affected versions, when a third-party provider uses an OpenAI-compatible … Sep 26, 2026
CVE-2026-100527 MEDIUM 5.3 OpenClaw before 2026.8.2 contains a denial of service vulnerability in the Browser extension relay that allows unauthenticated network sources to exhaust pending-authentication capacity. Attackers can … Sep 26, 2026
CVE-2026-100526 MEDIUM 5.3 OpenClaw's Discord integration (npm package @openclaw/discord) before version 2026.9.3 could lose the sender-scoped media policy in the emoji and sticker upload actions before loading a … Sep 26, 2026
CVE-2026-100525 MEDIUM 4.3 The OpenClaw Prometheus diagnostics plugin (@openclaw/diagnostics-prometheus) before version 2026.9.3 does not enforce the operator.read scope on its authenticated metrics endpoint. In deployments using an identity-bearing … Sep 26, 2026
CVE-2026-100524 MEDIUM 5.4 Cotonti through 1.0.0 contains a cross-site request forgery vulnerability in the extensions manager that allows attackers to perform state-changing actions without anti-CSRF token validation. Attackers … Sep 26, 2026
CVE-2026-100523 MEDIUM 6.1 Cotonti through 1.0.0 contains an open redirect vulnerability in message.php that base64-decodes the redirect parameter without domain validation. Unauthenticated attackers can craft malicious links with … Sep 26, 2026
CVE-2026-100522 MEDIUM 6.1 Cotonti through 1.0.0 contains a reflected cross-site scripting vulnerability in message.php where the lng parameter is not properly escaped before output in the confirmation dialog. … Sep 26, 2026
CVE-2026-100521 MEDIUM 6.1 Cotonti through 1.0.0 contains a reflected cross-site scripting vulnerability in the search plugin highlight parameter that performs no HTML or JavaScript escaping. Attackers can craft … Sep 26, 2026
CVE-2026-100520 HIGH 8.8 Laranode versions before 1.2.1 contain a path traversal vulnerability in the POST /filemanager/upload-file endpoint that allows authenticated users to write arbitrary files outside their home … Sep 26, 2026
CVE-2026-100505 MEDIUM 4.4 Ghidra versions 11.2 through 12.1.4 contain a heap out-of-bounds read vulnerability in StringManager::getCodepoint when decoding multi-byte UTF-8, UTF-16, or UTF-32 characters without validating remaining buffer … Sep 26, 2026