| CVE-2026-32041 | 6.9 | medium | openclaw / openclaw | OpenClaw versions prior to 2026.3.1 fail to properly handle authentication bootstrap errors during startup, allowi | 170d ago |
| CVE-2026-32007 | 6.8 | medium | openclaw / openclaw | OpenClaw versions prior to 2026.2.23 contain a path traversal vulnerability in the experimental apply_patch tool t | 170d ago |
| CVE-2026-32005 | 6.8 | medium | openclaw / openclaw | OpenClaw versions prior to 2026.2.25 fail to enforce sender authorization checks for interactive callbacks includi | 170d ago |
| CVE-2026-29607 | 6.8 | medium | openclaw / openclaw | OpenClaw versions prior to 2026.2.22 contain an authorization bypass vulnerability in allow-always wrapper persist | 171d ago |
| CVE-2026-22174 | 6.8 | medium | openclaw / openclaw | OpenClaw versions prior to 2026.2.22 inject the x-OpenClaw-relay-token header into Chrome CDP probe traffic on loo | 172d ago |
| CVE-2026-29608 | 6.7 | medium | openclaw / openclaw | OpenClaw 2026.3.1 contains an approval integrity vulnerability in system.run node-host execution where argv rewrit | 171d ago |
| CVE-2026-22169 | 6.7 | medium | openclaw / openclaw | OpenClaw versions prior to 2026.2.22 contain an allowlist bypass vulnerability in the safeBins configuration that | 172d ago |
| CVE-2026-32003 | 6.6 | medium | openclaw / openclaw | OpenClaw versions prior to 2026.2.22 contain an environment variable injection vulnerability in the system.run fun | 170d ago |
| CVE-2026-32054 | 6.5 | medium | openclaw / openclaw | OpenClaw versions prior to 2026.2.25 contain a symlink traversal vulnerability in browser trace and download outpu | 169d ago |
| CVE-2026-32053 | 6.5 | medium | openclaw / openclaw | OpenClaw versions prior to 2026.2.23 contain a vulnerability in Twilio webhook event deduplication where normalize | 169d ago |
| CVE-2026-32043 | 6.5 | medium | openclaw / openclaw | OpenClaw versions prior to 2026.2.25 contain a time-of-check-time-of-use vulnerability in approval-bound system.ru | 169d ago |
| CVE-2026-32036 | 6.5 | medium | openclaw / openclaw | OpenClaw gateway plugin versions prior to 2026.2.26 contain a path traversal vulnerability that allows remote atta | 170d ago |
| CVE-2026-32033 | 6.5 | medium | openclaw / openclaw | OpenClaw versions prior to 2026.2.24 contain a path traversal vulnerability where @-prefixed absolute paths bypass | 170d ago |
| CVE-2026-32027 | 6.5 | medium | openclaw / openclaw | OpenClaw versions prior to 2026.2.26 contain an authorization bypass vulnerability where DM pairing-store identiti | 170d ago |
| CVE-2026-32026 | 6.5 | medium | openclaw / openclaw | OpenClaw versions prior to 2026.2.24 contain an improper path validation vulnerability in sandbox media handling t | 170d ago |
| CVE-2026-32022 | 6.5 | medium | openclaw / openclaw | OpenClaw versions prior to 2026.2.21 contain a stdin-only policy bypass vulnerability in the grep tool within tool | 170d ago |
| CVE-2026-32021 | 6.5 | medium | openclaw / openclaw | OpenClaw versions prior to 2026.2.22 contain an authorization bypass vulnerability in the Feishu allowFrom allowli | 170d ago |
| CVE-2026-32008 | 6.5 | medium | openclaw / openclaw | OpenClaw versions prior to 2026.2.21 contain an improper URL scheme validation vulnerability in the assertBrowserN | 170d ago |
| CVE-2026-32004 | 6.5 | medium | openclaw / openclaw | OpenClaw versions prior to 2026.3.2 contain an authentication bypass vulnerability in the /api/channels route clas | 170d ago |
| CVE-2026-28449 | 6.5 | medium | openclaw / openclaw | OpenClaw versions prior to 2026.2.25 lack durable replay state for Nextcloud Talk webhook events, allowing valid s | 171d ago |
| CVE-2026-27522 | 6.5 | medium | openclaw / openclaw | OpenClaw versions prior to 2026.2.24 contain a local media root bypass vulnerability in sendAttachment and setGrou | 172d ago |
| CVE-2026-22178 | 6.5 | medium | openclaw / openclaw | OpenClaw versions prior to 2026.2.19 construct RegExp objects directly from unescaped Feishu mention metadata in t | 172d ago |
| CVE-2026-22170 | 6.5 | medium | openclaw / openclaw | OpenClaw versions prior to 2026.2.22 with the optional BlueBubbles plugin contain an access control bypass vulnera | 172d ago |
| CVE-2026-22168 | 6.5 | medium | openclaw / openclaw | OpenClaw versions prior to 2026.2.21 contain an approval-integrity mismatch vulnerability in system.run that allow | 172d ago |
| CVE-2026-32052 | 6.4 | medium | openclaw / openclaw | OpenClaw versions prior to 2026.2.24 contain a command injection vulnerability in the system.run shell-wrapper tha | 169d ago |
| CVE-2026-32010 | 6.3 | medium | openclaw / openclaw | OpenClaw versions prior to 2026.2.22 contain an allowlist bypass vulnerability in the safe-bin configuration when | 170d ago |
| CVE-2026-31999 | 6.3 | medium | openclaw / openclaw | OpenClaw versions 2026.2.26 prior to 2026.3.1 on Windows contain a current working directory injection vulnerabili | 171d ago |
| CVE-2026-4039 | 6.3 | medium | openclaw / openclaw | A vulnerability was determined in OpenClaw 2026.2.19-2. | 177d ago |
| CVE-2026-27646 | 6.1 | medium | openclaw / openclaw | OpenClaw versions prior to 2026.3.7 contain a sandbox escape vulnerability in the /acp spawn command that allows a | 166d ago |
| CVE-2026-31990 | 6.1 | medium | openclaw / openclaw | OpenClaw versions prior to 2026.3.2 contain a vulnerability in the stageSandboxMedia function in which it fails to | 171d ago |
| CVE-2026-22176 | 6.1 | medium | openclaw / openclaw | OpenClaw versions prior to 2026.2.19 contain a command injection vulnerability in Windows Scheduled Task script ge | 171d ago |
| CVE-2026-27545 | 6.1 | medium | openclaw / openclaw | OpenClaw versions prior to 2026.2.26 contain an approval bypass vulnerability in system.run execution that allows | 172d ago |
| CVE-2026-27523 | 6.1 | medium | openclaw / openclaw | OpenClaw versions prior to 2026.2.24 contain a sandbox bind validation vulnerability allowing attackers to bypass | 172d ago |
| CVE-2026-22217 | 6.1 | medium | openclaw / openclaw | OpenClaw version 2026.2.22 prior to 2026.2.23 contains an arbitrary code execution vulnerability in shell-env that | 172d ago |
| CVE-2026-22177 | 6.1 | medium | openclaw / openclaw | OpenClaw versions prior to 2026.2.21 fail to filter dangerous process-control environment variables from config en | 172d ago |
| CVE-2026-32037 | 6 | medium | openclaw / openclaw | OpenClaw versions prior to 2026.2.22 fail to consistently validate redirect chains against configured mediaAllowHo | 170d ago |
| CVE-2026-31997 | 6 | medium | openclaw / openclaw | OpenClaw versions prior to 2026.3.1 fail to pin executable identity for non-path-like argv[0] tokens in system.run | 171d ago |
| CVE-2026-32045 | 5.9 | medium | openclaw / openclaw | OpenClaw versions prior to 2026.2.21 incorrectly apply tokenless Tailscale header authentication to HTTP gateway r | 169d ago |
| CVE-2026-32039 | 5.9 | medium | openclaw / openclaw | OpenClaw versions prior to 2026.2.22 contain an authorization bypass vulnerability in the toolsBySender group poli | 170d ago |
| CVE-2026-32035 | 5.9 | medium | openclaw / openclaw | OpenClaw versions prior to 2026.3.2 fail to pass the senderIsOwner flag when processing Discord voice transcripts | 170d ago |
| CVE-2026-32009 | 5.7 | medium | openclaw / openclaw | OpenClaw versions prior to 2026.2.24 contain a policy bypass vulnerability in the safeBins allowlist evaluation th | 170d ago |
| CVE-2026-32044 | 5.5 | medium | openclaw / openclaw | OpenClaw versions prior to 2026.3.2 contain an archive extraction vulnerability in the tar.bz2 installer path that | 169d ago |
| CVE-2026-32024 | 5.5 | medium | openclaw / openclaw | OpenClaw versions prior to 2026.2.22 contain a symlink traversal vulnerability in avatar handling that allows atta | 170d ago |
| CVE-2026-32898 | 5.4 | medium | openclaw / openclaw | OpenClaw versions prior to 2026.2.23 contain an authorization bypass vulnerability in the ACP client that auto-app | 169d ago |
| CVE-2026-32895 | 5.4 | medium | openclaw / openclaw | OpenClaw versions prior to 2026.2.26 fail to enforce sender authorization in member and message subtype system eve | 169d ago |
| CVE-2026-32001 | 5.4 | medium | openclaw / openclaw | OpenClaw versions prior to 2026.2.22 contain an authentication bypass vulnerability that allows clients authentica | 170d ago |
| CVE-2026-27183 | 5.3 | medium | openclaw / openclaw | OpenClaw versions prior to 2026.3.7 contain a shell approval gating bypass vulnerability in system.run dispatch-wr | 166d ago |
| CVE-2026-32046 | 5.3 | medium | openclaw / openclaw | OpenClaw versions prior to 2026.2.21 contain an improper sandbox configuration vulnerability that allows attackers | 169d ago |
| CVE-2026-32029 | 5.3 | medium | openclaw / openclaw | OpenClaw versions prior to 2026.2.21 improperly parse the left-most X-Forwarded-For header value when requests ori | 170d ago |
| CVE-2026-32028 | 5.3 | medium | openclaw / openclaw | OpenClaw versions prior to 2026.2.25 fail to enforce dmPolicy and allowFrom authorization checks on Discord direct | 170d ago |
| CVE-2026-32002 | 5.3 | medium | openclaw / openclaw | OpenClaw versions prior to 2026.2.23 contain a sandbox bypass vulnerability in the sandboxed image tool that fails | 170d ago |
| CVE-2026-31995 | 5.3 | medium | openclaw / openclaw | OpenClaw versions 2026.1.21 prior to 2026.2.19 contain a command injection vulnerability in the Lobster extension' | 171d ago |
| CVE-2026-27670 | 5.3 | medium | openclaw / openclaw | OpenClaw versions prior to 2026.3.2 contain a race condition vulnerability in ZIP extraction that allows local att | 171d ago |
| CVE-2026-22180 | 5.3 | medium | openclaw / openclaw | OpenClaw versions prior to 2026.3.2 contain a path-confinement bypass vulnerability in browser output handling tha | 172d ago |
| CVE-2026-32896 | 4.8 | medium | openclaw / openclaw | The BlueBubbles webhook handler in OpenClaw versions prior to 2026.2.21 contains a passwordless fallback authentic | 169d ago |
| CVE-2026-32065 | 4.8 | medium | openclaw / openclaw | OpenClaw versions prior to 2026.2.25 contain an approval-integrity bypass vulnerability in system.run where render | 169d ago |
| CVE-2026-32031 | 4.8 | medium | openclaw / openclaw | OpenClaw versions prior to 2026.2.26 server-http contains an authentication bypass vulnerability in gateway authen | 170d ago |
| CVE-2026-31993 | 4.8 | medium | openclaw / openclaw | OpenClaw versions prior to 2026.2.22 contain an allowlist parsing mismatch vulnerability in the macOS companion ap | 171d ago |
| CVE-2026-32040 | 4.6 | medium | openclaw / openclaw | OpenClaw versions prior to 2026.2.23 contain an html injection vulnerability in the HTML session exporter that all | 170d ago |
| CVE-2026-31996 | 4.4 | medium | openclaw / openclaw | OpenClaw versions prior to 2026.2.19 tools.exec.safeBins contains an input validation bypass vulnerability that al | 171d ago |