| CVE-2026-22172 | 9.9 | critical | openclaw | OpenClaw versions prior to 2026.3.12 contain an authorization bypass vulnerability in the WebSocket connect path t | 169d ago |
| CVE-2026-53838 | 9.8 | critical | openclaw | OpenClaw before 2026.5.27 contains a state mutation vulnerability in node pairing reconnection that allows paired | 85d ago |
| CVE-2026-30741 | 9.8 | critical | openclaw | A remote code execution (RCE) vulnerability in OpenClaw Agent Platform v2026.2.6 allows attackers to execute arbit | 178d ago |
| CVE-2026-32038 | 9.8 | critical | openclaw | OpenClaw before 2026.2.24 contains a sandbox network isolation bypass vulnerability that allows trusted operators | 170d ago |
| CVE-2026-32913 | 9.3 | critical | openclaw | OpenClaw before 2026.3.7 contains an improper header validation vulnerability in fetchWithSsrFGuard that forwards | 166d ago |
| CVE-2026-62202 | 8.8 | high | openclaw | OpenClaw versions 2026.6.1 before 2026.6.9 contain a privilege escalation vulnerability in isolated cron jobs that | 50d ago |
| CVE-2026-32013 | 8.8 | high | openclaw | OpenClaw versions prior to 2026.2.25 contain a symlink traversal vulnerability in the agents.files.get and agents. | 170d ago |
| CVE-2026-62223 | 8.8 | high | openclaw | OpenClaw before 2026.5.18 contain an authorization bypass vulnerability in the device-pair approval feature that a | 50d ago |
| CVE-2026-62218 | 8.8 | high | openclaw | OpenClaw 2026.1.20 before 2026.5.27 contain an authorization bypass vulnerability in the device.pair.approve featu | 50d ago |
| CVE-2026-62217 | 8.8 | high | openclaw | OpenClaw 2026.5.14-beta.1 before 2026.5.27 contain an authorization flaw in the QQBot exec approvals feature. | 50d ago |
| CVE-2026-62207 | 8.8 | high | openclaw | OpenClaw versions before 2026.6.5 contain an authentication bypass vulnerability that allows lower-trust callers t | 50d ago |
| CVE-2026-62203 | 8.8 | high | openclaw | OpenClaw versions before 2026.6.6 contain an environment variable filtering vulnerability in host exec that fails | 50d ago |
| CVE-2026-62200 | 8.8 | high | openclaw | OpenClaw versions before 2026.6.6 contain a flaw in host exec environment filtering that could allow Git ext trans | 54d ago |
| CVE-2026-62199 | 8.8 | high | openclaw | OpenClaw versions before 2026.6.6 contain a flaw in host exec environment filtering that can miss interpreter star | 54d ago |
| CVE-2026-62194 | 8.8 | high | openclaw | OpenClaw versions 2026.5.20 before 2026.6.9 contain a privilege escalation vulnerability in plugin install command | 54d ago |
| CVE-2026-62190 | 8.8 | high | openclaw | OpenClaw versions before 2026.6.9 contain an authorization bypass vulnerability in the flock wrapper that allows l | 54d ago |
| CVE-2026-62229 | 8.8 | high | openclaw | OpenClaw before 2026.5.18 contain an authorization bypass vulnerability in exec allowlist glob matching that allow | 50d ago |
| CVE-2026-53843 | 8.8 | high | openclaw | OpenClaw before 2026.5.26 contains an authorization bypass vulnerability where a surviving pairing-scoped device s | 81d ago |
| CVE-2026-53836 | 8.8 | high | openclaw | OpenClaw before 2026.5.12 contains an allowlist bypass vulnerability in PowerShell encoded-command handling that a | 85d ago |
| CVE-2026-53828 | 8.8 | high | openclaw | OpenClaw before 2026.5.6 contains an authorization bypass vulnerability in native command handling that allows aut | 85d ago |
| CVE-2026-53822 | 8.8 | high | openclaw | OpenClaw before 2026.5.18 contains a command injection vulnerability where shell wrapper argv could change between | 85d ago |
| CVE-2026-53821 | 8.8 | high | openclaw | OpenClaw before 2026.5.18 accepts WebSocket client-declared operator scopes before binding to server-approved pair | 85d ago |
| CVE-2026-53819 | 8.8 | high | openclaw | OpenClaw before 2026.5.27 contains an arbitrary code execution vulnerability in skill install flows where workspac | 86d ago |
| CVE-2026-53817 | 8.8 | high | openclaw | OpenClaw before 2026.5.22 contains a locality validation vulnerability in Control UI pairing that allows attackers | 86d ago |
| CVE-2026-62228 | 8.8 | high | openclaw | OpenClaw before 2026.6.5 contain an authorization bypass vulnerability in node exec approvals that allows lower-tr | 50d ago |
| CVE-2026-53811 | 8.8 | high | openclaw | OpenClaw before 2026.5.7 contains a privilege escalation vulnerability in the Matrix allowFrom feature that allows | 86d ago |
| CVE-2026-53810 | 8.8 | high | openclaw | OpenClaw before 2026.5.18 contains a code execution vulnerability where marketplace runtime extension metadata can | 86d ago |
| CVE-2026-53807 | 8.8 | high | openclaw | OpenClaw before 2026.5.6 contains an authorization bypass vulnerability in Telegram interactive callbacks that all | 86d ago |
| CVE-2026-53806 | 8.8 | high | openclaw | OpenClaw before 2026.5.12 contains a shell option parsing vulnerability that allows combined POSIX shell flags to | 86d ago |
| CVE-2026-35674 | 8.8 | high | openclaw | OpenClaw before 2026.5.18 contains a scope bypass vulnerability in the Gateway chat.send route that allows scoped | 99d ago |
| CVE-2026-32042 | 8.8 | high | openclaw | OpenClaw versions 2026.2.22 prior to 2026.2.25 contain a privilege escalation vulnerability allowing unpaired devi | 169d ago |
| CVE-2026-32051 | 8.8 | high | openclaw | OpenClaw versions prior to 2026.3.1 contain an authorization mismatch vulnerability that allows authenticated call | 169d ago |
| CVE-2026-45006 | 8.8 | high | openclaw | OpenClaw before 2026.4.23 contains an improper access control vulnerability in the gateway tool's config.apply and | 117d ago |
| CVE-2026-31998 | 8.6 | high | openclaw | OpenClaw versions 2026.2.22 and 2026.2.23 contain an authorization bypass vulnerability in the synology-chat chann | 170d ago |
| CVE-2026-62197 | 8.5 | high | openclaw | OpenClaw before 2026.6.6 contains a policy bypass vulnerability in browser CDP discovery that accepts blocked WebS | 54d ago |
| CVE-2026-62226 | 8.5 | high | openclaw | OpenClaw 2026.3.28 before 2026.5.19 contain an authorization bypass vulnerability in the browser act route that fa | 50d ago |
| CVE-2026-62195 | 8.3 | high | openclaw | OpenClaw versions 2026.5.20 before 2026.6.6 contain an authorization bypass vulnerability in the MCP loopback feat | 54d ago |
| CVE-2026-62196 | 8.3 | high | openclaw | OpenClaw versions 2026.3.22 before 2026.6.6 contain an authorization bypass vulnerability where WhatsApp group IDs | 54d ago |
| CVE-2026-53831 | 8.3 | high | openclaw | OpenClaw before 2026.5.18 contains a policy enforcement vulnerability in system.run safe-bin allowlist validation | 85d ago |
| CVE-2026-32905 | 8.3 | high | openclaw | OpenClaw before 2026.5.4 contains an authorization bypass vulnerability in the bundled device-pair plugin that all | 99d ago |
| CVE-2026-53853 | 8.3 | high | openclaw | OpenClaw before 2026.5.12 contains an argument pattern validation bypass in the exec allowlist that allows attacke | 81d ago |
| CVE-2026-53814 | 8.3 | high | openclaw | OpenClaw before 2026.5.20 contains a privilege escalation vulnerability where hook-triggered agent runs incorrectl | 86d ago |
| CVE-2026-22171 | 8.2 | high | openclaw | OpenClaw versions prior to 2026.2.19 contain a path traversal vulnerability in the Feishu media download flow wher | 171d ago |
| CVE-2026-53864 | 8.1 | high | openclaw | OpenClaw before 2026.5.26 contains an insufficient sanitization vulnerability in the host environment sanitizer th | 81d ago |
| CVE-2026-53857 | 8.1 | high | openclaw | OpenClaw before 2026.5.3 contains a policy enforcement vulnerability where Zalo contacts with mutable display meta | 81d ago |
| CVE-2026-53855 | 8.1 | high | openclaw | OpenClaw before 2026.4.2 contains an inline-eval bypass vulnerability allowing authenticated operators to weaken s | 81d ago |
| CVE-2026-53849 | 8.1 | high | openclaw | OpenClaw before 2026.5.7 contains a privilege escalation vulnerability where the allowFrom feature improperly vali | 81d ago |
| CVE-2026-53823 | 8.1 | high | openclaw | OpenClaw before 2026.5.3 contains a privilege escalation vulnerability in the allowFrom feature that binds to muta | 85d ago |
| CVE-2026-62209 | 8.1 | high | openclaw | OpenClaw versions 2026.5.10-beta.1 before 2026.6.5 contain an authorization bypass in the ClickClack agent-mode di | 50d ago |
| CVE-2026-32034 | 8.1 | high | openclaw | OpenClaw versions prior to 2026.2.21 contain an authentication bypass vulnerability in the Control UI when allowIn | 170d ago |
| CVE-2026-32302 | 8.1 | high | openclaw | OpenClaw is a personal AI assistant. | 176d ago |
| CVE-2026-62192 | 8.1 | high | openclaw | OpenClaw versions 2026.6.6 before 2026.6.9 contain an authorization bypass vulnerability in Discord guild actions | 54d ago |
| CVE-2026-62188 | 8.1 | high | openclaw\/feishu | OpenClaw @openclaw/feishu versions 2026.6.6 and earlier contain an incorrect authorization vulnerability in which | 54d ago |
| CVE-2026-62187 | 8.1 | high | openclaw\/feishu | OpenClaw Feishu tools (npm package @openclaw/feishu) in versions <= 2026.6.6 could ignore per-account disablement. | 54d ago |
| CVE-2026-53866 | 8.1 | high | openclaw | OpenClaw before 2026.5.12 contains an allowlist bypass vulnerability in shell inline-command parsing that allows a | 81d ago |
| CVE-2026-35630 | 8 | high | openclaw | OpenClaw before 2026.5.18 contains an authorization bypass vulnerability in QQBot native approval buttons that fai | 99d ago |
| CVE-2026-53829 | 8 | high | openclaw | OpenClaw before 2026.5.18 contains an approval display truncation vulnerability allowing authenticated users to hi | 85d ago |
| CVE-2026-32014 | 8 | high | openclaw | OpenClaw versions prior to 2026.2.26 contain a metadata spoofing vulnerability where reconnect platform and device | 170d ago |
| CVE-2026-62215 | 8 | high | openclaw | OpenClaw versions before 2026.6.5 contain an authentication bypass vulnerability in HTTP Canvas responses that all | 50d ago |
| CVE-2026-32032 | 7.8 | high | openclaw | OpenClaw versions prior to 2026.2.22 contain an arbitrary shell execution vulnerability in shell environment fallb | 170d ago |
| CVE-2026-32015 | 7.8 | high | openclaw | OpenClaw versions 2026.1.21 prior to 2026.2.19 contain a path hijacking vulnerability in tools.exec.safeBins that | 170d ago |
| CVE-2026-45004 | 7.8 | high | openclaw | OpenClaw before 2026.4.23 contains an arbitrary code execution vulnerability in the bundled plugin setup resolver | 117d ago |
| CVE-2026-53813 | 7.8 | high | openclaw | OpenClaw before 2026.4.25 contains a path traversal vulnerability in memory-core artifact loading where workspace | 86d ago |
| CVE-2026-32016 | 7.8 | high | openclaw | OpenClaw versions prior to 2026.2.22 on macOS contain a path validation bypass vulnerability in the exec-approval | 170d ago |
| CVE-2026-62222 | 7.8 | high | openclaw | OpenClaw before 2026.5.22 contain a vulnerability in setup-mode discovery that allows loading of untrusted workspa | 50d ago |
| CVE-2026-53812 | 7.7 | high | openclaw | OpenClaw before 2026.5.18 contains a server-side request forgery vulnerability in browser control that allows auth | 86d ago |
| CVE-2026-53833 | 7.7 | high | openclaw | OpenClaw before 2026.4.29 contains an authorization bypass vulnerability in the QQBot streaming command that allow | 85d ago |
| CVE-2026-62227 | 7.7 | high | openclaw | OpenClaw 2026.4.14 before 2026.5.26 contain a server-side request forgery vulnerability in browser snapshot routes | 50d ago |
| CVE-2026-62201 | 7.7 | high | openclaw | OpenClaw versions before 2026.6.6 contain a network policy bypass vulnerability in the sandbox exec-server that al | 50d ago |
| CVE-2026-53832 | 7.7 | high | openclaw | OpenClaw before 2026.5.18 contains an identity header validation vulnerability allowing local same-host callers to | 85d ago |
| CVE-2026-32064 | 7.7 | high | openclaw | OpenClaw versions prior to 2026.2.21 sandbox browser entrypoint launches x11vnc without authentication for noVNC o | 169d ago |
| CVE-2026-22181 | 7.6 | high | openclaw | OpenClaw versions prior to 2026.3.2 contain a DNS pinning bypass vulnerability in strict URL fetch paths that allo | 171d ago |
| CVE-2026-62186 | 7.6 | high | openclaw | OpenClaw versions before 2026.6.8 contain an authorization bypass vulnerability in OpenAI-compatible HTTP model ov | 54d ago |
| CVE-2026-32055 | 7.6 | high | openclaw | OpenClaw versions prior to 2026.2.26 contain a path traversal vulnerability in workspace boundary validation that | 169d ago |
| CVE-2026-32048 | 7.5 | high | openclaw | OpenClaw versions prior to 2026.3.1 fail to enforce sandbox inheritance during cross-agent sessions_spawn operatio | 169d ago |
| CVE-2026-28461 | 7.5 | high | openclaw | OpenClaw versions prior to 2026.3.1 contain an unbounded memory growth vulnerability in the Zalo webhook endpoint | 170d ago |
| CVE-2026-32025 | 7.5 | high | openclaw | OpenClaw versions prior to 2026.2.25 contain an authentication hardening gap in browser-origin WebSocket clients t | 170d ago |
| CVE-2026-32030 | 7.5 | high | openclaw | OpenClaw versions prior to 2026.2.19 contain a path traversal vulnerability in the stageSandboxMedia function that | 170d ago |
| CVE-2026-32049 | 7.5 | high | openclaw | OpenClaw versions prior to 2026.2.22 fail to consistently enforce configured inbound media byte limits before buff | 169d ago |
| CVE-2026-32056 | 7.5 | high | openclaw | OpenClaw versions prior to 2026.2.22 fail to sanitize shell startup environment variables HOME and ZDOTDIR in the | 169d ago |
| CVE-2026-32011 | 7.5 | high | openclaw | OpenClaw versions prior to 2026.3.2 contain a denial of service vulnerability in webhook handlers for BlueBubbles | 170d ago |
| CVE-2026-53834 | 7.5 | high | openclaw | OpenClaw before 2026.4.27 contains an authorization bypass vulnerability in QQBot pre-dispatch slash commands that | 85d ago |
| CVE-2026-31989 | 7.4 | high | openclaw | OpenClaw versions prior to 2026.3.1 contain a server-side request forgery vulnerability in web_search citation red | 170d ago |
| CVE-2026-32019 | 7.4 | high | openclaw | OpenClaw versions prior to 2026.2.22 contain incomplete IPv4 special-use range validation in the isPrivateIpv4() f | 170d ago |
| CVE-2026-44995 | 7.3 | high | openclaw | OpenClaw before 2026.4.20 contains an improper environment variable validation vulnerability in MCP stdio server c | 117d ago |
| CVE-2026-8305 | 7.3 | high | openclaw | A vulnerability was detected in OpenClaw up to 2026.1.24. | 117d ago |
| CVE-2026-53816 | 7.2 | high | openclaw | OpenClaw before 2026.5.18 contains an insufficient provenance validation vulnerability in node event handling that | 86d ago |
| CVE-2026-22179 | 7.2 | high | openclaw | OpenClaw versions prior to 2026.2.22 in macOS node-host system.run contain an allowlist bypass vulnerability that | 171d ago |
| CVE-2026-32000 | 7.1 | high | openclaw | OpenClaw versions prior to 2026.2.19 contain a command injection vulnerability in the Lobster extension tool execu | 170d ago |
| CVE-2026-62205 | 7.1 | high | openclaw | OpenClaw versions 2026.4.12-beta.1 before 2026.6.6 contain a missing-authorization vulnerability in the MS Teams m | 50d ago |
| CVE-2026-27566 | 7.1 | high | openclaw | OpenClaw versions prior to 2026.2.22 contain an allowlist bypass vulnerability in system.run exec analysis that fa | 170d ago |
| CVE-2026-28460 | 7.1 | high | openclaw | OpenClaw versions prior to 2026.2.22 contain an allowlist bypass vulnerability in system.run that allows attackers | 170d ago |
| CVE-2026-62212 | 7.1 | high | openclaw | OpenClaw before 2026.5.28 contains a race condition in the MS Teams safeFetch DNS rebinding check. | 50d ago |
| CVE-2026-62206 | 7.1 | high | openclaw | OpenClaw versions before 2026.6.9 contain a missing authorization vulnerability in Discord moderation actions. | 50d ago |
| CVE-2026-45001 | 7.1 | high | openclaw | OpenClaw before 2026.4.20 contains a guard bypass vulnerability in the agent-facing gateway config.patch and confi | 117d ago |
| CVE-2026-22175 | 7.1 | high | openclaw | OpenClaw versions prior to 2026.2.23 contain an exec approval bypass vulnerability in allowlist mode where allow-a | 171d ago |
| CVE-2026-31992 | 7.1 | high | openclaw | OpenClaw versions prior to 2026.2.23 contain an allowlist bypass vulnerability in system.run guardrails that allow | 170d ago |
| CVE-2026-62219 | 7.1 | high | openclaw | OpenClaw 2026.2.12 before 2026.5.26 contain an authorization bypass vulnerability in the hooks allowedAgentIds val | 50d ago |
| CVE-2026-62191 | 7.1 | high | openclaw | OpenClaw versions 2026.6.6 before 2026.6.9 contain an authorization bypass vulnerability in message mutation handl | 54d ago |
| CVE-2026-62189 | 7.1 | high | openclaw | OpenClaw versions before 2026.6.9 contain a symlink following vulnerability in the mirror sync feature that allows | 54d ago |