VYPR

Openclaw

by OpenClaw

npm: openclaw

Source repositories

CVEs (660)

  • CVE-2026-28395MedMar 5, 2026
    risk 0.35cvss 6.5epss 0.01

    OpenClaw version 2026.1.14-1 prior to 2026.2.12 contains an improper network binding vulnerability in the Chrome extension (must be installed and enabled) relay server that treats wildcard hosts as loopback addresses, allowing the relay HTTP/WS server to bind to all interfaces…

  • CVE-2026-28394MedMar 5, 2026
    risk 0.35cvss 6.5epss 0.01

    OpenClaw versions prior to 2026.2.15 contain a denial of service vulnerability in the web_fetch tool that allows attackers to crash the Gateway process through memory exhaustion by parsing oversized or deeply nested HTML responses. Remote attackers can social-engineer users into…

  • CVE-2026-26329MedFeb 20, 2026
    risk 0.35cvss 6.5epss 0.00

    OpenClaw is a personal AI assistant. Prior to version 2026.2.14, authenticated attackers can read arbitrary files from the Gateway host by supplying absolute paths or path traversal sequences to the browser tool's `upload` action. The server passed these paths to Playwright's…

  • CVE-2026-26328MedFeb 20, 2026
    risk 0.35cvss 6.5epss 0.00

    OpenClaw is a personal AI assistant. Prior to version 2026.2.14, under iMessage `groupPolicy=allowlist`, group authorization could be satisfied by sender identities coming from the DM pairing store, broadening DM trust into group contexts. Version 2026.2.14 fixes the issue.

  • CVE-2026-26327MedFeb 19, 2026
    risk 0.35cvss 6.5epss 0.00

    OpenClaw is a personal AI assistant. Discovery beacons (Bonjour/mDNS and DNS-SD) include TXT records such as `lanHost`, `tailnetDns`, `gatewayPort`, and `gatewayTlsSha256`. TXT records are unauthenticated. Prior to version 2026.2.14, some clients treated TXT values as…

  • CVE-2026-26320MedFeb 19, 2026
    risk 0.35cvss 6.5epss 0.01

    OpenClaw is a personal AI assistant. OpenClaw macOS desktop client registers the `openclaw://` URL scheme. For `openclaw://agent` deep links without an unattended `key`, the app shows a confirmation dialog that previously displayed only the first 240 characters of the message,…

  • CVE-2026-102806MedSep 29, 2026
    risk 0.34cvss 6.3epss 0.00

    OpenClaw before 2026.9.5 contains an incorrect authorization vulnerability in the Gateway's local media root allowlist that breaks filesystem isolation between sandboxed sessions. Sandboxed sessions or untrusted content can cause the Gateway to read files from sibling session…

  • CVE-2026-100592MedSep 26, 2026
    risk 0.34cvss 6.3epss 0.00

    OpenClaw is an agent gateway distributed via npm. In versions >= 2026.4.10 and < 2026.7.1, persistent memory dreaming mutations omit owner permission checks. An authorized but non-owner external-channel sender can issue the persistent '/dreaming on' and '/dreaming off' commands…

  • CVE-2026-100591MedSep 26, 2026
    risk 0.34cvss 6.3epss 0.00

    OpenClaw is an npm-distributed agent gateway. In versions before 2026.7.1, the global Active Memory toggle mutations could omit owner checks. An authorized non-owner external-channel sender could therefore persistently enable or disable Active Memory for the Gateway, disabling…

  • CVE-2026-100577MedSep 26, 2026
    risk 0.34cvss 6.3epss 0.00

    OpenClaw versions before 2026.8.1 fail to validate video asset URLs returned by providers, allowing server-side requests to private destinations. A malicious or compromised provider can return private or loopback URLs to cause the CLI to make requests to internal services…

  • CVE-2026-100556MedSep 26, 2026
    risk 0.34cvss 6.3epss 0.00

    OpenClaw (npm package openclaw) versions >= 2026.5.2 and < 2026.8.1 contain an incorrect authorization vulnerability in WhatsApp group handling. A group sender who is admitted for ordinary messages but denied by commands.allowFrom or owner command authorization can issue the…

  • CVE-2026-95815MedSep 22, 2026
    risk 0.34cvss 6.3epss 0.00

    OpenClaw iOS before 2026.8.11 logs complete agent deep-link URLs including persistent bearer keys to unified logs as public diagnostic data. Attackers who obtain diagnostic archives can recover unrotated keys and replay them in forged deep links to submit agent requests without…

  • CVE-2026-43582MedMay 6, 2026
    risk 0.34cvss 6.3epss 0.00

    OpenClaw before 2026.4.10 contains a server-side request forgery vulnerability in browser navigation policy that allows attackers to bypass hostname validation through DNS rebinding attacks. Attackers can exploit inconsistent hostname resolution between validation and actual…

  • CVE-2026-32977MedMar 31, 2026
    risk 0.34cvss 6.3epss 0.00

    OpenClaw before 2026.3.11 contains a sandbox boundary bypass vulnerability in the fs-bridge writeFile commit step that uses an unanchored container path during the final move operation. An attacker can exploit a time-of-check-time-of-use race condition by modifying parent paths…

  • CVE-2026-32921MedMar 31, 2026
    risk 0.34cvss 6.3epss 0.00

    OpenClaw before 2026.3.8 contains an approval bypass vulnerability in system.run where mutable script operands are not bound across approval and execution phases. Attackers can obtain approval for script execution, modify the approved script file before execution, and execute…

  • CVE-2026-32010MedMar 19, 2026
    risk 0.34cvss 6.3epss 0.00

    OpenClaw versions prior to 2026.2.22 contain an allowlist bypass vulnerability in the safe-bin configuration when sort is manually added to tools.exec.safeBins. Attackers can invoke sort with the --compress-program flag to execute arbitrary external programs without operator…

  • CVE-2026-31999MedMar 19, 2026
    risk 0.34cvss 6.3epss 0.00

    OpenClaw versions 2026.2.26 prior to 2026.3.1 on Windows contain a current working directory injection vulnerability in wrapper resolution for .cmd/.bat files that allows attackers to influence execution behavior through cwd manipulation. Remote attackers can exploit improper…

  • CVE-2026-4039MedMar 12, 2026
    risk 0.34cvss 6.3epss 0.01

    A vulnerability was determined in OpenClaw 2026.2.19-2. This vulnerability affects the function applySkillConfigenvOverrides of the component Skill Env Handler. Executing a manipulation can lead to code injection. It is possible to launch the attack remotely. Upgrading to…

  • CVE-2026-53841MedJun 16, 2026
    risk 0.33cvss 6.1epss 0.00

    OpenClaw before 2026.5.12 contains a cross-site scripting vulnerability in exported session HTML that preserves unsafe javascript: and data: links in generated content. Attackers can execute browser-side scripts if a trusted operator opens the exported file and activates a…

  • CVE-2026-41373MedApr 28, 2026
    risk 0.33cvss 6.1epss 0.00

    OpenClaw before 2026.3.31 contains an incomplete host-env-security-policy.json that fails to restrict compiler binary environment variables, allowing untrusted models to substitute CC, CXX, CARGO_BUILD_RUSTC, and CMAKE_C_COMPILER via environment overrides. Attackers with…

Page 20 of 33