VYPR

Openclaw

by OpenClaw

npm: openclaw

Source repositories

CVEs (583)

  • CVE-2026-62226HigJul 17, 2026
    risk 0.00cvss 8.5epss 0.00

    OpenClaw 2026.3.28 before 2026.5.19 contain an authorization bypass vulnerability in the browser act route that fails to properly validate current-tab URL checks. Attackers with lower-trust access or configured input paths can perform actions requiring stronger authorization or…

  • CVE-2026-62225MedJul 17, 2026
    risk 0.00cvss 5.4epss 0.00

    OpenClaw versions before 2026.5.18 contain an authorization bypass vulnerability in skill command dispatch that allows lower-trust callers to execute or persist actions beyond their intended authorization. Attackers can bypass tool policy restrictions through configured input…

  • CVE-2026-62224MedJul 17, 2026
    risk 0.00cvss 5.4epss 0.00

    OpenClaw MS Teams before 2026.5.12 contain an authorization bypass vulnerability where the allowFrom feature binds to mutable display names. Attackers with lower-trust access can perform actions requiring stronger authorization by exploiting the mutable display name binding in…

  • CVE-2026-62223HigJul 17, 2026
    risk 0.00cvss 8.8epss 0.00

    OpenClaw before 2026.5.18 contain an authorization bypass vulnerability in the device-pair approval feature that allows lower-trust callers to execute actions beyond their intended authorization. Attackers can exploit misconfigured input paths to execute or persist unauthorized…

  • CVE-2026-62222HigJul 17, 2026
    risk 0.00cvss 7.8epss 0.00

    OpenClaw before 2026.5.22 contain a vulnerability in setup-mode discovery that allows loading of untrusted workspace plugins. Attackers with lower-trust caller access or control over configured input paths can execute or persist actions beyond their intended authorization level.

  • CVE-2026-62221MedJul 17, 2026
    risk 0.00cvss 5.4epss 0.00

    OpenClaw 2026.5.12 before 2026.5.26 contain an incorrect authorization vulnerability in the ClickClack allowFrom feature. When the affected feature is enabled and reachable, a lower-trust caller or configured input path could execute or persist actions beyond the caller's…

  • CVE-2026-62220MedJul 17, 2026
    risk 0.00cvss 5.3epss 0.00

    OpenClaw 2026.2.25 before 2026.5.26 allow a lower-trust caller or configured input path to bypass non-browser rate limits on WebSocket authentication attempts. When the affected feature is enabled and reachable by lower-trust input, this can consume gateway resources and reduce…

  • CVE-2026-62219HigJul 17, 2026
    risk 0.00cvss 7.1epss 0.00

    OpenClaw 2026.2.12 before 2026.5.26 contain an authorization bypass vulnerability in the hooks allowedAgentIds validation. A lower-trust caller or configured input path can bypass agent ID restrictions by submitting blank agent IDs, allowing actions that should require stronger…

  • CVE-2026-62218HigJul 17, 2026
    risk 0.00cvss 8.8epss 0.00

    OpenClaw 2026.1.20 before 2026.5.27 contain an authorization bypass vulnerability in the device.pair.approve feature that allows lower-trust callers to bypass role-management checks. Attackers can perform actions requiring stronger authorization by reaching the affected feature…

  • CVE-2026-62217HigJul 17, 2026
    risk 0.00cvss 8.8epss 0.00

    OpenClaw 2026.5.14-beta.1 before 2026.5.27 contain an authorization flaw in the QQBot exec approvals feature. When the feature is enabled and reachable, a lower-trust caller or configured input path could execute or persist actions beyond the caller's intended authorization,…

  • CVE-2026-62216MedJul 17, 2026
    risk 0.00cvss 5.0epss 0.00

    OpenClaw 2026.4.20 before 2026.5.28 contain a policy bypass in the QQBot media upload feature. A lower-trust caller or configured input path could cause the media upload to reach network destinations that should have been blocked by OpenClaw policy (server-side request forgery).…

  • CVE-2026-62215HigJul 17, 2026
    risk 0.00cvss 8.0epss 0.00

    OpenClaw versions before 2026.6.5 contain an authentication bypass vulnerability in HTTP Canvas responses that allows lower-trust callers to forge trusted A2UI actions. Attackers can perform actions requiring stronger authorization by submitting crafted requests through…

  • CVE-2026-62214MedJul 17, 2026
    risk 0.00cvss 6.5epss 0.00

    OpenClaw versions before 2026.5.28 Bot Framework contains an improper input validation vulnerability that allows lower-trust callers to expose bot tokens and credentials by failing to properly validate serviceUrl parameters. Attackers can supply malicious serviceUrl values…

  • CVE-2026-62213MedJul 17, 2026
    risk 0.00cvss 6.5epss 0.00

    OpenClaw versions before 2026.5.27 contain a token leakage vulnerability in MS Teams outbound requests that allows lower-trust callers to expose Bot Framework tokens. Attackers can access configured input paths to retrieve credentials that should remain within the trusted…

  • CVE-2026-62212HigJul 17, 2026
    risk 0.00cvss 7.1epss 0.00

    OpenClaw before 2026.5.28 contains a race condition in the MS Teams safeFetch DNS rebinding check. When the affected feature is enabled and reachable, a lower-trust caller or configured input path could win a timing window between the DNS validation check and use, allowing…

  • CVE-2026-62211MedJul 17, 2026
    risk 0.00cvss 5.0epss 0.00

    OpenClaw versions before 2026.6.1 contain a credential redaction bypass vulnerability in the trajectory export feature that allows lower-trust callers to access data that should remain within trusted boundaries. Attackers can exploit misconfigured input paths or feature…

  • CVE-2026-62210MedJul 17, 2026
    risk 0.00cvss 6.5epss 0.00

    OpenClaw versions before 2026.6.1 contain a denial of service vulnerability where remote media URLs can trigger slow-read attacks that exhaust gateway worker resources. Attackers with access to configured input paths can supply remote media URLs that consume gateway resources…

  • CVE-2026-62209HigJul 17, 2026
    risk 0.00cvss 8.1epss 0.00

    OpenClaw versions 2026.5.10-beta.1 before 2026.6.5 contain an authorization bypass in the ClickClack agent-mode dispatch feature, which could ignore the toolsAllow policy check. When the affected feature is enabled and reachable, a lower-trust caller or configured input path…

  • CVE-2026-62208MedJul 17, 2026
    risk 0.00cvss 6.5epss 0.00

    OpenClaw before 2026.6.5 could forward Authorization headers during MCP SSE redirects. When the affected feature is enabled and reachable, a lower-trust caller or configured input path could execute or persist actions beyond the caller's intended authorization. Impact depends on…

  • CVE-2026-62207HigJul 17, 2026
    risk 0.00cvss 8.8epss 0.00

    OpenClaw versions before 2026.6.5 contain an authentication bypass vulnerability that allows lower-trust callers to reach admin-scoped tools. Attackers can perform actions requiring stronger authorization by exploiting insufficient policy checks on configured input paths.