VYPR

Openclaw

by OpenClaw

npm: openclaw

Source repositories

CVEs (660)

  • CVE-2026-62203HigJul 17, 2026
    risk 0.00cvss 8.8epss 0.01

    OpenClaw versions before 2026.6.6 contain an environment variable filtering vulnerability in host exec that fails to properly sanitize rustup startup variables. Attackers with lower-trust caller access or configured input paths can execute or persist actions beyond their…

  • CVE-2026-62202HigJul 17, 2026
    risk 0.00cvss 8.8epss 0.01

    OpenClaw versions 2026.6.1 before 2026.6.9 contain a privilege escalation vulnerability in isolated cron jobs that allows lower-trust callers to regain denied execution tools. Attackers can execute or persist actions beyond their intended authorization by leveraging…

  • CVE-2026-62201HigJul 17, 2026
    risk 0.00cvss 7.7epss 0.00

    OpenClaw versions before 2026.6.6 contain a network policy bypass vulnerability in the sandbox exec-server that allows lower-trust callers to reach internal network destinations blocked by OpenClaw policy. Attackers can send HTTP requests through the exec-server to access…

  • CVE-2026-62200HigJul 13, 2026
    risk 0.00cvss 8.8epss 0.01

    OpenClaw versions before 2026.6.6 contain a flaw in host exec environment filtering that could allow Git ext transport to be abused. When the affected feature is enabled and reachable, a lower-trust caller or configured input path could execute or persist actions beyond the…

  • CVE-2026-62199HigJul 13, 2026
    risk 0.00cvss 8.8epss 0.01

    OpenClaw versions before 2026.6.6 contain a flaw in host exec environment filtering that can miss interpreter startup variables. When the affected feature is enabled and reachable, a lower-trust caller or configured input path can supply crafted environment variables to execute…

  • CVE-2026-62198MedJul 13, 2026
    risk 0.00cvss 4.3epss 0.00

    OpenClaw versions 2026.5.28 before 2026.6.6 contain an authorization bypass vulnerability in native web search that allows lower-trust callers to perform actions requiring stronger policy checks. Attackers can exploit misconfigured input paths to bypass intended authorization…

  • CVE-2026-62197HigJul 13, 2026
    risk 0.00cvss 8.5epss 0.00

    OpenClaw before 2026.6.6 contains a policy bypass vulnerability in browser CDP discovery that accepts blocked WebSocket URLs. Attackers with lower-trust access can reach network destinations that should have been blocked by OpenClaw policy when the affected feature is enabled.

  • CVE-2026-62195HigJul 13, 2026
    risk 0.00cvss 8.3epss 0.00

    OpenClaw versions 2026.5.20 before 2026.6.6 contain an authorization bypass vulnerability in the MCP loopback feature that allows lower-trust callers to execute owner-only tools. Attackers can bypass authorization checks through configured input paths to execute or persist…

  • CVE-2026-62194HigJul 13, 2026
    risk 0.00cvss 8.8epss 0.00

    OpenClaw versions 2026.5.20 before 2026.6.9 contain a privilege escalation vulnerability in plugin install commands that allows lower-trust callers to execute or persist actions beyond their intended authorization. Attackers can exploit misconfigured input paths or enabled…

  • CVE-2026-62193MedJul 13, 2026
    risk 0.00cvss 4.9epss 0.00

    OpenClaw versions 2026.6.5 before 2026.6.9 contain a vulnerability in the plugin install wrappers that could skip the install policy (authorization) check. When the affected feature is enabled and reachable, a lower-trust caller or a configured input path could execute or…

  • CVE-2026-62192HigJul 13, 2026
    risk 0.00cvss 8.1epss 0.00

    OpenClaw versions 2026.6.6 before 2026.6.9 contain an authorization bypass vulnerability in Discord guild actions that allows lower-trust callers to perform actions requiring stronger authorization checks. Attackers can exploit misconfigured input paths to skip cross-provider…

  • CVE-2026-62191HigJul 13, 2026
    risk 0.00cvss 7.1epss 0.00

    OpenClaw versions 2026.6.6 before 2026.6.9 contain an authorization bypass vulnerability in message mutation handling that allows lower-trust callers to perform actions requiring stronger authorization checks. Attackers can exploit misconfigured input paths to skip requester…

  • CVE-2026-62190HigJul 13, 2026
    risk 0.00cvss 8.8epss 0.01

    OpenClaw versions before 2026.6.9 contain an authorization bypass vulnerability in the flock wrapper that allows lower-trust callers to execute or persist actions beyond their intended authorization. Attackers can leverage configured input paths to bypass durable exec approval…

  • CVE-2026-62189HigJul 13, 2026
    risk 0.00cvss 7.1epss 0.00

    OpenClaw versions before 2026.6.9 contain a symlink following vulnerability in the mirror sync feature that allows lower-trust callers to perform actions requiring stronger authorization. Attackers can exploit remote symlink parents to bypass policy checks and authorization…

  • CVE-2026-62188HigJul 13, 2026
    risk 0.00cvss 8.1epss 0.00

    OpenClaw @openclaw/feishu versions 2026.6.6 and earlier contain an incorrect authorization vulnerability in which the Feishu permission tools could ignore per-account disablement settings. When the affected feature is enabled and reachable, a lower-trust caller or configured…

  • CVE-2026-62187HigJul 13, 2026
    risk 0.00cvss 8.1epss 0.00

    OpenClaw Feishu tools (npm package @openclaw/feishu) in versions <= 2026.6.6 could ignore per-account disablement. A lower-trust caller or a configured input path could perform actions that should have required a stronger authorization or policy check, resulting in unauthorized…

  • CVE-2026-62186HigJul 13, 2026
    risk 0.00cvss 7.6epss 0.00

    OpenClaw versions before 2026.6.8 contain an authorization bypass vulnerability in OpenAI-compatible HTTP model overrides that allows lower-trust callers to perform actions requiring stronger authorization checks. Attackers can exploit misconfigured input paths to bypass admin…

  • CVE-2026-59261HigJul 8, 2026
    risk 0.00cvss 7.1epss 0.00

    OpenClaw before 2026.5.28 contains a credential exposure vulnerability where workspace dotenv files can override provider credentials. Attackers with lower-trust access to configured input paths can expose sensitive data and credentials that should remain within trusted…

  • CVE-2026-28485HigMar 5, 2026
    risk 0.00cvss 8.4epss 0.00

    OpenClaw versions 2026.1.5 prior to 2026.2.12 fail to enforce mandatory authentication on the /agent/act browser-control HTTP route, allowing unauthorized local callers to invoke privileged operations. Remote attackers on the local network or local processes can execute…

  • CVE-2026-28478HigMar 5, 2026
    risk 0.00cvss 7.5epss 0.01

    OpenClaw versions prior to 2026.2.13 contain a denial of service vulnerability in webhook handlers that buffer request bodies without strict byte or time limits. Remote unauthenticated attackers can send oversized JSON payloads or slow uploads to webhook endpoints causing memory…

Page 33 of 33