← All vendors

openclaw

84 known vulnerabilities affecting openclaw products.

Products

openclaw 84

Vulnerabilities by priority

CVEPriorityEPSSCVSSKEVWhat
CVE-2026-32917 Medium 2.0% 9.8 OpenClaw before 2026.3.13 contains a remote command injection vulnerability in t…
CVE-2026-53822 Medium 1.1% 8.8 OpenClaw before 2026.5.18 contains a command injection vulnerability where shell…
CVE-2026-33579 Medium 0.8% 9.9 OpenClaw before 2026.3.28 contains a privilege escalation vulnerability in the /…
CVE-2026-62229 Medium 0.7% 8.8 OpenClaw before 2026.5.18 contain an authorization bypass vulnerability in exec …
CVE-2026-62207 Medium 0.6% 8.8 OpenClaw versions before 2026.6.5 contain an authentication bypass vulnerability…
CVE-2026-62202 Medium 0.5% 8.8 OpenClaw versions 2026.6.1 before 2026.6.9 contain a privilege escalation vulner…
CVE-2026-41364 Medium 0.5% 8.1 OpenClaw before 2026.3.31 contains a symlink following vulnerability in SSH sand…
CVE-2026-62203 Medium 0.5% 8.8 OpenClaw versions before 2026.6.6 contain an environment variable filtering vuln…
CVE-2026-28474 Medium 0.5% 9.8 OpenClaw's Nextcloud Talk plugin versions prior to 2026.2.6 accept equality matc…
CVE-2026-32916 Medium 0.5% 9.4 OpenClaw versions 2026.3.7 before 2026.3.11 contain an authorization bypass vuln…
CVE-2026-53836 Medium 0.5% 8.8 OpenClaw before 2026.5.12 contains an allowlist bypass vulnerability in PowerShe…
CVE-2026-62218 Medium 0.5% 8.8 OpenClaw 2026.1.20 before 2026.5.27 contain an authorization bypass vulnerabilit…
CVE-2026-62228 Medium 0.5% 8.8 OpenClaw before 2026.6.5 contain an authorization bypass vulnerability in node e…
CVE-2026-62217 Medium 0.4% 8.8 OpenClaw 2026.5.14-beta.1 before 2026.5.27 contain an authorization flaw in the …
CVE-2026-32982 Medium 0.4% 7.5 OpenClaw before 2026.3.13 contains an information disclosure vulnerability in th…
CVE-2026-62196 Medium 0.4% 8.3 OpenClaw versions 2026.3.22 before 2026.6.6 contain an authorization bypass vuln…
CVE-2026-62227 Medium 0.4% 7.7 OpenClaw 2026.4.14 before 2026.5.26 contain a server-side request forgery vulner…
CVE-2026-33577 Medium 0.4% 8.1 OpenClaw before 2026.3.28 contains an insufficient scope validation vulnerabilit…
CVE-2026-62209 Medium 0.4% 8.1 OpenClaw versions 2026.5.10-beta.1 before 2026.6.5 contain an authorization bypa…
CVE-2026-62205 Medium 0.4% 7.1 OpenClaw versions 2026.4.12-beta.1 before 2026.6.6 contain a missing-authorizati…
CVE-2026-62226 Medium 0.3% 8.5 OpenClaw 2026.3.28 before 2026.5.19 contain an authorization bypass vulnerabilit…
CVE-2026-34503 Medium 0.3% 8.1 OpenClaw before 2026.3.28 fails to disconnect active WebSocket sessions when dev…
CVE-2026-32920 Medium 0.3% 8.4 OpenClaw before 2026.3.12 automatically discovers and loads plugins from .OpenCl…
CVE-2026-62219 Medium 0.3% 7.1 OpenClaw 2026.2.12 before 2026.5.26 contain an authorization bypass vulnerabilit…
CVE-2026-53821 Medium 0.3% 8.8 OpenClaw before 2026.5.18 accepts WebSocket client-declared operator scopes befo…
CVE-2026-32971 Medium 0.3% 7.1 OpenClaw before 2026.3.11 contains an approval-integrity vulnerability in node-h…
CVE-2026-53828 Medium 0.3% 8.8 OpenClaw before 2026.5.6 contains an authorization bypass vulnerability in nativ…
CVE-2026-34426 Medium 0.3% 7.6 OpenClaw versions prior to commit b57b680 contain an approval bypass vulnerabili…
CVE-2026-41371 Medium 0.3% 8.5 OpenClaw before 2026.3.28 contains a privilege escalation vulnerability in chat.…
CVE-2026-35674 Medium 0.3% 8.8 OpenClaw before 2026.5.18 contains a scope bypass vulnerability in the Gateway c…
CVE-2026-32905 Medium 0.2% 8.3 OpenClaw before 2026.5.4 contains an authorization bypass vulnerability in the b…
CVE-2026-53829 Medium 0.2% 8.0 OpenClaw before 2026.5.18 contains an approval display truncation vulnerability …
CVE-2026-53838 Medium 0.2% 9.8 OpenClaw before 2026.5.27 contains a state mutation vulnerability in node pairin…
CVE-2026-34504 Medium 0.2% 8.3 OpenClaw before 2026.3.28 contains a server-side request forgery vulnerability i…
CVE-2026-53823 Medium 0.2% 8.1 OpenClaw before 2026.5.3 contains a privilege escalation vulnerability in the al…
CVE-2026-35630 Medium 0.2% 8.0 OpenClaw before 2026.5.18 contains an authorization bypass vulnerability in QQBo…
CVE-2026-53831 Medium 0.2% 8.3 OpenClaw before 2026.5.18 contains a policy enforcement vulnerability in system.…
CVE-2026-53833 Medium 0.2% 7.7 OpenClaw before 2026.4.29 contains an authorization bypass vulnerability in the …
CVE-2026-62222 Medium 0.2% 7.8 OpenClaw before 2026.5.22 contain a vulnerability in setup-mode discovery that a…
CVE-2026-53832 Medium 0.1% 7.7 OpenClaw before 2026.5.18 contains an identity header validation vulnerability a…
CVE-2026-32988 Medium 0.1% 7.5 OpenClaw before 2026.3.11 contains a sandbox boundary bypass vulnerability in fs…
CVE-2026-33581 Low 0.6% 6.5 OpenClaw before 2026.3.24 contains a sandbox bypass vulnerability in the message…
CVE-2026-62220 Low 0.5% 5.3 OpenClaw 2026.2.25 before 2026.5.26 allow a lower-trust caller or configured inp…
CVE-2026-62210 Low 0.5% 6.5 OpenClaw versions before 2026.6.1 contain a denial of service vulnerability wher…
CVE-2026-41370 Low 0.4% 6.5 OpenClaw before 2026.3.31 contains a path traversal vulnerability in ACP dispatc…
CVE-2026-53825 Low 0.4% 6.5 OpenClaw before 2026.4.7 contains an arbitrary file read vulnerability in the me…
CVE-2026-28465 Low 0.4% 5.9 OpenClaw's voice-call plugin versions before 2026.2.3 contain an improper authen…
CVE-2026-33580 Low 0.4% 6.5 OpenClaw before 2026.3.28 contains a missing rate limiting vulnerability in the …
CVE-2026-62213 Low 0.4% 6.5 OpenClaw versions before 2026.5.27 contain a token leakage vulnerability in MS T…
CVE-2026-33576 Low 0.4% 6.5 OpenClaw before 2026.3.28 downloads and stores inbound media from Zalo channels …
Page 1 of 2 Next →