← All vendors

openclaw

84 known vulnerabilities affecting openclaw products.

Products

openclaw 84

Vulnerabilities by priority

CVEPriorityEPSSCVSSKEVWhat
CVE-2026-41363 Low 0.3% 5.3 OpenClaw versions 2026.2.6 through 2026.3.24 contain a path traversal vulnerabil…
CVE-2026-41369 Low 0.3% 6.5 OpenClaw before 2026.3.31 contains insufficient environment variable sanitizatio…
CVE-2026-40037 Low 0.3% 6.5 OpenClaw before 2026.3.31 (patched in 2026.4.8) contains a request body replay v…
CVE-2026-34425 Low 0.3% 5.4 OpenClaw versions prior to commit 8aceaf5 contain a preflight validation bypass …
CVE-2026-33578 Low 0.3% 4.3 OpenClaw before 2026.3.28 contains a sender policy bypass vulnerability in the G…
CVE-2026-62216 Low 0.3% 5.0 OpenClaw 2026.4.20 before 2026.5.28 contain a policy bypass in the QQBot media u…
CVE-2026-41362 Low 0.3% 4.3 OpenClaw versions 2026.2.19 before 2026.3.31 contain an improper cache isolation…
CVE-2026-34505 Low 0.3% 6.5 OpenClaw before 2026.3.12 applies rate limiting only after successful webhook au…
CVE-2026-34506 Low 0.3% 4.3 OpenClaw before 2026.3.8 contains a sender allowlist bypass vulnerability in its…
CVE-2026-53839 Low 0.3% 6.5 OpenClaw before 2026.5.7 contains a hostname validation vulnerability in retry e…
CVE-2026-53827 Low 0.3% 6.5 OpenClaw before 2026.5.2 contains a credential exposure vulnerability in message…
CVE-2026-41372 Low 0.3% 5.8 OpenClaw before 2026.4.2 fails to normalize trailing-dot localhost hosts in remo…
CVE-2026-62225 Low 0.2% 5.4 OpenClaw versions before 2026.5.18 contain an authorization bypass vulnerability…
CVE-2026-32896 Low 0.2% 4.8 The BlueBubbles webhook handler in OpenClaw versions prior to 2026.2.21 contains…
CVE-2026-62221 Low 0.2% 5.4 OpenClaw 2026.5.12 before 2026.5.26 contain an incorrect authorization vulnerabi…
CVE-2026-34511 Low 0.2% 5.3 OpenClaw before 2026.4.2 reuses the PKCE verifier as the OAuth state parameter i…
CVE-2026-41368 Low 0.2% 6.5 OpenClaw before 2026.3.28 contains an environment variable disclosure vulnerabil…
CVE-2026-53830 Low 0.2% 6.5 OpenClaw before 2026.4.22 contains a webhook secret revocation bypass vulnerabil…
CVE-2026-32921 Low 0.2% 6.3 OpenClaw before 2026.3.8 contains an approval bypass vulnerability in system.run…
CVE-2026-32976 Low 0.2% 6.5 OpenClaw before 2026.3.11 contains an authorization bypass vulnerability allowin…
CVE-2026-53837 Low 0.2% 3.7 OpenClaw before 2026.5.6 contains an improper access control vulnerability in Ma…
CVE-2026-53826 Low 0.2% 4.3 OpenClaw before 2026.4.26 contains an information disclosure vulnerability in sa…
CVE-2026-41366 Low 0.2% 5.5 OpenClaw before 2026.3.31 contains a local roots self-whitelisting vulnerability…
CVE-2026-53824 Low 0.2% 6.5 OpenClaw before 2026.4.24 contains a token revocation vulnerability allowing cal…
CVE-2026-41365 Low 0.2% 5.4 OpenClaw before 2026.3.31 contains a sender allowlist bypass vulnerability in MS…
CVE-2026-32906 Low 0.2% 4.3 OpenClaw before 2026.5.12 contains a privilege escalation vulnerability in Slack…
CVE-2026-53835 Low 0.2% 4.3 OpenClaw before 2026.5.6 contains a configuration enforcement bypass vulnerabili…
CVE-2026-41367 Low 0.2% 5.0 OpenClaw versions 2026.2.14 through 2026.3.24 fail to consistently apply guild a…
CVE-2026-35673 Low 0.2% 6.5 OpenClaw before 2026.4.29 contains an SSRF policy bypass vulnerability in browse…
CVE-2026-62211 Low 0.2% 5.0 OpenClaw versions before 2026.6.1 contain a credential redaction bypass vulnerab…
CVE-2026-34507 Low 0.1% 5.4 OpenClaw before 2026.4.29 contains a policy bypass vulnerability in QQBot admin …
CVE-2026-32970 Low 0.1% 2.5 OpenClaw before 2026.3.11 contains a credential fallback vulnerability where una…
CVE-2026-53820 Low 0.1% 6.6 OpenClaw before 2026.5.12 contains an exec denylist bypass vulnerability in the …
CVE-2026-32977 Low 0.1% 6.3 OpenClaw before 2026.3.11 contains a sandbox boundary bypass vulnerability in th…
← Prev Page 2 of 2