openclaw
84 known vulnerabilities affecting openclaw products.
Products
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-41363 | Low | 0.3% | 5.3 | OpenClaw versions 2026.2.6 through 2026.3.24 contain a path traversal vulnerabil… | |
| CVE-2026-41369 | Low | 0.3% | 6.5 | OpenClaw before 2026.3.31 contains insufficient environment variable sanitizatio… | |
| CVE-2026-40037 | Low | 0.3% | 6.5 | OpenClaw before 2026.3.31 (patched in 2026.4.8) contains a request body replay v… | |
| CVE-2026-34425 | Low | 0.3% | 5.4 | OpenClaw versions prior to commit 8aceaf5 contain a preflight validation bypass … | |
| CVE-2026-33578 | Low | 0.3% | 4.3 | OpenClaw before 2026.3.28 contains a sender policy bypass vulnerability in the G… | |
| CVE-2026-62216 | Low | 0.3% | 5.0 | OpenClaw 2026.4.20 before 2026.5.28 contain a policy bypass in the QQBot media u… | |
| CVE-2026-41362 | Low | 0.3% | 4.3 | OpenClaw versions 2026.2.19 before 2026.3.31 contain an improper cache isolation… | |
| CVE-2026-34505 | Low | 0.3% | 6.5 | OpenClaw before 2026.3.12 applies rate limiting only after successful webhook au… | |
| CVE-2026-34506 | Low | 0.3% | 4.3 | OpenClaw before 2026.3.8 contains a sender allowlist bypass vulnerability in its… | |
| CVE-2026-53839 | Low | 0.3% | 6.5 | OpenClaw before 2026.5.7 contains a hostname validation vulnerability in retry e… | |
| CVE-2026-53827 | Low | 0.3% | 6.5 | OpenClaw before 2026.5.2 contains a credential exposure vulnerability in message… | |
| CVE-2026-41372 | Low | 0.3% | 5.8 | OpenClaw before 2026.4.2 fails to normalize trailing-dot localhost hosts in remo… | |
| CVE-2026-62225 | Low | 0.2% | 5.4 | OpenClaw versions before 2026.5.18 contain an authorization bypass vulnerability… | |
| CVE-2026-32896 | Low | 0.2% | 4.8 | The BlueBubbles webhook handler in OpenClaw versions prior to 2026.2.21 contains… | |
| CVE-2026-62221 | Low | 0.2% | 5.4 | OpenClaw 2026.5.12 before 2026.5.26 contain an incorrect authorization vulnerabi… | |
| CVE-2026-34511 | Low | 0.2% | 5.3 | OpenClaw before 2026.4.2 reuses the PKCE verifier as the OAuth state parameter i… | |
| CVE-2026-41368 | Low | 0.2% | 6.5 | OpenClaw before 2026.3.28 contains an environment variable disclosure vulnerabil… | |
| CVE-2026-53830 | Low | 0.2% | 6.5 | OpenClaw before 2026.4.22 contains a webhook secret revocation bypass vulnerabil… | |
| CVE-2026-32921 | Low | 0.2% | 6.3 | OpenClaw before 2026.3.8 contains an approval bypass vulnerability in system.run… | |
| CVE-2026-32976 | Low | 0.2% | 6.5 | OpenClaw before 2026.3.11 contains an authorization bypass vulnerability allowin… | |
| CVE-2026-53837 | Low | 0.2% | 3.7 | OpenClaw before 2026.5.6 contains an improper access control vulnerability in Ma… | |
| CVE-2026-53826 | Low | 0.2% | 4.3 | OpenClaw before 2026.4.26 contains an information disclosure vulnerability in sa… | |
| CVE-2026-41366 | Low | 0.2% | 5.5 | OpenClaw before 2026.3.31 contains a local roots self-whitelisting vulnerability… | |
| CVE-2026-53824 | Low | 0.2% | 6.5 | OpenClaw before 2026.4.24 contains a token revocation vulnerability allowing cal… | |
| CVE-2026-41365 | Low | 0.2% | 5.4 | OpenClaw before 2026.3.31 contains a sender allowlist bypass vulnerability in MS… | |
| CVE-2026-32906 | Low | 0.2% | 4.3 | OpenClaw before 2026.5.12 contains a privilege escalation vulnerability in Slack… | |
| CVE-2026-53835 | Low | 0.2% | 4.3 | OpenClaw before 2026.5.6 contains a configuration enforcement bypass vulnerabili… | |
| CVE-2026-41367 | Low | 0.2% | 5.0 | OpenClaw versions 2026.2.14 through 2026.3.24 fail to consistently apply guild a… | |
| CVE-2026-35673 | Low | 0.2% | 6.5 | OpenClaw before 2026.4.29 contains an SSRF policy bypass vulnerability in browse… | |
| CVE-2026-62211 | Low | 0.2% | 5.0 | OpenClaw versions before 2026.6.1 contain a credential redaction bypass vulnerab… | |
| CVE-2026-34507 | Low | 0.1% | 5.4 | OpenClaw before 2026.4.29 contains a policy bypass vulnerability in QQBot admin … | |
| CVE-2026-32970 | Low | 0.1% | 2.5 | OpenClaw before 2026.3.11 contains a credential fallback vulnerability where una… | |
| CVE-2026-53820 | Low | 0.1% | 6.6 | OpenClaw before 2026.5.12 contains an exec denylist bypass vulnerability in the … | |
| CVE-2026-32977 | Low | 0.1% | 6.3 | OpenClaw before 2026.3.11 contains a sandbox boundary bypass vulnerability in th… |
← Prev Page 2 of 2