Openclaw CVE Vulnerabilities & CVE List (582)

Products (CPE): — CVEs: 582

Openclaw vulnerability overview

Aggregates CVE and security vulnerability intelligence across all Openclaw-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.

Historical issues mainly involve vendor risk path handling, vendor risk ssrf, and vendor risk file inclusion and related problems; some flaws may lead to vendor impact file overwrite and vendor impact unauthorized access.

Vulnerability distribution trend (last 24 months)

Showing 120 of 582 CVEs
«« First « Prev Page 1 / 30 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2026-62229 OpenClaw before 2026.5.18 contain an authorization bypass vulnerability in exec allowlist glob matching that allows lower-trust callers to execute actions beyond intended authorization. Attackers can craft input paths that traverse the allowlist glob patterns to execute or persist unauthorized actions when the affected feature is enabled. [email protected] 7.7 0.46% 2026-07-16 2026-07-18
CVE-2026-62228 OpenClaw before 2026.6.5 contain an authorization bypass vulnerability in node exec approvals that allows lower-trust callers to execute actions beyond their intended authorization by using different gateway and node environments. Attackers can exploit mismatched environment configurations to persist or execute actions that exceed the caller's approved permissions. [email protected] 7.7 0.26% 2026-07-16 2026-07-18
CVE-2026-62227 OpenClaw 2026.4.14 before 2026.5.26 contain a server-side request forgery vulnerability in browser snapshot routes that fail to validate post-navigation destinations. Attackers with lower-trust access can bypass OpenClaw policy checks to reach network destinations that should have been blocked. [email protected] 4.9 0.24% 2026-07-16 2026-07-17
CVE-2026-62226 OpenClaw 2026.3.28 before 2026.5.19 contain an authorization bypass vulnerability in the browser act route that fails to properly validate current-tab URL checks. Attackers with lower-trust access or configured input paths can perform actions requiring stronger authorization or policy checks. [email protected] 5.1 0.25% 2026-07-16 2026-07-17
CVE-2026-62225 OpenClaw versions before 2026.5.18 contain an authorization bypass vulnerability in skill command dispatch that allows lower-trust callers to execute or persist actions beyond their intended authorization. Attackers can bypass tool policy restrictions through configured input paths to perform unauthorized actions when the affected feature is enabled and reachable. [email protected] 2.3 0.15% 2026-07-16 2026-07-20
CVE-2026-62223 OpenClaw before 2026.5.18 contain an authorization bypass vulnerability in the device-pair approval feature that allows lower-trust callers to execute actions beyond their intended authorization. Attackers can exploit misconfigured input paths to execute or persist unauthorized actions when the affected feature is enabled and reachable. [email protected] 7.7 0.26% 2026-07-16 2026-07-20
CVE-2026-62222 OpenClaw before 2026.5.22 contain a vulnerability in setup-mode discovery that allows loading of untrusted workspace plugins. Attackers with lower-trust caller access or control over configured input paths can execute or persist actions beyond their intended authorization level. [email protected] 7.1 0.12% 2026-07-16 2026-07-20
CVE-2026-62221 OpenClaw 2026.5.12 before 2026.5.26 contain an incorrect authorization vulnerability in the ClickClack allowFrom feature. When the affected feature is enabled and reachable, a lower-trust caller or configured input path could execute or persist actions beyond the caller's intended authorization, including running non-allowlisted commands. [email protected] 2.3 0.14% 2026-07-16 2026-07-17
CVE-2026-62220 OpenClaw 2026.2.25 before 2026.5.26 allow a lower-trust caller or configured input path to bypass non-browser rate limits on WebSocket authentication attempts. When the affected feature is enabled and reachable by lower-trust input, this can consume gateway resources and reduce service availability. [email protected] 6.3 0.31% 2026-07-16 2026-07-17
CVE-2026-62219 OpenClaw 2026.2.12 before 2026.5.26 contain an authorization bypass vulnerability in the hooks allowedAgentIds validation. A lower-trust caller or configured input path can bypass agent ID restrictions by submitting blank agent IDs, allowing actions that should require stronger authorization or policy checks. [email protected] 6.0 0.18% 2026-07-16 2026-07-20
CVE-2026-62218 OpenClaw 2026.1.20 before 2026.5.27 contain an authorization bypass vulnerability in the device.pair.approve feature that allows lower-trust callers to bypass role-management checks. Attackers can perform actions requiring stronger authorization by reaching the affected feature through configured input paths. [email protected] 8.7 0.26% 2026-07-16 2026-07-18
CVE-2026-62217 OpenClaw 2026.5.14-beta.1 before 2026.5.27 contain an authorization flaw in the QQBot exec approvals feature. When the feature is enabled and reachable, a lower-trust caller or configured input path could execute or persist actions beyond the caller's intended authorization, allowing non-allowlisted senders to perform unauthorized operations. [email protected] 7.7 0.25% 2026-07-16 2026-07-18
CVE-2026-62216 OpenClaw 2026.4.20 before 2026.5.28 contain a policy bypass in the QQBot media upload feature. A lower-trust caller or configured input path could cause the media upload to reach network destinations that should have been blocked by OpenClaw policy (server-side request forgery). The practical impact depends on the operator's configuration and whether lower-trust input can reach that path. [email protected] 2.3 0.22% 2026-07-16 2026-07-17
CVE-2026-62215 OpenClaw versions before 2026.6.5 contain an authentication bypass vulnerability in HTTP Canvas responses that allows lower-trust callers to forge trusted A2UI actions. Attackers can perform actions requiring stronger authorization by submitting crafted requests through configured input paths, bypassing intended policy checks. [email protected] 5.1 0.18% 2026-07-16 2026-07-20
CVE-2026-62214 OpenClaw versions before 2026.5.28 Bot Framework contains an improper input validation vulnerability that allows lower-trust callers to expose bot tokens and credentials by failing to properly validate serviceUrl parameters. Attackers can supply malicious serviceUrl values through configured input paths to retrieve sensitive authentication data outside the trusted boundary. [email protected] 6.0 0.31% 2026-07-16 2026-07-20
CVE-2026-62213 OpenClaw versions before 2026.5.27 contain a token leakage vulnerability in MS Teams outbound requests that allows lower-trust callers to expose Bot Framework tokens. Attackers can access configured input paths to retrieve credentials that should remain within the trusted boundary. [email protected] 6.0 0.26% 2026-07-16 2026-07-20
CVE-2026-62212 OpenClaw before 2026.5.28 contains a race condition in the MS Teams safeFetch DNS rebinding check. When the affected feature is enabled and reachable, a lower-trust caller or configured input path could win a timing window between the DNS validation check and use, allowing actions that should have required a stronger authorization or policy check. Practical impact depends on the operator's configuration and whether lower-trust input can reach that path. [email protected] 5.1 0.17% 2026-07-16 2026-07-20
CVE-2026-62211 OpenClaw versions before 2026.6.1 contain a credential redaction bypass vulnerability in the trajectory export feature that allows lower-trust callers to access data that should remain within trusted boundaries. Attackers can exploit misconfigured input paths or feature accessibility to expose sensitive credentials and data through the export mechanism. [email protected] 4.1 0.12% 2026-07-16 2026-07-20
CVE-2026-62210 OpenClaw versions before 2026.6.1 contain a denial of service vulnerability where remote media URLs can trigger slow-read attacks that exhaust gateway worker resources. Attackers with access to configured input paths can supply remote media URLs that consume gateway resources and reduce availability. [email protected] 6.0 0.31% 2026-07-16 2026-07-20
CVE-2026-62209 OpenClaw versions 2026.5.10-beta.1 before 2026.6.5 contain an authorization bypass in the ClickClack agent-mode dispatch feature, which could ignore the toolsAllow policy check. When the affected feature is enabled and reachable, a lower-trust caller or configured input path could perform actions that should have required a stronger authorization or policy check. [email protected] 7.6 0.22% 2026-07-16 2026-07-18
«« First « Prev Page 1 / 30 Next »
cvelogic Threat Intelligence