Package impact

npm NPM / openclaw

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2026-44110 high 8.8 8.8 28d ago OpenClaw: Matrix room control-command authorization no longer trusts DM pairing-store entries
CVE-2026-43584 high 8.8 8.8 28d ago OpenClaw: Exec environment denylist missed high-risk interpreter startup variables
CVE-2026-43571 high 8.8 8.8 1mo ago OpenClaw: Channel setup catalog lookups could include untrusted workspace plugin shadows
CVE-2026-43569 high 8.8 8.8 1mo ago OpenClaw: Workspace provider auth choices could auto-enable untrusted provider plugins
CVE-2026-43531 high 8.8 8.8 1mo ago OpenClaw: Workspace .env could inject OpenClaw runtime-control variables
CVE-2026-43530 high 8.8 8.8 1mo ago OpenClaw: busybox and toybox applet execution weakened exec approval binding
CVE-2026-42435 high 8.8 8.8 1mo ago OpenClaw: Shell-wrapper detection missed env-argv assignment injection forms
CVE-2026-42434 high 8.8 8.8 1mo ago OpenClaw: Sandboxed agents could escape exec routing via host=node override
CVE-2026-42426 high 8.8 8.8 1mo ago OpenClaw `node.pair.approve` placed in `operator.write` scope instead of `operator.pairing` allows unprivileged pairing approval
CVE-2026-42422 high 8.8 8.8 1mo ago OpenClaw `device.token.rotate` mints tokens for unapproved roles, bypassing device role-upgrade pairing
CVE-2026-41404 high 8.8 8.8 1mo ago OpenClaw: Incomplete scope-clearing fix allows operator.admin escalation via trusted-proxy auth mode
CVE-2026-41378 high 8.8 8.8 1mo ago OpenClaw: Paired node escalates to gateway RCE via unrestricted node.event agent dispatch
CVE-2026-41359 high 8.8 8.8 1mo ago OpenClaw: Gateway operator.write Can Reach Admin-Class Telegram Config and Cron Persistence via send
CVE-2026-41352 high 8.8 8.8 1mo ago OpenClaw: Device-Paired Node Skips Node Scope Gate → Host RCE.md
CVE-2026-41344 high 8.8 8.8 1mo ago OpenClaw: Gateway `operator.write` can reach admin-only persisted `verboseLevel` via `chat.send` `/verbose`
CVE-2026-44116 high 8.6 8.6 28d ago OpenClaw validates Zalo outbound photo URLs through the SSRF guard
CVE-2026-43533 high 8.6 8.6 1mo ago OpenClaw: QQBot media tags could read arbitrary local files through reply text
CVE-2026-42439 high 8.5 8.5 1mo ago OpenClaw: Browser tabs action select and close routes bypassed SSRF policy
CVE-2026-41914 high 8.5 8.5 1mo ago OpenClaw QQ Bot Extension missing SSRF Protection on All Media Fetch Paths
CVE-2026-41394 high 8.2 8.2 1mo ago OpenClaw: Unauthenticated plugin-auth HTTP routes receive operator runtime scopes
CVE-2026-43535 high 8.1 8.1 1mo ago OpenClaw: Collect-mode queue batches could reuse the last sender authorization context
CVE-2026-42431 high 8.1 8.1 1mo ago OpenClaw `node.invoke(browser.proxy)` bypasses `browser.request` persistent profile-mutation guard
CVE-2026-41383 high 8.1 8.1 1mo ago OpenClaw: OpenShell mirror mode could delete arbitrary remote directories when roots were mis-scoped
CVE-2026-41364 high 8.1 8.1 1mo ago OpenClaw: SSH sandbox tar upload follows symlinks, enabling arbitrary file write on remote host
CVE-2026-41342 high 8.1 8.1 1mo ago OpenClaw: CLI Remote Onboarding Persists Unauthenticated Discovery Endpoint and Exfiltrates Gateway Credentials
CVE-2026-45004 high 7.8 7.8 24d ago OpenClaw vulnerable to arbitrary code execution via attacker-controlled setup-api.js loaded from cwd during env-key resolution
CVE-2026-44118 high 7.8 7.8 28d ago OpenClaw: MCP loopback owner context is derived from server-issued bearer tokens
CVE-2026-44114 high 7.8 7.8 28d ago OpenClaw: Workspace dotenv could override runtime-control environment variables
CVE-2026-42432 high 7.8 7.8 1mo ago OpenClaw: Node Pairing Reconnect Command Escalation Bypasses operator.admin Scope Requirement
CVE-2026-41396 high 7.8 7.8 1mo ago OpenClaw: Workspace `.env` can override the bundled plugin trust root
CVE-2026-41387 high 7.8 7.8 1mo ago OpenClaw's incomplete host env sanitization blocklist allows supply-chain redirection via package-manager env overrides
CVE-2026-41384 high 7.8 7.8 1mo ago OpenClaw Has Incomplete Fix for CVE-2026-4039: CLI Backend Environment Variable Injection via Workspace Config
CVE-2026-41336 high 7.8 7.8 1mo ago OpenClaw: Workspace `.env` can override the bundled hooks root and load attacker hook code
CVE-2026-44113 high 7.7 7.7 28d ago OpenClaw: OpenShell FS bridge reads pin and verify the opened file before returning bytes
CVE-2026-43580 high 7.7 7.7 28d ago OpenClaw: Browser press/type interaction routes missed complete navigation guard coverage
CVE-2026-43576 high 7.7 7.7 28d ago OpenClaw: CDP /json/version WebSocket URL could pivot to untrusted second-hop targets
CVE-2026-43573 high 7.7 7.7 1mo ago OpenClaw: Existing-session browser interaction routes bypassed SSRF policy enforcement
CVE-2026-43532 high 7.7 7.7 1mo ago OpenClaw: Discord event cover images bypassed sandbox media normalization
CVE-2026-43527 high 7.7 7.7 1mo ago OpenClaw: Browser SSRF policy default allowed private-network navigation
CVE-2026-42438 high 7.7 7.7 1mo ago OpenClaw: Sender policy bypass in host media attachment reads allows unauthorized local file disclosure
CVE-2026-42436 high 7.7 7.7 1mo ago OpenClaw: Browser snapshot and screenshot routes could expose internal page content after navigation
CVE-2026-41912 high 7.6 7.6 1mo ago OpenClaw has Browser SSRF Policy Bypass via Interaction-Triggered Navigation
CVE-2026-42437 high 7.5 7.5 1mo ago OpenClaw: Voice-call realtime WebSocket accepted oversized frames
CVE-2026-42423 high 7.5 7.5 1mo ago OpenClaw: strictInlineEval explicit-approval boundary bypassed by approval-timeout fallback on gateway and node exec hosts
CVE-2026-41405 high 7.5 7.5 1mo ago OpenClaw: MS Teams webhook parses body before JWT validation, enabling unauthenticated resource exhaustion
CVE-2026-41400 high 7.5 7.5 1mo ago OpenClaw: Voice-call still parses large WebSocket frames before start validation (Incomplete fix for CVE-2026-32062)
CVE-2026-41399 high 7.5 7.5 1mo ago OpenClaw: Gateway WebSocket Denial of Service via unbounded pre-auth upgrades
CVE-2026-41395 high 7.5 7.5 1mo ago OpenClaw: Voice-call Plivo V3 webhook replay key uses unsorted URL, allowing replay via query-parameter reordering
CVE-2026-41346 high 7.5 7.5 1mo ago OpenClaw: Pairing pending-request caps were enforced per channel instead of per account
CVE-2026-44995 high 7.3 7.3 24d ago OpenClaw: MCP stdio server env could load dangerous startup variables from workspace config
CVE-2026-41392 high 7.3 7.3 1mo ago OpenClaw: Shell init-file options could satisfy exec allowlist script matching
CVE-2026-41390 high 7.3 7.3 1mo ago OpenClaw has a gateway exec allowlist allow-always bypass via unregistered /usr/bin/script wrapper
CVE-2026-41380 high 7.3 7.3 1mo ago OpenClaw gateway exec allow-always over-trusts positional carrier executables
CVE-2026-41355 high 7.3 7.3 1mo ago OpenClaw: OpenShell `mirror` mode can convert untrusted sandbox files into explicitly enabled workspace hooks and execute them on the host during gateway startup
CVE-2026-42429 high 7.1 7.1 1mo ago OpenClaw: Gateway plugin HTTP `auth: gateway` widens identity-bearing `operator.read` requests into runtime `operator.write`
CVE-2026-42428 high 7.1 7.1 1mo ago OpenClaw B-M3: ClawHub package downloads are not enforced with integrity verification
CVE-2026-41379 high 7.1 7.1 1mo ago OpenClaw: Gateway operator.write Can Reach Admin-Class Talk Voice Config Persistence via chat.send
CVE-2026-41347 high 7.1 7.1 1mo ago OpenClaw: HTTP operator endpoints lack browser-origin validation in trusted-proxy mode
CVE-2026-43583 medium 6.5 6.5 28d ago OpenClaw: Delivery queue recovery could lose group tool-policy context for media replay
CVE-2026-43574 medium 6.5 6.5 1mo ago OpenClaw: Empty approver lists could grant explicit approval authorization
CVE-2026-43570 medium 6.5 6.5 1mo ago OpenClaw contains a symlink traversal vulnerability
CVE-2026-43568 medium 6.5 6.5 1mo ago OpenClaw: Memory dreaming config persistence was reachable from operator.write commands
CVE-2026-43567 medium 6.5 6.5 1mo ago OpenClaw: screen_record outPath bypassed workspace-only filesystem guard
CVE-2026-43528 medium 6.5 6.5 1mo ago OpenClaw: config.get redaction bypass through sourceConfig and runtimeConfig aliases
CVE-2026-42433 medium 6.5 6.5 1mo ago OpenClaw: Matrix profile config persistence was reachable from operator.write message tools
CVE-2026-42430 medium 6.5 6.5 1mo ago OpenClaw: Strict browser SSRF bypass in Playwright redirect handling leaves private targets reachable
CVE-2026-42420 medium 6.5 6.5 1mo ago OpenClaw: Multiple Code Paths Missing Base64 Pre-Allocation Size Checks
CVE-2026-41911 medium 6.5 6.5 1mo ago OpenClaw: Feishu docx upload_file/upload_image Bypasses Workspace-Only Filesystem Policy (GHSA-qf48-qfv4-jjm9 Incomplete Fix)
CVE-2026-41408 medium 6.5 6.5 1mo ago OpenClaw: Tlon media downloads can bypass core safety limits and exhaust disk
CVE-2026-41388 medium 6.5 6.5 1mo ago OpenClaw: Tlon Startup Migration Rehydrates Empty-Array Revocations From File Config
CVE-2026-41385 medium 6.5 6.5 1mo ago OpenClaw Nostr privateKey config redaction bypass leaks plaintext signing key via config.get
CVE-2026-41376 medium 6.5 6.5 1mo ago OpenClaw: Matrix thread root and reply context bypass sender allowlist
CVE-2026-41375 medium 6.5 6.5 1mo ago OpenClaw: `/phone arm`/`/phone disarm` Bypasses `operator.admin` Scope Check for External Channels
CVE-2026-41369 medium 6.5 6.5 1mo ago OpenClaw: Host exec environment sanitization misses package, registry, Docker, compiler, and TLS override variables
CVE-2026-41363 medium 6.5 6.5 1mo ago OpenClaw: Feishu extension resolveUploadInput bypasses file-system sandbox and allows arbitrary file reads via upload_image
CVE-2026-41908 medium 6.5 6.5 1mo ago OpenClaw: Assistant media route missed scope enforcement for trusted-proxy authorization
CVE-2026-43582 medium 6.3 6.3 28d ago OpenClaw: Browser SSRF hostname validation could be bypassed by DNS rebinding
CVE-2026-41915 medium 6.1 6.1 1mo ago OpenClaw: GIT_DIR and related git plumbing env vars missing from exec env denylist (GHSA-m866-6qv5-p2fg variant)
CVE-2026-41391 medium 6.1 6.1 1mo ago OpenClaw: PIP_INDEX_URL and UV_INDEX_URL bypass host exec env sanitization and redirect Python package-index traffic
CVE-2026-41373 medium 6.1 6.1 1mo ago OpenClaw: Incomplete host-env-security-policy allows untrusted model to substitute compiler binaries via env overrides
CVE-2026-45005 medium 6.0 6.0 24d ago OpenClaw's Webhooks SecretRef route secret remains valid after rotation/reload
CVE-2026-44117 medium 5.8 5.8 28d ago OpenClaw: QQBot direct media upload skipped URL SSRF validation
CVE-2026-41372 medium 5.8 5.8 1mo ago OpenClaw: Trailing-dot localhost CDP hosts could bypass remote loopback protections
CVE-2026-41389 medium 5.8 5.8 2mo ago OpenClaw: Webchat media embedding enforces local-root containment for tool-result files
CVE-2026-42421 medium 5.4 5.4 1mo ago OpenClaw: Existing WS sessions survive shared gateway token rotation
CVE-2026-41916 medium 5.4 5.4 1mo ago OpenClaw: resolvedAuth closure becomes stale after config reload
CVE-2026-41406 medium 5.4 5.4 1mo ago OpenClaw: Feishu thread history and quoted messages bypass sender allowlist
CVE-2026-41402 medium 5.4 5.4 1mo ago OpenClaw: Zalo webhook replay cache cross-target messageId scope bypass
CVE-2026-41382 medium 5.4 5.4 1mo ago OpenClaw: Discord voice ingress authorization can be bypassed via channel, name, and stale-role validation gaps
CVE-2026-41381 medium 5.4 5.4 1mo ago OpenClaw: Discord voice manager bypasses channel-level member access allowlist
CVE-2026-41365 medium 5.4 5.4 1mo ago OpenClaw: MSTeams thread history bypasses sender allowlist via Graph API
CVE-2026-41358 medium 5.4 5.4 1mo ago OpenClaw: Slack thread context could include messages from non-allowlisted senders
CVE-2026-41356 medium 5.4 5.4 1mo ago OpenClaw: Gateway `device.token.rotate` does not terminate active WebSocket sessions after credential rotation
CVE-2026-41348 medium 5.4 5.4 1mo ago OpenClaw: Discord Slash Commands Bypass Group DM Channel Allowlist
CVE-2026-41341 medium 5.4 5.4 1mo ago OpenClaw: Discord Component Interaction Misclassifies Group DM as Direct Message
CVE-2026-45002 medium 5.3 5.3 24d ago OpenClaw: Hook mapping templates could bypass hook session-key opt-in
CVE-2026-44999 medium 5.3 5.3 24d ago OpenClaw: Isolated cron awareness events were recorded as trusted system events
CVE-2026-43572 medium 5.3 5.3 1mo ago OpenClaw: Microsoft Teams SSO invoke handler missed sender authorization checks
CVE-2026-42427 medium 5.3 5.3 1mo ago OpenClaw: HGRCPATH, CARGO_BUILD_RUSTC_WRAPPER, RUSTC_WRAPPER, and MAKEFLAGS missing from exec env denylist — RCE via build tool env injection (GHSA-cm8v-2vh9-cxf3 class)
CVE-2026-41407 medium 5.3 5.3 1mo ago OpenClaw: Shared-secret comparison call sites leaked length information through timing