| CVE-2026-24763 |
🔴 HIGH |
8.8 |
OpenClaw/Clawdbot Docker Execution has Authenticated Command Injection via PATH Environment Variable |
2026-02-02 |
| CVE-2026-25253 |
🔴 HIGH |
8.8 |
OpenClaw/Clawdbot has 1-Click RCE via Authentication Token Exfiltration From gatewayUrl |
2026-02-01 |
| CVE-2026-28478 |
🔴 HIGH |
8.7 |
OpenClaw affected by denial of service via unbounded webhook request body buffering |
2026-03-05 |
| CVE-2026-53814 |
🔴 HIGH |
8.7 |
OpenClaw: Hook-triggered CLI runs could receive owner MCP tool authority |
2026-06-11 |
| CVE-2026-53817 |
🔴 HIGH |
8.7 |
OpenClaw < 2026.5.22 - Control UI Locality Spoofing in Device Pairing |
2026-06-11 |
| CVE-2026-53836 |
🔴 HIGH |
8.7 |
OpenClaw < 2026.5.12 - Allowlist Bypass via PowerShell Encoded-Command Aliases |
2026-06-12 |
| CVE-2026-53843 |
🔴 HIGH |
8.7 |
OpenClaw: Pairing-scoped device session could restore revoked node token authority |
2026-06-16 |
| CVE-2026-53819 |
🔴 HIGH |
8.7 |
OpenClaw: Workspace .env could override Homebrew executable selection for skill install flows |
2026-06-11 |
| CVE-2026-53816 |
🔴 HIGH |
8.6 |
OpenClaw < 2026.5.18 - Exec Lifecycle Event Forgery via Paired Node |
2026-06-11 |
| CVE-2026-53857 |
🔴 HIGH |
8.6 |
OpenClaw < 2026.5.3 - Mutable Display Name Binding in Zalo allowFrom Policy |
2026-06-16 |
| CVE-2026-53849 |
🔴 HIGH |
8.6 |
OpenClaw: Discord allowFrom could bind to mutable display names |
2026-06-16 |
| CVE-2026-28469 |
🔴 HIGH |
8.2 |
OpenClaw Google Chat shared-path webhook target ambiguity allowed cross-account policy-context misrouting |
2026-03-05 |
| CVE-2026-53834 |
🔴 HIGH |
8.2 |
OpenClaw < 2026.4.27 - Authorization Bypass in QQBot Pre-dispatch Slash Commands |
2026-06-12 |
| CVE-2026-35630 |
🔴 HIGH |
8 |
OpenClaw: QQBot native approval buttons did not enforce configured approver identity |
2026-05-29 |
| CVE-2026-25157 |
🔴 HIGH |
7.8 |
OpenClaw/Clawdbot has OS Command Injection via Project Root Path in sshNodeCommand |
2026-02-04 |
| CVE-2026-53806 |
🔴 HIGH |
7.7 |
OpenClaw < 2026.5.12 - Shell Option Parsing Bypass in Exec Revalidation |
2026-06-11 |
| CVE-2026-53810 |
🔴 HIGH |
7.7 |
OpenClaw's marketplace runtime extension metadata could point at unscanned payloads |
2026-06-11 |
| CVE-2026-53811 |
🔴 HIGH |
7.7 |
OpenClaw: Matrix allowFrom could bind to mutable display names |
2026-06-11 |
| CVE-2026-53831 |
🔴 HIGH |
7.6 |
OpenClaw's POSIX node system.run safe-bin allowlist could be widened by shell expansion |
2026-06-12 |
| CVE-2026-53853 |
🔴 HIGH |
7.6 |
OpenClaw: Linux and macOS exec allowlists skipped configured argument patterns |
2026-06-16 |
| CVE-2026-53855 |
🔴 HIGH |
7.6 |
OpenClaw < 2026.4.2 - Shell Positional Parameters Bypass in Inline-Eval Checks |
2026-06-16 |
| CVE-2026-53864 |
🔴 HIGH |
7.6 |
OpenClaw: Host environment sanitizer missed two Node.js control variables |
2026-06-16 |
| CVE-2026-53866 |
🔴 HIGH |
7.6 |
OpenClaw < 2026.5.12 - Allowlist Bypass in Shell Inline-Command Parsing |
2026-06-16 |
| CVE-2026-28458 |
🔴 HIGH |
7.4 |
OpenClaw's Browser Relay /cdp websocket is missing auth which could allow cross-tab cookie access |
2026-03-05 |
| CVE-2026-53832 |
🔴 HIGH |
7.4 |
OpenClaw < 2026.5.18 - Identity Header Forgery via Trusted-Proxy Configuration |
2026-06-12 |
| CVE-2026-53833 |
🔴 HIGH |
7.4 |
OpenClaw: QQBot streaming command could mutate config without explicit allowFrom |
2026-06-12 |
| CVE-2026-53813 |
🔴 HIGH |
7.3 |
OpenClaw: Fake package roots could influence memory-core artifact loading |
2026-06-11 |
| CVE-2026-53865 |
🔴 HIGH |
7.2 |
OpenClaw: Workspace-derived service PATH could influence trash command selection |
2026-06-16 |
| CVE-2026-26317 |
🔴 HIGH |
7.1 |
OpenClaw affected by cross-site request forgery (CSRF) through loopback browser mutation endpoints |
2026-02-19 |
| CVE-2026-53815 |
🔴 HIGH |
7.1 |
OpenClaw < 2026.5.19 - Channel Allowlist Bypass in Message Read Actions |
2026-06-11 |
| CVE-2026-43531 |
🔴 HIGH |
7 |
OpenClaw < 2026.4.9 - Environment Variable Injection via Workspace .env File |
2026-05-05 |
| CVE-2026-53842 |
🔴 HIGH |
7 |
OpenClaw: Workspace .env CLOUDSDK_PYTHON could influence Gmail setup gcloud execution |
2026-06-16 |
| CVE-2026-53846 |
🔴 HIGH |
7 |
OpenClaw: Workspace .env npm_execpath could influence bundled runtime dependency install |
2026-06-16 |
| CVE-2026-53858 |
🔴 HIGH |
7 |
OpenClaw: Workspace .env STATE_DIRECTORY could influence bundled runtime dependency roots |
2026-06-16 |
| CVE-2026-28480 |
🟡 MEDIUM |
6.9 |
OpenClaw Telegram allowlist authorization accepted mutable usernames |
2026-03-05 |
| CVE-2026-53818 |
🟡 MEDIUM |
6.9 |
OpenClaw < 2026.4.24 - Owner-Only Tool Policy Bypass via MCP Loopback |
2026-06-11 |
| CVE-2026-29612 |
🟡 MEDIUM |
6.8 |
OpenClaw < 2026.2.14 - Denial of Service via Large Base64 Media File Decoding |
2026-03-05 |
| CVE-2026-53850 |
🟡 MEDIUM |
6.8 |
OpenClaw < 2026.4.25 - Control Scope Enforcement Bypass in Focus Command |
2026-06-16 |
| CVE-2026-28452 |
🟡 MEDIUM |
6.7 |
OpenClaw affected by denial of service through unguarded archive extraction allowing high expansion/resource abuse (ZIP/TAR) |
2026-03-05 |
| CVE-2026-26328 |
🟡 MEDIUM |
6.5 |
OpenClaw iMessage group allowlist authorization inherited DM pairing-store identities |
2026-02-19 |
| CVE-2026-53837 |
🟡 MEDIUM |
6.3 |
OpenClaw: Mattermost handlers could fall open when channel type was missing |
2026-06-12 |
| CVE-2026-53851 |
🟡 MEDIUM |
6.3 |
OpenClaw < 2026.5.12 - Slack Reaction Event Notification Bypass |
2026-06-16 |
| CVE-2026-53830 |
🟡 MEDIUM |
6 |
OpenClaw < 2026.4.22 - Webhook Secret Revocation Bypass via secrets.reload |
2026-06-12 |
| CVE-2026-53838 |
🟡 MEDIUM |
6 |
OpenClaw < 2026.5.27 - Node Pairing State Mutation via Reconnection |
2026-06-12 |
| CVE-2026-53840 |
🟡 MEDIUM |
6 |
OpenClaw: MCP Streamable HTTP redirects could forward configured custom headers to another origin |
2026-06-16 |
| CVE-2026-53844 |
🟡 MEDIUM |
6 |
OpenClaw < 2026.4.29 - Session Visibility Check Bypass in Shared Memory Search |
2026-06-16 |
| CVE-2026-53854 |
🟡 MEDIUM |
6 |
OpenClaw: Internal/webchat command auth could inherit ownerAllowFrom wildcard state |
2026-06-16 |
| CVE-2026-53863 |
🟡 MEDIUM |
6 |
OpenClaw < 2026.4.25 - Unvalidated Group ID Acceptance in Tool Group Policy |
2026-06-16 |
| CVE-2026-53859 |
🟡 MEDIUM |
6 |
OpenClaw < 2026.5.26 - Hostname Validation Bypass via Trailing-Dot Inconsistency |
2026-06-16 |
| CVE-2026-53856 |
🟡 MEDIUM |
5.7 |
OpenClaw: Config recovery could restore openclaw.json with broad file permissions |
2026-06-16 |
| CVE-2026-53847 |
🟡 MEDIUM |
5.3 |
OpenClaw < 2026.5.6 - Privilege Escalation via Active Memory Write Scope |
2026-06-16 |
| CVE-2026-53861 |
🟡 MEDIUM |
5.3 |
OpenClaw < 2026.5.6 - Allowlist Bypass via Combined POSIX Inline Flags on macOS |
2026-06-16 |
| CVE-2026-53812 |
🟡 MEDIUM |
4.9 |
OpenClaw's browser act interactions could bypass private-network navigation checks |
2026-06-11 |
| CVE-2026-53809 |
🟡 MEDIUM |
4.8 |
OpenClaw < 2026.4.25 - Provider Alias Confusion in Embedded Runner Policy |
2026-06-11 |
| CVE-2026-53845 |
🟢 LOW |
2.3 |
OpenClaw: Skill-command dispatch could skip before-tool-call hooks |
2026-06-16 |
| CVE-2026-53852 |
🟢 LOW |
2.3 |
OpenClaw < 2026.4.25 - Scope Bypass via Empty-Scope Device Re-pairing |
2026-06-16 |
| CVE-2026-53860 |
🟢 LOW |
2.3 |
OpenClaw: BlueBubbles sender policy could match mutable conversation identifiers |
2026-06-16 |
| CVE-2026-53848 |
🟢 LOW |
2.3 |
OpenClaw < 2026.5.26 - Exec Allowlist Bypass via Transparent Command Wrappers |
2026-06-16 |
| CVE-2026-53862 |
🟢 LOW |
2.3 |
OpenClaw < 2026.5.12 - Bootstrap Token Replay via Pending Pairing Scope Widening |
2026-06-16 |
| CVE-2026-53841 |
🟢 LOW |
2.1 |
OpenClaw: Exported session HTML could keep unsafe markdown links |
2026-06-16 |