openclaw
npm221 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting openclawpage 3 of 5
- CVE-2026-41343MEDIUMCVSS 5.3EG 5.3✓ Fixed in 2026.3.312026-04-23
OpenClaw before 2026.3.31 lacks a shared pre-auth concurrency budget on the public LINE webhook path, allowing attackers to cause transient availability loss. Remote attackers can flood the webhook endpoint with concurrent requests before …
- CVE-2026-41344MEDIUMCVSS 5.4EG 5.4✓ Fixed in 2026.3.282026-04-23
OpenClaw before 2026.3.28 contains a privilege escalation vulnerability in the chat.send endpoint that allows write-scoped gateway callers to persist admin-only verboseLevel session overrides. Attackers can exploit the /verbose parameter t…
- CVE-2026-41346MEDIUMCVSS 5.3EG 5.3✓ Fixed in 2026.3.312026-04-23
OpenClaw 2026.2.26 before 2026.3.31 enforces pending pairing-request caps per channel file instead of per account, allowing attackers to exhaust the shared pending window. Remote attackers can submit pairing requests from other accounts to…
- CVE-2026-41347HIGHCVSS 7.1EG 7.1✓ Fixed in 2026.3.312026-04-23
OpenClaw before 2026.3.31 lacks browser-origin validation in HTTP operator endpoints when operating in trusted-proxy mode, allowing cross-site request forgery attacks. Attackers can exploit this by sending malicious requests from a browser…
- CVE-2026-41348MEDIUMCVSS 5.4EG 5.4✓ Fixed in 2026.3.312026-04-23
OpenClaw before 2026.3.31 contains an authorization bypass vulnerability in Discord slash command and autocomplete paths that fail to enforce group DM channel allowlist restrictions. Authorized Discord users can bypass channel restrictions…
- CVE-2026-41351MEDIUMCVSS 5.3EG 5.3✓ Fixed in 2026.3.312026-04-23
OpenClaw before 2026.3.31 contains a replay detection bypass vulnerability in webhook signature handling that treats Base64 and Base64URL encoded signatures as distinct requests. Attackers can re-encode Telnyx webhook signatures to bypass …
- CVE-2026-41352HIGHCVSS 8.8EG 8.8✓ Fixed in 2026.3.312026-04-23
OpenClaw before 2026.3.31 contains a remote code execution vulnerability where a device-paired node can bypass the node scope gate authentication mechanism. Attackers with device pairing credentials can execute arbitrary node commands on t…
- CVE-2026-41354LOWCVSS 3.7EG 3.7✓ Fixed in 2026.4.22026-04-23
OpenClaw before 2026.4.2 contains an insufficient scope vulnerability in Zalo webhook replay dedupe keys that allows legitimate events from different conversations or senders to collide. Attackers can exploit weak deduplication scoping to …
- CVE-2026-41355HIGHCVSS 7.3EG 7.3✓ Fixed in 2026.3.282026-04-23
OpenClaw before 2026.3.28 contains an arbitrary code execution vulnerability in mirror mode that converts untrusted sandbox files into workspace hooks. Attackers with mirror mode access can execute arbitrary code on the host during gateway…
- CVE-2026-41356MEDIUMCVSS 5.4EG 5.4✓ Fixed in 2026.3.312026-04-23
OpenClaw before 2026.3.31 fails to terminate active WebSocket sessions when rotating device tokens. Attackers with previously compromised credentials can maintain unauthorized access through existing WebSocket connections after token rotat…
- CVE-2026-41358MEDIUMCVSS 5.4EG 5.4✓ Fixed in 2026.4.22026-04-23
OpenClaw before 2026.4.2 fails to filter Slack thread context by sender allowlist, allowing non-allowlisted messages to enter agent context. Attackers can inject unauthorized thread messages through allowlisted user replies to bypass sende…
- CVE-2026-41359HIGHCVSS 7.1EG 7.1✓ Fixed in 2026.3.282026-04-23
OpenClaw before 2026.3.28 contains a privilege escalation vulnerability allowing authenticated operators with write permissions to access admin-class Telegram configuration and cron persistence settings via the send endpoint. Attackers wit…
- CVE-2026-41363MEDIUMCVSS 5.3EG 5.3✓ Fixed in 2026.3.282026-04-28
OpenClaw versions 2026.2.6 through 2026.3.24 contain a path traversal vulnerability in the Feishu extension resolveUploadInput function that bypasses file-system sandbox restrictions. Attackers can exploit improper path resolution during u…
- CVE-2026-41364HIGHCVSS 8.1EG 8.1✓ Fixed in 2026.3.312026-04-28
OpenClaw before 2026.3.31 contains a symlink following vulnerability in SSH sandbox tar upload that allows remote attackers to write arbitrary files. Attackers can exploit this by uploading tar archives containing symlinks to escape the sa…
- CVE-2026-41365MEDIUMCVSS 5.4EG 5.4✓ Fixed in 2026.3.312026-04-28
OpenClaw before 2026.3.31 contains a sender allowlist bypass vulnerability in MS Teams thread history fetched via Graph API. Attackers can retrieve thread messages that should be filtered by sender allowlists, bypassing message filtering r…
- CVE-2026-41369MEDIUMCVSS 6.5EG 6.5✓ Fixed in 2026.3.312026-04-28
OpenClaw before 2026.3.31 contains insufficient environment variable sanitization in host exec operations, failing to filter package, registry, Docker, compiler, and TLS override variables. Attackers can exploit this by injecting malicious…
- CVE-2026-41372MEDIUMCVSS 5.8EG 5.8✓ Fixed in 2026.4.22026-04-28
OpenClaw before 2026.4.2 fails to normalize trailing-dot localhost hosts in remote CDP discovery responses, allowing bypass of loopback protections. Attackers can craft hostile discovery responses returning localhost. to retarget authentic…
- CVE-2026-41373MEDIUMCVSS 6.1EG 6.1✓ Fixed in 2026.3.312026-04-28
OpenClaw before 2026.3.31 contains an incomplete host-env-security-policy.json that fails to restrict compiler binary environment variables, allowing untrusted models to substitute CC, CXX, CARGO_BUILD_RUSTC, and CMAKE_C_COMPILER via envir…
- CVE-2026-41374MEDIUMCVSS 5.3EG 5.3✓ Fixed in 2026.3.312026-04-28
OpenClaw before 2026.3.31 performs Discord audio preflight transcription before validating member authorization, allowing unauthenticated attackers to consume resources. Remote attackers can trigger audio preflight processing without membe…
- CVE-2026-41375MEDIUMCVSS 6.5EG 6.5✓ Fixed in 2026.3.282026-04-28
OpenClaw before 2026.3.28 contains an authorization bypass vulnerability in the /phone arm and /phone disarm endpoints that fails to properly enforce operator.admin scope checks for external channels. Attackers can bypass authentication re…
- CVE-2026-41376MEDIUMCVSS 5.4EG 5.4✓ Fixed in 2026.3.312026-04-28
OpenClaw before 2026.3.31 contains an allowlist bypass vulnerability in Matrix thread root and reply context handling that fails to properly validate message senders. Attackers can fetch thread-root and reply context messages that should b…
- CVE-2026-41377MEDIUMCVSS 4.6EG 4.6✓ Fixed in 2026.3.312026-04-28
OpenClaw before 2026.3.31 contains a fail-open vulnerability in the plugin installation flow where security scan failures do not block installation. Attackers can exploit scan failures to install untrusted plugins when operators proceed de…
- CVE-2026-41378HIGHCVSS 8.8EG 8.8✓ Fixed in 2026.3.312026-04-28
OpenClaw before 2026.3.31 contains a privilege escalation vulnerability allowing paired nodes with role=node to dispatch node.event agent requests with unrestricted gateway-side tool access. Attackers with trusted paired node credentials c…
- CVE-2026-41379HIGHCVSS 7.1EG 7.1✓ Fixed in 2026.3.282026-04-28
OpenClaw before 2026.3.28 contains a privilege escalation vulnerability allowing authenticated operators with write permissions to access admin-class Talk Voice configuration persistence. Attackers with operator.write privileges can exploi…
- CVE-2026-41380HIGHCVSS 7.3EG 7.3✓ Fixed in 2026.3.282026-04-28
OpenClaw before 2026.3.28 contains an execution approval vulnerability in exec-approvals-allowlist.ts that allows allow-always persistence to trust wrapper carrier executables instead of invoked targets. Attackers can exploit positional ca…
- CVE-2026-41381MEDIUMCVSS 5.4EG 5.4✓ Fixed in 2026.3.312026-04-28
OpenClaw before 2026.3.31 contains an access control bypass vulnerability in the Discord voice manager that allows attackers to bypass channel-level member access allowlist restrictions. Attackers can send Discord voice ingress requests be…
- CVE-2026-41382MEDIUMCVSS 5.4EG 5.4✓ Fixed in 2026.3.312026-04-28
OpenClaw before 2026.3.31 contains an authorization bypass vulnerability in Discord voice ingress that allows attackers to bypass channel and member allowlist restrictions. Attackers can exploit stale-role validation gaps and improper chan…
- CVE-2026-41383HIGHCVSS 8.1EG 8.1✓ Fixed in 2026.4.22026-04-28
OpenClaw before 2026.4.2 contains an arbitrary directory deletion vulnerability in mirror mode that allows attackers to delete remote directories by influencing remoteWorkspaceDir and remoteAgentWorkspaceDir configuration values. Attackers…
- CVE-2026-41384HIGHCVSS 7.8EG 7.8✓ Fixed in 2026.3.242026-04-28
OpenClaw before 2026.3.24 contains an environment variable injection vulnerability in the CLI backend runner that allows attackers to inject malicious environment variables through workspace configuration. Attackers can craft malicious wor…
- CVE-2026-41385MEDIUMCVSS 6.5EG 6.5✓ Fixed in 2026.3.312026-04-28
OpenClaw before 2026.3.31 stores Nostr privateKey as plaintext in configuration, allowing exposure through config.get method calls that bypass redaction mechanisms. Attackers can retrieve unredacted configuration data to obtain plaintext s…
- CVE-2026-41386CRITICALCVSS 9.1EG 9.1✓ Fixed in 2026.3.222026-04-28
OpenClaw before 2026.3.22 contains a privilege escalation vulnerability where bootstrap setup codes are not bound to intended device roles and scopes during pairing. Attackers can exploit this during first-use device pairing to escalate pr…
- CVE-2026-41387HIGHCVSS 7.8EG 7.8✓ Fixed in 2026.3.222026-04-28
OpenClaw before 2026.3.22 contains an incomplete host environment variable sanitization vulnerability in host-env-security-policy.json and host-env-security.ts that allows package-manager environment overrides. Attackers can exploit approv…
- CVE-2026-41388MEDIUMCVSS 6.5EG 6.5✓ Fixed in 2026.3.312026-04-28
OpenClaw before 2026.3.31 contains a configuration management vulnerability where startup migration treats empty-array settings as missing values. Attackers can restart the application to rehydrate revoked Tlon configuration from file stat…
- CVE-2026-41389MEDIUMCVSS 5.8EG 5.8✓ Fixed in 2026.4.152026-04-20
OpenClaw versions 2026.4.7 before 2026.4.15 fail to enforce local-root containment on tool-result media paths, allowing arbitrary local and UNC file access. Attackers can craft malicious tool-result media references to trigger host-side fi…
- CVE-2026-41390HIGHCVSS 7.3EG 7.3✓ Fixed in 2026.3.282026-04-28
OpenClaw before 2026.3.28 contains an exec allowlist bypass vulnerability where allow-always persistence fails to unwrap /usr/bin/script and similar wrappers before storing trust decisions. Attackers can obtain user approval for one wrappe…
- CVE-2026-41391MEDIUMCVSS 5.3EG 5.3✓ Fixed in 2026.3.312026-04-28
OpenClaw before 2026.3.31 fails to properly sanitize PIP_INDEX_URL and UV_INDEX_URL environment variables in host execution contexts, allowing attackers to redirect Python package-index traffic. Attackers can exploit this bypass to interce…
- CVE-2026-41392MEDIUMCVSS 6.7EG 6.7✓ Fixed in 2026.3.312026-04-28
OpenClaw before 2026.3.31 contains an exec allowlist bypass vulnerability allowing attackers to inherit allowlist trust via shell init-file wrapper invocations. Attackers can exploit shell options like --rcfile, --init-file, and --startup-…
- CVE-2026-41393MEDIUMCVSS 4.8EG 4.8✓ Fixed in 2026.3.312026-04-28
OpenClaw before 2026.3.31 contains a wide-area discovery vulnerability allowing arbitrary tailnet peers to be accepted as DNS authorities. Attackers with same-tailnet position and CA-trusted endpoint access can exfiltrate operator credenti…
- CVE-2026-41394HIGHCVSS 8.2EG 8.2✓ Fixed in 2026.3.312026-04-28
OpenClaw before 2026.3.31 contains an authentication bypass vulnerability where unauthenticated plugin-auth HTTP routes receive operator runtime write scopes. Attackers can access these routes without authentication to perform privileged r…
- CVE-2026-41395HIGHCVSS 7.5EG 7.5✓ Fixed in 2026.3.282026-04-28
OpenClaw before 2026.3.28 contains a webhook replay vulnerability in Plivo V3 signature verification that canonicalizes query ordering for signatures but hashes raw URLs for replay detection. Attackers can reorder query parameters to bypas…
- CVE-2026-41396HIGHCVSS 7.8EG 7.8✓ Fixed in 2026.3.312026-04-28
OpenClaw before 2026.3.31 allows workspace .env files to override the OPENCLAW_BUNDLED_PLUGINS_DIR environment variable, compromising plugin trust verification. Attackers with control over workspace configuration can inject malicious plugi…
- CVE-2026-41397MEDIUMCVSS 6.8EG 6.8✓ Fixed in 2026.3.312026-04-28
OpenClaw before 2026.3.31 contains a sandbox escape vulnerability allowing attackers to traverse directory boundaries through symlink exploitation during file synchronization operations. Remote attackers can bypass sandbox restrictions by …
- CVE-2026-41398MEDIUMCVSS 4.6EG 4.6✓ Fixed in 2026.4.22026-04-28
OpenClaw before 2026.4.2 contains an improper access control vulnerability in the iOS A2UI bridge that treats generic local-network pages as trusted origins. Attackers can inject unauthorized agent.request runs by loading attacker-controll…
- CVE-2026-41399HIGHCVSS 7.5EG 7.5✓ Fixed in 2026.3.282026-04-28
OpenClaw before 2026.3.28 accepts unbounded concurrent unauthenticated WebSocket upgrades without pre-authentication budget allocation. Unauthenticated network attackers can exhaust socket and worker capacity to disrupt WebSocket availabil…
- CVE-2026-41400MEDIUMCVSS 5.3EG 5.3✓ Fixed in 2026.3.312026-04-28
OpenClaw before 2026.3.31 contains an incomplete fix for CVE-2026-32062 where the voice-call component parses large WebSocket frames before start validation. Remote attackers can send oversized pre-start WebSocket frames to cause resource …
- CVE-2026-41402MEDIUMCVSS 4.2EG 4.2✓ Fixed in 2026.3.312026-04-28
OpenClaw before 2026.3.31 contains a scope bypass vulnerability in webhook replay cache deduplication that allows authenticated attackers to replay messages across sibling targets using the same messageId. Attackers can exploit overly broa…
- CVE-2026-41403LOWCVSS 2.9EG 2.9✓ Fixed in 2026.3.312026-04-28
OpenClaw before 2026.3.31 misclassifies proxied remote requests as loopback connections in the diffs viewer when allowRemoteViewer is disabled, allowing unauthorized access. Attackers can bypass access controls by sending proxied requests …
- CVE-2026-41404HIGHCVSS 8.8EG 8.8✓ Fixed in 2026.3.312026-04-28
OpenClaw before 2026.3.31 contains an incomplete scope-clearing vulnerability in trusted-proxy authentication mode that allows operator.admin privilege escalation. Attackers can exploit this by declaring operator scopes on non-Control-UI c…
- CVE-2026-41405HIGHCVSS 7.5EG 7.5✓ Fixed in 2026.3.312026-04-28
OpenClaw before 2026.3.31 parses MS Teams webhook request bodies before performing JWT validation, allowing unauthenticated attackers to trigger resource exhaustion. Remote attackers can send malicious Teams webhook payloads to exhaust ser…
- CVE-2026-41406MEDIUMCVSS 5.4EG 5.4✓ Fixed in 2026.3.312026-04-28
OpenClaw before 2026.3.31 contains a sender allowlist bypass vulnerability that allows remote attackers to access restricted messages. Attackers can exploit fetched quoted, root, and thread context messages to bypass sender allowlist restr…
Check whether openclaw is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for openclaw CVEs against the assets you own.
Start Free Scan →