Security Intelligence

AI Agent Security Feed

Daily-updated CVE and GHSA advisories for OpenClaw, NemoClaw, NanoClaw, and Claude Code. Vulnerabilities tracked, scored, and enriched with affected packages so you can prioritize what matters.

Powered by OpenClawCVEs

Last updated: September 23, 2026

147 advisories3 Critical66 High61 Medium17 Low
MEDIUM · 6.3Jul 17, 2026
OpenClawNemoClawNanoClaw

CVE-2026-62220

OpenClaw 2026.2.25 < 2026.5.26 WebSocket Rate Limit Bypass

MEDIUM · 6.0Jul 17, 2026
OpenClawNemoClawNanoClaw

CVE-2026-62205

OpenClaw 2026.4.12-beta.1 < 2026.6.6 Authorization Bypass via message actions

MEDIUM · 6.0Jul 17, 2026
OpenClawNemoClawNanoClaw

CVE-2026-62210

OpenClaw < 2026.6.1 Denial of Service via Remote Media URLs

MEDIUM · 4.9Jul 17, 2026
OpenClawNemoClawNanoClaw

CVE-2026-62201

OpenClaw < 2026.6.6 Network Policy Bypass via exec-server

LOW · 2.3Jul 17, 2026
OpenClawNemoClawNanoClaw

CVE-2026-62221

OpenClaw 2026.5.12 < 2026.5.26 Authorization Bypass via allowFrom

MEDIUM · 4.8Jul 9, 2026
OpenClawNemoClawNanoClaw

CVE-2026-15193

AidanPark openclaw-android Android WebView Bridge JsBridge.kt os command injection

HIGH · 8.7Jun 16, 2026
OpenClawNemoClawNanoClaw

CVE-2026-53843

CWE-284CWE-863
npm/openclaw

Affected: < 2026.5.26

OpenClaw: Pairing-scoped device session could restore revoked node token authority

HIGH · 8.6Jun 16, 2026
OpenClawNemoClawNanoClaw

CVE-2026-53849

CWE-290
npm/openclaw

Affected: <= 2026.5.6

OpenClaw: Discord allowFrom could bind to mutable display names

HIGH · 8.6Jun 16, 2026
OpenClawNemoClawNanoClaw

CVE-2026-53857

CWE-290
npm/openclaw

Affected: <= 2026.5.2

OpenClaw < 2026.5.3 - Mutable Display Name Binding in Zalo allowFrom Policy

HIGH · 7.6Jun 16, 2026
OpenClawNemoClawNanoClaw

CVE-2026-53855

CWE-78CWE-269CWE-284CWE-863
npm/openclaw

Affected: < 2026.4.2

OpenClaw < 2026.4.2 - Shell Positional Parameters Bypass in Inline-Eval Checks

HIGH · 7.6Jun 16, 2026
OpenClawNemoClawNanoClaw

CVE-2026-53853

CWE-693CWE-863
npm/openclaw

Affected: < 2026.5.12

OpenClaw: Linux and macOS exec allowlists skipped configured argument patterns

HIGH · 7.6Jun 16, 2026
OpenClawNemoClawNanoClaw

CVE-2026-53864

CWE-184
npm/openclaw

Affected: <= 2026.5.22

OpenClaw: Host environment sanitizer missed two Node.js control variables

HIGH · 7.6Jun 16, 2026
OpenClawNemoClawNanoClaw

CVE-2026-53866

CWE-184
npm/openclaw

Affected: <= 2026.5.10-beta.1

OpenClaw < 2026.5.12 - Allowlist Bypass in Shell Inline-Command Parsing

HIGH · 7.2Jun 16, 2026
OpenClawNemoClawNanoClaw

CVE-2026-53865

CWE-426
npm/openclaw

Affected: < 2026.5.2

OpenClaw: Workspace-derived service PATH could influence trash command selection

HIGH · 7.0Jun 16, 2026
OpenClawNemoClawNanoClaw

CVE-2026-53842

CWE-426
npm/openclaw

Affected: < 2026.5.2

OpenClaw: Workspace .env CLOUDSDK_PYTHON could influence Gmail setup gcloud execution

HIGH · 7.0Jun 16, 2026
OpenClawNemoClawNanoClaw

CVE-2026-53846

CWE-426
npm/openclaw

Affected: < 2026.4.29

OpenClaw: Workspace .env npm_execpath could influence bundled runtime dependency install

HIGH · 7.0Jun 16, 2026
OpenClawNemoClawNanoClaw

CVE-2026-53858

CWE-426
npm/openclaw

Affected: < 2026.5.2

OpenClaw: Workspace .env STATE_DIRECTORY could influence bundled runtime dependency roots

MEDIUM · 6.8Jun 16, 2026
OpenClawNemoClawNanoClaw

CVE-2026-53850

CWE-862
npm/openclaw

Affected: <= 2026.4.24

OpenClaw < 2026.4.25 - Control Scope Enforcement Bypass in Focus Command

MEDIUM · 6.3Jun 16, 2026
OpenClawNemoClawNanoClaw

CVE-2026-53851

CWE-285
npm/openclaw

Affected: <= 2026.5.7

OpenClaw < 2026.5.12 - Slack Reaction Event Notification Bypass

MEDIUM · 6.0Jun 16, 2026
OpenClawNemoClawNanoClaw

CVE-2026-53840

CWE-200
npm/openclaw

Affected: < 2026.5.12

OpenClaw: MCP Streamable HTTP redirects could forward configured custom headers to another origin

MEDIUM · 6.0Jun 16, 2026
OpenClawNemoClawNanoClaw

CVE-2026-53844

CWE-862
npm/openclaw

Affected: <= 2026.4.27

OpenClaw < 2026.4.29 - Session Visibility Check Bypass in Shared Memory Search

MEDIUM · 6.0Jun 16, 2026
OpenClawNemoClawNanoClaw

CVE-2026-53854

CWE-863
npm/openclaw

Affected: <= 2026.4.24

OpenClaw: Internal/webchat command auth could inherit ownerAllowFrom wildcard state

MEDIUM · 6.0Jun 16, 2026
OpenClawNemoClawNanoClaw

CVE-2026-53859

CWE-20CWE-918
npm/openclaw

Affected: <= 2026.5.22

OpenClaw < 2026.5.26 - Hostname Validation Bypass via Trailing-Dot Inconsistency

MEDIUM · 6.0Jun 16, 2026
OpenClawNemoClawNanoClaw

CVE-2026-53863

CWE-639
npm/openclaw

Affected: <= 2026.4.24

OpenClaw < 2026.4.25 - Unvalidated Group ID Acceptance in Tool Group Policy

MEDIUM · 5.7Jun 16, 2026
OpenClawNemoClawNanoClaw

CVE-2026-53856

CWE-276
npm/openclaw

Affected: = 2026.4.23

OpenClaw: Config recovery could restore openclaw.json with broad file permissions

MEDIUM · 5.3Jun 16, 2026
OpenClawNemoClawNanoClaw

CVE-2026-53847

CWE-266
npm/openclaw

Affected: <= 2026.5.5

OpenClaw < 2026.5.6 - Privilege Escalation via Active Memory Write Scope

MEDIUM · 5.3Jun 16, 2026
OpenClawNemoClawNanoClaw

CVE-2026-53861

CWE-184
npm/openclaw

Affected: <= 2026.5.5

OpenClaw < 2026.5.6 - Allowlist Bypass via Combined POSIX Inline Flags on macOS

LOW · 2.3Jun 16, 2026
OpenClawNemoClawNanoClaw

CVE-2026-53845

CWE-693
npm/openclaw

Affected: <= 2026.5.5

OpenClaw: Skill-command dispatch could skip before-tool-call hooks

LOW · 2.3Jun 16, 2026
OpenClawNemoClawNanoClaw

CVE-2026-53848

CWE-78CWE-184
npm/openclaw

Affected: <= 2026.5.22

OpenClaw < 2026.5.26 - Exec Allowlist Bypass via Transparent Command Wrappers

LOW · 2.3Jun 16, 2026
OpenClawNemoClawNanoClaw

CVE-2026-53852

CWE-636
npm/openclaw

Affected: <= 2026.4.24

OpenClaw < 2026.4.25 - Scope Bypass via Empty-Scope Device Re-pairing

LOW · 2.3Jun 16, 2026
OpenClawNemoClawNanoClaw

CVE-2026-53860

CWE-863
npm/openclaw

Affected: <= 2026.5.6

OpenClaw: BlueBubbles sender policy could match mutable conversation identifiers

LOW · 2.3Jun 16, 2026
OpenClawNemoClawNanoClaw

CVE-2026-53862

CWE-269
npm/openclaw

Affected: <= 2026.5.10-beta.2

OpenClaw < 2026.5.12 - Bootstrap Token Replay via Pending Pairing Scope Widening

LOW · 2.1Jun 16, 2026
OpenClawNemoClawNanoClaw

CVE-2026-53841

CWE-79
npm/openclaw

Affected: <= 2026.5.7

OpenClaw: Exported session HTML could keep unsafe markdown links

HIGH · 8.7Jun 12, 2026
OpenClawNemoClawNanoClaw

CVE-2026-53822

OpenClaw < 2026.5.18 - Command Argument Modification via Shell Wrapper Between Approval and Execution

HIGH · 8.7Jun 12, 2026
OpenClawNemoClawNanoClaw

CVE-2026-53836

CWE-184
npm/openclaw

Affected: <= 2026.5.7

OpenClaw < 2026.5.12 - Allowlist Bypass via PowerShell Encoded-Command Aliases

HIGH · 8.5Jun 12, 2026
OpenClawNemoClawNanoClaw

CVE-2026-53829

OpenClaw < 2026.5.18 - Command Truncation in Exec Approval Display

HIGH · 8.2Jun 12, 2026
OpenClawNemoClawNanoClaw

CVE-2026-53834

CWE-863
npm/openclaw

Affected: <= 2026.4.26

OpenClaw < 2026.4.27 - Authorization Bypass in QQBot Pre-dispatch Slash Commands

HIGH · 7.6Jun 12, 2026
OpenClawNemoClawNanoClaw

CVE-2026-53831

CWE-78CWE-200CWE-284CWE-367
npm/openclaw

Affected: < 2026.5.18

OpenClaw's POSIX node system.run safe-bin allowlist could be widened by shell expansion

HIGH · 7.4Jun 12, 2026
OpenClawNemoClawNanoClaw

CVE-2026-53833

CWE-863
npm/openclaw

Affected: <= 2026.4.27

OpenClaw: QQBot streaming command could mutate config without explicit allowFrom

HIGH · 7.4Jun 12, 2026
OpenClawNemoClawNanoClaw

CVE-2026-53832

CWE-269CWE-284CWE-287CWE-290CWE-863
npm/openclaw

Affected: < 2026.5.18

OpenClaw < 2026.5.18 - Identity Header Forgery via Trusted-Proxy Configuration

MEDIUM · 6.3Jun 12, 2026
OpenClawNemoClawNanoClaw

CVE-2026-53837

CWE-636
npm/openclaw

Affected: <= 2026.5.5

OpenClaw: Mattermost handlers could fall open when channel type was missing

MEDIUM · 6.0Jun 12, 2026
OpenClawNemoClawNanoClaw

CVE-2026-53830

CWE-613
npm/openclaw

Affected: <= 2026.4.21

OpenClaw < 2026.4.22 - Webhook Secret Revocation Bypass via secrets.reload

MEDIUM · 6.0Jun 12, 2026
OpenClawNemoClawNanoClaw

CVE-2026-53838

CWE-367
npm/openclaw

Affected: < 2026.5.27

OpenClaw < 2026.5.27 - Node Pairing State Mutation via Reconnection

HIGH · 8.7Jun 11, 2026
OpenClawNemoClawNanoClaw

CVE-2026-53814

CWE-200CWE-266CWE-284
npm/openclaw

Affected: < 2026.5.20

OpenClaw: Hook-triggered CLI runs could receive owner MCP tool authority

HIGH · 8.7Jun 11, 2026
OpenClawNemoClawNanoClaw

CVE-2026-53817

CWE-284CWE-287CWE-290CWE-863
npm/openclaw

Affected: < 2026.5.22

OpenClaw < 2026.5.22 - Control UI Locality Spoofing in Device Pairing

HIGH · 8.7Jun 11, 2026
OpenClawNemoClawNanoClaw

CVE-2026-53819

CWE-426
npm/openclaw

Affected: < 2026.5.27

OpenClaw: Workspace .env could override Homebrew executable selection for skill install flows

HIGH · 8.6Jun 11, 2026
OpenClawNemoClawNanoClaw

CVE-2026-53816

CWE-284CWE-862CWE-863
npm/openclaw

Affected: < 2026.5.18

OpenClaw < 2026.5.18 - Exec Lifecycle Event Forgery via Paired Node

HIGH · 7.7Jun 11, 2026
OpenClawNemoClawNanoClaw

CVE-2026-53806

CWE-367
npm/openclaw

Affected: <= 2026.5.7

OpenClaw < 2026.5.12 - Shell Option Parsing Bypass in Exec Revalidation

HIGH · 7.7Jun 11, 2026
OpenClawNemoClawNanoClaw

CVE-2026-53810

CWE-78CWE-94CWE-284CWE-829
npm/openclaw

Affected: < 2026.5.18

OpenClaw's marketplace runtime extension metadata could point at unscanned payloads

HIGH · 7.7Jun 11, 2026
OpenClawNemoClawNanoClaw

CVE-2026-53811

CWE-290
npm/openclaw

Affected: <= 2026.5.6

OpenClaw: Matrix allowFrom could bind to mutable display names

HIGH · 7.3Jun 11, 2026
OpenClawNemoClawNanoClaw

CVE-2026-53813

CWE-427
npm/openclaw

Affected: <= 2026.4.24

OpenClaw: Fake package roots could influence memory-core artifact loading

HIGH · 7.1Jun 11, 2026
OpenClawNemoClawNanoClaw

CVE-2026-53815

CWE-200CWE-862
npm/openclaw

Affected: <= 2026.5.19-beta.2

OpenClaw < 2026.5.19 - Channel Allowlist Bypass in Message Read Actions

MEDIUM · 6.9Jun 11, 2026
OpenClawNemoClawNanoClaw

CVE-2026-53818

CWE-862
npm/openclaw

Affected: < 2026.4.24

OpenClaw < 2026.4.24 - Owner-Only Tool Policy Bypass via MCP Loopback

MEDIUM · 4.9Jun 11, 2026
OpenClawNemoClawNanoClaw

CVE-2026-53812

CWE-284CWE-918
npm/openclaw

Affected: < 2026.5.18

OpenClaw's browser act interactions could bypass private-network navigation checks

MEDIUM · 4.8Jun 11, 2026
OpenClawNemoClawNanoClaw

CVE-2026-53809

CWE-863
npm/openclaw

Affected: <= 2026.4.24

OpenClaw < 2026.4.25 - Provider Alias Confusion in Embedded Runner Policy

HIGH · 8.0May 29, 2026
OpenClawNemoClawNanoClaw

CVE-2026-35630

CWE-862
npm/openclaw

Affected: < 2026.5.18

OpenClaw: QQBot native approval buttons did not enforce configured approver identity

LOW · 2.3May 29, 2026
OpenClawNemoClawNanoClaw

CVE-2026-32906

OpenClaw < 2026.5.12 - Privilege Escalation in Slack Plugin Approvals via Exec Approver Gate

LOW · 2.3May 29, 2026
OpenClawNemoClawNanoClaw

CVE-2026-34507

OpenClaw < 2026.4.29 - Policy Bypass in QQBot Admin Commands via DM-only and allowFrom Checks

MEDIUM · 6.8May 11, 2026
OpenClawNemoClawNanoClaw

CVE-2026-45224

Crabbox < 0.9.0 Path Traversal via Islo Provider Workspace Resolution

MEDIUM · 6.0May 11, 2026
OpenClawNemoClawNanoClaw

CVE-2026-45001

OpenClaw < 2026.4.20 - Gateway Config Mutation Guard Bypass via Agent Tool Access

LOW · 2.3May 11, 2026
OpenClawNemoClawNanoClaw

CVE-2026-44993

OpenClaw < 2026.4.20 - Direct Message Misclassification in Feishu Card Actions

LOW · 2.3May 11, 2026
OpenClawNemoClawNanoClaw

CVE-2026-44991

OpenClaw < 2026.4.21 - Authorization Bypass in Owner-Enforced Commands via Wildcard Channel Senders

HIGH · 8.9May 5, 2026
OpenClawNemoClawNanoClaw

CVE-2026-43533

OpenClaw < 2026.4.10 - Arbitrary Local File Read via QQBot Media Tags

HIGH · 7.0May 5, 2026
OpenClawNemoClawNanoClaw

CVE-2026-43531

OpenClaw < 2026.4.9 - Environment Variable Injection via Workspace .env File

HIGH · 8.5Apr 28, 2026
OpenClawNemoClawNanoClaw

CVE-2026-41396

OpenClaw < 2026.3.31 - Environment Variable Override of Plugin Trust Root

HIGH · 7.7Apr 28, 2026
OpenClawNemoClawNanoClaw

CVE-2026-42422

OpenClaw < 2026.4.8 - Role Bypass in device.token.rotate Function

HIGH · 7.5Apr 28, 2026
OpenClawNemoClawNanoClaw

CVE-2026-42428

OpenClaw < 2026.4.8 - Missing Integrity Verification in Package Downloads

HIGH · 7.3Apr 28, 2026
OpenClawNemoClawNanoClaw

CVE-2026-42432

OpenClaw < 2026.4.8 - Command Escalation via Node Pairing Reconnect Bypass

HIGH · 7.1Apr 28, 2026
OpenClawNemoClawNanoClaw

CVE-2026-41375

OpenClaw < 2026.3.28 - Authorization Bypass in /phone arm and /phone disarm Endpoints

MEDIUM · 5.9Apr 28, 2026
OpenClawNemoClawNanoClaw

CVE-2026-41393

OpenClaw < 2026.3.31 - Arbitrary DNS Authority Acceptance and Credential Exfiltration via Wide-Area Discovery

LOW · 2.3Apr 28, 2026
OpenClawNemoClawNanoClaw

CVE-2026-41402

OpenClaw < 2026.3.31 - Webhook Replay Cache Cross-Target messageId Scope Bypass

LOW · 2.3Apr 28, 2026
OpenClawNemoClawNanoClaw

CVE-2026-41408

OpenClaw < 2026.3.31 - Disk Exhaustion via Media Download Bypass

LOW · 2.3Apr 28, 2026
OpenClawNemoClawNanoClaw

CVE-2026-41916

OpenClaw < 2026.4.8 - Stale Authentication State via Config Reload

HIGH · 7.2Apr 27, 2026
OpenClawNemoClawNanoClaw

CVE-2026-41364

OpenClaw < 2026.3.31 - Arbitrary File Write via Symlink Following in SSH Sandbox Tar Upload

MEDIUM · 6.9Apr 27, 2026
OpenClawNemoClawNanoClaw

CVE-2026-41372

OpenClaw < 2026.4.2 - Loopback Protection Bypass via Trailing-Dot Localhost in CDP Discovery

MEDIUM · 6.0Apr 27, 2026
OpenClawNemoClawNanoClaw

CVE-2026-41366

OpenClaw < 2026.3.31 - Arbitrary Host File Read via appendLocalMediaParentRoots Self-Whitelisting

MEDIUM · 5.3Apr 27, 2026
OpenClawNemoClawNanoClaw

CVE-2026-41367

OpenClaw 2026.2.14 < 2026.3.28 - Policy Enforcement Bypass in Discord Component Interactions

HIGH · 8.7Apr 23, 2026
OpenClawNemoClawNanoClaw

CVE-2026-41349

OpenClaw < 2026.3.28 - Agentic Consent Bypass via config.patch

HIGH · 7.1Apr 23, 2026
OpenClawNemoClawNanoClaw

CVE-2026-41359

OpenClaw < 2026.3.28 - Privilege Escalation via operator.write to Admin-Class Telegram Config and Cron Persistence

MEDIUM · 6.9Apr 23, 2026
OpenClawNemoClawNanoClaw

CVE-2026-41343

OpenClaw < 2026.3.31 - Denial of Service via LINE Webhook Handler Pre-Auth Concurrency

MEDIUM · 6.9Apr 23, 2026
OpenClawNemoClawNanoClaw

CVE-2026-41335

OpenClaw < 2026.3.31 - Information Disclosure via Control UI Bootstrap JSON

MEDIUM · 4.3Apr 23, 2026
OpenClawNemoClawNanoClaw

CVE-2026-41338

OpenClaw < 2026.3.31 - Time-of-Check-Time-of-Use (TOCTOU) Vulnerability in Sandbox File Operations

HIGH · 7.1Apr 20, 2026
OpenClawNemoClawNanoClaw

CVE-2026-41299

OpenClaw < 2026.3.28 - Client Identity Spoofing in chat.send Gateway Provenance Guard

MEDIUM · 6.9Apr 20, 2026
OpenClawNemoClawNanoClaw

CVE-2026-41301

OpenClaw 2026.3.22 < 2026.3.31 - Forged Nostr DM Pairing State Creation via Signature Verification Bypass

HIGH · 8.7Apr 10, 2026
OpenClawNemoClawNanoClaw

CVE-2026-35663

OpenClaw < 2026.3.25 - Privilege Escalation via Backend Reconnect Scope Self-Claim

HIGH · 7.1Apr 10, 2026
OpenClawNemoClawNanoClaw

CVE-2026-35621

OpenClaw < 2026.3.24 - Privilege Escalation via chat.send to Allowlist Persistence

MEDIUM · 6.9Apr 10, 2026
OpenClawNemoClawNanoClaw

CVE-2026-35652

OpenClaw < 2026.3.22 - Unauthorized Action Execution via Callback Dispatch

MEDIUM · 6.3Apr 10, 2026
OpenClawNemoClawNanoClaw

CVE-2026-35649

OpenClaw < 2026.3.22 - Settings Reconciliation Bypass via Empty Allowlist

MEDIUM · 6.3Apr 10, 2026
OpenClawNemoClawNanoClaw

CVE-2026-35656

OpenClaw < 2026.3.22 - XFF Loopback Spoofing Bypass in Canvas Authentication and Rate Limiter

HIGH · 8.7Apr 9, 2026
OpenClawNemoClawNanoClaw

CVE-2026-35639

OpenClaw < 2026.3.22 - Privilege Escalation via device.pair.approve Scope Validation

HIGH · 7.2Apr 9, 2026
OpenClawNemoClawNanoClaw

CVE-2026-34512

OpenClaw < 2026.3.25 - Improper Access Control in /sessions/:sessionKey/kill Endpoint

HIGH · 7.1Apr 9, 2026
OpenClawNemoClawNanoClaw

CVE-2026-35636

OpenClaw 2026.3.11 < 2026.3.25 - Session Isolation Bypass via sessionId Resolution

LOW · 2.3Apr 9, 2026
OpenClawNemoClawNanoClaw

CVE-2026-35617

OpenClaw < 2026.3.25 - Authorization Bypass via Group Policy Rebinding with Mutable Space displayName

LOW · 2.3Apr 9, 2026
OpenClawNemoClawNanoClaw

CVE-2026-35624

OpenClaw < 2026.3.22 - Policy Confusion via Room Name Collision in Nextcloud Talk

MEDIUM · 5.3Apr 2, 2026
OpenClawNemoClawNanoClaw

CVE-2026-34425

OpenClaw - Shell-Bleed Protection Preflight Validation Bypass

MEDIUM · 6.3Mar 31, 2026
OpenClawNemoClawNanoClaw

CVE-2026-33580

OpenClaw < 2026.3.28 - Brute Force Attack via Missing Rate Limiting on Webhook Shared Secret Authentication

MEDIUM · 5.8Mar 31, 2026
OpenClawNemoClawNanoClaw

CVE-2026-32988

OpenClaw < 2026.3.11 - Sandbox Boundary Bypass via Unvalidated Temporary File Creation

MEDIUM · 5.8Mar 31, 2026
OpenClawNemoClawNanoClaw

CVE-2026-32977

OpenClaw < 2026.3.11 - Sandbox Boundary Bypass via Unanchored writeFile Commit Path

MEDIUM · 5.3Mar 31, 2026
OpenClawNemoClawNanoClaw

CVE-2026-33578

OpenClaw < 2026.3.28 - Sender Policy Allowlist Bypass via Policy Downgrade in Google Chat and Zalouser Extensions

CRITICAL · 9.2Mar 29, 2026
OpenClawNemoClawNanoClaw

CVE-2026-32918

OpenClaw < 2026.3.11 - Session Sandbox Escape via session_status Tool

MEDIUM · 6.9Mar 29, 2026
OpenClawNemoClawNanoClaw

CVE-2026-32919

OpenClaw < 2026.3.11 - Unauthorized Session Reset via agent Slash Commands

HIGH · 8.7Mar 26, 2026
OpenClawNemoClawNanoClaw

CVE-2026-32846

OpenClaw Media Parsing Path Traversal to Arbitrary File Read

MEDIUM · 5.8Mar 23, 2026
OpenClawNemoClawNanoClaw

CVE-2026-27646

OpenClaw < 2026.3.7 - Sandbox Escape via /acp spawn Command

HIGH · 8.7Mar 21, 2026
OpenClawNemoClawNanoClaw

CVE-2026-32042

OpenClaw < 2026.2.25 - Privilege Escalation via Unpaired Device Identity in Shared Gateway Authentication

HIGH · 8.7Mar 21, 2026
OpenClawNemoClawNanoClaw

CVE-2026-32049

OpenClaw < 2026.2.22 - Denial of Service via Inbound Media Download Byte Limit Bypass

HIGH · 7.7Mar 21, 2026
OpenClawNemoClawNanoClaw

CVE-2026-32048

OpenClaw < 2026.3.1 - Sandbox Escape via Cross-Agent sessions_spawn

MEDIUM · 6.7Mar 21, 2026
OpenClawNemoClawNanoClaw

CVE-2026-32044

OpenClaw < 2026.3.2 - Tar Archive Safety Bypass in Skills Installation

MEDIUM · 5.9Mar 21, 2026
OpenClawNemoClawNanoClaw

CVE-2026-32054

OpenClaw < 2026.2.25 - Symlink Traversal in Browser Trace/Download Path Handling

CRITICAL · 9.4Mar 20, 2026
OpenClawNemoClawNanoClaw

CVE-2026-22172

OpenClaw < 2026.3.12 - Scope Elevation in WebSocket Shared-Auth Connections

MEDIUM · 5.8Mar 19, 2026
OpenClawNemoClawNanoClaw

CVE-2026-32035

OpenClaw < 2026.3.2 - Missing Owner Flag Validation in Discord Voice Transcript Handler

MEDIUM · 5.8Mar 19, 2026
OpenClawNemoClawNanoClaw

CVE-2026-31995

OpenClaw 2026.1.21 < 2026.2.19 - Command Injection via Windows Shell Fallback in Lobster Extension

MEDIUM · 4.8Mar 19, 2026
OpenClawNemoClawNanoClaw

CVE-2026-32020

OpenClaw < 2026.2.22 - Arbitrary File Read via Symlink Following in Static File Handler

HIGH · 8.8Mar 18, 2026
OpenClawNemoClawNanoClaw

CVE-2026-22171

OpenClaw < 2026.2.19 - Path Traversal in Feishu Media Temporary File Naming

HIGH · 7.1Mar 18, 2026
OpenClawNemoClawNanoClaw

CVE-2026-22169

OpenClaw < 2026.2.22 - Allowlist Bypass via sort Configuration in safeBins

MEDIUM · 6.9Mar 18, 2026
OpenClawNemoClawNanoClaw

CVE-2026-27523

OpenClaw < 2026.2.24 - Sandbox Bind Validation Bypass via Symlink-Parent Missing-Leaf Paths

MEDIUM · 6.9Mar 18, 2026
OpenClawNemoClawNanoClaw

CVE-2026-27545

OpenClaw < 2026.2.26 - Approval Bypass via Parent Symlink Current Working Directory Rebind

MEDIUM · 4.8Mar 18, 2026
OpenClawNemoClawNanoClaw

CVE-2026-22180

OpenClaw < 2026.3.2 - Path Confinement Bypass in Browser Output and File Write Operations

HIGH · 8.7Mar 11, 2026
OpenClawNemoClawNanoClaw

CVE-2026-32060

OpenClaw < 2026.2.14 - Path Traversal in apply_patch via Crafted Paths

MEDIUM · 0.0Mar 11, 2026
OpenClawNemoClawNanoClaw

CVE-2026-30741

A remote code execution (RCE) vulnerability in OpenClaw Agent Platform v2026.2.6

CRITICAL · 9.2Mar 5, 2026
OpenClawNemoClawNanoClaw

CVE-2026-28446

OpenClaw < 2026.2.1 - Inbound Allowlist Policy Bypass in voice-call Extension via Empty Caller ID and Suffix Matching

HIGH · 8.7Mar 5, 2026
OpenClawNemoClawNanoClaw

CVE-2026-28462

OpenClaw < 2026.2.13 - Path Traversal in Trace and Download Output Paths

HIGH · 8.7Mar 5, 2026
OpenClawNemoClawNanoClaw

CVE-2026-28478

CWE-400
npm/openclawnpm/clawdbot

Affected: < 2026.2.13, <= 2026.1.24-3

OpenClaw affected by denial of service via unbounded webhook request body buffering

HIGH · 8.4Mar 5, 2026
OpenClawNemoClawNanoClaw

CVE-2026-28482

OpenClaw < 2026.2.12 - Path Traversal via Unsanitized sessionId and sessionFile Parameters

HIGH · 8.3Mar 5, 2026
OpenClawNemoClawNanoClaw

CVE-2026-28393

OpenClaw 2.0.0-beta3 < 2026.2.14 - Arbitrary JavaScript Module Loading via Hook Transform Path Traversal

HIGH · 8.2Mar 5, 2026
OpenClawNemoClawNanoClaw

CVE-2026-28469

CWE-284CWE-639
npm/openclawnpm/clawdbot

Affected: < 2026.2.14, <= 2026.1.24-3

OpenClaw Google Chat shared-path webhook target ambiguity allowed cross-account policy-context misrouting

HIGH · 7.4Mar 5, 2026
OpenClawNemoClawNanoClaw

CVE-2026-28458

CWE-306
npm/openclawnpm/moltbot

Affected: >= 2026.1.20, < 2026.2.1, <= 0.1.0

OpenClaw's Browser Relay /cdp websocket is missing auth which could allow cross-tab cookie access

MEDIUM · 6.9Mar 5, 2026
OpenClawNemoClawNanoClaw

CVE-2026-28480

CWE-284CWE-290
npm/openclawnpm/clawdbot

Affected: < 2026.2.14, <= 2026.1.24-3

OpenClaw Telegram allowlist authorization accepted mutable usernames

MEDIUM · 6.8Mar 5, 2026
OpenClawNemoClawNanoClaw

CVE-2026-29612

CWE-400CWE-770
npm/openclawnpm/clawdbot

Affected: < 2026.2.14, <= 2026.1.24-3

OpenClaw < 2026.2.14 - Denial of Service via Large Base64 Media File Decoding

MEDIUM · 6.7Mar 5, 2026
OpenClawNemoClawNanoClaw

CVE-2026-28452

CWE-400CWE-770
npm/openclawnpm/clawdbot

Affected: < 2026.2.14, <= 2026.1.24-3

OpenClaw affected by denial of service through unguarded archive extraction allowing high expansion/resource abuse (ZIP/TAR)

MEDIUM · 6.3Mar 5, 2026
OpenClawNemoClawNanoClaw

CVE-2026-28448

OpenClaw 2026.1.29 < 2026.2.1 - Authorization Bypass in Twitch Plugin allowFrom Access Control

MEDIUM · 6.3Mar 5, 2026
OpenClawNemoClawNanoClaw

CVE-2026-28471

OpenClaw 2026.1.14-1 < 2026.2.2 - Allowlist Bypass via displayName and Cross-Homeserver localpart Matching in Matrix Plugin

MEDIUM · 5.6Mar 5, 2026
OpenClawNemoClawNanoClaw

CVE-2026-28457

OpenClaw < 2026.2.14 - Path Traversal in Sandbox Skill Mirroring via Name Parameter

MEDIUM · 6.8Mar 1, 2026
Claude Code

CVE-2026-33068

CWE-284
claude-code

Affected: < 2.1.50

Workspace trust dialog bypass via repo-controlled settings. A malicious .claude/settings.json could auto-approve dangerous permissions when the repository is opened.

HIGH · 8.6Feb 19, 2026
OpenClawNemoClawNanoClaw

CVE-2026-26323

OpenClaw has a command injection in maintainer clawtributors updater

HIGH · 7.7Feb 19, 2026
OpenClawNemoClawNanoClaw

CVE-2026-27002

OpenClaw: Docker container escape via unvalidated bind mount config injection

HIGH · 7.1Feb 19, 2026
OpenClawNemoClawNanoClaw

CVE-2026-26317

CWE-352
npm/openclawnpm/clawdbot

Affected: < 2026.2.14, <= 2026.1.24-3

OpenClaw affected by cross-site request forgery (CSRF) through loopback browser mutation endpoints

MEDIUM · 6.9Feb 19, 2026
OpenClawNemoClawNanoClaw

CVE-2026-27004

OpenClaw session tool visibility hardening and Telegram webhook secret fallback

MEDIUM · 6.5Feb 19, 2026
OpenClawNemoClawNanoClaw

CVE-2026-26328

CWE-284CWE-863
npm/openclawnpm/clawdbot

Affected: < 2026.2.14, < 2026.2.14

OpenClaw iMessage group allowlist authorization inherited DM pairing-store identities

LOW · 3.7Feb 19, 2026
OpenClawNemoClawNanoClaw

CVE-2026-24764

OpenClaw has Remote Code Execution via System Prompt Injection in Slack Channel Descriptions

HIGH · 7.8Feb 4, 2026
OpenClawNemoClawNanoClaw

CVE-2026-25157

CWE-78
npm/clawdbot

Affected: < 2026.1.29

OpenClaw/Clawdbot has OS Command Injection via Project Root Path in sshNodeCommand

HIGH · 8.8Feb 2, 2026
OpenClawNemoClawNanoClaw

CVE-2026-24763

CWE-78
npm/clawdbot

Affected: <= 2026.1.24

OpenClaw/Clawdbot Docker Execution has Authenticated Command Injection via PATH Environment Variable

HIGH · 8.8Feb 1, 2026
OpenClawNemoClawNanoClaw

CVE-2026-25253

CWE-668
npm/clawdbot

Affected: <= 2026.1.28

OpenClaw/Clawdbot has 1-Click RCE via Authentication Token Exfiltration From gatewayUrl

MEDIUM · 6.5Feb 1, 2026
Claude Code

CVE-2026-24887

CWE-78
claude-code

Affected: < 2.1.0

Command injection via find command bypass. Claude Code's denylist for dangerous commands could be bypassed using the find command's -exec flag.

MEDIUM · 5.3Jan 10, 2026
Claude Code

CVE-2026-21852

CWE-522
claude-code

Affected: < 2.0.65

API key exfiltration via ANTHROPIC_BASE_URL override. A malicious .env file could redirect API calls to an attacker-controlled endpoint, leaking the user's API key.

HIGH · 8.7Jul 15, 2025
Claude Code

CVE-2025-59536

CWE-94
claude-code

Affected: < 1.0.111

Remote code execution via malicious hooks/MCP configs in untrusted repos. Opening an untrusted repository could trigger pre-trust code execution through crafted hook configurations.

HIGH · 7.1Jun 1, 2025
Claude Code

CVE-2025-55284

CWE-200
claude-code

Affected: < 1.0.90

Data exfiltration via DNS requests through prompt injection. Malicious content in project files could trigger DNS-based data exfiltration bypassing network controls.

HIGH · 7.5May 15, 2025
Claude Code

CVE-2025-54794

CWE-74
claude-code

Affected: < 1.0.80

Prompt injection bypassing approval prompts. Crafted file contents could manipulate Claude Code into executing unapproved tool calls without user consent.

Protect your AI agent and Claude Code deployments

Clawkeeper scans your AI agents and Claude Code environments against known CVEs, misconfigurations, and exposed credentials — then tells you exactly what to fix.

$ curl -fsSL https://clawkeeper.dev/install.sh | bash