Daily-updated CVE and GHSA advisories for OpenClaw, NemoClaw, NanoClaw, and Claude Code. Vulnerabilities tracked, scored, and enriched with affected packages so you can prioritize what matters.
Powered by OpenClawCVEsLast updated: September 23, 2026
OpenClaw 2026.2.25 < 2026.5.26 WebSocket Rate Limit Bypass
OpenClaw 2026.4.12-beta.1 < 2026.6.6 Authorization Bypass via message actions
OpenClaw < 2026.6.1 Denial of Service via Remote Media URLs
OpenClaw < 2026.6.6 Network Policy Bypass via exec-server
OpenClaw 2026.5.12 < 2026.5.26 Authorization Bypass via allowFrom
AidanPark openclaw-android Android WebView Bridge JsBridge.kt os command injection
Affected: < 2026.5.26
OpenClaw: Pairing-scoped device session could restore revoked node token authority
Affected: <= 2026.5.6
OpenClaw: Discord allowFrom could bind to mutable display names
Affected: <= 2026.5.2
OpenClaw < 2026.5.3 - Mutable Display Name Binding in Zalo allowFrom Policy
Affected: < 2026.4.2
OpenClaw < 2026.4.2 - Shell Positional Parameters Bypass in Inline-Eval Checks
Affected: < 2026.5.12
OpenClaw: Linux and macOS exec allowlists skipped configured argument patterns
Affected: <= 2026.5.22
OpenClaw: Host environment sanitizer missed two Node.js control variables
Affected: <= 2026.5.10-beta.1
OpenClaw < 2026.5.12 - Allowlist Bypass in Shell Inline-Command Parsing
Affected: < 2026.5.2
OpenClaw: Workspace-derived service PATH could influence trash command selection
Affected: < 2026.5.2
OpenClaw: Workspace .env CLOUDSDK_PYTHON could influence Gmail setup gcloud execution
Affected: < 2026.4.29
OpenClaw: Workspace .env npm_execpath could influence bundled runtime dependency install
Affected: < 2026.5.2
OpenClaw: Workspace .env STATE_DIRECTORY could influence bundled runtime dependency roots
Affected: <= 2026.4.24
OpenClaw < 2026.4.25 - Control Scope Enforcement Bypass in Focus Command
Affected: <= 2026.5.7
OpenClaw < 2026.5.12 - Slack Reaction Event Notification Bypass
Affected: < 2026.5.12
OpenClaw: MCP Streamable HTTP redirects could forward configured custom headers to another origin
Affected: <= 2026.4.27
OpenClaw < 2026.4.29 - Session Visibility Check Bypass in Shared Memory Search
Affected: <= 2026.4.24
OpenClaw: Internal/webchat command auth could inherit ownerAllowFrom wildcard state
Affected: <= 2026.5.22
OpenClaw < 2026.5.26 - Hostname Validation Bypass via Trailing-Dot Inconsistency
Affected: <= 2026.4.24
OpenClaw < 2026.4.25 - Unvalidated Group ID Acceptance in Tool Group Policy
Affected: = 2026.4.23
OpenClaw: Config recovery could restore openclaw.json with broad file permissions
Affected: <= 2026.5.5
OpenClaw < 2026.5.6 - Privilege Escalation via Active Memory Write Scope
Affected: <= 2026.5.5
OpenClaw < 2026.5.6 - Allowlist Bypass via Combined POSIX Inline Flags on macOS
Affected: <= 2026.5.5
OpenClaw: Skill-command dispatch could skip before-tool-call hooks
Affected: <= 2026.5.22
OpenClaw < 2026.5.26 - Exec Allowlist Bypass via Transparent Command Wrappers
Affected: <= 2026.4.24
OpenClaw < 2026.4.25 - Scope Bypass via Empty-Scope Device Re-pairing
Affected: <= 2026.5.6
OpenClaw: BlueBubbles sender policy could match mutable conversation identifiers
Affected: <= 2026.5.10-beta.2
OpenClaw < 2026.5.12 - Bootstrap Token Replay via Pending Pairing Scope Widening
Affected: <= 2026.5.7
OpenClaw: Exported session HTML could keep unsafe markdown links
OpenClaw < 2026.5.18 - Command Argument Modification via Shell Wrapper Between Approval and Execution
Affected: <= 2026.5.7
OpenClaw < 2026.5.12 - Allowlist Bypass via PowerShell Encoded-Command Aliases
OpenClaw < 2026.5.18 - Command Truncation in Exec Approval Display
Affected: <= 2026.4.26
OpenClaw < 2026.4.27 - Authorization Bypass in QQBot Pre-dispatch Slash Commands
Affected: < 2026.5.18
OpenClaw's POSIX node system.run safe-bin allowlist could be widened by shell expansion
Affected: <= 2026.4.27
OpenClaw: QQBot streaming command could mutate config without explicit allowFrom
Affected: < 2026.5.18
OpenClaw < 2026.5.18 - Identity Header Forgery via Trusted-Proxy Configuration
Affected: <= 2026.5.5
OpenClaw: Mattermost handlers could fall open when channel type was missing
Affected: <= 2026.4.21
OpenClaw < 2026.4.22 - Webhook Secret Revocation Bypass via secrets.reload
Affected: < 2026.5.27
OpenClaw < 2026.5.27 - Node Pairing State Mutation via Reconnection
Affected: < 2026.5.20
OpenClaw: Hook-triggered CLI runs could receive owner MCP tool authority
Affected: < 2026.5.22
OpenClaw < 2026.5.22 - Control UI Locality Spoofing in Device Pairing
Affected: < 2026.5.27
OpenClaw: Workspace .env could override Homebrew executable selection for skill install flows
Affected: < 2026.5.18
OpenClaw < 2026.5.18 - Exec Lifecycle Event Forgery via Paired Node
Affected: <= 2026.5.7
OpenClaw < 2026.5.12 - Shell Option Parsing Bypass in Exec Revalidation
Affected: < 2026.5.18
OpenClaw's marketplace runtime extension metadata could point at unscanned payloads
Affected: <= 2026.5.6
OpenClaw: Matrix allowFrom could bind to mutable display names
Affected: <= 2026.4.24
OpenClaw: Fake package roots could influence memory-core artifact loading
Affected: <= 2026.5.19-beta.2
OpenClaw < 2026.5.19 - Channel Allowlist Bypass in Message Read Actions
Affected: < 2026.4.24
OpenClaw < 2026.4.24 - Owner-Only Tool Policy Bypass via MCP Loopback
Affected: < 2026.5.18
OpenClaw's browser act interactions could bypass private-network navigation checks
Affected: <= 2026.4.24
OpenClaw < 2026.4.25 - Provider Alias Confusion in Embedded Runner Policy
Affected: < 2026.5.18
OpenClaw: QQBot native approval buttons did not enforce configured approver identity
OpenClaw < 2026.5.12 - Privilege Escalation in Slack Plugin Approvals via Exec Approver Gate
OpenClaw < 2026.4.29 - Policy Bypass in QQBot Admin Commands via DM-only and allowFrom Checks
Crabbox < 0.9.0 Path Traversal via Islo Provider Workspace Resolution
OpenClaw < 2026.4.20 - Gateway Config Mutation Guard Bypass via Agent Tool Access
OpenClaw < 2026.4.20 - Direct Message Misclassification in Feishu Card Actions
OpenClaw < 2026.4.21 - Authorization Bypass in Owner-Enforced Commands via Wildcard Channel Senders
OpenClaw < 2026.4.10 - Arbitrary Local File Read via QQBot Media Tags
OpenClaw < 2026.4.9 - Environment Variable Injection via Workspace .env File
OpenClaw < 2026.3.31 - Environment Variable Override of Plugin Trust Root
OpenClaw < 2026.4.8 - Role Bypass in device.token.rotate Function
OpenClaw < 2026.4.8 - Missing Integrity Verification in Package Downloads
OpenClaw < 2026.4.8 - Command Escalation via Node Pairing Reconnect Bypass
OpenClaw < 2026.3.28 - Authorization Bypass in /phone arm and /phone disarm Endpoints
OpenClaw < 2026.3.31 - Arbitrary DNS Authority Acceptance and Credential Exfiltration via Wide-Area Discovery
OpenClaw < 2026.3.31 - Webhook Replay Cache Cross-Target messageId Scope Bypass
OpenClaw < 2026.3.31 - Disk Exhaustion via Media Download Bypass
OpenClaw < 2026.4.8 - Stale Authentication State via Config Reload
OpenClaw < 2026.3.31 - Arbitrary File Write via Symlink Following in SSH Sandbox Tar Upload
OpenClaw < 2026.4.2 - Loopback Protection Bypass via Trailing-Dot Localhost in CDP Discovery
OpenClaw < 2026.3.31 - Arbitrary Host File Read via appendLocalMediaParentRoots Self-Whitelisting
OpenClaw 2026.2.14 < 2026.3.28 - Policy Enforcement Bypass in Discord Component Interactions
OpenClaw < 2026.3.28 - Agentic Consent Bypass via config.patch
OpenClaw < 2026.3.28 - Privilege Escalation via operator.write to Admin-Class Telegram Config and Cron Persistence
OpenClaw < 2026.3.31 - Denial of Service via LINE Webhook Handler Pre-Auth Concurrency
OpenClaw < 2026.3.31 - Information Disclosure via Control UI Bootstrap JSON
OpenClaw < 2026.3.31 - Time-of-Check-Time-of-Use (TOCTOU) Vulnerability in Sandbox File Operations
OpenClaw < 2026.3.28 - Client Identity Spoofing in chat.send Gateway Provenance Guard
OpenClaw 2026.3.22 < 2026.3.31 - Forged Nostr DM Pairing State Creation via Signature Verification Bypass
OpenClaw < 2026.3.25 - Privilege Escalation via Backend Reconnect Scope Self-Claim
OpenClaw < 2026.3.24 - Privilege Escalation via chat.send to Allowlist Persistence
OpenClaw < 2026.3.22 - Unauthorized Action Execution via Callback Dispatch
OpenClaw < 2026.3.22 - Settings Reconciliation Bypass via Empty Allowlist
OpenClaw < 2026.3.22 - XFF Loopback Spoofing Bypass in Canvas Authentication and Rate Limiter
OpenClaw < 2026.3.22 - Privilege Escalation via device.pair.approve Scope Validation
OpenClaw < 2026.3.25 - Improper Access Control in /sessions/:sessionKey/kill Endpoint
OpenClaw 2026.3.11 < 2026.3.25 - Session Isolation Bypass via sessionId Resolution
OpenClaw < 2026.3.25 - Authorization Bypass via Group Policy Rebinding with Mutable Space displayName
OpenClaw < 2026.3.22 - Policy Confusion via Room Name Collision in Nextcloud Talk
OpenClaw - Shell-Bleed Protection Preflight Validation Bypass
OpenClaw < 2026.3.28 - Brute Force Attack via Missing Rate Limiting on Webhook Shared Secret Authentication
OpenClaw < 2026.3.11 - Sandbox Boundary Bypass via Unvalidated Temporary File Creation
OpenClaw < 2026.3.11 - Sandbox Boundary Bypass via Unanchored writeFile Commit Path
OpenClaw < 2026.3.28 - Sender Policy Allowlist Bypass via Policy Downgrade in Google Chat and Zalouser Extensions
OpenClaw < 2026.3.11 - Session Sandbox Escape via session_status Tool
OpenClaw < 2026.3.11 - Unauthorized Session Reset via agent Slash Commands
OpenClaw Media Parsing Path Traversal to Arbitrary File Read
OpenClaw < 2026.3.7 - Sandbox Escape via /acp spawn Command
OpenClaw < 2026.2.25 - Privilege Escalation via Unpaired Device Identity in Shared Gateway Authentication
OpenClaw < 2026.2.22 - Denial of Service via Inbound Media Download Byte Limit Bypass
OpenClaw < 2026.3.1 - Sandbox Escape via Cross-Agent sessions_spawn
OpenClaw < 2026.3.2 - Tar Archive Safety Bypass in Skills Installation
OpenClaw < 2026.2.25 - Symlink Traversal in Browser Trace/Download Path Handling
OpenClaw < 2026.3.12 - Scope Elevation in WebSocket Shared-Auth Connections
OpenClaw < 2026.3.2 - Missing Owner Flag Validation in Discord Voice Transcript Handler
OpenClaw 2026.1.21 < 2026.2.19 - Command Injection via Windows Shell Fallback in Lobster Extension
OpenClaw < 2026.2.22 - Arbitrary File Read via Symlink Following in Static File Handler
OpenClaw < 2026.2.19 - Path Traversal in Feishu Media Temporary File Naming
OpenClaw < 2026.2.22 - Allowlist Bypass via sort Configuration in safeBins
OpenClaw < 2026.2.24 - Sandbox Bind Validation Bypass via Symlink-Parent Missing-Leaf Paths
OpenClaw < 2026.2.26 - Approval Bypass via Parent Symlink Current Working Directory Rebind
OpenClaw < 2026.3.2 - Path Confinement Bypass in Browser Output and File Write Operations
OpenClaw < 2026.2.14 - Path Traversal in apply_patch via Crafted Paths
A remote code execution (RCE) vulnerability in OpenClaw Agent Platform v2026.2.6
OpenClaw < 2026.2.1 - Inbound Allowlist Policy Bypass in voice-call Extension via Empty Caller ID and Suffix Matching
OpenClaw < 2026.2.13 - Path Traversal in Trace and Download Output Paths
Affected: < 2026.2.13, <= 2026.1.24-3
OpenClaw affected by denial of service via unbounded webhook request body buffering
OpenClaw < 2026.2.12 - Path Traversal via Unsanitized sessionId and sessionFile Parameters
OpenClaw 2.0.0-beta3 < 2026.2.14 - Arbitrary JavaScript Module Loading via Hook Transform Path Traversal
Affected: < 2026.2.14, <= 2026.1.24-3
OpenClaw Google Chat shared-path webhook target ambiguity allowed cross-account policy-context misrouting
Affected: >= 2026.1.20, < 2026.2.1, <= 0.1.0
OpenClaw's Browser Relay /cdp websocket is missing auth which could allow cross-tab cookie access
Affected: < 2026.2.14, <= 2026.1.24-3
OpenClaw Telegram allowlist authorization accepted mutable usernames
Affected: < 2026.2.14, <= 2026.1.24-3
OpenClaw < 2026.2.14 - Denial of Service via Large Base64 Media File Decoding
Affected: < 2026.2.14, <= 2026.1.24-3
OpenClaw affected by denial of service through unguarded archive extraction allowing high expansion/resource abuse (ZIP/TAR)
OpenClaw 2026.1.29 < 2026.2.1 - Authorization Bypass in Twitch Plugin allowFrom Access Control
OpenClaw 2026.1.14-1 < 2026.2.2 - Allowlist Bypass via displayName and Cross-Homeserver localpart Matching in Matrix Plugin
OpenClaw < 2026.2.14 - Path Traversal in Sandbox Skill Mirroring via Name Parameter
Affected: < 2.1.50
Workspace trust dialog bypass via repo-controlled settings. A malicious .claude/settings.json could auto-approve dangerous permissions when the repository is opened.
OpenClaw has a command injection in maintainer clawtributors updater
OpenClaw: Docker container escape via unvalidated bind mount config injection
Affected: < 2026.2.14, <= 2026.1.24-3
OpenClaw affected by cross-site request forgery (CSRF) through loopback browser mutation endpoints
OpenClaw session tool visibility hardening and Telegram webhook secret fallback
Affected: < 2026.2.14, < 2026.2.14
OpenClaw iMessage group allowlist authorization inherited DM pairing-store identities
OpenClaw has Remote Code Execution via System Prompt Injection in Slack Channel Descriptions
Affected: < 2026.1.29
OpenClaw/Clawdbot has OS Command Injection via Project Root Path in sshNodeCommand
Affected: <= 2026.1.24
OpenClaw/Clawdbot Docker Execution has Authenticated Command Injection via PATH Environment Variable
Affected: <= 2026.1.28
OpenClaw/Clawdbot has 1-Click RCE via Authentication Token Exfiltration From gatewayUrl
Affected: < 2.1.0
Command injection via find command bypass. Claude Code's denylist for dangerous commands could be bypassed using the find command's -exec flag.
Affected: < 2.0.65
API key exfiltration via ANTHROPIC_BASE_URL override. A malicious .env file could redirect API calls to an attacker-controlled endpoint, leaking the user's API key.
Affected: < 1.0.111
Remote code execution via malicious hooks/MCP configs in untrusted repos. Opening an untrusted repository could trigger pre-trust code execution through crafted hook configurations.
Affected: < 1.0.90
Data exfiltration via DNS requests through prompt injection. Malicious content in project files could trigger DNS-based data exfiltration bypassing network controls.
Affected: < 1.0.80
Prompt injection bypassing approval prompts. Crafted file contents could manipulate Claude Code into executing unapproved tool calls without user consent.