Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.6 HIGH
CVE-2026-100559 — OpenClaw before 2026.8.1 Command Injection via Escaped Newlines

OpenClaw versions before 2026.8.1 contain a command parser vulnerability where escaped newlines confuse exec allowlist parsing, allowing hidden commands to execute. Attackers can craft input with esc…

Remote | Injection
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
8.7 HIGH
CVE-2026-100558 — OpenClaw before 2026.8.1 Resource Exhaustion via WebSocket Upgrade

OpenClaw versions before 2026.8.1 contain a resource exhaustion vulnerability in the Gateway listener that allows unauthenticated clients to retain response sockets by sending WebSocket upgrade reque…

Remote | Denial of Service
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
8.7 HIGH
CVE-2026-100557 — OpenClaw before 2026.8.1 Authorization Bypass via Skill Tool Dispatch

OpenClaw versions before 2026.8.1 contain an authorization bypass vulnerability in skill tool dispatch that fails to carry the sender's owner status. Non-owner senders authorized to invoke skill comm…

Remote | Authorization
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
6.3 MEDIUM
CVE-2026-100556 — OpenClaw before 2026.8.1 Authentication Bypass via Session Reset

OpenClaw (npm package openclaw) versions >= 2026.5.2 and < 2026.8.1 contain an incorrect authorization vulnerability in WhatsApp group handling. A group sender who is admitted for ordinary messages b…

Remote | Authorization
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
7.1 HIGH
CVE-2026-100555 — OpenClaw before 2026.8.1 DNS Rebinding via attachment delivery

OpenClaw is an npm-distributed gateway application. In versions >= 2026.7.1 and < 2026.8.1, Synology Chat attachment delivery could lose DNS pinning: the Gateway validated a single DNS result for a s…

Remote | Server-Side Request Forgery
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
4.2 MEDIUM
CVE-2026-100554 — OpenClaw before 2026.8.1 Canvas Capability Revocation Bypass

OpenClaw (npm package 'openclaw') versions >= 2026.5.12 and < 2026.8.1 do not immediately invalidate Canvas HTTP authorization when a paired node is revoked. Node revocation invalidates the WebSocket…

Remote | Authorization
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
5.3 MEDIUM
CVE-2026-100553 — OpenClaw 2026.6.9 before 2026.8.1 Cross-Context Policy Bypass via Feishu unpin

OpenClaw versions >= 2026.6.9 and < 2026.8.1 do not declare the native chatId parameter as a delivery target in the Feishu unpin feature, so unpin requests can bypass the shared same-provider cross-c…

Remote | Authorization
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
8.8 HIGH
CVE-2026-100552 — OpenClaw before 2026.8.1 Policy Bypass via Native Tools

OpenClaw (npm package 'openclaw') before 2026.8.1 does not correctly enforce per-chat tool policies for Codex app-server runtime tools. A conversation-level tools.allow rule filtered OpenClaw tools b…

Remote | Authorization
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
9.0 CRITICAL
CVE-2026-100551 — OpenClaw iOS Control UI TLS Pin Enforcement Bypass

OpenClaw for iOS versions >= 2026.7.1 and < 2026.8.11 do not enforce saved Gateway TLS pins in the Control UI. While native connections enforced the saved Gateway fingerprint, the authenticated Termi…

Remote | Authentication
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
5.4 MEDIUM
CVE-2026-100550 — OpenClaw before 2026.8.1 Authentication Bypass via Access Group

OpenClaw (npm package 'openclaw') before 2026.8.1 contains an access-control bypass in the Microsoft Teams integration. When groupPolicy is set to allowlist, a missing or unsupported configured acces…

Remote | Authorization
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
5.4 MEDIUM
CVE-2026-100549 — OpenClaw before 2026.8.1 Path Traversal via QQBot voice filenames

OpenClaw versions before 2026.8.1 contain a path traversal vulnerability in QQBot voice attachment handling where filenames are decoded twice, allowing encoded traversal segments to reappear after sa…

Remote | Path Traversal
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
6.0 MEDIUM
CVE-2026-100548 — OpenClaw before 2026.8.1 Credential Exposure via Embedding Fallback

OpenClaw (npm package 'openclaw') versions >= 2026.3.28 and < 2026.8.1 contain a credential exposure issue in memory embedding failover. When remote embedding fallback is configured and the primary e…

Remote | Cryptography
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
6.8 MEDIUM
CVE-2026-100547 — OpenClaw before 2026.8.1 Authentication Bypass via File URL

OpenClaw is a coding agent distributed as the npm package `openclaw`. In affected versions (2026.7.1 through 2026.7.2), alternate but valid `file:` URL spellings supplied over the Agent Client Protoc…

| Path Traversal
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
6.4 MEDIUM
CVE-2026-100546 — OpenClaw 2026.7.2 before 2026.9.2 Authentication Bypass via Voice Transcript

OpenClaw (npm package `openclaw`) versions >= 2026.7.2 and < 2026.9.2 contain a race condition in the Discord realtime voice transcript path. Concurrent control-classified voice transcripts could con…

Remote | Race Condition
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
6.0 MEDIUM
CVE-2026-100545 — OpenClaw before 2026.8.1 Policy Bypass via Session Filename Generation

OpenClaw (npm package `openclaw`) before 2026.8.1 incorrectly enforces sender tool policies during session-memory filename generation. In affected versions, filename generation created an embedded he…

Remote | Misconfiguration
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
8.8 HIGH
CVE-2026-100544 — openclaw voice-call before 2026.8.1 Authorization Bypass

openclaw's @openclaw/voice-call package before 2026.8.1 launches the configured agent for classic inbound voice calls without propagating the caller's identity or non-owner status. As a result, owner…

Remote | Authorization
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
7.7 HIGH
CVE-2026-100543 — OpenClaw before 2026.8.1 Information Disclosure via Configuration Hash

OpenClaw (npm package openclaw) before 2026.8.1 could include deterministic hashes computed over the original, unredacted configuration in redacted configuration responses. When the Gateway password …

Remote | Cryptography
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
3.1 LOW
CVE-2026-100542 — OpenClaw before 2026.8.1 Extraction Limit Bypass via tar.bz2

OpenClaw (npm package 'openclaw') versions >= 2026.5.28 and < 2026.8.1 mishandle archive listings in the tar.bz2 skill installer: bounded command-output suffixes were treated as complete listings of …

Remote | Misconfiguration
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
7.7 HIGH
CVE-2026-100541 — OpenClaw Matrix before 2026.8.1 Authorization Bypass via Case Folding

OpenClaw's Matrix integration (npm package @openclaw/matrix) versions >= 2026.2.2 and < 2026.8.1 lowercase complete Matrix user IDs — including historical localparts and the case-sensitive server-nam…

Remote | Authorization
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
7.6 HIGH
CVE-2026-100540 — OpenClaw Feishu before 2026.8.1 Authentication Bypass via Disabled Account

OpenClaw Feishu before 2026.8.1 fails to validate whether a configured default account is disabled before selecting it for model tool operations. Attackers can exploit multi-account setups where a di…

Remote | Authentication
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
Showing 20 of 14637 Results