Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.1 HIGH
CVE-2026-100538 — OpenClaw before 2026.8.1 Local File Read via Outbound Attachments

OpenClaw (npm package 'openclaw') before 2026.8.1 does not apply the originating sender's global or per-agent toolsBySender policy when handling outbound attachments. A sender that has been explicitl…

Remote | Path Traversal
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
3.1 LOW
CVE-2026-100537 — OpenClaw before 2026.8.1 Authentication Bypass via Active Memory

OpenClaw (npm package 'openclaw') before 2026.8.1 fails to apply the originating requester's effective tool policy during Active Memory automatic recall. In deployments that use Active Memory togethe…

Remote | Authorization
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
7.1 HIGH
CVE-2026-100536 — OpenClaw before 2026.8.1 Path Traversal via Structured Attachments

OpenClaw versions before 2026.8.1 fail to validate all source fields in structured message attachments, allowing attackers to hide unvalidated host paths behind allowed attachment sources. Attackers …

Remote | Path Traversal
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
7.7 HIGH
CVE-2026-100535 — OpenClaw before 2026.8.1 Privilege Escalation via Session Memory

OpenClaw (npm package 'openclaw') versions >= 2026.4.5 and < 2026.8.1 can lose the originating requester's restrictions and untrusted provenance when session-derived text is persisted to session memo…

Remote | Misconfiguration
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
3.1 LOW
CVE-2026-100534 — OpenClaw before 2026.8.1 Session Cancellation Authorization Bypass

OpenClaw versions before 2026.8.1 contain an authorization bypass vulnerability in webhook TaskFlow cancellation that allows attackers to cancel unrelated sessions. An attacker with a webhook route s…

Remote | Authorization
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
6.0 MEDIUM
CVE-2026-100533 — OpenClaw before 2026.8.1 Path Traversal via Unicode Fallback

OpenClaw versions before 2026.8.1 contain a path traversal vulnerability in the tools.fs.workspaceOnly feature where Unicode filename fallback can normalize validated parent directory components. Adm…

Remote | Path Traversal
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
8.1 HIGH
CVE-2026-100532 — openclaw WhatsApp before 2026.8.1 Authentication Bypass

@openclaw/whatsapp (npm) before 2026.8.1 exposes the WhatsApp login tool through the generic channel-tool path without preserving the originating sender's owner status, so the owner-only tool boundar…

Remote | Authentication
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
7.1 HIGH
CVE-2026-100531 — openclaw Slack before 2026.8.1 Authorization Bypass

The @openclaw/slack npm package before 2026.8.1 contains an authorization flaw in its Slack download-file handler: when a file lacks the share metadata used to prove it belongs to the requested conve…

Remote | Authorization
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
8.5 HIGH
CVE-2026-100530 — OpenClaw before 2026.8.1 Exec Approval Directory Binding

OpenClaw versions before 2026.8.1 fail to bind working directory context to reusable exec approvals, allowing approved commands to execute in different directories. Attackers with an allow-always app…

Remote | Authorization
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
7.4 HIGH
CVE-2026-100529 — OpenClaw before 2026.8.1 Authorization Scope Widening via File-Transfer

OpenClaw versions before 2026.8.1 contain an authorization scope widening vulnerability in file-transfer allow-always approvals that allows attackers to reuse standing grants for unreviewed paths. At…

Remote | Authorization
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
5.9 MEDIUM
CVE-2026-100528 — OpenClaw before 2026.8.1 Credential Disclosure via Provider Endpoint

OpenClaw (npm package 'openclaw') before 2026.8.1 could send third-party provider credentials to the wrong endpoint. In affected versions, when a third-party provider uses an OpenAI-compatible API an…

Remote | Misconfiguration
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
6.9 MEDIUM
CVE-2026-100527 — OpenClaw before 2026.8.2 Denial of Service via Browser Relay

OpenClaw before 2026.8.2 contains a denial of service vulnerability in the Browser extension relay that allows unauthenticated network sources to exhaust pending-authentication capacity. Attackers ca…

Remote | Denial of Service
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
6.0 MEDIUM
CVE-2026-100526 — Vulnerability in discord

OpenClaw's Discord integration (npm package @openclaw/discord) before version 2026.9.3 could lose the sender-scoped media policy in the emoji and sticker upload actions before loading a local file. A…

Remote | Path Traversal
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
5.3 MEDIUM
CVE-2026-100525 — OpenClaw diagnostics-prometheus before 2026.9.3 Authentication Bypass

The OpenClaw Prometheus diagnostics plugin (@openclaw/diagnostics-prometheus) before version 2026.9.3 does not enforce the operator.read scope on its authenticated metrics endpoint. In deployments us…

Remote | Authorization
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
5.4 MEDIUM
CVE-2026-100524 — Cotonti through 1.0.0 Cross-Site Request Forgery via Extensions Manager

Cotonti through 1.0.0 contains a cross-site request forgery vulnerability in the extensions manager that allows attackers to perform state-changing actions without anti-CSRF token validation. Attacke…

Remote | Cross-Site Request Forgery
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
6.1 MEDIUM
CVE-2026-100523 — Cotonti through 1.0.0 Open Redirect via message.php redirect parameter

Cotonti through 1.0.0 contains an open redirect vulnerability in message.php that base64-decodes the redirect parameter without domain validation. Unauthenticated attackers can craft malicious links …

Remote | Misconfiguration
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
6.1 MEDIUM
CVE-2026-100522 — Cotonti through 1.0.0 Reflected XSS via message.php lng parameter

Cotonti through 1.0.0 contains a reflected cross-site scripting vulnerability in message.php where the lng parameter is not properly escaped before output in the confirmation dialog. Unauthenticated …

Remote | Cross-Site Scripting
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
6.1 MEDIUM
CVE-2026-100521 — Cotonti through 1.0.0 Reflected XSS via search highlight parameter

Cotonti through 1.0.0 contains a reflected cross-site scripting vulnerability in the search plugin highlight parameter that performs no HTML or JavaScript escaping. Attackers can craft malicious link…

Remote | Cross-Site Scripting
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
8.8 HIGH
CVE-2026-100520 — Laranode before 1.2.1 Path Traversal in File Manager Upload Endpoint

Laranode versions before 1.2.1 contain a path traversal vulnerability in the POST /filemanager/upload-file endpoint that allows authenticated users to write arbitrary files outside their home directo…

Remote | Path Traversal
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
4.8 MEDIUM
CVE-2026-100505 — Ghidra 11.2 through 12.1.4 Heap Out-of-Bounds Read via StringManager

Ghidra versions 11.2 through 12.1.4 contain a heap out-of-bounds read vulnerability in StringManager::getCodepoint when decoding multi-byte UTF-8, UTF-16, or UTF-32 characters without validating rema…

| Memory Corruption
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
Showing 20 of 14636 Results