PatchSiren

OpenClaw CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH OpenClaw CVE published 2026-07-17

CVE-2026-62228

A vulnerability was found in OpenClaw before version 2026.6.5. The issue is an authorization bypass in node exec approvals, which allows lower-trust callers to execute actions beyond their intended authorization by using different gateway and node environments. This vulnerability has a high impact on OpenClaw deployments, as it can allow attackers to persist or execute actions that exceed the caller's app [truncated]

MEDIUM OpenClaw CVE published 2026-07-17

CVE-2026-62227

OpenClaw 2026.4.14 before 2026.5.26 contain a server-side request forgery vulnerability in browser snapshot routes that fail to validate post-navigation destinations. Attackers with lower-trust access can bypass OpenClaw policy checks to reach network destinations that should have been blocked. This vulnerability has a CVSS score of 4.9 and is classified as MEDIUM severity. The vulnerability affects OpenC [truncated]

MEDIUM OpenClaw CVE published 2026-07-17

CVE-2026-62226

OpenClaw 2026.3.28 before 2026.5.19 contain an authorization bypass vulnerability in the browser act route that fails to properly validate current-tab URL checks. Attackers with lower-trust access or configured input paths can perform actions requiring stronger authorization or policy checks. This vulnerability has a CVSS score of 5.1 and is classified as MEDIUM severity. Users of OpenClaw 2026.3.28 befor [truncated]

LOW openclaw CVE published 2026-07-17

CVE-2026-62224

CVE-2026-62224 is an authorization bypass vulnerability in OpenClaw MS Teams before version 2026.5.12. The vulnerability arises from the allowFrom feature binding to mutable display names, allowing attackers with lower-trust access to perform actions requiring stronger authorization. This vulnerability can impact users of OpenClaw MS Teams, particularly those with lower-trust access, and may allow unautho [truncated]

HIGH OpenClaw CVE published 2026-07-17

CVE-2026-62222

OpenClaw before 2026.5.22 contains a vulnerability in setup-mode discovery that allows loading of untrusted workspace plugins. Attackers with lower-trust caller access or control over configured input paths can execute or persist actions beyond their intended authorization level. This vulnerability has a CVSS score of 7.1, indicating high severity. The vulnerability exists in the setup-mode discovery of O [truncated]

LOW OpenClaw CVE published 2026-07-17

CVE-2026-62221

OpenClaw 2026.5.12 before 2026.5.26 contain an incorrect authorization vulnerability in the ClickClack allowFrom feature. When the affected feature is enabled and reachable, a lower-trust caller or configured input path could execute or persist actions beyond the caller's intended authorization, including running non-allowlisted commands. This vulnerability has a CVSS score of 2.3 and is rated as LOW. The [truncated]

MEDIUM OpenClaw CVE published 2026-07-17

CVE-2026-62220

CVE-2026-62220 is a MEDIUM severity vulnerability in OpenClaw 2026.2.25 before 2026.5.26 that allows a lower-trust caller or configured input path to bypass non-browser rate limits on WebSocket authentication attempts. This can consume gateway resources and reduce service availability when the affected feature is enabled and reachable by lower-trust input. The vulnerability class is related to WebSocket a [truncated]

MEDIUM OpenClaw CVE published 2026-07-17

CVE-2026-62219

CVE-2026-62219 is an authorization bypass vulnerability in OpenClaw 2026.2.12 before 2026.5.26. The vulnerability exists in the hooks allowedAgentIds validation. A lower-trust caller or configured input path can bypass agent ID restrictions by submitting blank agent IDs, allowing actions that should require stronger authorization or policy checks. The CVSS score for this vulnerability is 6, and the severi [truncated]

HIGH OpenClaw CVE published 2026-07-17

CVE-2026-62217

A high-severity authorization flaw was found in OpenClaw 2026.5.14-beta.1. The QQBot exec approvals feature, when enabled and reachable, allows lower-trust callers or configured input paths to execute or persist actions beyond their intended authorization. This could enable non-allowlisted senders to perform unauthorized operations. The vulnerability has a CVSS score of 7.7 and is classified as HIGH sever [truncated]

LOW OpenClaw CVE published 2026-07-17

CVE-2026-62216

OpenClaw 2026.4.20 before 2026.5.28 contains a policy bypass in the QQBot media upload feature. A lower-trust caller or configured input path could cause the media upload to reach network destinations that should have been blocked by OpenClaw policy (server-side request forgery). The practical impact depends on the operator's configuration and whether lower-trust input can reach that path. Users of OpenCl [truncated]

MEDIUM OpenClaw CVE published 2026-07-17

CVE-2026-62215

CVE-2026-62215 is an authentication bypass vulnerability in OpenClaw versions before 2026.6.5. The vulnerability exists in HTTP Canvas responses, allowing lower-trust callers to forge trusted A2UI actions. This could enable attackers to perform actions requiring stronger authorization by submitting crafted requests through configured input paths, potentially bypassing intended policy checks.

MEDIUM openclaw CVE published 2026-07-17

CVE-2026-62214

CVE-2026-62214 is an improper input validation vulnerability in OpenClaw Bot Framework versions before 2026.5.28. The vulnerability allows lower-trust callers to expose bot tokens and credentials by failing to properly validate serviceUrl parameters. Attackers can supply malicious serviceUrl values through configured input paths to retrieve sensitive authentication data outside the trusted boundary. This [truncated]

MEDIUM openclaw CVE published 2026-07-17

CVE-2026-62213

CVE-2026-62213 is a medium-severity vulnerability in OpenClaw versions before 2026.5.27. The issue involves a token leakage vulnerability in MS Teams outbound requests, potentially exposing Bot Framework tokens to lower-trust callers. To address this vulnerability, users should update OpenClaw to version 2026.5.27 or later and review their configurations to ensure that sensitive credentials are not expose [truncated]

MEDIUM OpenClaw CVE published 2026-07-17

CVE-2026-62212

CVE-2026-62212 is a race condition vulnerability in OpenClaw before version 2026.5.28. The issue affects the MS Teams safeFetch DNS rebinding check. When the feature is enabled and reachable, a lower-trust caller or configured input path could exploit a timing window between the DNS validation check and use. This could allow actions that should require stronger authorization or policy checks. The practica [truncated]

MEDIUM OpenClaw CVE published 2026-07-17

CVE-2026-62211

CVE-2026-62211 is a medium-severity vulnerability in OpenClaw versions before 2026.6.1. The vulnerability is caused by a credential redaction bypass in the trajectory export feature, which allows lower-trust callers to access sensitive data that should remain within trusted boundaries. Attackers can exploit misconfigured input paths or feature accessibility to expose sensitive credentials and data through [truncated]

MEDIUM OpenClaw CVE published 2026-07-17

CVE-2026-62210

CVE-2026-62210 is a denial of service vulnerability in OpenClaw versions before 2026.6.1. Remote media URLs can trigger slow-read attacks, exhausting gateway worker resources. Attackers with access to configured input paths can supply remote media URLs that consume gateway resources and reduce availability. This vulnerability has a CVSS score of 6 and a severity of MEDIUM. Users of OpenClaw should apply t [truncated]

HIGH OpenClaw CVE published 2026-07-17

CVE-2026-62209

A vulnerability was found in OpenClaw versions 2026.5.10-beta.1 before 2026.6.5. The ClickClack agent-mode dispatch feature contains an authorization bypass, potentially allowing a lower-trust caller or configured input path to perform actions requiring stronger authorization or policy checks. This issue has a high CVSS score of 7.6, indicating a high severity vulnerability. Users of OpenClaw should be aw [truncated]

MEDIUM OpenClaw CVE published 2026-07-17

CVE-2026-62208

OpenClaw before 2026.6.5 could forward Authorization headers during MCP SSE redirects, potentially allowing a lower-trust caller or configured input path to execute or persist actions beyond the caller's intended authorization. This vulnerability has a medium severity and requires operator verification to ensure the affected feature is not enabled or is properly restricted.

HIGH OpenClaw CVE published 2026-07-17

CVE-2026-62207

CVE-2026-62207 is an authentication bypass vulnerability in OpenClaw versions before 2026.6.5. The vulnerability allows lower-trust callers to reach admin-scoped tools by exploiting insufficient policy checks on configured input paths. This could lead to unauthorized access and actions within the system. Users of OpenClaw versions before 2026.6.5 should verify their installations and update to the latest [truncated]

MEDIUM OpenClaw CVE published 2026-07-17

CVE-2026-62206

A missing authorization vulnerability was found in OpenClaw versions before 2026.6.9. The vulnerability allows a lower-trust caller or configured input path to perform moderation actions that require stronger authorization or policy checks. The practical impact depends on the operator's configuration and whether lower-trust input can reach the affected path. This issue has a CVSS score of 6 and a severity of MEDIUM.

MEDIUM OpenClaw CVE published 2026-07-17

CVE-2026-62205

A missing-authorization vulnerability was found in OpenClaw versions 2026.4.12-beta.1 before 2026.6.6. The issue is located in the MS Teams message actions feature. When the affected feature is enabled and reachable, a lower-trust caller or a configured input path can perform actions that should have required a stronger authorization or policy check. The vulnerability has a CVSS score of 6 and a severity [truncated]

HIGH OpenClaw CVE published 2026-07-17

CVE-2026-62203

OpenClaw versions before 2026.6.6 contain an environment variable filtering vulnerability in host exec that fails to properly sanitize rustup startup variables. This vulnerability allows attackers with lower-trust caller access or configured input paths to execute or persist actions beyond their intended authorization level. The vulnerability is classified as HIGH with a CVSS score of 7.7. Users of OpenCl [truncated]

HIGH OpenClaw CVE published 2026-07-17

CVE-2026-62202

A high-severity privilege escalation vulnerability exists in OpenClaw versions 2026.6.1 before 2026.6.9. The vulnerability is located in isolated cron jobs and allows lower-trust callers to regain denied execution tools, potentially leading to unauthorized actions. This could impact users of OpenClaw who have not updated to version 2026.6.9 or later. The vulnerability is caused by misconfigured input path [truncated]

HIGH OpenClaw CVE published 2026-07-13

CVE-2026-62200

A flaw in OpenClaw versions before 2026.6.1 could allow Git ext transport to be abused when the affected feature is enabled and reachable. This vulnerability has a high severity with a CVSS score of 8.7. Users of OpenClaw should assess the risk of the flaw in host exec environment filtering and prioritize updating to version 2026.6.1 or later. The CVE record and NVD entry provide further details.

HIGH OpenClaw CVE published 2026-07-13

CVE-2026-62199

A vulnerability in OpenClaw versions before 2026.6.6 can allow a lower-trust caller or configured input path to supply crafted environment variables, potentially leading to unauthorized actions. This flaw occurs in the host exec environment filtering and can be exploited when the affected feature is enabled and reachable. Users of OpenClaw should be aware of this vulnerability and take steps to mitigate i [truncated]

MEDIUM OpenClaw CVE published 2026-07-13

CVE-2026-62198

OpenClaw versions 2026.5.28 before 2026.6.6 contain an authorization bypass vulnerability in native web search. This vulnerability allows lower-trust callers to perform actions requiring stronger policy checks. Attackers can exploit misconfigured input paths to bypass intended authorization controls and execute restricted operations. The vulnerability affects the native web search functionality of OpenCla [truncated]

MEDIUM OpenClaw CVE published 2026-07-13

CVE-2026-62197

CVE-2026-62197 is a policy bypass vulnerability in OpenClaw browser CDP discovery that accepts blocked WebSocket URLs. Attackers with lower-trust access can reach network destinations that should have been blocked by OpenClaw policy when the affected feature is enabled. This vulnerability has a medium severity level with a CVSS score of 6.3. Users of OpenClaw before version 2026.6.6 should apply the patch [truncated]

HIGH OpenClaw CVE published 2026-07-13

CVE-2026-62196

CVE-2026-62196 is an authorization bypass vulnerability in OpenClaw versions 2026.3.22 before 2026.6.6. The vulnerability allows attackers with lower-trust access to perform actions requiring stronger authorization by leveraging group ID validation in the affected feature. OpenClaw's WhatsApp group IDs can satisfy elevated sender allowlists. This vulnerability has a high severity with a CVSS score of 8.7. [truncated]

HIGH OpenClaw CVE published 2026-07-13

CVE-2026-62195

OpenClaw versions 2026.5.20 before 2026.6.6 contain an authorization bypass vulnerability in the MCP loopback feature. This vulnerability allows lower-trust callers to execute owner-only tools by bypassing authorization checks through configured input paths. The vulnerability has a high severity with a CVSS score of 8.7. Users of OpenClaw should be aware of this vulnerability and take steps to mitigate it [truncated]

HIGH OpenClaw CVE published 2026-07-13

CVE-2026-62194

OpenClaw versions 2026.5.20 before 2026.6.9 contain a privilege escalation vulnerability in plugin install commands. This vulnerability allows lower-trust callers to execute or persist actions beyond their intended authorization. The vulnerability is caused by a lack of proper authorization in the plugin install commands of OpenClaw. Attackers can exploit misconfigured input paths or enabled features to e [truncated]

MEDIUM OpenClaw CVE published 2026-07-13

CVE-2026-62193

OpenClaw versions 2026.6.5 before 2026.6.9 contain a vulnerability in the plugin install wrappers that could skip the install policy (authorization) check. This allows lower-trust callers or configured input paths to execute or persist actions beyond the caller's intended authorization. Impact depends on the operator's configuration and whether lower-trust input can reach the affected path. The issue is f [truncated]

HIGH OpenClaw CVE published 2026-07-13

CVE-2026-62192

CVE-2026-62192 is an authorization bypass vulnerability in OpenClaw versions 2026.6.6 before 2026.6.9. The vulnerability allows lower-trust callers to perform actions requiring stronger authorization checks. Attackers can exploit misconfigured input paths to skip cross-provider requester authorization and execute restricted operations. This vulnerability has a high CVSS score of 7.2 and is classified as H [truncated]

HIGH OpenClaw CVE published 2026-07-13

CVE-2026-62191

CVE-2026-62191 is an authorization bypass vulnerability in OpenClaw versions 2026.6.6 before 2026.6.9. The vulnerability allows lower-trust callers to perform actions requiring stronger authorization checks. Attackers can exploit misconfigured input paths to skip requester authorization and execute privileged operations when the affected feature is enabled and reachable. This vulnerability has a high seve [truncated]

HIGH OpenClaw CVE published 2026-07-13

CVE-2026-62189

CVE-2026-62189 is a high-severity vulnerability in OpenClaw versions before 2026.6.9, caused by a symlink following issue in the mirror sync feature. This vulnerability allows lower-trust callers to perform actions requiring stronger authorization, potentially leading to bypass of policy checks and authorization boundaries. The vulnerability has significant implications for users of OpenClaw, particularly [truncated]

HIGH openclaw CVE published 2026-07-13

CVE-2026-62188

CVE-2026-62188 is an incorrect authorization vulnerability in OpenClaw @openclaw/feishu versions 2026.6.6 and earlier. The Feishu permission tools could ignore per-account disablement settings when the affected feature is enabled and reachable. A lower-trust caller or configured input path could perform actions that should have required a stronger authorization or policy check. The issue is fixed in versi [truncated]

HIGH openclaw CVE published 2026-07-13

CVE-2026-62187

The OpenClaw Feishu tools (npm package @openclaw/feishu) in versions <= 2026.6.6 are vulnerable to an authorization bypass. A lower-trust caller or a configured input path could perform actions that should have required a stronger authorization or policy check, resulting in unauthorized operations. The issue is fixed in version 2026.6.9. This vulnerability could allow attackers to perform actions that sho [truncated]

HIGH OpenClaw CVE published 2026-07-13

CVE-2026-62186

OpenClaw versions before 2026.6.8 contain an authorization bypass vulnerability in OpenAI-compatible HTTP model overrides that allows lower-trust callers to perform actions requiring stronger authorization checks. This vulnerability can be exploited by attackers to bypass admin authorization policies and execute restricted operations. The vulnerability has a high severity with a CVSS score of 7.2. Users a [truncated]

HIGH OpenClaw CVE published 2026-06-16

CVE-2026-53866

CVE-2026-53866 is a HIGH-severity vulnerability in OpenClaw, a software that contains an allowlist bypass vulnerability in shell inline-command parsing. This vulnerability, with a CVSS score of 7.6, allows authenticated operators to execute unapproved commands. A command request using shell inline-command forms could route through a parser case missing the expected allowlist decision, enabling shell conte [truncated]

HIGH OpenClaw CVE published 2026-06-16

CVE-2026-53865

CVE-2026-53865 is a HIGH-severity vulnerability in OpenClaw, a software that is vulnerable to path traversal attacks. The vulnerability, which has a CVSS score of 7.2, allows workspace-derived service paths to influence trash command selection, enabling attackers to execute unintended local executables from operator-unintended paths during maintenance operations.

HIGH OpenClaw CVE published 2026-06-16

CVE-2026-53864

CVE-2026-53864 is a HIGH-severity vulnerability in OpenClaw, a software that failed to properly sanitize environment variables, allowing attackers to influence child processes or coverage output paths. The vulnerability was published on [cvePublishedAt] and modified on [cveModifiedAt].

MEDIUM OpenClaw CVE published 2026-06-16

CVE-2026-53863

CVE-2026-53863 is a MEDIUM severity vulnerability in OpenClaw, a tool that contains an input validation vulnerability in tool group policy callers that accept unvalidated group IDs. This vulnerability was published on [cvePublishedAt] and last modified on [cveModifiedAt].

LOW OpenClaw CVE published 2026-06-16

CVE-2026-53862

CVE-2026-53862 is a low-severity vulnerability in OpenClaw, a software that enables secure pairing and authentication. The vulnerability, disclosed on June 16, 2026, allows an attacker to replay bootstrap tokens before approval, potentially escalating pairing authority beyond intended scope limits.

MEDIUM OpenClaw CVE published 2026-06-16

CVE-2026-53861

CVE-2026-53861 is a MEDIUM severity vulnerability in OpenClaw before version 2026.5.6. The vulnerability is caused by an allowlist bypass in the macOS Swift exec feature, which misses combined POSIX inline-command flags. This allows attackers to execute shell content outside the intended allowlist check by using combined flag forms, potentially allowing unauthorized command execution depending on operator [truncated]

LOW OpenClaw CVE published 2026-06-16

CVE-2026-53860

CVE-2026-53860 is a low-severity vulnerability in OpenClaw, specifically in the BlueBubbles component. The vulnerability allows participants to bypass sender policy by matching allowlist entries through conversation metadata rather than stable sender identity. This could potentially allow attackers to influence conversation-level identifiers and receive agent responses intended for configured senders, byp [truncated]

MEDIUM OpenClaw CVE published 2026-06-16

CVE-2026-53859

CVE-2026-53859 is a MEDIUM-severity vulnerability in OpenClaw, a software that contains a hostname validation vulnerability. This vulnerability allows attackers to bypass blocklist comparisons using trailing-dot notation in model or workspace-derived URLs. As a result, attackers can reach destinations that operators intended to block through hostname policies.

HIGH OpenClaw CVE published 2026-06-16

CVE-2026-53858

CVE-2026-53858 is a HIGH severity vulnerability in OpenClaw before version 2026.5.2. The vulnerability is caused by an environment variable injection issue where the workspace .env STATE_DIRECTORY could influence bundled runtime dependency roots. This allows attackers to manipulate the STATE_DIRECTORY variable to load runtime dependencies from unintended local paths, potentially executing malicious code d [truncated]

HIGH OpenClaw CVE published 2026-06-16

CVE-2026-53857

CVE-2026-53857 is a HIGH-severity vulnerability in OpenClaw, a software that contains a policy enforcement issue. The vulnerability has a CVSS score of 8.6. The issue arises from OpenClaw's handling of Zalo contacts with mutable display metadata, which could allow an attacker to receive agent responses intended for different Zalo identities when the feature is enabled. This vulnerability was published on [truncated]

MEDIUM OpenClaw CVE published 2026-06-16

CVE-2026-53856

CVE-2026-53856 is a MEDIUM-severity vulnerability in OpenClaw, a software that contains an insecure file permissions vulnerability in its config recovery feature. The vulnerability allows local attackers on shared hosts to read sensitive configuration data by exploiting the recovery path to access the restored config file.

HIGH OpenClaw CVE published 2026-06-16

CVE-2026-53855

CVE-2026-53855 is a HIGH-severity vulnerability in OpenClaw, a software that enables users to manage and automate various tasks. The vulnerability, which has a CVSS score of 7.6, allows authenticated operators to bypass strict allowlist checks via shell positional parameters, potentially enabling the execution of unapproved shell-provided content.

MEDIUM OpenClaw CVE published 2026-06-16

CVE-2026-53854

CVE-2026-53854 is a medium-severity privilege escalation vulnerability in OpenClaw before version 2026.4.25. The vulnerability allows senders to inherit the 'ownerAllowFrom' wildcard state across channel boundaries, potentially bypassing access controls. Attackers can exploit this by sending commands on affected internal or webchat paths to execute owner-style command behavior outside intended channel scope.