PatchSiren

OpenClaw CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

LOW OpenClaw CVE published 2026-09-15

CVE-2026-91836

A flaw in OpenClaw ClawScan up to 0.1.6 affects the Static Scanner component, allowing for incomplete comparison with missing factors. This issue can be exploited locally. Upgrading to version 0.1.7 mitigates this issue. The vulnerability is located in the internal/runner/static_scanner.go file. Defenders should assess exposure and prioritize upgrading to version 0.1.7. The CVE record and NVD entry provid [truncated]

HIGH OpenClaw CVE published 2026-07-17

CVE-2026-62228

A vulnerability was found in OpenClaw before version 2026.6.5. The issue is an authorization bypass in node exec approvals, which allows lower-trust callers to execute actions beyond their intended authorization by using different gateway and node environments. This vulnerability has a high impact on OpenClaw deployments, as it can allow attackers to persist or execute actions that exceed the caller's app [truncated]

MEDIUM OpenClaw CVE published 2026-07-17

CVE-2026-62227

OpenClaw 2026.4.14 before 2026.5.26 contain a server-side request forgery vulnerability in browser snapshot routes that fail to validate post-navigation destinations. Attackers with lower-trust access can bypass OpenClaw policy checks to reach network destinations that should have been blocked. This vulnerability has a CVSS score of 4.9 and is classified as MEDIUM severity. The vulnerability affects OpenC [truncated]

MEDIUM OpenClaw CVE published 2026-07-17

CVE-2026-62226

OpenClaw 2026.3.28 before 2026.5.19 contain an authorization bypass vulnerability in the browser act route that fails to properly validate current-tab URL checks. Attackers with lower-trust access or configured input paths can perform actions requiring stronger authorization or policy checks. This vulnerability has a CVSS score of 5.1 and is classified as MEDIUM severity. Users of OpenClaw 2026.3.28 befor [truncated]

LOW openclaw CVE published 2026-07-17

CVE-2026-62224

CVE-2026-62224 is an authorization bypass vulnerability in OpenClaw MS Teams before version 2026.5.12. The vulnerability arises from the allowFrom feature binding to mutable display names, allowing attackers with lower-trust access to perform actions requiring stronger authorization. This vulnerability can impact users of OpenClaw MS Teams, particularly those with lower-trust access, and may allow unautho [truncated]

HIGH OpenClaw CVE published 2026-07-17

CVE-2026-62222

OpenClaw before 2026.5.22 contains a vulnerability in setup-mode discovery that allows loading of untrusted workspace plugins. Attackers with lower-trust caller access or control over configured input paths can execute or persist actions beyond their intended authorization level. This vulnerability has a CVSS score of 7.1, indicating high severity. The vulnerability exists in the setup-mode discovery of O [truncated]

LOW OpenClaw CVE published 2026-07-17

CVE-2026-62221

OpenClaw 2026.5.12 before 2026.5.26 contain an incorrect authorization vulnerability in the ClickClack allowFrom feature. When the affected feature is enabled and reachable, a lower-trust caller or configured input path could execute or persist actions beyond the caller's intended authorization, including running non-allowlisted commands. This vulnerability has a CVSS score of 2.3 and is rated as LOW. The [truncated]

MEDIUM OpenClaw CVE published 2026-07-17

CVE-2026-62220

CVE-2026-62220 is a MEDIUM severity vulnerability in OpenClaw 2026.2.25 before 2026.5.26 that allows a lower-trust caller or configured input path to bypass non-browser rate limits on WebSocket authentication attempts. This can consume gateway resources and reduce service availability when the affected feature is enabled and reachable by lower-trust input. The vulnerability class is related to WebSocket a [truncated]

MEDIUM OpenClaw CVE published 2026-07-17

CVE-2026-62219

CVE-2026-62219 is an authorization bypass vulnerability in OpenClaw 2026.2.12 before 2026.5.26. The vulnerability exists in the hooks allowedAgentIds validation. A lower-trust caller or configured input path can bypass agent ID restrictions by submitting blank agent IDs, allowing actions that should require stronger authorization or policy checks. The CVSS score for this vulnerability is 6, and the severi [truncated]

HIGH OpenClaw CVE published 2026-07-17

CVE-2026-62217

A high-severity authorization flaw was found in OpenClaw 2026.5.14-beta.1. The QQBot exec approvals feature, when enabled and reachable, allows lower-trust callers or configured input paths to execute or persist actions beyond their intended authorization. This could enable non-allowlisted senders to perform unauthorized operations. The vulnerability has a CVSS score of 7.7 and is classified as HIGH sever [truncated]

LOW OpenClaw CVE published 2026-07-17

CVE-2026-62216

OpenClaw 2026.4.20 before 2026.5.28 contains a policy bypass in the QQBot media upload feature. A lower-trust caller or configured input path could cause the media upload to reach network destinations that should have been blocked by OpenClaw policy (server-side request forgery). The practical impact depends on the operator's configuration and whether lower-trust input can reach that path. Users of OpenCl [truncated]

MEDIUM OpenClaw CVE published 2026-07-17

CVE-2026-62215

CVE-2026-62215 is an authentication bypass vulnerability in OpenClaw versions before 2026.6.5. The vulnerability exists in HTTP Canvas responses, allowing lower-trust callers to forge trusted A2UI actions. This could enable attackers to perform actions requiring stronger authorization by submitting crafted requests through configured input paths, potentially bypassing intended policy checks.

MEDIUM openclaw CVE published 2026-07-17

CVE-2026-62214

CVE-2026-62214 is an improper input validation vulnerability in OpenClaw Bot Framework versions before 2026.5.28. The vulnerability allows lower-trust callers to expose bot tokens and credentials by failing to properly validate serviceUrl parameters. Attackers can supply malicious serviceUrl values through configured input paths to retrieve sensitive authentication data outside the trusted boundary. This [truncated]

MEDIUM openclaw CVE published 2026-07-17

CVE-2026-62213

CVE-2026-62213 is a medium-severity vulnerability in OpenClaw versions before 2026.5.27. The issue involves a token leakage vulnerability in MS Teams outbound requests, potentially exposing Bot Framework tokens to lower-trust callers. To address this vulnerability, users should update OpenClaw to version 2026.5.27 or later and review their configurations to ensure that sensitive credentials are not expose [truncated]

MEDIUM OpenClaw CVE published 2026-07-17

CVE-2026-62212

CVE-2026-62212 is a race condition vulnerability in OpenClaw before version 2026.5.28. The issue affects the MS Teams safeFetch DNS rebinding check. When the feature is enabled and reachable, a lower-trust caller or configured input path could exploit a timing window between the DNS validation check and use. This could allow actions that should require stronger authorization or policy checks. The practica [truncated]

MEDIUM OpenClaw CVE published 2026-07-17

CVE-2026-62211

CVE-2026-62211 is a medium-severity vulnerability in OpenClaw versions before 2026.6.1. The vulnerability is caused by a credential redaction bypass in the trajectory export feature, which allows lower-trust callers to access sensitive data that should remain within trusted boundaries. Attackers can exploit misconfigured input paths or feature accessibility to expose sensitive credentials and data through [truncated]

MEDIUM OpenClaw CVE published 2026-07-17

CVE-2026-62210

CVE-2026-62210 is a denial of service vulnerability in OpenClaw versions before 2026.6.1. Remote media URLs can trigger slow-read attacks, exhausting gateway worker resources. Attackers with access to configured input paths can supply remote media URLs that consume gateway resources and reduce availability. This vulnerability has a CVSS score of 6 and a severity of MEDIUM. Users of OpenClaw should apply t [truncated]

HIGH OpenClaw CVE published 2026-07-17

CVE-2026-62209

A vulnerability was found in OpenClaw versions 2026.5.10-beta.1 before 2026.6.5. The ClickClack agent-mode dispatch feature contains an authorization bypass, potentially allowing a lower-trust caller or configured input path to perform actions requiring stronger authorization or policy checks. This issue has a high CVSS score of 7.6, indicating a high severity vulnerability. Users of OpenClaw should be aw [truncated]

MEDIUM OpenClaw CVE published 2026-07-17

CVE-2026-62208

OpenClaw before 2026.6.5 could forward Authorization headers during MCP SSE redirects, potentially allowing a lower-trust caller or configured input path to execute or persist actions beyond the caller's intended authorization. This vulnerability has a medium severity and requires operator verification to ensure the affected feature is not enabled or is properly restricted.

HIGH OpenClaw CVE published 2026-07-17

CVE-2026-62207

CVE-2026-62207 is an authentication bypass vulnerability in OpenClaw versions before 2026.6.5. The vulnerability allows lower-trust callers to reach admin-scoped tools by exploiting insufficient policy checks on configured input paths. This could lead to unauthorized access and actions within the system. Users of OpenClaw versions before 2026.6.5 should verify their installations and update to the latest [truncated]

MEDIUM OpenClaw CVE published 2026-07-17

CVE-2026-62206

A missing authorization vulnerability was found in OpenClaw versions before 2026.6.9. The vulnerability allows a lower-trust caller or configured input path to perform moderation actions that require stronger authorization or policy checks. The practical impact depends on the operator's configuration and whether lower-trust input can reach the affected path. This issue has a CVSS score of 6 and a severity of MEDIUM.

MEDIUM OpenClaw CVE published 2026-07-17

CVE-2026-62205

A missing-authorization vulnerability was found in OpenClaw versions 2026.4.12-beta.1 before 2026.6.6. The issue is located in the MS Teams message actions feature. When the affected feature is enabled and reachable, a lower-trust caller or a configured input path can perform actions that should have required a stronger authorization or policy check. The vulnerability has a CVSS score of 6 and a severity [truncated]

HIGH OpenClaw CVE published 2026-07-17

CVE-2026-62203

OpenClaw versions before 2026.6.6 contain an environment variable filtering vulnerability in host exec that fails to properly sanitize rustup startup variables. This vulnerability allows attackers with lower-trust caller access or configured input paths to execute or persist actions beyond their intended authorization level. The vulnerability is classified as HIGH with a CVSS score of 7.7. Users of OpenCl [truncated]

HIGH OpenClaw CVE published 2026-07-17

CVE-2026-62202

A high-severity privilege escalation vulnerability exists in OpenClaw versions 2026.6.1 before 2026.6.9. The vulnerability is located in isolated cron jobs and allows lower-trust callers to regain denied execution tools, potentially leading to unauthorized actions. This could impact users of OpenClaw who have not updated to version 2026.6.9 or later. The vulnerability is caused by misconfigured input path [truncated]

HIGH OpenClaw CVE published 2026-07-13

CVE-2026-62200

A flaw in OpenClaw versions before 2026.6.1 could allow Git ext transport to be abused when the affected feature is enabled and reachable. This vulnerability has a high severity with a CVSS score of 8.7. Users of OpenClaw should assess the risk of the flaw in host exec environment filtering and prioritize updating to version 2026.6.1 or later. The CVE record and NVD entry provide further details.

HIGH OpenClaw CVE published 2026-07-13

CVE-2026-62199

A vulnerability in OpenClaw versions before 2026.6.6 can allow a lower-trust caller or configured input path to supply crafted environment variables, potentially leading to unauthorized actions. This flaw occurs in the host exec environment filtering and can be exploited when the affected feature is enabled and reachable. Users of OpenClaw should be aware of this vulnerability and take steps to mitigate i [truncated]

MEDIUM OpenClaw CVE published 2026-07-13

CVE-2026-62198

OpenClaw versions 2026.5.28 before 2026.6.6 contain an authorization bypass vulnerability in native web search. This vulnerability allows lower-trust callers to perform actions requiring stronger policy checks. Attackers can exploit misconfigured input paths to bypass intended authorization controls and execute restricted operations. The vulnerability affects the native web search functionality of OpenCla [truncated]

MEDIUM OpenClaw CVE published 2026-07-13

CVE-2026-62197

CVE-2026-62197 is a policy bypass vulnerability in OpenClaw browser CDP discovery that accepts blocked WebSocket URLs. Attackers with lower-trust access can reach network destinations that should have been blocked by OpenClaw policy when the affected feature is enabled. This vulnerability has a medium severity level with a CVSS score of 6.3. Users of OpenClaw before version 2026.6.6 should apply the patch [truncated]

HIGH OpenClaw CVE published 2026-07-13

CVE-2026-62196

CVE-2026-62196 is an authorization bypass vulnerability in OpenClaw versions 2026.3.22 before 2026.6.6. The vulnerability allows attackers with lower-trust access to perform actions requiring stronger authorization by leveraging group ID validation in the affected feature. OpenClaw's WhatsApp group IDs can satisfy elevated sender allowlists. This vulnerability has a high severity with a CVSS score of 8.7. [truncated]

HIGH OpenClaw CVE published 2026-07-13

CVE-2026-62195

OpenClaw versions 2026.5.20 before 2026.6.6 contain an authorization bypass vulnerability in the MCP loopback feature. This vulnerability allows lower-trust callers to execute owner-only tools by bypassing authorization checks through configured input paths. The vulnerability has a high severity with a CVSS score of 8.7. Users of OpenClaw should be aware of this vulnerability and take steps to mitigate it [truncated]