PatchSiren

OpenClaw CVE debriefs · Page 3

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM OpenClaw CVE published 2026-06-16

CVE-2026-53844

CVE-2026-53844 is a session visibility check bypass vulnerability in OpenClaw before version 2026.4.29. The vulnerability allows authenticated callers to access memory entries without proper authorization, effectively bypassing session visibility guards on the search path. This could enable attackers to retrieve memory entries that should not be visible to their session.

HIGH OpenClaw CVE published 2026-06-16

CVE-2026-53843

CVE-2026-53843 is a HIGH-severity vulnerability in OpenClaw before version 2026.5.26. The vulnerability allows an authorization bypass, enabling a paired device to regain WebSocket node-level access without renewed approval after revocation. This weakness in revocation controls can maintain unauthorized access longer than intended. The Common Vulnerability Scoring System (CVSS) score for this vulnerability is 8.7.

LOW OpenClaw CVE published 2026-06-16

CVE-2026-53841

CVE-2026-53841 is a low-severity cross-site scripting (XSS) vulnerability in OpenClaw before version 2026.5.12. The vulnerability occurs in exported session HTML, where unsafe javascript: and data: links are preserved, allowing attackers to execute browser-side scripts if a trusted operator opens the exported file and activates a malicious link.

MEDIUM OpenClaw CVE published 2026-06-16

CVE-2026-53840

CVE-2026-53840 is an information disclosure vulnerability in OpenClaw before 2026.5.12. The vulnerability affects streamable-http MCP servers that forward user-configured custom headers during cross-origin redirects. This allows attackers controlling or compromising an MCP endpoint to redirect requests and exfiltrate sensitive headers like API keys or tenant-routing credentials to attacker-controlled orig [truncated]

MEDIUM OpenClaw CVE published 2026-06-12

CVE-2026-53839

CVE-2026-53839 is a medium-severity vulnerability in OpenClaw, a software that contains a hostname validation vulnerability in retry endpoint checks. The vulnerability allows attackers to craft a hostname prefix resembling a trusted host to send authentication material to untrusted endpoints. The Common Vulnerability Scoring System (CVSS) score for this vulnerability is 6, indicating a medium severity level.

MEDIUM OpenClaw CVE published 2026-06-12

CVE-2026-53838

CVE-2026-53838 is a medium-severity vulnerability in OpenClaw, a software that enables node pairing. The vulnerability, tracked as CWE-367, allows paired nodes to confuse approval scope decisions due to a state mutation issue in the node pairing reconnection logic. This could enable attackers to bypass approval restrictions by exploiting the reconnection logic to restore or present broader node authority [truncated]

HIGH OpenClaw CVE published 2026-06-12

CVE-2026-53836

CVE-2026-53836 is a HIGH severity vulnerability in OpenClaw that allows remote authenticated operators to bypass execution allowlist checks using unrecognized encoded-command alias forms to execute arbitrary PowerShell content. The vulnerability has a CVSS score of 8.7.

LOW OpenClaw CVE published 2026-06-12

CVE-2026-53835

CVE-2026-53835 is a configuration enforcement bypass vulnerability in OpenClaw before version 2026.5.6. The vulnerability affects the Feishu dynamic-agent bindings, allowing authenticated senders to create or update bindings without honoring configured config-write controls. This could enable attackers to change sender-agent binding state beyond intended policy, potentially allowing unauthorized binding m [truncated]

HIGH OpenClaw CVE published 2026-06-12

CVE-2026-53834

CVE-2026-53834 is a HIGH-severity vulnerability in OpenClaw, a software that contains an authorization bypass vulnerability in QQBot pre-dispatch slash commands. The vulnerability, which has a CVSS score of 8.2, allows authenticated senders to skip allowFrom policy checks, potentially triggering command handling from blocked senders depending on operator configuration.

HIGH OpenClaw CVE published 2026-06-12

CVE-2026-53832

CVE-2026-53832 is a HIGH-severity vulnerability in OpenClaw, a software that enables identity header validation. The vulnerability has a CVSS score of 7.4 and allows local same-host callers to forge trusted-proxy identity headers. This could potentially enable attackers with access to the proxy-facing Gateway port to assume operator identity and escalate privileges.

HIGH OpenClaw CVE published 2026-06-12

CVE-2026-53831

CVE-2026-53831 is a high-severity policy enforcement vulnerability in OpenClaw before version 2026.5.18. The vulnerability is located in the system.run safe-bin allowlist validation and allows shell expansion to modify command interpretation on POSIX nodes. Authenticated operators can exploit shell metacharacters in approved commands to read unintended node-local files and expose sensitive configuration d [truncated]

MEDIUM OpenClaw CVE published 2026-06-12

CVE-2026-53830

CVE-2026-53830 is a MEDIUM-severity vulnerability in OpenClaw, a software that contains a webhook secret revocation bypass vulnerability. The vulnerability allows callers with old Slack and Zalo webhook secrets to remain active after secrets.reload. This means that attackers can exploit the stale-secret window to deliver webhook events after operator-expected secret revocation, potentially accepting previ [truncated]

HIGH OpenClaw CVE published 2026-06-12

CVE-2026-53829

CVE-2026-53829 is a HIGH severity vulnerability in OpenClaw before 2026.5.18. The approval display truncation vulnerability allows authenticated users to hide command suffixes from approvers. Attackers can submit oversized exec commands with benign prefixes and malicious suffixes to execute unauthorized operations after approval.

MEDIUM OpenClaw CVE published 2026-06-12

CVE-2026-53827

CVE-2026-53827 is a credential exposure vulnerability in OpenClaw before version 2026.5.2. The vulnerability occurs in the message.action forwarding feature, which allows model-controlled metadata to forward action payloads with Gateway credentials to attacker-supplied loopback URLs. This enables remote attackers to intercept Gateway tokens and action payloads by providing malicious loopback targets throu [truncated]

HIGH OpenClaw CVE published 2026-06-12

CVE-2026-53825

CVE-2026-53825 is a HIGH severity vulnerability in OpenClaw before version 2026.4.7. The vulnerability is an arbitrary file read issue in the memory-wiki ingest feature, allowing authenticated Gateway operators with operator.write scope to read local files outside intended ingest sources. Attackers with operator.write access can specify arbitrary local file paths to import file content into wiki memory, b [truncated]

MEDIUM OpenClaw CVE published 2026-06-12

CVE-2026-53824

CVE-2026-53824 is a medium-severity vulnerability in OpenClaw, a software that enables slash command functionality. The vulnerability occurs due to a token revocation issue, where callers with revoked slash tokens can continue executing commands during monitor refresh windows. This allows attackers to exploit stale token acceptance and invoke slash command behavior briefly after token revocation, potentia [truncated]

HIGH OpenClaw CVE published 2026-06-12

CVE-2026-53823

CVE-2026-53823 is a HIGH severity vulnerability in OpenClaw before 2026.5.3. The allowFrom feature binds to mutable Slack display names, allowing attackers with Slack account access to change display name metadata to match policy entries, potentially gaining unauthorized agent access intended for other identities. The vulnerability has a CVSS score of 8.6.

HIGH OpenClaw CVE published 2026-06-12

CVE-2026-53822

CVE-2026-53822 is a high-severity command injection vulnerability in OpenClaw before version 2026.5.18. The vulnerability occurs in the shell wrapper argv, which can change between approval and execution, allowing attackers to rebuild command arguments and potentially bypass security controls. The CVSS score for this vulnerability is 8.7, indicating a high severity.

HIGH OpenClaw CVE published 2026-06-12

CVE-2026-53821

CVE-2026-53821 is a HIGH-severity vulnerability in OpenClaw, a software that enables trusted-proxy Control UI clients. The vulnerability has a CVSS score of 8.7. The issue arises from OpenClaw's acceptance of WebSocket client-declared operator scopes before binding to server-approved pairing or trusted-proxy authorization baseline. This allows unpaired or restricted trusted-proxy Control UI clients to obt [truncated]

MEDIUM OpenClaw CVE published 2026-06-12

CVE-2026-53820

CVE-2026-53820 is a MEDIUM-severity vulnerability in OpenClaw, a software that contains an exec denylist bypass vulnerability in the bundle MCP loopback session-spawn path. This vulnerability allows authenticated callers to bypass intended command restrictions, potentially leading to unauthorized access or malicious activity.

HIGH OpenClaw CVE published 2026-06-11

CVE-2026-53819

CVE-2026-53819 is a HIGH-severity vulnerability in OpenClaw before version 2026.5.27. The vulnerability allows for arbitrary code execution during skill setup when an attacker with access to a trusted operator workspace can override the Homebrew executable selection using workspace .env files.

MEDIUM OpenClaw CVE published 2026-06-11

CVE-2026-53818

CVE-2026-53818 is a MEDIUM-severity vulnerability in OpenClaw, a software framework. The vulnerability exists in the MCP loopback feature and allows non-owner callers to bypass owner-only tool policies and before-tool-call hooks. This could enable attackers to execute restricted tools when the feature is enabled and reachable. The vulnerability was published on [cvePublishedAt] and modified on [cveModifiedAt].

HIGH OpenClaw CVE published 2026-06-11

CVE-2026-53817

CVE-2026-53817 is a HIGH severity vulnerability in OpenClaw before 2026.5.22. The vulnerability is caused by insufficient locality-derived trust validation in Control UI pairing, allowing attackers with network access to spoof locality information and obtain durable admin-capable device tokens. This can be exploited to convert temporary shared access into persistent administrative credentials that survive [truncated]

HIGH OpenClaw CVE published 2026-06-11

CVE-2026-53816

CVE-2026-53816 is a HIGH-severity vulnerability in OpenClaw, a software framework, which was published on 2026-06-11T21:16:23.830Z and modified on 2026-06-12T20:08:26.270Z. The vulnerability has a CVSS score of 8.6 and is categorized under CWE-862. The vulnerability exists in the node event handling of OpenClaw, allowing paired nodes to forge exec lifecycle events without proper authorization, potentially [truncated]

HIGH OpenClaw CVE published 2026-06-11

CVE-2026-53815

CVE-2026-53815 is an authorization bypass vulnerability in OpenClaw before version 2026.5.19. The vulnerability affects the message read actions, where insufficient validation was performed, allowing lower-trust callers to request messages from channels not intended for them. This could potentially expose sensitive channel messages. The vulnerability has a CVSS score of 7.1 and is considered HIGH severity.

HIGH OpenClaw CVE published 2026-06-11

CVE-2026-53814

CVE-2026-53814 is a high-severity privilege escalation vulnerability in OpenClaw before version 2026.5.20. The vulnerability occurs when hook-triggered agent runs incorrectly receive owner-scoped MCP loopback authority instead of hook-appropriate scope. This allows attackers with a valid hook token to exploit the /hooks/agent endpoint, potentially leading to the execution of privileged actions such as per [truncated]

HIGH OpenClaw CVE published 2026-06-11

CVE-2026-53813

CVE-2026-53813 is a HIGH-severity vulnerability in OpenClaw, a software that is susceptible to a path traversal attack. The vulnerability exists in the memory-core artifact loading process, where an attacker with access to an affected workspace can load artifacts from unintended local locations. This could potentially allow the execution of malicious code or access to sensitive data.

MEDIUM OpenClaw CVE published 2026-06-11

CVE-2026-53812

CVE-2026-53812 is a medium-severity server-side request forgery vulnerability in OpenClaw before version 2026.5.18. Authenticated users can bypass private-network navigation checks through Playwright act interactions, allowing attackers to trigger navigation to private-network targets via action-triggered redirects and read restricted page content using browser evaluation capabilities.

HIGH OpenClaw CVE published 2026-06-11

CVE-2026-53810

CVE-2026-53810 is a high-severity vulnerability in OpenClaw. The vulnerability exists in OpenClaw before version 2026.5.18 and allows for code execution where marketplace runtime extension metadata can redirect loading toward unscanned package payloads. Attackers with trusted operator access can manipulate extension metadata to load plugin code outside reviewed package entry points, bypassing security sca [truncated]

MEDIUM OpenClaw CVE published 2026-06-11

CVE-2026-53809

CVE-2026-53809 is a policy bypass vulnerability in OpenClaw before 2026.4.25. The vulnerability is caused by the embedded runner policy allowing requests using provider aliases to compare against aliases instead of canonical provider identities. This can lead to attackers exploiting this confusion to select bundled tool access outside intended provider policy restrictions when the affected feature is enab [truncated]