PatchSiren

OpenClaw CVE debriefs · Page 4

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM OpenClaw CVE published 2026-06-11

CVE-2026-53808

CVE-2026-53808 is a MEDIUM severity vulnerability in OpenClaw, a software that contains an approval policy bypass vulnerability in the Skill Workshop apply flow. The vulnerability allows agent tool calls to set apply: true despite approvalPolicy: pending configuration. Attackers can exploit this by reaching the affected apply path to apply workshop changes before the expected approval step, potentially mo [truncated]

HIGH OpenClaw CVE published 2026-06-11

CVE-2026-53807

CVE-2026-53807 is a HIGH-severity vulnerability in OpenClaw, a software that contains an authorization bypass vulnerability in Telegram interactive callbacks. This vulnerability allows authenticated users to skip commands.allowFrom validation, potentially triggering command behavior outside configured Telegram sender restrictions.

HIGH OpenClaw CVE published 2026-06-11

CVE-2026-53806

CVE-2026-53806 is a HIGH severity vulnerability in OpenClaw that allows combined POSIX shell flags to bypass exec revalidation checks, potentially enabling unauthorized command execution. The vulnerability has a CVSS score of 7.7 and was published on 2026-06-11T21:16:22.443Z. The affected product is OpenClaw, and the vulnerability is tracked under CWE-367.

HIGH OpenClaw CVE published 2026-05-29

CVE-2026-35674

A scope bypass vulnerability in OpenClaw before 2026.5.18 allows attackers with operator.write scope to execute privileged commands through the Gateway chat.send route. The vulnerability stems from improper authorization checks when scoped clients deliver commands through inherited external routes, bypassing required operator.approvals and operator.admin scope validations. This enables unauthorized mutati [truncated]

MEDIUM OpenClaw CVE published 2026-05-29

CVE-2026-35673

CVE-2026-35673 documents a Server-Side Request Forgery (SSRF) policy bypass vulnerability in OpenClaw versions prior to 2026.4.29. The flaw exists within browser debug and export routes, where an attacker with access to these routes can circumvent private-network SSRF protections by reusing already-open blocked tabs to export or inspect protected content. The vulnerability is classified as CWE-863 (Incorr [truncated]

HIGH OpenClaw CVE published 2026-05-29

CVE-2026-35630

CVE-2026-35630 documents an authorization bypass vulnerability in OpenClaw versions prior to 2026.5.18. The flaw exists in the QQBot native approval buttons, which fail to enforce configured approver identity requirements. This allows non-approver users to click approval buttons and resolve pending execution or plugin approval requests without proper authorization. The vulnerability is classified as CWE-8 [truncated]

LOW OpenClaw CVE published 2026-05-29

CVE-2026-34507

A policy bypass vulnerability in OpenClaw's QQBot admin commands allows authenticated senders to circumvent DM-only and allowFrom policy checks. The flaw permits routing of admin commands from unauthorized senders or contexts, enabling execution of restricted behavior that policy should have blocked. The vulnerability affects OpenClaw versions prior to 2026.4.29. The CVSS 4.0 vector indicates network atta [truncated]

LOW OpenClaw CVE published 2026-05-29

CVE-2026-32906

A privilege escalation vulnerability in OpenClaw before version 2026.5.12 allows exec-authorized users to resolve plugin approvals through the exec approver gate, bypassing intended approval splits. Attackers with limited exec approval permissions can approve plugin actions outside operator configuration. The vulnerability is classified as CWE-863 (Incorrect Authorization) and carries a LOW severity CVSS [truncated]

HIGH OpenClaw CVE published 2026-05-29

CVE-2026-32905

OpenClaw before 2026.5.4 contains an authorization bypass vulnerability in the bundled device-pair plugin. The flaw allows non-owner authorized chat senders to issue device-pairing bootstrap codes without proper scope validation. Attackers with chat command access can create setup codes to enroll devices with operator/node capabilities, granting persistent credentials until manual removal. The vulnerabili [truncated]

CRITICAL openclaw CVE published 2026-05-14

CVE-2026-8634

Crabbox prior to v0.12.0 contains an environment variable exposure vulnerability that allows attackers with access to a malicious or compromised repository to forward local secrets such as API tokens, cloud credentials, and broker tokens into the remote command environment. The vulnerability is caused by overly permissive environment variable allowlisting in repo-local Crabbox configuration, which can be [truncated]

HIGH openclaw CVE published 2026-05-14

CVE-2026-8629

CVE-2026-8629 is a high-severity vulnerability in Crabbox, a software that allows users to obtain Code, WebVNC, and Egress agent tickets by sending POST requests to ticket endpoints, potentially leading to privilege escalation. This vulnerability affects users with shared visibility-only access and can be exploited due to insufficient access control checks on the /v1/leases/:id/code/ticket, /v1/leases/:id [truncated]

HIGH openclaw CVE published 2026-05-14

CVE-2026-8621

CVE-2026-8621 is an authentication bypass vulnerability in Crabbox prior to v0.12.0. The vulnerability allows non-admin shared-token callers to impersonate other owners or organizations by spoofing identity headers. This could lead to unauthorized access to sensitive operations. Users should apply the patch to prevent authentication bypass attacks. The vulnerability exists due to improper validation of X- [truncated]

MEDIUM openclaw CVE published 2026-05-11

CVE-2026-45224

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-05-11T19:16:28.297Z and has not been modified since then. Crabbox before 0.9.0 contains a path traversal vulnerability in the Islo provider's workspace path resolution. Attackers can craft a malicious .crabbox.yaml or crabbox.yaml file with traversal sequences to cause arbitrary file deletion and overw [truncated]

HIGH openclaw CVE published 2026-05-11

CVE-2026-45223

CVE-2026-45223 is an authentication bypass vulnerability in Crabbox before 0.9.0. The vulnerability exists in the coordinator user-token verification path where the verifyUserToken() function fails to reject payloads containing an admin claim. This allows attackers to escalate privileges by crafting a user-token payload with admin: true, signing it using HMAC-SHA256, and presenting it to admin-only coordi [truncated]

HIGH OpenClaw CVE published 2026-05-05

CVE-2026-42437

A denial-of-service vulnerability exists in OpenClaw versions 2026.4.9 before 2026.4.10, affecting the voice-call realtime WebSocket path. The application accepts oversized WebSocket frames without proper validation, allowing remote attackers to cause service unavailability by sending maliciously large frames to exposed endpoints. The vulnerability is classified as HIGH severity with a CVSS score of 8.2. [truncated]

HIGH OpenClaw CVE published 2026-04-28

CVE-2026-42432

OpenClaw versions prior to 2026.4.8 contain a privilege escalation vulnerability in the node pairing and reconnection mechanism. Previously paired nodes can reconnect to the local assistant system and execute commands with elevated privileges without requiring the operator.admin scope. The vulnerability stems from insufficient authentication validation during the reconnection phase, allowing attackers to [truncated]

MEDIUM OpenClaw CVE published 2026-04-28

CVE-2026-42429

A privilege escalation vulnerability exists in OpenClaw versions prior to 2026.4.8, specifically within the gateway plugin's HTTP authentication mechanism. The flaw allows an attacker with operator.read permissions to escalate to operator.write permissions on runtime operations by sending read-scoped requests through the gateway authentication route. This represents an incorrect authorization control (CWE [truncated]

MEDIUM Openclaw CVE published 2026-04-23

CVE-2026-41355

CVE-2026-41355 affects OpenClaw versions before 2026.3.28. In mirror mode, untrusted sandbox files can be converted into workspace hooks, allowing an attacker with mirror mode access to execute arbitrary code on the host during gateway startup. The published vulnerability data classifies the issue as medium severity and links it to CWE-829.

MEDIUM OpenClaw CVE published 2026-04-03

CVE-2026-34511

CVE-2026-34511 is a vulnerability in OpenClaw before version 2026.4.2. The issue arises from the reuse of the PKCE verifier as the OAuth state parameter in the Gemini OAuth flow. This allows attackers who capture the redirect URL to obtain both the authorization code and PKCE verifier, effectively defeating PKCE protection and enabling token redemption. The vulnerability has a CVSS score of 6 and is class [truncated]

MEDIUM OpenClaw CVE published 2026-03-31

CVE-2026-32988

CVE-2026-32988 is a medium-severity vulnerability in OpenClaw, a sandbox boundary bypass issue via unvalidated temporary file creation. The vulnerability exists in OpenClaw before version 2026.3.11 and allows attackers to exploit a race condition in parent-path alias changes to write attacker-controlled bytes outside the intended validated path. This could potentially lead to unauthorized data access or m [truncated]

HIGH OpenClaw CVE published 2026-03-31

CVE-2026-32982

CVE-2026-32982 is an information disclosure vulnerability in OpenClaw, a software that was found to leak Telegram bot tokens in error messages related to media downloads. The vulnerability exists in the fetchRemoteMedia function and affects OpenClaw versions prior to 2026.3.13. When media downloads fail, the original Telegram file URLs containing bot tokens are embedded in MediaFetchError strings and leak [truncated]

MEDIUM OpenClaw CVE published 2026-03-31

CVE-2026-32977

CVE-2026-32977 is a medium-severity vulnerability in OpenClaw, a sandbox boundary bypass issue via unanchored container path in fs-bridge writeFile commit step. An attacker can exploit a time-of-check-time-of-use race condition by modifying parent paths inside the sandbox to redirect committed files outside the validated writable path within the container mount namespace. This vulnerability affects OpenCl [truncated]

HIGH OpenClaw CVE published 2026-03-31

CVE-2026-32976

CVE-2026-32976 is an authorization bypass vulnerability in OpenClaw before 2026.3.11. The vulnerability allows channel commands to mutate protected sibling-account configuration despite configWrites restrictions. Attackers with authorized access on one account can execute channel commands like /config set channels.<provider>.accounts.<id> to modify configuration on target accounts with configWrites: false [truncated]

HIGH OpenClaw CVE published 2026-03-31

CVE-2026-32971

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-03-31T12:16:29.280Z and has not been modified since then. The NVD entry is currently Analyzed. OpenClaw before 2026.3.11 contains an approval-integrity vulnerability in node-host system.run approvals that displays extracted shell payloads instead of the executed argv. Attackers can place wrapper binari [truncated]

LOW OpenClaw CVE published 2026-03-31

CVE-2026-32970

OpenClaw before 2026.3.11 contains a credential fallback vulnerability where unavailable local gateway.auth.token and gateway.auth.password SecretRefs are treated as unset, allowing fallback to remote credentials in local mode. This vulnerability can be exploited by attackers who manipulate local auth references, potentially bypassing intended local authentication boundaries. The vulnerability has a low C [truncated]

MEDIUM OpenClaw CVE published 2026-03-31

CVE-2026-32921

CVE-2026-32921 is an approval bypass vulnerability in OpenClaw before version 2026.3.8. The vulnerability exists in the system.run function where mutable script operands are not bound across approval and execution phases. This allows attackers to obtain approval for script execution, modify the approved script file before execution, and execute different content while maintaining the same approved command shape.

HIGH OpenClaw CVE published 2026-03-31

CVE-2026-32920

CVE-2026-32920 is a high-severity vulnerability in OpenClaw before version 2026.3.12. The vulnerability allows for arbitrary code execution due to the automatic discovery and loading of plugins from .OpenClaw/extensions/ without explicit trust verification. Attackers can exploit this by including malicious plugins in cloned repositories, which execute when users run OpenClaw from the directory. This issue [truncated]

CRITICAL OpenClaw CVE published 2026-03-31

CVE-2026-32916

OpenClaw versions 2026.3.7 before 2026.3.11 contain an authorization bypass vulnerability where plugin subagent routes execute gateway methods through a synthetic operator client with broad administrative scopes. This vulnerability allows remote unauthenticated requests to plugin-owned routes to invoke runtime.subagent methods to perform privileged gateway actions, including session deletion and agent exe [truncated]

HIGH OpenClaw CVE published 2026-03-26

CVE-2026-32846

CVE-2026-32846 is a high-severity path traversal issue in OpenClaw’s media parsing flow. As published by NVD on 2026-03-26 and last modified on 2026-05-20, the flaw can let attackers bypass path validation and read arbitrary files outside the intended sandbox, including sensitive local files.

MEDIUM OpenClaw CVE published 2026-03-21

CVE-2026-32896

CVE-2026-32896 is a medium-severity vulnerability in OpenClaw's BlueBubbles webhook handler, affecting versions prior to 2026.2.21. The vulnerability allows unauthenticated webhook events in certain reverse-proxy or local routing configurations, potentially enabling attackers to bypass webhook authentication. This issue is particularly concerning for defenders responsible for OpenClaw BlueBubbles plugin d [truncated]