PatchSiren

OpenClaw CVE debriefs · Page 5

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

LOW OpenClaw CVE published 2026-03-21

CVE-2026-32067

OpenClaw versions prior to 2026.2.26 contain an authorization bypass vulnerability in the pairing-store access control for direct message pairing policy. An attacker approved as a sender in one account can be automatically accepted in another account in multi-account deployments without explicit approval, bypassing authorization boundaries.

MEDIUM OpenClaw CVE published 2026-03-19

CVE-2026-32022

OpenClaw versions prior to 2026.2.21 contain a policy bypass vulnerability in the grep tool within tools.exec.safeBins. The vulnerability allows attackers to read arbitrary files by supplying a pattern via the -e flag parameter and including a positional filename operand, which bypasses file access restrictions intended to limit operations to stdin-only. This enables reading sensitive files such as .env f [truncated]

MEDIUM OpenClaw CVE published 2026-03-18

CVE-2026-22217

OpenClaw versions 2026.2.22 and earlier contain an arbitrary code execution vulnerability in the shell-env component. The flaw stems from trusted-prefix fallback logic for the $SHELL environment variable, which can be exploited when attackers control the $SHELL variable on systems with writable trusted-prefix directories such as /opt/homebrew/bin. This allows execution of attacker-controlled binaries with [truncated]

HIGH Openclaw CVE published 2026-03-11

CVE-2026-32062

CVE-2026-32062 affects OpenClaw versions 2026.2.21-2 prior to 2026.2.22 and @openclaw/voice-call versions 2026.2.21 prior to 2026.2.22. The issue lets media-stream WebSocket upgrades complete before stream validation, so unauthenticated clients can keep idle sockets open and consume connection resources until service availability degrades.

CRITICAL OpenClaw CVE published 2026-03-05

CVE-2026-28474

CVE-2026-28474 debrief based on the supplied source corpus. The CVE record was published on 2026-03-05T22:16:21.423Z and has not been modified since then. OpenClaw's Nextcloud Talk plugin versions prior to 2026.2.6 are vulnerable due to equality matching on the mutable actor.name display name field for allowlist validation. This allows attackers to bypass DM and room allowlists by changing their Nextcloud [truncated]

HIGH OpenClaw CVE published 2026-03-05

CVE-2026-28465

CVE-2026-28465 is a HIGH severity vulnerability in OpenClaw's voice-call plugin versions before 2026.2.3. The vulnerability allows remote attackers to bypass webhook verification by supplying untrusted forwarded headers, potentially enabling attackers to spoof webhook events. This issue affects OpenClaw's voice-call plugin deployments, and defenders should assess their exposure and prioritize verification [truncated]

MEDIUM OpenClaw CVE published 2026-03-05

CVE-2026-28395

OpenClaw versions 2026.1.14-1 through 2026.2.11 contain an improper network binding vulnerability in the Chrome extension relay server. When a wildcard cdpUrl is configured, the relay HTTP/WebSocket server incorrectly treats wildcard hosts as loopback addresses, causing it to bind to all network interfaces rather than localhost. This exposes the relay HTTP endpoints to remote attackers, enabling service p [truncated]