Vulnerabilities in openclaw

537 results
CVE-2026-32043MEDIUMOpenClaw < 2026.2.25 - Time-of-Check-Time-of-Use via Mutable Symlink in system.run cwd ParameterEPSS 0.1%CVE-2026-53818MEDIUMOpenClaw < 2026.4.24 - Owner-Only Tool Policy Bypass via MCP LoopbackEPSS 0.1%CVE-2026-32919MEDIUMOpenClaw < 2026.3.11 - Unauthorized Session Reset via agent Slash CommandsEPSS 0.1%CVE-2026-27545MEDIUMOpenClaw < 2026.2.26 - Approval Bypass via Parent Symlink Current Working Directory RebindEPSS 0.1%CVE-2026-53856MEDIUMOpenClaw 2026.4.23 < 2026.4.24 - Insecure File Permissions in Config Recovery via OpenClaw.jsonEPSS 0.1%CVE-2026-53820MEDIUMOpenClaw < 2026.5.12 - Exec Denylist Bypass in Bundle MCP Loopback Session SpawnEPSS 0.1%CVE-2026-53809MEDIUMOpenClaw < 2026.4.25 - Provider Alias Confusion in Embedded Runner PolicyEPSS 0.1%CVE-2026-53850MEDIUMOpenClaw < 2026.4.25 - Control Scope Enforcement Bypass in Focus CommandEPSS 0.1%CVE-2026-31997MEDIUMOpenClaw < 2026.3.1 - Executable Rebind via Unbound PATH-token in system.run ApprovalsEPSS 0.1%CVE-2026-41360MEDIUMOpenClaw < 2026.4.2 - Approval Integrity Bypass in pnpm dlx Local Script BindingEPSS 0.1%CVE-2026-41338MEDIUMOpenClaw < 2026.3.31 - Time-of-Check-Time-of-Use (TOCTOU) Vulnerability in Sandbox File OperationsEPSS 0.1%CVE-2026-53862LOWOpenClaw < 2026.5.12 - Bootstrap Token Replay via Pending Pairing Scope WideningEPSS 0.1%CVE-2026-33574MEDIUMOpenClaw < 2026.3.8 - Path Traversal via Tools Root Rebinding in Skills DownloadEPSS 0.1%CVE-2026-27670MEDIUMOpenClaw < 2026.3.2 - Arbitrary File Write via ZIP Extraction Parent Symlink Race ConditionEPSS 0.1%CVE-2026-32988MEDIUMOpenClaw < 2026.3.11 - Sandbox Boundary Bypass via Unvalidated Temporary File CreationEPSS 0.1%CVE-2026-43529LOWOpenClaw < 2026.4.10 - Time-of-Check-Time-of-Use (TOCTOU) Race Condition in exec Script Preflight ValidatorEPSS 0.1%CVE-2026-32977MEDIUMOpenClaw < 2026.3.11 - Sandbox Boundary Bypass via Unanchored writeFile Commit PathEPSS 0.1%