Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
33925
Total
2632
Critical
10022
High
10229
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-40115 | MEDIUM | 6.2 | PraisonAI is a multi-agent teams system. Prior to 4.5.128, the WSGI-based recipe registry server (server.py) reads the entire HTTP request body into memory based on … | Apr 09, 2026 |
| CVE-2026-40114 | HIGH | 7.2 | PraisonAI is a multi-agent teams system. Prior to 4.5.128, the /api/v1/runs endpoint accepts an arbitrary webhook_url in the request body with no URL validation. When … | Apr 09, 2026 |
| CVE-2026-40113 | HIGH | 8.4 | PraisonAI is a multi-agent teams system. Prior to 4.5.128, deploy.py constructs a single comma-delimited string for the gcloud run deploy --set-env-vars argument by directly interpolating … | Apr 09, 2026 |
| CVE-2026-40112 | MEDIUM | 5.4 | PraisonAI is a multi-agent teams system. Prior to 4.5.128, the Flask API endpoint in src/praisonai/api.py renders agent output as HTML without effective sanitization. The _sanitize_html … | Apr 09, 2026 |
| CVE-2026-40111 | UNKNOWN | — | PraisonAIAgents is a multi-agent teams system. Prior to 1.5.128, he memory hooks executor in praisonaiagents passes a user-controlled command string directly to subprocess.run() with shell=True … | Apr 09, 2026 |
| CVE-2026-39848 | MEDIUM | 6.5 | Dockyard is a Docker container management app. Prior to 1.1.0, Docker container start and stop operations are performed through GET requests without CSRF protection. A … | Apr 09, 2026 |
| CVE-2026-35646 | MEDIUM | 4.8 | OpenClaw before 2026.3.25 contains a pre-authentication rate-limit bypass vulnerability in webhook token validation that allows attackers to brute-force weak webhook secrets. The vulnerability exists because … | Apr 09, 2026 |
| CVE-2026-35645 | HIGH | 8.1 | OpenClaw before 2026.3.25 contains a privilege escalation vulnerability in the gateway plugin subagent fallback deleteSession function that uses a synthetic operator.admin runtime scope. Attackers can … | Apr 09, 2026 |
| CVE-2026-35644 | MEDIUM | 6.5 | OpenClaw before 2026.3.22 contains an information disclosure vulnerability that allows attackers with operator.read scope to expose credentials embedded in channel baseUrl and httpUrl fields. Attackers … | Apr 09, 2026 |
| CVE-2026-35642 | MEDIUM | 4.3 | OpenClaw before 2026.3.25 contains an authorization bypass vulnerability where group reaction events bypass the requireMention access control mechanism. Attackers can trigger reactions in mention-gated groups … | Apr 09, 2026 |
| CVE-2026-35640 | MEDIUM | 5.3 | OpenClaw before 2026.3.25 parses JSON request bodies before validating webhook signatures, allowing unauthenticated attackers to force resource-intensive parsing operations. Remote attackers can send malicious webhook … | Apr 09, 2026 |
| CVE-2026-35639 | HIGH | 8.8 | OpenClaw before 2026.3.22 contains a privilege escalation vulnerability in the device.pair.approve method that allows an operator.pairing approver to approve pending device requests with broader operator … | Apr 09, 2026 |
| CVE-2026-35638 | HIGH | 8.8 | OpenClaw before 2026.3.22 contains a privilege escalation vulnerability in the Control UI that allows unauthenticated sessions to retain self-declared privileged scopes without device identity verification. … | Apr 09, 2026 |
| CVE-2026-35637 | HIGH | 7.3 | OpenClaw before 2026.3.22 performs cite expansion before completing channel and DM authorization checks, allowing cite work and content handling prior to final auth decisions. Attackers … | Apr 09, 2026 |
| CVE-2026-35636 | MEDIUM | 6.5 | OpenClaw versions 2026.3.11 through 2026.3.24 contain a session isolation bypass vulnerability where session_status resolves sessionId to canonical session keys before enforcing visibility checks. Sandboxed child … | Apr 09, 2026 |
| CVE-2026-35635 | MEDIUM | 4.8 | OpenClaw before 2026.3.22 contains a webhook path route replacement vulnerability in the Synology Chat extension that allows attackers to collapse multi-account configurations onto shared webhook … | Apr 09, 2026 |
| CVE-2026-35634 | MEDIUM | 5.1 | OpenClaw before 2026.3.23 contains an authentication bypass vulnerability in the Canvas gateway where authorizeCanvasRequest() unconditionally allows local-direct requests without validating bearer tokens or canvas capabilities. … | Apr 09, 2026 |
| CVE-2026-35633 | MEDIUM | 5.3 | OpenClaw before 2026.3.22 contains an unbounded memory allocation vulnerability in remote media HTTP error handling that allows attackers to trigger excessive memory consumption. Attackers can … | Apr 09, 2026 |
| CVE-2026-35632 | HIGH | 7.1 | OpenClaw through 2026.2.22 contains a symlink traversal vulnerability in agents.create and agents.update handlers that use fs.appendFile on IDENTITY.md without symlink containment checks. Attackers with workspace … | Apr 09, 2026 |
| CVE-2026-35631 | MEDIUM | 6.5 | OpenClaw before 2026.3.22 fails to enforce operator.admin scope on mutating internal ACP chat commands, allowing unauthorized modifications. Attackers without admin privileges can execute mutating control-plane … | Apr 09, 2026 |
| CVE-2026-35629 | HIGH | 7.4 | OpenClaw before 2026.3.25 contains a server-side request forgery vulnerability in multiple channel extensions that fail to properly guard configured base URLs against SSRF attacks. Attackers … | Apr 09, 2026 |
| CVE-2026-35628 | MEDIUM | 4.8 | OpenClaw before 2026.3.25 contains a missing rate limiting vulnerability in Telegram webhook authentication that allows attackers to brute-force weak webhook secrets. The vulnerability enables repeated … | Apr 09, 2026 |
| CVE-2026-35627 | MEDIUM | 6.5 | OpenClaw before 2026.3.22 performs cryptographic and dispatch operations on inbound Nostr direct messages before enforcing sender and pairing policy validation. Attackers can trigger unauthorized pre-authentication … | Apr 09, 2026 |
| CVE-2026-35626 | MEDIUM | 5.3 | OpenClaw before 2026.3.22 contains an unauthenticated resource exhaustion vulnerability in voice call webhook handling that buffers request bodies before provider signature checks. Attackers can send … | Apr 09, 2026 |
| CVE-2026-35625 | HIGH | 7.8 | OpenClaw before 2026.3.25 contains a privilege escalation vulnerability where silent local shared-auth reconnects auto-approve scope-upgrade requests, widening paired device permissions from operator.read to operator.admin. Attackers … | Apr 09, 2026 |