Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
26391
Total
1955
Critical
7971
High
8223
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-53857 | HIGH | 8.1 | OpenClaw before 2026.5.3 contains a policy enforcement vulnerability where Zalo contacts with mutable display metadata could match allowFrom policy entries through display name changes. Attackers … | Jun 16, 2026 |
| CVE-2026-53856 | MEDIUM | 5.5 | OpenClaw before 2026.4.24 contains an insecure file permissions vulnerability in config recovery that restores OpenClaw.json with overly broad permissions. Local attackers on shared hosts can … | Jun 16, 2026 |
| CVE-2026-53855 | HIGH | 8.1 | OpenClaw before 2026.4.2 contains an inline-eval bypass vulnerability allowing authenticated operators to weaken strict allowlist checks via shell positional parameters. Attackers can combine allowlisted tools … | Jun 16, 2026 |
| CVE-2026-53854 | MEDIUM | 6.5 | OpenClaw before 2026.4.25 contains a privilege escalation vulnerability in internal and webchat command authentication that allows senders to inherit wildcard ownerAllowFrom state across channel boundaries. … | Jun 16, 2026 |
| CVE-2026-53853 | HIGH | 8.3 | OpenClaw before 2026.5.12 contains an argument pattern validation bypass in the exec allowlist that allows attackers to execute disallowed arguments for allowlisted executables on Linux … | Jun 16, 2026 |
| CVE-2026-53852 | MEDIUM | 5.4 | OpenClaw before 2026.4.25 contains a scope containment bypass vulnerability in device re-pairing that allows authenticated operators to restore broader scopes than intended by submitting empty-scope … | Jun 16, 2026 |
| CVE-2026-53851 | MEDIUM | 5.3 | OpenClaw before 2026.5.12 contains a notification bypass vulnerability allowing Slack reaction events to enter the agent pipeline despite disabled reaction notifications. Attackers can trigger unintended … | Jun 16, 2026 |
| CVE-2026-53850 | MEDIUM | 5.5 | OpenClaw before 2026.4.25 contains a control scope enforcement bypass vulnerability in the focus command that allows authenticated callers to execute the command without proper authorization … | Jun 16, 2026 |
| CVE-2026-53849 | HIGH | 8.1 | OpenClaw before 2026.5.7 contains a privilege escalation vulnerability where the allowFrom feature improperly validates Discord account identity using mutable display names instead of immutable user … | Jun 16, 2026 |
| CVE-2026-53848 | MEDIUM | 4.3 | OpenClaw before 2026.5.26 contains an exec allowlist bypass vulnerability allowing authenticated operators to execute wrapper-level side effects outside allowlisted command intent. Attackers can craft command … | Jun 16, 2026 |
| CVE-2026-53847 | MEDIUM | 5.4 | OpenClaw before 2026.5.6 contains a privilege escalation vulnerability in the Active Memory write scope that allows Gateway operators with operator.write access to modify global configuration … | Jun 16, 2026 |
| CVE-2026-53846 | HIGH | 7.1 | OpenClaw before 2026.4.29 contains a path traversal vulnerability in the install helper that allows workspace .env files to override the npm_execpath configuration used for bundled … | Jun 16, 2026 |
| CVE-2026-53845 | MEDIUM | 4.3 | OpenClaw before 2026.5.6 contains a hook bypass vulnerability where skill commands routed through the affected dispatch path skip before-tool-call hook coverage. Attackers can exploit this … | Jun 16, 2026 |
| CVE-2026-53844 | MEDIUM | 6.5 | OpenClaw before 2026.4.29 contains a session visibility check bypass vulnerability in shared memory search that allows authenticated callers to access memory entries without proper authorization. … | Jun 16, 2026 |
| CVE-2026-53843 | HIGH | 8.8 | OpenClaw before 2026.5.26 contains an authorization bypass vulnerability where a surviving pairing-scoped device session can re-establish node token authority after revocation. Attackers with a paired … | Jun 16, 2026 |
| CVE-2026-53842 | HIGH | 7.1 | OpenClaw before 2026.5.2 contains an environment variable injection vulnerability allowing workspace .env files to influence Python runtime selection through CLOUDSDK_PYTHON during Gmail setup gcloud execution. … | Jun 16, 2026 |
| CVE-2026-53841 | MEDIUM | 6.1 | OpenClaw before 2026.5.12 contains a cross-site scripting vulnerability in exported session HTML that preserves unsafe javascript: and data: links in generated content. Attackers can execute … | Jun 16, 2026 |
| CVE-2026-53840 | HIGH | 7.1 | OpenClaw before 2026.5.12 contains an information disclosure vulnerability in streamable-http MCP servers that forwards operator-configured custom headers during cross-origin redirects. Attackers controlling or compromising an … | Jun 16, 2026 |
| CVE-2026-50656 | HIGH | 7.8 | Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "RoguePlanet ". We are … | Jun 16, 2026 |
| CVE-2026-4367 | MEDIUM | 5.5 | A flaw was found in libXpm. A local user with low privileges could exploit an Out-of-Bounds Read vulnerability in the `xpmNextWord()` function by processing a … | Jun 16, 2026 |
| CVE-2026-48775 | MEDIUM | 6.8 | LangGraph SQLite Checkpoint is an implementation of LangGraph CheckpointSaver that uses SQLite DB (both sync and async, via aiosqlite). In versions 4.1.0 and prior, the … | Jun 16, 2026 |
| CVE-2026-47964 | HIGH | 7.8 | DNG SDK versions 1.7.1 2536 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context … | Jun 16, 2026 |
| CVE-2026-47963 | MEDIUM | 5.5 | DNG SDK versions 1.7.1 2536 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could … | Jun 16, 2026 |
| CVE-2026-47934 | MEDIUM | 5.5 | DNG SDK versions 1.7.1 2536 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could … | Jun 16, 2026 |
| CVE-2026-47927 | MEDIUM | 5.5 | DNG SDK versions 1.7.1 2536 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could … | Jun 16, 2026 |