Where
AND
-Infinity
0

OpenClaw OpenClawOpenClaw < 2026.5.18 Authorization Bypass via Skill Command Dispatch

Risk 34
Severity
2.3
First published (updated )

OpenClaw OpenClawOpenClaw 2026.5.12 < 2026.5.26 Authorization Bypass via allowFrom

Risk 34
Severity
2.3
First published (updated )

OpenClaw OpenClawOpenClaw 2026.4.20 < 2026.5.28 Policy Bypass via Media Upload

Risk 26
Severity
2.3
First published (updated )

OpenClaw Openclaw Node.jsOpenClaw < 2026.5.12 - Bootstrap Token Replay via Pending Pairing Scope Widening

Risk 34
Severity
2.3
First published (updated )

OpenClaw Openclaw Node.jsOpenClaw < 2026.5.7 - Sender Policy Bypass via Mutable Conversation Identifiers in BlueBubbles

Risk 34
Severity
2.3
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

OpenClaw Openclaw Node.jsOpenClaw < 2026.4.25 - Scope Bypass via Empty-Scope Device Re-pairing

Risk 34
Severity
2.3
First published (updated )

OpenClaw Openclaw Node.jsOpenClaw < 2026.5.26 - Exec Allowlist Bypass via Transparent Command Wrappers

Risk 22
Severity
2.3
First published (updated )

OpenClaw Openclaw Node.jsOpenClaw < 2026.5.6 - Skill-Command Dispatch Hook Bypass via Before-Tool-Call Hook Skipping

Risk 22
Severity
2.3
First published (updated )

OpenClaw Openclaw Node.jsOpenClaw < 2026.5.12 - Cross-Site Scripting via Unsafe Markdown Links in Exported Session HTML

Risk 38
Severity
2.1
First published (updated )

OpenClaw OpenClawOpenClaw < 2026.4.26 - Information Disclosure via Sandboxed Session Spawn

Risk 22
Severity
2.3
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

OpenClaw OpenClawOpenClaw < 2026.4.29 - Policy Bypass in QQBot Admin Commands via DM-only and allowFrom Checks

Risk 34
Severity
2.3
First published (updated )

OpenClaw OpenClawOpenClaw < 2026.5.12 - Privilege Escalation in Slack Plugin Approvals via Exec Approver Gate

Risk 22
Severity
2.3
First published (updated )

OpenClaw OpenClawOpenClaw < 2026.4.20 - Server-Side Request Forgery via Browser CDP Profile Creation

Risk 26
Severity
2.3
First published (updated )

OpenClaw OpenClawOpenClaw < 2026.4.20 - Tool Policy Bypass via Bundled MCP/LSP Tools

Risk 34
Severity
2.3
First published (updated )

OpenClaw OpenClawOpenClaw < 2026.4.22 - Security Envelope Constraint Bypass in ACP Child Sessions

Risk 22
Severity
2.3
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

OpenClaw OpenClawOpenClaw < 2026.4.20 - Direct Message Misclassification in Feishu Card Actions

Risk 34
Severity
2.3
First published (updated )

OpenClaw OpenClawOpenClaw < 2026.4.21 - Authorization Bypass in Owner-Enforced Commands via Wildcard Channel Senders

Risk 29
Severity
2.3
First published (updated )

OpenClaw OpenClawOpenClaw < 2026.4.15 - Arbitrary Markdown File Read via QMD memory_get

Risk 22
Severity
2.3
First published (updated )

OpenClaw OpenClawOpenClaw < 2026.4.8 - WebSocket Session Persistence via Shared Gateway Token Rotation

Risk 34
Severity
2.3
First published (updated )

OpenClaw OpenClawOpenClaw < 2026.4.8 - Stale Authentication State via Config Reload

Risk 34
Severity
2.3
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

OpenClaw OpenClawOpenClaw < 2026.4.8 - Missing Owner-Only Enforcement in /allowlist Cross-Channel Writes

Risk 22
Severity
2.3
First published (updated )

OpenClaw OpenClawOpenClaw < 2026.3.31 - Disk Exhaustion via Media Download Bypass

Risk 38
Severity
2.3
First published (updated )

OpenClaw OpenClawOpenClaw < 2026.3.31 - Sender Allowlist Bypass via Thread History and Quoted Messages

Risk 34
Severity
2.3
First published (updated )

OpenClaw OpenClawOpenClaw < 2026.3.31 - Webhook Replay Cache Cross-Target messageId Scope Bypass

Risk 34
Severity
2.3
First published (updated )

OpenClaw OpenClawOpenClaw - Unauthorized Agent Request Dispatch via Untrusted Local-Network Pages in iOS A2UI Bridge

Risk 30
Severity
2.1
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

OpenClaw OpenClawOpenClaw < 2026.3.31 - Access Control Bypass in Discord Voice Manager via Channel Allowlist

Risk 34
Severity
2.3
First published (updated )

OpenClaw OpenClawOpenClaw < 2026.3.31 - Matrix Thread Context Allowlist Bypass via Sender Validation

Risk 40
Severity
2.3
First published (updated )

OpenClaw OpenClawOpenClaw 2026.2.19 through 2026.3.30 - Webhook Replay Dedupe Cache Event Suppression via Shared Authentication

Risk 22
Severity
2.3
First published (updated )

OpenClaw OpenClawOpenClaw < 2026.4.2 - Sender Allowlist Bypass via Slack Thread Context

Risk 34
Severity
2.3
First published (updated )

OpenClaw OpenClawOpenClaw < 2026.3.31 - Unsanitized Environment Variable Leakage in SSH Sandbox Backends

Risk 18
Severity
2
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203