CVE Severity Distribution (Last 30 Days)
Found 11 CVEs in the last 30 days.
CVE-2026-32013
HIGH
CVSS: 8.8
EPSS: 0.6%
CWE-59
T1083
OpenClaw versions prior to 2026.2.25 contain a symlink traversal vulnerability in the agents.files.get and agents.files.set methods that allows reading and writing files outside the agent workspace. Attackers can exploit symlinked allowlisted files to access arbitrary host files within gateway process permissions, potentially enabling code execution through file overwrite attacks.
Published: 2026-03-19
CVE-2026-32014
HIGH
CVSS: 8.0
EPSS: 0.2%
CWE-290
OpenClaw versions prior to 2026.2.26 contain a metadata spoofing vulnerability where reconnect platform and deviceFamily fields are accepted from the client without being bound into the device-auth signature. An attacker with a paired node identity on the trusted network can spoof reconnect metadata to bypass platform-based node command policies and gain access to restricted commands.
Published: 2026-03-19
CVE-2026-32015
HIGH
CVSS: 7.8
EPSS: 0.1%
CWE-426
OpenClaw versions 2026.1.21 prior to 2026.2.19 contain a path hijacking vulnerability in tools.exec.safeBins that allows attackers to bypass allowlist checks by controlling process PATH resolution. Attackers who can influence the gateway process PATH or launch environment can execute trojan binaries with allowlisted names, such as jq, circumventing executable validation controls.
Published: 2026-03-19
CVE-2026-32016
HIGH
CVSS: 7.8
EPSS: 0.1%
CWE-426
OpenClaw versions prior to 2026.2.22 on macOS contain a path validation bypass vulnerability in the exec-approval allowlist mode that allows local attackers to execute unauthorized binaries by exploiting basename-only allowlist entries. Attackers can execute same-name local binaries ./echo without approval when security=allowlist and ask=on-miss are configured, bypassing intended path-based policy restrictions.
Published: 2026-03-19
CVE-2026-32011
HIGH
CVSS: 7.5
EPSS: 0.4%
CWE-770
T1499
OpenClaw versions prior to 2026.3.2 contain a denial of service vulnerability in webhook handlers for BlueBubbles and Google Chat that parse request bodies before performing authentication and signature validation. Unauthenticated attackers can exploit this by sending slow or oversized request bodies to exhaust parser resources and degrade service availability.
Published: 2026-03-19
CVE-2026-32019
HIGH
CVSS: 7.4
EPSS: 0.2%
CWE-918
T1190
OpenClaw versions prior to 2026.2.22 contain incomplete IPv4 special-use range validation in the isPrivateIpv4() function, allowing requests to RFC-reserved ranges to bypass SSRF policy checks. Attackers with network reachability to special-use IPv4 ranges can exploit web_fetch functionality to access blocked addresses such as 198.18.0.0/15 and other non-global ranges.
Published: 2026-03-19
CVE-2026-32017
HIGH
CVSS: 7.1
EPSS: 0.3%
CWE-184
OpenClaw versions prior to 2026.2.19 contain an allowlist bypass vulnerability in the exec safeBins policy that allows attackers to write arbitrary files using short-option payloads. Attackers can bypass argument validation by attaching short options like -o to whitelisted binaries, enabling unauthorized file-write operations that should be denied by safeBins checks.
Published: 2026-03-19
CVE-2026-32010
MEDIUM
CVSS: 6.3
EPSS: 0.3%
CWE-78
T1059
OpenClaw versions prior to 2026.2.22 contain an allowlist bypass vulnerability in the safe-bin configuration when sort is manually added to tools.exec.safeBins. Attackers can invoke sort with the --compress-program flag to execute arbitrary external programs without operator approval in allowlist mode with ask=on-miss enabled.
Published: 2026-03-19
CVE-2026-3201
MEDIUM
CVSS: 4.7
EPSS: 0.2%
CWE-1325
CWE-770
T1499
USB HID protocol dissector memory exhaustion in Wireshark 4.6.0 to 4.6.3 and 4.4.0 to 4.4.13 allows denial of service
Published: 2026-02-25
CVE-2026-32018
LOW
CVSS: 3.6
EPSS: 0.1%
CWE-362
T1068
OpenClaw versions prior to 2026.2.19 contain a race condition vulnerability in concurrent updateRegistry and removeRegistryEntry operations for sandbox containers and browsers. Attackers can exploit unsynchronized read-modify-write operations without locking to cause registry updates to lose data, resurrect removed entries, or corrupt sandbox state affecting list, prune, and recreate operations.
Published: 2026-03-19
CVE-2026-32012
UNKNOWN
Rejected reason: This CVE ID has been rejected.
Published: 2026-03-23