|
31
|
7.8 |
HIGH
Local
|
-
|
-
|
OpenClaw before 2026.4.23 contains an arbitrary code execution vulnerability in the bundled plugin setup resolver that loads setup-api.js from process.cwd() during provider setup metadata resolution.…
New
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2026-45004
|
2026-05-12 03:16 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
32
|
5.0 |
MEDIUM
Local
|
-
|
-
|
OpenClaw before 2026.4.22 allows workspace dotenv files to override connector endpoint hosts for Matrix, Mattermost, IRC, and Synology connectors. Attackers with workspace access can redirect runtime…
New
|
CWE-441
Confused Deputy
|
CVE-2026-45003
|
2026-05-12 03:16 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
33
|
5.3 |
MEDIUM
Network
|
-
|
-
|
OpenClaw before 2026.4.20 contains a hook session-key bypass vulnerability that allows attackers to circumvent the hooks.allowRequestSessionKey opt-in restriction. Attackers can render externally inf…
New
|
CWE-863
Incorrect Authorization
|
CVE-2026-45002
|
2026-05-12 03:16 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
34
|
7.1 |
HIGH
Network
|
-
|
-
|
OpenClaw before 2026.4.20 contains a guard bypass vulnerability in the agent-facing gateway config.patch and config.apply endpoints that fails to protect operator-trusted settings including sandbox p…
New
|
CWE-862
Missing Authorization
|
CVE-2026-45001
|
2026-05-12 03:16 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
35
|
5.0 |
MEDIUM
Network
|
-
|
-
|
OpenClaw before 2026.4.20 contains a server-side request forgery vulnerability in browser CDP profile creation that skips strict-mode SSRF policy checks. Attackers can create stored profiles pointing…
New
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-45000
|
2026-05-12 03:16 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
36
|
5.3 |
MEDIUM
Network
|
-
|
-
|
OpenClaw before 2026.4.20 fails to properly preserve untrusted labels for isolated cron awareness events, allowing webhook-triggered cron agent output to be recorded as trusted system events. Attacke…
New
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2026-44999
|
2026-05-12 03:16 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
37
|
5.4 |
MEDIUM
Network
|
-
|
-
|
OpenClaw before 2026.4.20 contains a tool policy bypass vulnerability allowing bundled MCP and LSP tools to circumvent configured tool restrictions. Attackers with local agent access can append restr…
New
|
CWE-863
Incorrect Authorization
|
CVE-2026-44998
|
2026-05-12 03:16 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
38
|
4.3 |
MEDIUM
Network
|
-
|
-
|
OpenClaw before 2026.4.22 contains a security envelope constraint bypass vulnerability allowing restricted subagents to spawn ACP child sessions that fail to inherit depth, child-count limits, contro…
New
|
CWE-266
Incorrect Privilege Assignment
|
CVE-2026-44997
|
2026-05-12 03:16 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
39
|
3.7 |
LOW
Network
|
-
|
-
|
OpenClaw before 2026.4.15 contains an arbitrary local file read vulnerability in the webchat audio embedding helper that fails to apply local media root containment checks. Attackers can influence ag…
New
|
CWE-22
Path Traversal
|
CVE-2026-44996
|
2026-05-12 03:16 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
40
|
7.3 |
HIGH
Local
|
-
|
-
|
OpenClaw before 2026.4.20 contains an improper environment variable validation vulnerability in MCP stdio server configuration that allows attackers to execute arbitrary code. Malicious workspace con…
New
|
CWE-829
Inclusion of Functionality from Untrusted Control Sphere
|
CVE-2026-44995
|
2026-05-12 03:16 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|