Known Vulnerabilities for OpenClaw by Na
Listed below are 10 of the newest known vulnerabilities associated with "OpenClaw" by "Na".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-45006 json | OpenClaw before 2026.4.23 contains an improper access control vulnerability in the gateway tool's config.apply and config.pat... | Not Provided | 2026-05-11 | 2026-05-11 |
| CVE-2026-45005 json | OpenClaw before 2026.4.23 caches resolved webhook route secrets backed by SecretRef values, allowing stale secrets to remain ... | Not Provided | 2026-05-11 | 2026-05-11 |
| CVE-2026-45004 json | OpenClaw before 2026.4.23 contains an arbitrary code execution vulnerability in the bundled plugin setup resolver that loads ... | Not Provided | 2026-05-11 | 2026-05-11 |
| CVE-2026-45003 json | OpenClaw before 2026.4.22 allows workspace dotenv files to override connector endpoint hosts for Matrix, Mattermost, IRC, and... | Not Provided | 2026-05-11 | 2026-05-11 |
| CVE-2026-45002 json | OpenClaw before 2026.4.20 contains a hook session-key bypass vulnerability that allows attackers to circumvent the hooks.allo... | Not Provided | 2026-05-11 | 2026-05-11 |
| CVE-2026-45001 json | OpenClaw before 2026.4.20 contains a guard bypass vulnerability in the agent-facing gateway config.patch and config.apply end... | Not Provided | 2026-05-11 | 2026-05-11 |
| CVE-2026-45000 json | OpenClaw before 2026.4.20 contains a server-side request forgery vulnerability in browser CDP profile creation that skips str... | Not Provided | 2026-05-11 | 2026-05-11 |
| CVE-2026-44999 json | OpenClaw before 2026.4.20 fails to properly preserve untrusted labels for isolated cron awareness events, allowing webhook-tr... | Not Provided | 2026-05-11 | 2026-05-12 |
| CVE-2026-44998 json | OpenClaw before 2026.4.20 contains a tool policy bypass vulnerability allowing bundled MCP and LSP tools to circumvent config... | Not Provided | 2026-05-11 | 2026-05-11 |
| CVE-2026-44997 json | OpenClaw before 2026.4.22 contains a security envelope constraint bypass vulnerability allowing restricted subagents to spawn... | Not Provided | 2026-05-11 | 2026-05-11 |