Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 7.4 CVE-2026-53832

OpenClaw < 2026.5.18 - Identity Header Forgery via Trusted-Proxy Configuration_CVE-2026-53832

OpenClaw before 2026.5.18 contains an identity header validation vulnerability allowing local same-host callers to forge trusted-proxy identity hea...

OpenClaw OpenClaw CVE
HIGH 7.6 CVE-2026-53831

OpenClaw < 2026.5.18 - Arbitrary File Read via Shell Expansion in system.run Safe-bin Allowlist_CVE-2026-53831

OpenClaw before 2026.5.18 contains a policy enforcement vulnerability in system.run safe-bin allowlist validation that allows shell expansion to mo...

OpenClaw OpenClaw CVE
HIGH 8.5 CVE-2026-53829

OpenClaw < 2026.5.18 - Command Truncation in Exec Approval Display_CVE-2026-53829

OpenClaw before 2026.5.18 contains an approval display truncation vulnerability allowing authenticated users to hide command suffixes from approver...

OpenClaw OpenClaw CVE
HIGH 7.7 CVE-2026-53828

OpenClaw < 2026.5.6 - Native Command Authorization Bypass via Owner-Command Enforcement_CVE-2026-53828

OpenClaw before 2026.5.6 contains an authorization bypass vulnerability in native command handling that allows authenticated senders to execute own...

OpenClaw OpenClaw CVE
HIGH 7.1 CVE-2026-53825

OpenClaw < 2026.4.7 - Arbitrary Local File Read via memory-wiki Ingest with operator.write Scope_CVE-2026-53825

OpenClaw before 2026.4.7 contains an arbitrary file read vulnerability in the memory-wiki ingest feature that allows authenticated Gateway operator...

OpenClaw OpenClaw CVE
HIGH 8.6 CVE-2026-53823

OpenClaw < 2026.5.3 - Privilege Escalation via Mutable Slack Display Names in allowFrom_CVE-2026-53823

OpenClaw before 2026.5.3 contains a privilege escalation vulnerability in the allowFrom feature that binds to mutable Slack display names. Attacker...

OpenClaw OpenClaw CVE
HIGH 8.7 CVE-2026-53822

OpenClaw < 2026.5.18 - Command Argument Modification via Shell Wrapper Between Approval and Execution_CVE-2026-53822

OpenClaw before 2026.5.18 contains a command injection vulnerability where shell wrapper argv could change between approval and execution. Attacker...

OpenClaw OpenClaw CVE
HIGH 8.7 CVE-2026-53821

OpenClaw < 2026.5.18 - Scope Elevation in trusted-proxy Control UI WebSocket_CVE-2026-53821

OpenClaw before 2026.5.18 accepts WebSocket client-declared operator scopes before binding to server-approved pairing or trusted-proxy authorizatio...

OpenClaw OpenClaw CVE
HIGH 7.8 CVE-2025-7017

Avira antivirus engine heap buffer OOB read when scanning a malformed Windows MSI file_CVE-2025-7017

Heap buffer out-of-bounds read vulnerability in Avira Antivirus engine when scanning a malformed Windows MSI file may allow Local Execution of Code...

Gen Digital Avira Antivirus CVE
HIGH 7.8 CVE-2025-7011

Avast antivirus heap OOB when scanning a malformed zip file_CVE-2025-7011

Heap out-of-bounds read vulnerability in Avast Antivirus when scanning a malformed zip file containing XML may allow Local Execution of Code or Den...

Gen Digital Avast Antivirus 25020100 CVE