Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 6 CVE-2026-53859

OpenClaw < 2026.5.26 - Hostname Validation Bypass via Trailing-Dot Inconsistency_CVE-2026-53859

OpenClaw before 2026.5.26 contains a hostname validation vulnerability allowing attackers to bypass blocklist comparisons using trailing-dot notati...

OpenClaw OpenClaw CVE
MEDIUM 5.7 CVE-2026-53856

OpenClaw < 2026.4.24 - Insecure File Permissions in Config Recovery via OpenClaw.json_CVE-2026-53856

OpenClaw before 2026.4.24 contains an insecure file permissions vulnerability in config recovery that restores OpenClaw.json with overly broad perm...

OpenClaw OpenClaw 2026.4.23 CVE
MEDIUM 6 CVE-2026-53854

OpenClaw < 2026.4.25 - Privilege Escalation via ownerAllowFrom Wildcard Inheritance in Internal/Webchat Commands_CVE-2026-53854

OpenClaw before 2026.4.25 contains a privilege escalation vulnerability in internal and webchat command authentication that allows senders to inher...

OpenClaw OpenClaw CVE
MEDIUM 6.3 CVE-2026-53851

OpenClaw < 2026.5.12 - Slack Reaction Event Notification Bypass_CVE-2026-53851

OpenClaw before 2026.5.12 contains a notification bypass vulnerability allowing Slack reaction events to enter the agent pipeline despite disabled ...

OpenClaw OpenClaw CVE
MEDIUM 6.8 CVE-2026-53850

OpenClaw < 2026.4.25 - Control Scope Enforcement Bypass in Focus Command_CVE-2026-53850

OpenClaw before 2026.4.25 contains a control scope enforcement bypass vulnerability in the focus command that allows authenticated callers to execu...

OpenClaw OpenClaw CVE
MEDIUM 5.3 CVE-2026-53847

OpenClaw < 2026.5.6 - Privilege Escalation via Active Memory Write Scope_CVE-2026-53847

OpenClaw before 2026.5.6 contains a privilege escalation vulnerability in the Active Memory write scope that allows Gateway operators with operator...

OpenClaw OpenClaw CVE
MEDIUM 6 CVE-2026-53844

OpenClaw < 2026.4.29 - Session Visibility Check Bypass in Shared Memory Search_CVE-2026-53844

OpenClaw before 2026.4.29 contains a session visibility check bypass vulnerability in shared memory search that allows authenticated callers to acc...

OpenClaw OpenClaw CVE
MEDIUM 6 CVE-2026-53840

OpenClaw < 2026.5.12 - Custom Header Leakage via MCP Streamable HTTP Cross-Origin Redirects_CVE-2026-53840

OpenClaw before 2026.5.12 contains an information disclosure vulnerability in streamable-http MCP servers that forwards operator-configured custom ...

OpenClaw OpenClaw CVE
MEDIUM 5.5 CVE-2026-4367

Libxpm: libxpm: denial of service via out-of-bounds read in xpm file parsing_CVE-2026-4367

A flaw was found in libXpm. A local user with low privileges could exploit an Out-of-Bounds Read vulnerability in the `xpmNextWord()` function by p...

Red Hat Red Hat Enterprise Linux 10 CVE
MEDIUM 6.8 CVE-2026-48775

LangGraph Checkpoint: Unsafe JSON deserialization in checkpoint loading_CVE-2026-48775

LangGraph SQLite Checkpoint is an implementation of LangGraph CheckpointSaver that uses SQLite DB (both sync and async, via aiosqlite). In versions...

langchain-ai langgraph < 1.2.2 CVE