Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 5.3 CVE-2026-12301

Memory safety bug fixed in Thunderbird 152_CVE-2026-12301

Memory safety bug fixed in Thunderbird 152. This vulnerability was fixed in Firefox 152 and Thunderbird 152.

Mozilla Firefox 152 CVE
MEDIUM 5.3 CVE-2026-12300

Memory safety bug fixed in Thunderbird 152_CVE-2026-12300

Memory safety bug fixed in Thunderbird 152. This vulnerability was fixed in Firefox 152 and Thunderbird 152.

Mozilla Firefox 152 CVE
HIGH 7.6 CVE-2026-53866

OpenClaw < 2026.5.12 - Allowlist Bypass in Shell Inline-Command Parsing_CVE-2026-53866

OpenClaw before 2026.5.12 contains an allowlist bypass vulnerability in shell inline-command parsing that allows authenticated operators to execute...

OpenClaw OpenClaw CVE
HIGH 7.2 CVE-2026-53865

OpenClaw < 2026.5.2 - Arbitrary Command Execution via Workspace-Derived Service PATH_CVE-2026-53865

OpenClaw before 2026.5.2 contains a path traversal vulnerability in maintenance task execution that allows workspace-derived service paths to influ...

OpenClaw OpenClaw CVE
HIGH 7.6 CVE-2026-53864

OpenClaw < 2026.5.26 - Insufficient Environment Variable Sanitization in Node.js Control Variables_CVE-2026-53864

OpenClaw before 2026.5.26 contains an insufficient sanitization vulnerability in the host environment sanitizer that allows Node.js control variabl...

OpenClaw OpenClaw CVE
MEDIUM 6 CVE-2026-53863

OpenClaw < 2026.4.25 - Unvalidated Group ID Acceptance in Tool Group Policy_CVE-2026-53863

OpenClaw before 2026.4.25 contains an input validation vulnerability in tool group policy callers that accept unvalidated group IDs. Attackers who ...

OpenClaw OpenClaw CVE
LOW 2.3 CVE-2026-53862

OpenClaw < 2026.5.12 - Bootstrap Token Replay via Pending Pairing Scope Widening_CVE-2026-53862

OpenClaw before 2026.5.12 contains a bootstrap token replay vulnerability allowing callers with pending token access to reuse tokens with broader r...

OpenClaw OpenClaw CVE
MEDIUM 5.3 CVE-2026-53861

OpenClaw < 2026.5.6 - Allowlist Bypass via Combined POSIX Inline Flags on macOS_CVE-2026-53861

OpenClaw before 2026.5.6 contains an allowlist bypass vulnerability in the macOS Swift exec feature that misses combined POSIX inline-command flags...

OpenClaw OpenClaw CVE
LOW 2.3 CVE-2026-53860

OpenClaw < 2026.5.7 - Sender Policy Bypass via Mutable Conversation Identifiers in BlueBubbles_CVE-2026-53860

OpenClaw before 2026.5.7 contains a sender policy bypass vulnerability in BlueBubbles that allows participants to match allowlist entries through c...

OpenClaw OpenClaw CVE
MEDIUM 6 CVE-2026-53859

OpenClaw < 2026.5.26 - Hostname Validation Bypass via Trailing-Dot Inconsistency_CVE-2026-53859

OpenClaw before 2026.5.26 contains a hostname validation vulnerability allowing attackers to bypass blocklist comparisons using trailing-dot notati...

OpenClaw OpenClaw CVE