Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 8.6 CVE-2026-53857

OpenClaw < 2026.5.3 - Mutable Display Name Binding in Zalo allowFrom Policy_CVE-2026-53857

OpenClaw before 2026.5.3 contains a policy enforcement vulnerability where Zalo contacts with mutable display metadata could match allowFrom policy...

OpenClaw OpenClaw CVE
MEDIUM 5.7 CVE-2026-53856

OpenClaw < 2026.4.24 - Insecure File Permissions in Config Recovery via OpenClaw.json_CVE-2026-53856

OpenClaw before 2026.4.24 contains an insecure file permissions vulnerability in config recovery that restores OpenClaw.json with overly broad perm...

OpenClaw OpenClaw 2026.4.23 CVE
HIGH 7.6 CVE-2026-53855

OpenClaw < 2026.4.2 - Shell Positional Parameters Bypass in Inline-Eval Checks_CVE-2026-53855

OpenClaw before 2026.4.2 contains an inline-eval bypass vulnerability allowing authenticated operators to weaken strict allowlist checks via shell ...

OpenClaw OpenClaw CVE
MEDIUM 6 CVE-2026-53854

OpenClaw < 2026.4.25 - Privilege Escalation via ownerAllowFrom Wildcard Inheritance in Internal/Webchat Commands_CVE-2026-53854

OpenClaw before 2026.4.25 contains a privilege escalation vulnerability in internal and webchat command authentication that allows senders to inher...

OpenClaw OpenClaw CVE
HIGH 7.6 CVE-2026-53853

OpenClaw < 2026.5.12 - Argument Pattern Bypass in Exec Allowlist via Linux and macOS_CVE-2026-53853

OpenClaw before 2026.5.12 contains an argument pattern validation bypass in the exec allowlist that allows attackers to execute disallowed argument...

OpenClaw OpenClaw CVE
LOW 2.3 CVE-2026-53852

OpenClaw < 2026.4.25 - Scope Bypass via Empty-Scope Device Re-pairing_CVE-2026-53852

OpenClaw before 2026.4.25 contains a scope containment bypass vulnerability in device re-pairing that allows authenticated operators to restore bro...

OpenClaw OpenClaw CVE
MEDIUM 6.3 CVE-2026-53851

OpenClaw < 2026.5.12 - Slack Reaction Event Notification Bypass_CVE-2026-53851

OpenClaw before 2026.5.12 contains a notification bypass vulnerability allowing Slack reaction events to enter the agent pipeline despite disabled ...

OpenClaw OpenClaw CVE
MEDIUM 6.8 CVE-2026-53850

OpenClaw < 2026.4.25 - Control Scope Enforcement Bypass in Focus Command_CVE-2026-53850

OpenClaw before 2026.4.25 contains a control scope enforcement bypass vulnerability in the focus command that allows authenticated callers to execu...

OpenClaw OpenClaw CVE
HIGH 8.6 CVE-2026-53849

OpenClaw < 2026.5.7 - Privilege Escalation via Mutable Discord Display Names in allowFrom_CVE-2026-53849

OpenClaw before 2026.5.7 contains a privilege escalation vulnerability where the allowFrom feature improperly validates Discord account identity us...

OpenClaw OpenClaw CVE
LOW 2.3 CVE-2026-53848

OpenClaw < 2026.5.26 - Exec Allowlist Bypass via Transparent Command Wrappers_CVE-2026-53848

OpenClaw before 2026.5.26 contains an exec allowlist bypass vulnerability allowing authenticated operators to execute wrapper-level side effects ou...

OpenClaw OpenClaw CVE