Security Advisories
open_in_newView CVE open_in_newView allA list of vulnerabilities (CVE / GHSA) publicly disclosed by Tencent Zhuque Lab.
bug_report
Vulnerabilities
71
deployed_code
Products
23
leaderboard
Severity Breakdown
-
open_in_newMedium CVE-2026-42439 CWE-862/CWE-918
OpenClaw: Browser tabs action select and close routes bypassed SSRF policy
deployed_code Affected: openclaw < 2026.4.10 calendar_today Published: April 17, 2026 -
open_in_newMedium CVE-2026-43576 CWE-601/CWE-918
OpenClaw: CDP /json/version WebSocket URL could pivot to untrusted second-hop targets
deployed_code Affected: openclaw < 2026.4.5 calendar_today Published: April 17, 2026 -
open_in_newHigh CVE-2026-43584 CWE-184
OpenClaw: Exec environment denylist missed high-risk interpreter startup variables
deployed_code Affected: openclaw < 2026.4.10 calendar_today Published: April 17, 2026 -
open_in_newHigh CVE-2026-43533 CWE-23
OpenClaw: QQBot media tags could read arbitrary local files through reply text
deployed_code Affected: openclaw < 2026.4.10 calendar_today Published: April 17, 2026 -
open_in_newHigh CVE-2026-42427 CWE-78/CWE-184
OpenClaw: HGRCPATH, CARGO_BUILD_RUSTC_WRAPPER, RUSTC_WRAPPER, and MAKEFLAGS missing from exec env denylist — RCE via build tool env injection (GHSA-cm8v-2vh9-cxf3 class)
deployed_code Affected: openclaw < 2026.4.8 calendar_today Published: April 09, 2026 -
open_in_newMedium CVE-2026-42422 CWE-863
OpenClaw `device.token.rotate` mints tokens for unapproved roles, bypassing device role-upgrade pairing
deployed_code Affected: openclaw < 2026.4.8 calendar_today Published: April 09, 2026 -
open_in_newMedium CVE-2026-42431 CWE-863
OpenClaw `node.invoke(browser.proxy)` bypasses `browser.request` persistent profile-mutation guard
deployed_code Affected: openclaw < 2026.4.8 calendar_today Published: April 09, 2026 -
open_in_newMedium CVE-2026-41916 CWE-613
OpenClaw: resolvedAuth closure becomes stale after config reload
deployed_code Affected: openclaw < 2026.4.8 calendar_today Published: April 09, 2026 -
open_in_newMedium CVE-2026-42421 CWE-613
OpenClaw: Existing WS sessions survive shared gateway token rotation
deployed_code Affected: openclaw < 2026.4.8 calendar_today Published: April 09, 2026 -
open_in_newMedium CVE-2026-42426 CWE-269/CWE-863
OpenClaw `node.pair.approve` placed in `operator.write` scope instead of `operator.pairing` allows unprivileged pairing approval
deployed_code Affected: openclaw < 2026.4.8 calendar_today Published: April 09, 2026
Per page
