Openclaw
Multi-channel AI gateway with extensible messaging integrations
Security Advisories for Openclaw in npm
High
about 1 month ago
OpenClaw: Native command authorization could skip owner-command enforcement
npm
openclaw
High
about 1 month ago
OpenClaw: PowerShell encoded-command aliases could miss exec allowlist checks
npm
openclaw
High
about 1 month ago
OpenClaw: Trusted retry endpoint checks could match hostname prefixes
npm
openclaw
High
about 1 month ago
OpenClaw: Telegram interactive callbacks could skip commands.allowFrom
npm
openclaw
Moderate
about 1 month ago
OpenClaw: Mattermost slash token revocation could lag until monitor refresh
npm
openclaw
High
about 1 month ago
OpenClaw: Paired nodes could forge exec lifecycle events without system.run provenance
npm
openclaw
High
about 1 month ago
OpenClaw: Combined POSIX shell options could confuse exec revalidation
npm
openclaw
Moderate
about 1 month ago
OpenClaw: MCP loopback could skip owner-only tool policy for non-owner callers
npm
openclaw
Moderate
about 1 month ago
OpenClaw: Slack and Zalo webhook secrets could remain active after secrets.reload
npm
openclaw
Low
about 1 month ago
OpenClaw: Feishu dynamic-agent bindings could miss configWrites enforcement
npm
openclaw
Moderate
about 1 month ago
OpenClaw: Sandboxed session spawn could expose the real workspace path to child prompts
npm
openclaw
Moderate
about 1 month ago
OpenClaw: Embedded runner policy could be confused by provider aliases
npm
openclaw
High
about 1 month ago
OpenClaw: Fake package roots could influence memory-core artifact loading
npm
openclaw
High
about 1 month ago
OpenClaw: Workspace .env could override Homebrew executable selection for skill install flows
npm
openclaw
Moderate
about 1 month ago
OpenClaw: QQBot pre-dispatch slash commands could skip allowFrom checks
npm
openclaw
High
about 1 month ago
OpenClaw: Non-owner chat senders could issue device-pairing bootstrap codes
npm
openclaw
Moderate
about 1 month ago
OpenClaw: Browser debug/export routes could reuse already-open blocked tabs
npm
openclaw
Moderate
about 1 month ago
OpenClaw: message.action forwarding could send Gateway credentials to model-supplied loopback URLs
npm
openclaw
Critical
about 1 month ago
OpenClaw: QQBot admin commands could skip DM-only and allowFrom policy
npm
openclaw
Moderate
about 1 month ago
OpenClaw: Mattermost handlers could fall open when channel type was missing
npm
openclaw
High
about 1 month ago
OpenClaw: Trusted-proxy Control UI WebSocket accepted client-declared scopes before pairing
npm
openclaw
Moderate
about 1 month ago
OpenClaw: Skill Workshop apply flow could override pending approval
npm
openclaw
High
about 1 month ago
OpenClaw: QQBot streaming command could mutate config without explicit allowFrom
npm
openclaw
High
about 1 month ago
OpenClaw: Node pairing reconnection could confuse approval scope state
npm
openclaw
Moderate
about 1 month ago
OpenClaw's Slack plugin approvals used the exec approver gate for plugin actions
npm
openclaw
Moderate
about 1 month ago
OpenClaw: memory-wiki ingest could read local files with operator.write scope
npm
openclaw
High
about 1 month ago
OpenClaw: Scoped chat.send route inheritance could bypass admin command scope gates
npm
openclaw
High
about 1 month ago
OpenClaw's POSIX node system.run safe-bin allowlist could be widened by shell expansion
npm
openclaw
High
about 1 month ago
OpenClaw: QQBot native approval buttons did not enforce configured approver identity
npm
openclaw
High
about 1 month ago
OpenClaw: Hook-triggered CLI runs could receive owner MCP tool authority
npm
openclaw
High
about 1 month ago
OpenClaw: Control UI locality spoofing could mint a durable admin device token
npm
openclaw
High
about 1 month ago
OpenClaw: Same-host trusted-proxy deployments could accept local forged identity headers
npm
openclaw
High
about 1 month ago
OpenClaw's marketplace runtime extension metadata could point at unscanned payloads
npm
openclaw
Moderate
about 1 month ago
OpenClaw's browser act interactions could bypass private-network navigation checks
npm
openclaw
High
about 1 month ago
OpenClaw: Shell wrapper argv could change between approval and execution
npm
Openclaw
Moderate
about 1 month ago
OpenClaw: Bundle MCP loopback could miss its exec denylist on session spawn
npm
openclaw
High
about 1 month ago
OpenClaw: Exec approval display truncation could hide the command being approved
npm
openclaw
High
about 1 month ago
OpenClaw: Message read actions could skip channel allowlist checks
npm
openclaw
Moderate
about 1 month ago
OpenClaw MCP SSE redirects could forward Authorization headers
npm
openclaw
Moderate
about 2 months ago
OpenClaw: Internal/webchat command auth could inherit ownerAllowFrom wildcard state
npm
openclaw
Low
about 2 months ago
OpenClaw: Empty-scope device re-pairing could confuse caller scope containment
npm
openclaw
High
about 2 months ago
OpenClaw: Workspace-derived service PATH could influence trash command selection
npm
openclaw
High
about 2 months ago
OpenClaw: Workspace .env STATE_DIRECTORY could influence bundled runtime dependency roots
npm
openclaw
High
about 2 months ago
OpenClaw: Discord allowFrom could bind to mutable display names
npm
openclaw
Moderate
about 2 months ago
OpenClaw: Focus command could miss controlScope enforcement
npm
openclaw
High
about 2 months ago
OpenClaw: Workspace .env npm_execpath could influence bundled runtime dependency install
npm
openclaw
High
about 2 months ago
OpenClaw: Linux and macOS exec allowlists skipped configured argument patterns
npm
openclaw
Low
about 2 months ago
OpenClaw: BlueBubbles sender policy could match mutable conversation identifiers
npm
openclaw
Moderate
about 2 months ago
OpenClaw: memory-wiki shared search could miss session visibility checks
npm
openclaw
Moderate
about 2 months ago
OpenClaw: Config recovery could restore openclaw.json with broad file permissions
npm
openclaw
Low
about 2 months ago
OpenClaw: Skill-command dispatch could skip before-tool-call hooks
npm
openclaw
Moderate
about 2 months ago
OpenClaw: Active Memory write scope could mutate global config
npm
openclaw
Moderate
about 2 months ago
OpenClaw: Exported session HTML could keep unsafe markdown links
npm
openclaw
Moderate
about 2 months ago
OpenClaw: Slack reaction events could ignore reaction notification settings
npm
openclaw
Low
about 2 months ago
OpenClaw: Bootstrap token replay could widen pending pairing scopes
npm
openclaw
High
about 2 months ago
OpenClaw: Shell positional parameters could weaken strict inline-eval checks
npm
openclaw
Moderate
about 2 months ago
OpenClaw: Hostname checks could treat trailing-dot hosts inconsistently
npm
openclaw
Low
about 2 months ago
OpenClaw: Exec allowlist could miss side effects from transparent command wrappers
npm
openclaw
Moderate
about 2 months ago
OpenClaw: macOS Swift exec allowlist missed combined POSIX inline flags
npm
openclaw
Moderate
about 2 months ago
OpenClaw: Tool group policy callers could accept unvalidated group IDs
npm
openclaw
High
about 2 months ago
OpenClaw: Workspace .env CLOUDSDK_PYTHON could influence Gmail setup gcloud execution
npm
openclaw
High
about 2 months ago
OpenClaw: Shell inline-command parsing could miss an allowlist check
npm
openclaw
High
about 2 months ago
OpenClaw: Pairing-scoped device session could restore revoked node token authority
npm
openclaw
High
about 2 months ago
OpenClaw: Host environment sanitizer missed two Node.js control variables
npm
openclaw
High
about 2 months ago
OpenClaw: MCP Streamable HTTP redirects could forward configured custom headers to another origin
npm
openclaw
High
3 months ago
OpenClaw's gateway config mutation guard allowed unsafe model-driven config writes
npm
openclaw
Moderate
3 months ago
OpenClaw's Webhooks SecretRef route secret remains valid after rotation/reload
npm
openclaw
Moderate
3 months ago
OpenClaw's Gateway Control UI bootstrap config required Gateway auth
npm
openclaw
Moderate
3 months ago
OpenClaw: OpenShell FS bridge reads pin and verify the opened file before returning bytes
npm
openclaw
Moderate
3 months ago
OpenClaw: OpenShell FS bridge writes stay pinned to the sandbox mount root
npm
openclaw
Moderate
3 months ago
OpenClaw's exec allowlist analysis rejects shell expansion in unquoted heredocs
npm
openclaw
High
3 months ago
OpenClaw: MCP loopback owner context is derived from server-issued bearer tokens
npm
openclaw
Moderate
3 months ago
OpenClaw: Workspace dotenv files cannot override connector endpoint hosts
npm
openclaw
Moderate
3 months ago
OpenClaw's ACP child sessions inherit subagent security envelope constraints
npm
openclaw
Moderate
3 months ago
OpenClaw validates Zalo outbound photo URLs through the SSRF guard
npm
openclaw
Low
3 months ago
OpenClaw: Slack thread context could include messages from non-allowlisted senders
npm
openclaw
Moderate
4 months ago
OpenClaw: Webchat audio embedding could read local files without local-root containment
npm
openclaw
Moderate
4 months ago
OpenClaw: Owner-enforced commands could accept wildcard channel senders as command owners
npm
openclaw
Moderate
4 months ago
OpenClaw: Agent gateway config mutations could change protected operator settings
npm
openclaw
Moderate
4 months ago
OpenClaw: Bundled MCP/LSP tools could bypass configured tool policy
npm
openclaw
Moderate
4 months ago
OpenClaw: Workspace dotenv MiniMax host override could redirect credentialed requests
npm
openclaw
Low
4 months ago
OpenClaw: Browser CDP profile creation skipped strict-mode SSRF checks
npm
openclaw
Low
4 months ago
OpenClaw: Paired-device pairing actions were not limited to the caller device
npm
openclaw
Moderate
4 months ago
OpenClaw: MCP stdio server env could load dangerous startup variables from workspace config
npm
openclaw
Low
4 months ago
OpenClaw: Isolated cron awareness events were recorded as trusted system events
npm
openclaw
High
4 months ago
OpenClaw: Workspace dotenv could override runtime-control environment variables
npm
openclaw
Moderate
4 months ago
OpenClaw: Feishu card actions could misclassify DMs and skip dmPolicy
npm
openclaw
Low
4 months ago
OpenClaw: Assistant media route missed scope enforcement for trusted-proxy authorization
npm
openclaw
Moderate
4 months ago
OpenClaw: Hook mapping templates could bypass hook session-key opt-in
npm
openclaw
Moderate
4 months ago
OpenClaw: QMD memory_get restricts reads to canonical or indexed memory paths
npm
openclaw
Moderate
4 months ago
OpenClaw: Webchat media embedding enforces local-root containment for tool-result files
npm
openclaw
Critical
4 months ago
OpenClaw: Feishu webhook and card-action validation now fail closed
npm
openclaw
High
4 months ago
OpenClaw: Matrix room control-command authorization no longer trusts DM pairing-store entries
npm
openclaw
Critical
4 months ago
OpenClaw: Gateway HTTP endpoints re-resolve bearer auth after SecretRef rotation
npm
openclaw