Search

Find a vulnerability

Search criteria

    1356 vulnerabilities by openclaw

    CVE-2026-101884 (GCVE-0-2026-101884)

    Vulnerability from nvd – Published: 2026-09-30 19:16 – Updated: 2026-09-30 19:33
    VLAI
    Title
    OpenClaw Windows Node before 2026.7.1 Remote Code Execution via Environment Override
    Summary
    OpenClaw Windows Node before 2026.7.1 contains an incomplete environment-variable sanitizer in system.run that fails to block GIT_CONFIG_*, DOTNET_STARTUP_HOOKS, and JAVA_TOOL_OPTIONS variables. Attackers with gateway or agent access can supply these variables to allowlisted tools like git, dotnet, or java to load attacker-controlled code and achieve arbitrary code execution.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-30 19:33 UTC
    CWE
    • CWE-184 - Incomplete List of Disallowed Inputs
    Impacted products
    Vendor Product Version
    OpenClaw OpenClaw Windows Node Affected: 0 , < 2026.7.1 (custom)
    Create a notification for this product.
    Date Public
    2026-09-03 05:32
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-101884",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-30T19:33:07.973543Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-30T19:33:24.196Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "exploit"
                ],
                "url": "https://github.com/openclaw/openclaw-windows-node/security/advisories/GHSA-39cf-qcfw-g8pg"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "OpenClaw Windows Node",
              "repo": "https://github.com/openclaw/openclaw-windows-node",
              "vendor": "OpenClaw",
              "versions": [
                {
                  "lessThan": "2026.7.1",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Cameron Beeley (anagnorisis2peripeteia)"
            }
          ],
          "datePublic": "2026-09-03T05:32:25.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "OpenClaw Windows Node before 2026.7.1 contains an incomplete environment-variable sanitizer in system.run that fails to block GIT_CONFIG_*, DOTNET_STARTUP_HOOKS, and JAVA_TOOL_OPTIONS variables. Attackers with gateway or agent access can supply these variables to allowlisted tools like git, dotnet, or java to load attacker-controlled code and achieve arbitrary code execution."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "LOW",
                "attackRequirements": "PRESENT",
                "attackVector": "NETWORK",
                "baseScore": 7.7,
                "baseSeverity": "HIGH",
                "privilegesRequired": "LOW",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH"
              },
              "format": "CVSS"
            },
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-184",
                  "description": "Incomplete List of Disallowed Inputs",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-30T19:16:04.686Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "name": "GitHub Security Advisory (GHSA-39cf-qcfw-g8pg)",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://github.com/openclaw/openclaw-windows-node/security/advisories/GHSA-39cf-qcfw-g8pg"
            },
            {
              "tags": [
                "patch"
              ],
              "url": "https://github.com/openclaw/openclaw-windows-node/commit/261ba11aaad671834ad141bb85101b50cf1a38f6"
            },
            {
              "name": "OpenClaw Windows Node v2026.7.1 Release Notes",
              "tags": [
                "release-notes"
              ],
              "url": "https://github.com/openclaw/openclaw-windows-node/releases/tag/v2026.7.1"
            },
            {
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/openclaw/openclaw-windows-node/blob/v0.6.12/src/OpenClaw.Shared/ExecEnvSanitizer.cs#L15-L50"
            },
            {
              "name": "VulnCheck Advisory: OpenClaw Windows Node before 2026.7.1 Remote Code Execution via Environment Override",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/openclaw-windows-node-before-2026.7.1-remote-code-execution-via-environment-override"
            }
          ],
          "title": "OpenClaw Windows Node before 2026.7.1 Remote Code Execution via Environment Override",
          "x_generator": {
            "engine": "vulncheck-endgame"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-101884",
        "datePublished": "2026-09-30T19:16:04.686Z",
        "dateReserved": "2026-09-28T15:44:45.389Z",
        "dateUpdated": "2026-09-30T19:33:24.196Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-101883 (GCVE-0-2026-101883)

    Vulnerability from nvd – Published: 2026-09-30 19:16 – Updated: 2026-09-30 19:16
    VLAI
    Title
    OpenClaw Windows Node through 2026.9.4 SSRF via canvas.present
    Summary
    OpenClaw Windows Node through 2026.9.4 contains a server-side request forgery vulnerability in the canvas.present capability that bypasses URL risk evaluation enforced by canvas.navigate. Attackers with gateway or agent access can issue canvas.present to make the node's WebView send requests to localhost, private networks, or tailnet services from the user's machine.
    CWE
    • CWE-918 - Server-Side Request Forgery (SSRF)
    Impacted products
    Vendor Product Version
    OpenClaw OpenClaw Windows Node Affected: 0 , ≤ 2026.9.4 (custom)
    Create a notification for this product.
    Date Public
    2026-09-03 05:32
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "OpenClaw Windows Node",
              "repo": "https://github.com/openclaw/openclaw-windows-node",
              "vendor": "OpenClaw",
              "versions": [
                {
                  "lessThanOrEqual": "2026.9.4",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Cameron Beeley (anagnorisis2peripeteia)"
            }
          ],
          "datePublic": "2026-09-03T05:32:23.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "OpenClaw Windows Node through 2026.9.4 contains a server-side request forgery vulnerability in the canvas.present capability that bypasses URL risk evaluation enforced by canvas.navigate. Attackers with gateway or agent access can issue canvas.present to make the node\u0027s WebView send requests to localhost, private networks, or tailnet services from the user\u0027s machine."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "privilegesRequired": "LOW",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "LOW",
                "vulnIntegrityImpact": "LOW"
              },
              "format": "CVSS"
            },
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 5.4,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "LOW",
                "integrityImpact": "LOW",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-918",
                  "description": "Server-Side Request Forgery (SSRF)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-30T19:16:03.985Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "name": "GitHub Security Advisory (GHSA-7vch-pmw9-3g4q)",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://github.com/openclaw/openclaw-windows-node/security/advisories/GHSA-7vch-pmw9-3g4q"
            },
            {
              "tags": [
                "patch"
              ],
              "url": "https://github.com/openclaw/openclaw-windows-node/commit/16528aadaa45d7bc6718b07ccf8b01f3eb033ad1"
            },
            {
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/openclaw/openclaw-windows-node/blob/v2026.9.4/src/OpenClaw.Tray.WinUI/Services/NodeService.cs#L1244-L1270"
            },
            {
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/openclaw/openclaw-windows-node/blob/v0.6.12/src/OpenClaw.Tray.WinUI/Windows/CanvasWindow.xaml.cs#L77-L109"
            },
            {
              "name": "VulnCheck Advisory: OpenClaw Windows Node through 2026.9.4 SSRF via canvas.present",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/openclaw-windows-node-through-2026.9.4-ssrf-via-canvas-present"
            }
          ],
          "title": "OpenClaw Windows Node through 2026.9.4 SSRF via canvas.present",
          "x_generator": {
            "engine": "vulncheck-endgame"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-101883",
        "datePublished": "2026-09-30T19:16:03.985Z",
        "dateReserved": "2026-09-28T15:44:45.389Z",
        "dateUpdated": "2026-09-30T19:16:03.985Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-101882 (GCVE-0-2026-101882)

    Vulnerability from nvd – Published: 2026-09-30 19:16 – Updated: 2026-10-01 15:29
    VLAI
    Title
    OpenClaw Windows Node before 2026.7.1 Remote Code Execution via system.execApprovals.set
    Summary
    OpenClaw Windows Node before 2026.7.1 contains an incomplete validation vulnerability in system.execApprovals.set that accepts wildcard-executable rules and abusable system binaries like mshta, rundll32, and certutil. Remote callers can add broad allow rules to execute arbitrary commands on the Windows host through system.run without operator checks or user prompts.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-10-01 15:28 UTC
    CWE
    • CWE-184 - Incomplete List of Disallowed Inputs
    Impacted products
    Vendor Product Version
    OpenClaw OpenClaw Windows Node Affected: 0 , < 2026.7.1 (custom)
    Create a notification for this product.
    Date Public
    2026-09-03 05:32
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-101882",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-10-01T15:28:47.813494Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-10-01T15:29:01.764Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "exploit"
                ],
                "url": "https://github.com/openclaw/openclaw-windows-node/security/advisories/GHSA-f32j-8759-w2fp"
              },
              {
                "tags": [
                  "exploit"
                ],
                "url": "https://github.com/openclaw/openclaw-windows-node/security/advisories/GHSA-g95v-c9r6-2hmq"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "OpenClaw Windows Node",
              "repo": "https://github.com/openclaw/openclaw-windows-node",
              "vendor": "OpenClaw",
              "versions": [
                {
                  "lessThan": "2026.7.1",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Cameron Beeley (anagnorisis2peripeteia)"
            }
          ],
          "datePublic": "2026-09-03T05:32:21.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "OpenClaw Windows Node before 2026.7.1 contains an incomplete validation vulnerability in system.execApprovals.set that accepts wildcard-executable rules and abusable system binaries like mshta, rundll32, and certutil. Remote callers can add broad allow rules to execute arbitrary commands on the Windows host through system.run without operator checks or user prompts."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 8.7,
                "baseSeverity": "HIGH",
                "privilegesRequired": "LOW",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH"
              },
              "format": "CVSS"
            },
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 8.8,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-184",
                  "description": "Incomplete List of Disallowed Inputs",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-30T19:16:03.309Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "name": "GitHub Security Advisory (GHSA-f32j-8759-w2fp)",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://github.com/openclaw/openclaw-windows-node/security/advisories/GHSA-f32j-8759-w2fp"
            },
            {
              "name": "GitHub Security Advisory (GHSA-g95v-c9r6-2hmq)",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://github.com/openclaw/openclaw-windows-node/security/advisories/GHSA-g95v-c9r6-2hmq"
            },
            {
              "tags": [
                "patch"
              ],
              "url": "https://github.com/openclaw/openclaw-windows-node/commit/8f07ad92beb28376bc228c0b07093173a043a656"
            },
            {
              "tags": [
                "patch"
              ],
              "url": "https://github.com/openclaw/openclaw-windows-node/commit/988df5badc84ab5efd5b4e291766a1fa5e7e268a"
            },
            {
              "name": "OpenClaw Windows Node v2026.7.1 Release Notes",
              "tags": [
                "release-notes"
              ],
              "url": "https://github.com/openclaw/openclaw-windows-node/releases/tag/v2026.7.1"
            },
            {
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/openclaw/openclaw-windows-node/blob/v0.6.12/src/OpenClaw.Shared/Capabilities/SystemCapability.cs#L791-L853"
            },
            {
              "name": "VulnCheck Advisory: OpenClaw Windows Node before 2026.7.1 Remote Code Execution via system.execApprovals.set",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/openclaw-windows-node-before-2026.7.1-remote-code-execution-via-system-execapprovals-set"
            }
          ],
          "title": "OpenClaw Windows Node before 2026.7.1 Remote Code Execution via system.execApprovals.set",
          "x_generator": {
            "engine": "vulncheck-endgame"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-101882",
        "datePublished": "2026-09-30T19:16:03.309Z",
        "dateReserved": "2026-09-28T15:44:45.389Z",
        "dateUpdated": "2026-10-01T15:29:01.764Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-101881 (GCVE-0-2026-101881)

    Vulnerability from nvd – Published: 2026-09-30 19:16 – Updated: 2026-09-30 19:53
    VLAI
    Title
    OpenClaw Windows Node before 2026.7.1 Denial of Service
    Summary
    OpenClaw Windows Node before 2026.7.1 contains an allocation of resources without limits vulnerability in the gateway WebSocket transport that allows connected gateways to exhaust node memory. Attackers can send an unending sequence of WebSocket continuation frames without EndOfMessage to cause unbounded memory growth until the node process crashes.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-30 19:53 UTC
    CWE
    • CWE-770 - Allocation of Resources Without Limits or Throttling
    Impacted products
    Vendor Product Version
    OpenClaw OpenClaw Windows Node Affected: 0 , < 2026.7.1 (custom)
    Create a notification for this product.
    Date Public
    2026-09-03 05:32
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-101881",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-30T19:53:03.562709Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-30T19:53:47.897Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "exploit"
                ],
                "url": "https://github.com/openclaw/openclaw-windows-node/security/advisories/GHSA-xxr2-xm56-9cw5"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "OpenClaw Windows Node",
              "repo": "https://github.com/openclaw/openclaw-windows-node",
              "vendor": "OpenClaw",
              "versions": [
                {
                  "lessThan": "2026.7.1",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Cameron Beeley (anagnorisis2peripeteia)"
            }
          ],
          "datePublic": "2026-09-03T05:32:19.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "OpenClaw Windows Node before 2026.7.1 contains an allocation of resources without limits vulnerability in the gateway WebSocket transport that allows connected gateways to exhaust node memory. Attackers can send an unending sequence of WebSocket continuation frames without EndOfMessage to cause unbounded memory growth until the node process crashes."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 7.1,
                "baseSeverity": "HIGH",
                "privilegesRequired": "LOW",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "NONE",
                "vulnIntegrityImpact": "NONE"
              },
              "format": "CVSS"
            },
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 6.5,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-770",
                  "description": "Allocation of Resources Without Limits or Throttling",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-30T19:16:02.477Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "name": "GitHub Security Advisory (GHSA-xxr2-xm56-9cw5)",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://github.com/openclaw/openclaw-windows-node/security/advisories/GHSA-xxr2-xm56-9cw5"
            },
            {
              "tags": [
                "patch"
              ],
              "url": "https://github.com/openclaw/openclaw-windows-node/commit/1810e357aa0d0639099b347f31c746ba7d31512a"
            },
            {
              "name": "OpenClaw Windows Node v2026.7.1 Release Notes",
              "tags": [
                "release-notes"
              ],
              "url": "https://github.com/openclaw/openclaw-windows-node/releases/tag/v2026.7.1"
            },
            {
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/openclaw/openclaw-windows-node/blob/v0.6.12/src/OpenClaw.Shared/WebSocketClientBase.cs#L217-L263"
            },
            {
              "name": "VulnCheck Advisory: OpenClaw Windows Node before 2026.7.1 Denial of Service",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/openclaw-windows-node-before-2026.7.1-denial-of-service"
            }
          ],
          "title": "OpenClaw Windows Node before 2026.7.1 Denial of Service",
          "x_generator": {
            "engine": "vulncheck-endgame"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-101881",
        "datePublished": "2026-09-30T19:16:02.477Z",
        "dateReserved": "2026-09-28T15:44:45.389Z",
        "dateUpdated": "2026-09-30T19:53:47.897Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-101880 (GCVE-0-2026-101880)

    Vulnerability from nvd – Published: 2026-09-30 19:16 – Updated: 2026-09-30 19:34
    VLAI
    Title
    OpenClaw Windows Node before 2026.7.1 Authorization Bypass
    Summary
    OpenClaw Windows Node before 2026.7.1 contains an incorrect authorization vulnerability in the system.run exec-approval policy where ExecShellWrapperParser fails to split commands on pipe operators or extract command substitutions. Connected gateways or agents can bypass approval rules by placing denied commands behind allowed prefixes using pipe operators or command substitution syntax, achieving arbitrary command execution on Windows hosts.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-30 19:33 UTC
    CWE
    • CWE-863 - Incorrect Authorization
    Impacted products
    Vendor Product Version
    OpenClaw OpenClaw Windows Node Affected: 0 , < 2026.7.1 (custom)
    Create a notification for this product.
    Date Public
    2026-09-03 05:32
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-101880",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-30T19:33:47.048317Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-30T19:34:05.680Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "exploit"
                ],
                "url": "https://github.com/openclaw/openclaw-windows-node/security/advisories/GHSA-r3x2-vf2f-vvj8"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "OpenClaw Windows Node",
              "repo": "https://github.com/openclaw/openclaw-windows-node",
              "vendor": "OpenClaw",
              "versions": [
                {
                  "lessThan": "2026.7.1",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Cameron Beeley (anagnorisis2peripeteia)"
            }
          ],
          "datePublic": "2026-09-03T05:32:07.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "OpenClaw Windows Node before 2026.7.1 contains an incorrect authorization vulnerability in the system.run exec-approval policy where ExecShellWrapperParser fails to split commands on pipe operators or extract command substitutions. Connected gateways or agents can bypass approval rules by placing denied commands behind allowed prefixes using pipe operators or command substitution syntax, achieving arbitrary command execution on Windows hosts."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 8.7,
                "baseSeverity": "HIGH",
                "privilegesRequired": "LOW",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH"
              },
              "format": "CVSS"
            },
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 8.8,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-863",
                  "description": "Incorrect Authorization",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-30T19:16:01.717Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "name": "GitHub Security Advisory (GHSA-r3x2-vf2f-vvj8)",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://github.com/openclaw/openclaw-windows-node/security/advisories/GHSA-r3x2-vf2f-vvj8"
            },
            {
              "name": "GitHub Security Advisory (GHSA-vg38-vjq2-vgvh)",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://github.com/openclaw/openclaw-windows-node/security/advisories/GHSA-vg38-vjq2-vgvh"
            },
            {
              "tags": [
                "patch"
              ],
              "url": "https://github.com/openclaw/openclaw-windows-node/commit/2077aa3e7159101bddcee2f4efcb9d604a81619e"
            },
            {
              "name": "OpenClaw Windows Node v2026.7.1 Release Notes",
              "tags": [
                "release-notes"
              ],
              "url": "https://github.com/openclaw/openclaw-windows-node/releases/tag/v2026.7.1"
            },
            {
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/openclaw/openclaw-windows-node/blob/v0.6.12/src/OpenClaw.Shared/ExecShellWrapperParser.cs#L253"
            },
            {
              "name": "VulnCheck Advisory: OpenClaw Windows Node before 2026.7.1 Authorization Bypass",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/openclaw-windows-node-before-2026.7.1-authorization-bypass"
            }
          ],
          "title": "OpenClaw Windows Node before 2026.7.1 Authorization Bypass",
          "x_generator": {
            "engine": "vulncheck-endgame"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-101880",
        "datePublished": "2026-09-30T19:16:01.717Z",
        "dateReserved": "2026-09-28T15:44:45.389Z",
        "dateUpdated": "2026-09-30T19:34:05.680Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-101879 (GCVE-0-2026-101879)

    Vulnerability from nvd – Published: 2026-09-30 19:16 – Updated: 2026-09-30 19:16
    VLAI
    Title
    OpenClaw Windows Node before 2026.7.1-3 Missing Authorization
    Summary
    OpenClaw Windows Node before 2026.7.1-3 contains a missing authorization vulnerability in NodeService capture handlers that allows connected gateways or agents to perform screen snapshots, camera snaps, and location captures without consent prompts. Attackers can invoke screen.snapshot, camera.snap, and location.get over the node WebSocket to silently capture screenshots, photograph users through webcams, and obtain device geolocation without user interaction.
    CWE
    Impacted products
    Vendor Product Version
    OpenClaw OpenClaw Windows Node Affected: 0 , < 2026.7.1-3 (custom)
    Create a notification for this product.
    Date Public
    2026-09-03 05:31
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "OpenClaw Windows Node",
              "repo": "https://github.com/openclaw/openclaw-windows-node",
              "vendor": "OpenClaw",
              "versions": [
                {
                  "lessThan": "2026.7.1-3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Cameron Beeley (anagnorisis2peripeteia)"
            }
          ],
          "datePublic": "2026-09-03T05:31:51.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "OpenClaw Windows Node before 2026.7.1-3 contains a missing authorization vulnerability in NodeService capture handlers that allows connected gateways or agents to perform screen snapshots, camera snaps, and location captures without consent prompts. Attackers can invoke screen.snapshot, camera.snap, and location.get over the node WebSocket to silently capture screenshots, photograph users through webcams, and obtain device geolocation without user interaction."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 7.1,
                "baseSeverity": "HIGH",
                "privilegesRequired": "LOW",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "NONE"
              },
              "format": "CVSS"
            },
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 6.5,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "NONE",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-862",
                  "description": "Missing Authorization",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-30T19:16:01.014Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "name": "GitHub Security Advisory (GHSA-fxch-cgcp-4v5h)",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://github.com/openclaw/openclaw-windows-node/security/advisories/GHSA-fxch-cgcp-4v5h"
            },
            {
              "tags": [
                "patch"
              ],
              "url": "https://github.com/openclaw/openclaw-windows-node/commit/31a8c6557df740232898079b21f0eb677a4119cf"
            },
            {
              "tags": [
                "patch"
              ],
              "url": "https://github.com/openclaw/openclaw-windows-node/commit/16cb6897941fa7832ce2811e9d550caed9a49b4b"
            },
            {
              "name": "OpenClaw Windows Node v2026.7.1-3 Release Notes",
              "tags": [
                "release-notes"
              ],
              "url": "https://github.com/openclaw/openclaw-windows-node/releases/tag/v2026.7.1-3"
            },
            {
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/openclaw/openclaw-windows-node/blob/v2026.7.1-2/src/OpenClaw.Tray.WinUI/Services/NodeService.cs#L1891-L1913"
            },
            {
              "name": "VulnCheck Advisory: OpenClaw Windows Node before 2026.7.1-3 Missing Authorization",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/openclaw-windows-node-before-2026.7.1-3-missing-authorization"
            }
          ],
          "title": "OpenClaw Windows Node before 2026.7.1-3 Missing Authorization",
          "x_generator": {
            "engine": "vulncheck-endgame"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-101879",
        "datePublished": "2026-09-30T19:16:01.014Z",
        "dateReserved": "2026-09-28T15:44:45.389Z",
        "dateUpdated": "2026-09-30T19:16:01.014Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-102807 (GCVE-0-2026-102807)

    Vulnerability from nvd – Published: 2026-09-29 17:22 – Updated: 2026-09-29 17:58
    VLAI
    Title
    OpenClaw before 2026.9.4 Authorization Bypass via MCP App Standalone Ticket
    Summary
    OpenClaw before 2026.9.4 contains an incorrect authorization vulnerability in the mcp.app.view method that allows read-scoped operators to execute MCP App tools requiring operator.write scope. Attackers with operator.read tokens can obtain a standalone ticket from mcp.app.view and redeem it at the MCP app view endpoint to invoke state-changing tools without proper authorization checks.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-29 17:58 UTC
    CWE
    • CWE-863 - Incorrect Authorization
    Impacted products
    Vendor Product Version
    OpenClaw OpenClaw Affected: 0 , < 2026.9.4 (semver)
    Unaffected: 2026.9.4 (semver)
        cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-09-09 00:00
    Credits
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-102807",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-29T17:58:34.738470Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-29T17:58:40.914Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageURL": "pkg:npm/openclaw",
              "product": "OpenClaw",
              "vendor": "OpenClaw",
              "versions": [
                {
                  "lessThan": "2026.9.4",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "status": "unaffected",
                  "version": "2026.9.4",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "2026.9.4",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Wentao He"
            }
          ],
          "datePublic": "2026-09-09T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "OpenClaw before 2026.9.4 contains an incorrect authorization vulnerability in the mcp.app.view method that allows read-scoped operators to execute MCP App tools requiring operator.write scope. Attackers with operator.read tokens can obtain a standalone ticket from mcp.app.view and redeem it at the MCP app view endpoint to invoke state-changing tools without proper authorization checks."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "LOW",
                "attackRequirements": "PRESENT",
                "attackVector": "NETWORK",
                "baseScore": 6,
                "baseSeverity": "MEDIUM",
                "privilegesRequired": "LOW",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "NONE",
                "vulnIntegrityImpact": "HIGH"
              },
              "format": "CVSS"
            },
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-863",
                  "description": "Incorrect Authorization",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-29T17:22:40.440Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "name": "Pull Request #142661",
              "tags": [
                "issue-tracking",
                "patch"
              ],
              "url": "https://github.com/openclaw/openclaw/pull/142661"
            },
            {
              "name": "Patch Commit",
              "tags": [
                "patch"
              ],
              "url": "https://github.com/openclaw/openclaw/commit/3bd8ec2b39b5f9e80aef0973f7d17eadc745b8f8"
            },
            {
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/openclaw/openclaw/blob/1391f7cd2d40ab5bbcf2f5f831d3a64f520e72d7/src/gateway/mcp-app-standalone.ts#L209-L215"
            },
            {
              "tags": [
                "release-notes"
              ],
              "url": "https://docs.openclaw.ai/releases/2026.9.4"
            },
            {
              "tags": [
                "product"
              ],
              "url": "https://github.com/openclaw/openclaw"
            },
            {
              "name": "VulnCheck Advisory: OpenClaw before 2026.9.4 Authorization Bypass via MCP App Standalone Ticket",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/openclaw-before-2026.9.4-authorization-bypass-via-mcp-app-standalone-ticket"
            }
          ],
          "title": "OpenClaw before 2026.9.4 Authorization Bypass via MCP App Standalone Ticket",
          "x_generator": {
            "engine": "vulncheck-endgame"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-102807",
        "datePublished": "2026-09-29T17:22:40.440Z",
        "dateReserved": "2026-09-29T17:11:35.367Z",
        "dateUpdated": "2026-09-29T17:58:40.914Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-102806 (GCVE-0-2026-102806)

    Vulnerability from nvd – Published: 2026-09-29 17:22 – Updated: 2026-09-29 19:55
    VLAI
    Title
    OpenClaw before 2026.9.5 Sandbox Isolation Bypass via Media Pipelines
    Summary
    OpenClaw before 2026.9.5 contains an incorrect authorization vulnerability in the Gateway's local media root allowlist that breaks filesystem isolation between sandboxed sessions. Sandboxed sessions or untrusted content can cause the Gateway to read files from sibling session sandboxes or shared workspace directories through media pipeline functions that fail to restrict reads to the active session.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-29 19:55 UTC
    CWE
    • CWE-863 - Incorrect Authorization
    Impacted products
    Vendor Product Version
    OpenClaw OpenClaw Affected: 0 , < 2026.9.5 (semver)
    Unaffected: 2026.9.5 (semver)
        cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-09-17 00:00
    Credits
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-102806",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-29T19:55:26.822879Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-29T19:55:47.830Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageURL": "pkg:npm/openclaw",
              "product": "OpenClaw",
              "vendor": "OpenClaw",
              "versions": [
                {
                  "lessThan": "2026.9.5",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "status": "unaffected",
                  "version": "2026.9.5",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "2026.9.5",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Wentao He"
            }
          ],
          "datePublic": "2026-09-17T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "OpenClaw before 2026.9.5 contains an incorrect authorization vulnerability in the Gateway\u0027s local media root allowlist that breaks filesystem isolation between sandboxed sessions. Sandboxed sessions or untrusted content can cause the Gateway to read files from sibling session sandboxes or shared workspace directories through media pipeline functions that fail to restrict reads to the active session."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "LOW",
                "attackRequirements": "PRESENT",
                "attackVector": "NETWORK",
                "baseScore": 6,
                "baseSeverity": "MEDIUM",
                "privilegesRequired": "LOW",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "NONE"
              },
              "format": "CVSS"
            },
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 6.3,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "NONE",
                "privilegesRequired": "LOW",
                "scope": "CHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-863",
                  "description": "Incorrect Authorization",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-29T17:22:39.784Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "name": "Pull Request #144347",
              "tags": [
                "issue-tracking",
                "patch"
              ],
              "url": "https://github.com/openclaw/openclaw/pull/144347"
            },
            {
              "name": "Patch Commit",
              "tags": [
                "patch"
              ],
              "url": "https://github.com/openclaw/openclaw/commit/fca04893b5b337d2eb70a6ba41f03fc8e33eff83"
            },
            {
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/openclaw/openclaw/blob/3a9d69db306cd7f081e06254cb89c4bcc14a7107/src/media/local-roots.ts#L33-L60"
            },
            {
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/openclaw/openclaw/blob/3a9d69db306cd7f081e06254cb89c4bcc14a7107/src/media-understanding/runner.attachments.ts#L40-L50"
            },
            {
              "tags": [
                "release-notes"
              ],
              "url": "https://docs.openclaw.ai/releases/2026.9.5"
            },
            {
              "tags": [
                "product"
              ],
              "url": "https://github.com/openclaw/openclaw"
            },
            {
              "name": "VulnCheck Advisory: OpenClaw before 2026.9.5 Sandbox Isolation Bypass via Media Pipelines",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/openclaw-before-2026.9.5-sandbox-isolation-bypass-via-media-pipelines"
            }
          ],
          "title": "OpenClaw before 2026.9.5 Sandbox Isolation Bypass via Media Pipelines",
          "x_generator": {
            "engine": "vulncheck-endgame"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-102806",
        "datePublished": "2026-09-29T17:22:39.784Z",
        "dateReserved": "2026-09-29T17:11:26.586Z",
        "dateUpdated": "2026-09-29T19:55:47.830Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-100604 (GCVE-0-2026-100604)

    Vulnerability from nvd – Published: 2026-09-26 13:22 – Updated: 2026-09-26 13:22
    VLAI
    Title
    ClawHub Authentication Bypass via Former Publisher Skill Control
    Summary
    ClawHub (openclaw/clawhub) contains an incorrect authorization vulnerability in the ClawHub application/backend: an organization-owned skill retains the ownerUserId of its original publisher, and transfer and lifecycle authorization checks trust that historical user before requiring current organization privileges. An authenticated user who originally published an organization skill can therefore transfer, delete, or restore that skill — taking control of its trusted name and history — even after their organization privileges have been revoked or downgraded. The issue was confirmed at revision cbfee7343ddc867316dd9b3de6fa8856730f9f41; the complete historical affected range was not established. It is fixed by PR #3680, included in revision 8c2de6c506bb4efabe3f0c2ffb8370b9e23d4650, which was deployed to clawhub.ai on 2026-09-11; self-hosted deployments should update to that revision or a later descendant. The npm CLI and OpenClaw runtime are separate products and are not affected.
    CWE
    • CWE-863 - Incorrect Authorization
    Impacted products
    Vendor Product Version
    openclaw clawhub Affected: 0 , < 8c2de6c506bb4efabe3f0c2ffb8370b9e23d4650 (git)
    Unaffected: 8c2de6c506bb4efabe3f0c2ffb8370b9e23d4650 (git)
    Create a notification for this product.
    Date Public
    2026-09-11 00:00
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "clawhub",
              "vendor": "openclaw",
              "versions": [
                {
                  "lessThan": "8c2de6c506bb4efabe3f0c2ffb8370b9e23d4650",
                  "status": "affected",
                  "version": "0",
                  "versionType": "git"
                },
                {
                  "status": "unaffected",
                  "version": "8c2de6c506bb4efabe3f0c2ffb8370b9e23d4650",
                  "versionType": "git"
                }
              ]
            }
          ],
          "datePublic": "2026-09-11T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "ClawHub (openclaw/clawhub) contains an incorrect authorization vulnerability in the ClawHub application/backend: an organization-owned skill retains the ownerUserId of its original publisher, and transfer and lifecycle authorization checks trust that historical user before requiring current organization privileges. An authenticated user who originally published an organization skill can therefore transfer, delete, or restore that skill \u2014 taking control of its trusted name and history \u2014 even after their organization privileges have been revoked or downgraded. The issue was confirmed at revision cbfee7343ddc867316dd9b3de6fa8856730f9f41; the complete historical affected range was not established. It is fixed by PR #3680, included in revision 8c2de6c506bb4efabe3f0c2ffb8370b9e23d4650, which was deployed to clawhub.ai on 2026-09-11; self-hosted deployments should update to that revision or a later descendant. The npm CLI and OpenClaw runtime are separate products and are not affected."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "LOW",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "LOW",
                "vulnConfidentialityImpact": "NONE",
                "vulnIntegrityImpact": "LOW",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS"
            },
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "LOW",
                "baseScore": 5.4,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "LOW",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-863",
                  "description": "Incorrect Authorization",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-26T13:22:48.436Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "name": "GitHub Security Advisory (GHSA-9558-q4f9-324f)",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://github.com/openclaw/clawhub/security/advisories/GHSA-9558-q4f9-324f"
            },
            {
              "name": "Patch Commit",
              "tags": [
                "patch"
              ],
              "url": "https://github.com/openclaw/clawhub/commit/8c2de6c506bb4efabe3f0c2ffb8370b9e23d4650"
            },
            {
              "name": "VulnCheck Advisory: ClawHub Authentication Bypass via Former Publisher Skill Control",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/clawhub-authentication-bypass-via-former-publisher-skill-control"
            }
          ],
          "title": "ClawHub Authentication Bypass via Former Publisher Skill Control",
          "x_generator": {
            "engine": "vulncheck-endgame"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-100604",
        "datePublished": "2026-09-26T13:22:48.436Z",
        "dateReserved": "2026-09-26T01:04:47.562Z",
        "dateUpdated": "2026-09-26T13:22:48.436Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-100603 (GCVE-0-2026-100603)

    Vulnerability from nvd – Published: 2026-09-26 13:22 – Updated: 2026-09-28 17:05
    VLAI
    Title
    ClawHub before 8c2de6c506 Skill Hiding via Coordinated Reports
    Summary
    ClawHub (openclaw/clawhub) application/backend contains a flaw in the skill report moderation flow: four distinct ordinary authenticated accounts can report a visible skill and trigger automatic hiding (moderationStatus: hidden) of that skill from the catalog without any moderator decision. Because the reporter quota counts only reports filed against visible targets, the same accounts can repeat the process against additional skills; official skills are not exempt. The issue was confirmed at revision cbfee7343ddc867316dd9b3de6fa8856730f9f41; the complete historical affected range was not established. The fix (PR #3681) is included in revision 8c2de6c506bb4efabe3f0c2ffb8370b9e23d4650; self-hosted deployments should update to that revision or a later descendant. The npm CLI and OpenClaw runtime are separate products and are not affected.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-28 17:05 UTC
    CWE
    • CWE-799 - Improper Control of Interaction Frequency
    Impacted products
    Vendor Product Version
    openclaw clawhub Affected: 0 , < 8c2de6c506bb4efabe3f0c2ffb8370b9e23d4650 (git)
    Unaffected: 8c2de6c506bb4efabe3f0c2ffb8370b9e23d4650 (git)
    Create a notification for this product.
    Date Public
    2026-09-11 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-100603",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-28T17:05:07.198454Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-28T17:05:43.542Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "clawhub",
              "vendor": "openclaw",
              "versions": [
                {
                  "lessThan": "8c2de6c506bb4efabe3f0c2ffb8370b9e23d4650",
                  "status": "affected",
                  "version": "0",
                  "versionType": "git"
                },
                {
                  "status": "unaffected",
                  "version": "8c2de6c506bb4efabe3f0c2ffb8370b9e23d4650",
                  "versionType": "git"
                }
              ]
            }
          ],
          "datePublic": "2026-09-11T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "ClawHub (openclaw/clawhub) application/backend contains a flaw in the skill report moderation flow: four distinct ordinary authenticated accounts can report a visible skill and trigger automatic hiding (moderationStatus: hidden) of that skill from the catalog without any moderator decision. Because the reporter quota counts only reports filed against visible targets, the same accounts can repeat the process against additional skills; official skills are not exempt. The issue was confirmed at revision cbfee7343ddc867316dd9b3de6fa8856730f9f41; the complete historical affected range was not established. The fix (PR #3681) is included in revision 8c2de6c506bb4efabe3f0c2ffb8370b9e23d4650; self-hosted deployments should update to that revision or a later descendant. The npm CLI and OpenClaw runtime are separate products and are not affected."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 8.7,
                "baseSeverity": "HIGH",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "LOW",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS"
            },
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "LOW",
                "baseScore": 5.4,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "LOW",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-799",
                  "description": "Improper Control of Interaction Frequency",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-26T13:22:47.730Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "name": "GitHub Security Advisory (GHSA-5jj4-m8c9-gwcq)",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://github.com/openclaw/clawhub/security/advisories/GHSA-5jj4-m8c9-gwcq"
            },
            {
              "name": "Patch Commit",
              "tags": [
                "patch"
              ],
              "url": "https://github.com/openclaw/clawhub/commit/8c2de6c506bb4efabe3f0c2ffb8370b9e23d4650"
            },
            {
              "name": "VulnCheck Advisory: ClawHub before 8c2de6c506 Skill Hiding via Coordinated Reports",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/clawhub-before-8c2de6c506-skill-hiding-via-coordinated-reports"
            }
          ],
          "title": "ClawHub before 8c2de6c506 Skill Hiding via Coordinated Reports",
          "x_generator": {
            "engine": "vulncheck-endgame"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-100603",
        "datePublished": "2026-09-26T13:22:47.730Z",
        "dateReserved": "2026-09-26T01:04:47.561Z",
        "dateUpdated": "2026-09-28T17:05:43.542Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-100602 (GCVE-0-2026-100602)

    Vulnerability from nvd – Published: 2026-09-26 13:22 – Updated: 2026-09-28 19:13
    VLAI
    Title
    ClawHub Changelog Preview Information Disclosure via Authorization Bypass
    Summary
    ClawHub (openclaw/clawhub application/backend) contains a missing authorization check in the changelog preview feature. A signed-in caller can invoke the public skills:generateChangelogPreview action for a skill they are not authorized to access; the previous version is read without the file-read authorization enforced on normal content access, and up to 8,000 characters of quarantined content may be submitted to the AI provider and reflected in the preview returned to the caller, disclosing restricted skill content. The issue was confirmed at revision cbfee7343ddc867316dd9b3de6fa8856730f9f41; the complete historical affected range was not established. It is fixed by PR #3682, included in revision 8c2de6c506bb4efabe3f0c2ffb8370b9e23d4650, which was deployed to clawhub.ai on 2026-09-11; self-hosted deployments should update to that revision or a later descendant. The npm CLI and OpenClaw runtime are separate products and are not affected.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-28 19:13 UTC
    CWE
    Impacted products
    Vendor Product Version
    openclaw clawhub Affected: 0 , < 8c2de6c506bb4efabe3f0c2ffb8370b9e23d4650 (git)
    Unaffected: 8c2de6c506bb4efabe3f0c2ffb8370b9e23d4650 (git)
    Create a notification for this product.
    Date Public
    2026-09-11 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-100602",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-28T19:13:10.079746Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-28T19:13:23.012Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "clawhub",
              "vendor": "openclaw",
              "versions": [
                {
                  "lessThan": "8c2de6c506bb4efabe3f0c2ffb8370b9e23d4650",
                  "status": "affected",
                  "version": "0",
                  "versionType": "git"
                },
                {
                  "status": "unaffected",
                  "version": "8c2de6c506bb4efabe3f0c2ffb8370b9e23d4650",
                  "versionType": "git"
                }
              ]
            }
          ],
          "datePublic": "2026-09-11T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "ClawHub (openclaw/clawhub application/backend) contains a missing authorization check in the changelog preview feature. A signed-in caller can invoke the public skills:generateChangelogPreview action for a skill they are not authorized to access; the previous version is read without the file-read authorization enforced on normal content access, and up to 8,000 characters of quarantined content may be submitted to the AI provider and reflected in the preview returned to the caller, disclosing restricted skill content. The issue was confirmed at revision cbfee7343ddc867316dd9b3de6fa8856730f9f41; the complete historical affected range was not established. It is fixed by PR #3682, included in revision 8c2de6c506bb4efabe3f0c2ffb8370b9e23d4650, which was deployed to clawhub.ai on 2026-09-11; self-hosted deployments should update to that revision or a later descendant. The npm CLI and OpenClaw runtime are separate products and are not affected."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 7.1,
                "baseSeverity": "HIGH",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "LOW",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "NONE",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS"
            },
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 6.5,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "NONE",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-862",
                  "description": "Missing Authorization",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-26T13:22:47.020Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "name": "GitHub Security Advisory (GHSA-g3jp-jj55-jrcr)",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://github.com/openclaw/clawhub/security/advisories/GHSA-g3jp-jj55-jrcr"
            },
            {
              "name": "Patch Commit",
              "tags": [
                "patch"
              ],
              "url": "https://github.com/openclaw/clawhub/commit/8c2de6c506bb4efabe3f0c2ffb8370b9e23d4650"
            },
            {
              "name": "VulnCheck Advisory: ClawHub Changelog Preview Information Disclosure via Authorization Bypass",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/clawhub-changelog-preview-information-disclosure-via-authorization-bypass"
            }
          ],
          "title": "ClawHub Changelog Preview Information Disclosure via Authorization Bypass",
          "x_generator": {
            "engine": "vulncheck-endgame"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-100602",
        "datePublished": "2026-09-26T13:22:47.020Z",
        "dateReserved": "2026-09-26T01:04:47.561Z",
        "dateUpdated": "2026-09-28T19:13:23.012Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-100601 (GCVE-0-2026-100601)

    Vulnerability from nvd – Published: 2026-09-26 13:22 – Updated: 2026-09-30 12:47
    VLAI
    Title
    ClawHub SSRF via Unchecked DNS Resolution in Profile Image
    Summary
    ClawHub (openclaw/clawhub) application/backend contains a server-side request forgery vulnerability in the public profile preview's image fetching. The preview accepts a user-supplied image URL and checks the textual hostname against private-address patterns, but does not validate or pin the resolved network destination, so a public-looking hostname can resolve to an internal address or change resolution between validation and connection (DNS rebinding). A maintainer-run local harness demonstrated an outbound connection to an owner-controlled loopback listener; access to production internal services, credential disclosure, and code execution were not demonstrated. The issue was confirmed at revision cbfee7343ddc867316dd9b3de6fa8856730f9f41; the complete historical affected range was not established. Fixed by PR #3683, included in revision 8c2de6c506bb4efabe3f0c2ffb8370b9e23d4650, which was deployed to clawhub.ai on 2026-09-11; self-hosted deployments should update to that revision or a later descendant. The npm CLI and OpenClaw runtime are separate products and are not affected.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-30 12:47 UTC
    CWE
    • CWE-918 - Server-Side Request Forgery (SSRF)
    Impacted products
    Vendor Product Version
    openclaw clawhub Affected: 0 , < 8c2de6c506bb4efabe3f0c2ffb8370b9e23d4650 (git)
    Unaffected: 8c2de6c506bb4efabe3f0c2ffb8370b9e23d4650 (git)
    Create a notification for this product.
    Date Public
    2026-09-11 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-100601",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-30T12:47:07.077181Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-30T12:47:18.560Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "clawhub",
              "vendor": "openclaw",
              "versions": [
                {
                  "lessThan": "8c2de6c506bb4efabe3f0c2ffb8370b9e23d4650",
                  "status": "affected",
                  "version": "0",
                  "versionType": "git"
                },
                {
                  "status": "unaffected",
                  "version": "8c2de6c506bb4efabe3f0c2ffb8370b9e23d4650",
                  "versionType": "git"
                }
              ]
            }
          ],
          "datePublic": "2026-09-11T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "ClawHub (openclaw/clawhub) application/backend contains a server-side request forgery vulnerability in the public profile preview\u0027s image fetching. The preview accepts a user-supplied image URL and checks the textual hostname against private-address patterns, but does not validate or pin the resolved network destination, so a public-looking hostname can resolve to an internal address or change resolution between validation and connection (DNS rebinding). A maintainer-run local harness demonstrated an outbound connection to an owner-controlled loopback listener; access to production internal services, credential disclosure, and code execution were not demonstrated. The issue was confirmed at revision cbfee7343ddc867316dd9b3de6fa8856730f9f41; the complete historical affected range was not established. Fixed by PR #3683, included in revision 8c2de6c506bb4efabe3f0c2ffb8370b9e23d4650, which was deployed to clawhub.ai on 2026-09-11; self-hosted deployments should update to that revision or a later descendant. The npm CLI and OpenClaw runtime are separate products and are not affected."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 6.9,
                "baseSeverity": "MEDIUM",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "NONE",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "LOW",
                "subConfidentialityImpact": "LOW",
                "subIntegrityImpact": "LOW",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:L/SI:L/SA:L",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "NONE",
                "vulnIntegrityImpact": "LOW",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS"
            },
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "LOW",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-918",
                  "description": "Server-Side Request Forgery (SSRF)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-26T13:22:46.283Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "name": "GitHub Security Advisory (GHSA-48gp-hx8w-wjvm)",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://github.com/openclaw/clawhub/security/advisories/GHSA-48gp-hx8w-wjvm"
            },
            {
              "name": "Patch Commit",
              "tags": [
                "patch"
              ],
              "url": "https://github.com/openclaw/clawhub/commit/8c2de6c506bb4efabe3f0c2ffb8370b9e23d4650"
            },
            {
              "name": "VulnCheck Advisory: ClawHub SSRF via Unchecked DNS Resolution in Profile Image",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/clawhub-ssrf-via-unchecked-dns-resolution-in-profile-image"
            }
          ],
          "title": "ClawHub SSRF via Unchecked DNS Resolution in Profile Image",
          "x_generator": {
            "engine": "vulncheck-endgame"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-100601",
        "datePublished": "2026-09-26T13:22:46.283Z",
        "dateReserved": "2026-09-26T01:04:47.561Z",
        "dateUpdated": "2026-09-30T12:47:18.560Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-100600 (GCVE-0-2026-100600)

    Vulnerability from nvd – Published: 2026-09-26 13:22 – Updated: 2026-09-26 13:22
    VLAI
    Title
    ClawHub before 8c2de6c506 Quota Exhaustion via Anonymous API
    Summary
    ClawHub (the openclaw/clawhub application/backend) does not bind anonymous HTTP API requests to a trusted caller identity, so all direct anonymous API requests share a single default quota allowance. A remote, unauthenticated caller can drain that shared allowance and thereby deny or degrade API access for unrelated visitors. In addition, when the TRUST_FORWARDED_IPS option is enabled without an authenticated edge/proxy, clients can supply arbitrary forwarded IP headers to select quota identities of their choosing and evade rate limiting. The issue was confirmed at revision cbfee7343ddc867316dd9b3de6fa8856730f9f41; the complete historical affected range was not established. It is fixed in revision 8c2de6c506bb4efabe3f0c2ffb8370b9e23d4650 (PR #3684), where direct anonymous calls are redirected to the public API origin without consuming quota and forged identity assertions return HTTP 401. The npm CLI and OpenClaw runtime are separate products and are not affected.
    CWE
    • CWE-770 - Allocation of Resources Without Limits or Throttling
    Impacted products
    Vendor Product Version
    openclaw clawhub Affected: 0 , < 8c2de6c506bb4efabe3f0c2ffb8370b9e23d4650 (git)
    Unaffected: 8c2de6c506bb4efabe3f0c2ffb8370b9e23d4650 (git)
    Create a notification for this product.
    Date Public
    2026-09-11 00:00
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "clawhub",
              "vendor": "openclaw",
              "versions": [
                {
                  "lessThan": "8c2de6c506bb4efabe3f0c2ffb8370b9e23d4650",
                  "status": "affected",
                  "version": "0",
                  "versionType": "git"
                },
                {
                  "status": "unaffected",
                  "version": "8c2de6c506bb4efabe3f0c2ffb8370b9e23d4650",
                  "versionType": "git"
                }
              ]
            }
          ],
          "datePublic": "2026-09-11T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "ClawHub (the openclaw/clawhub application/backend) does not bind anonymous HTTP API requests to a trusted caller identity, so all direct anonymous API requests share a single default quota allowance. A remote, unauthenticated caller can drain that shared allowance and thereby deny or degrade API access for unrelated visitors. In addition, when the TRUST_FORWARDED_IPS option is enabled without an authenticated edge/proxy, clients can supply arbitrary forwarded IP headers to select quota identities of their choosing and evade rate limiting. The issue was confirmed at revision cbfee7343ddc867316dd9b3de6fa8856730f9f41; the complete historical affected range was not established. It is fixed in revision 8c2de6c506bb4efabe3f0c2ffb8370b9e23d4650 (PR #3684), where direct anonymous calls are redirected to the public API origin without consuming quota and forged identity assertions return HTTP 401. The npm CLI and OpenClaw runtime are separate products and are not affected."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 6.9,
                "baseSeverity": "MEDIUM",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "NONE",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "LOW",
                "vulnConfidentialityImpact": "NONE",
                "vulnIntegrityImpact": "NONE",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS"
            },
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "LOW",
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-770",
                  "description": "Allocation of Resources Without Limits or Throttling",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-26T13:22:45.578Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "name": "GitHub Security Advisory (GHSA-4c7q-g7xf-5628)",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://github.com/openclaw/clawhub/security/advisories/GHSA-4c7q-g7xf-5628"
            },
            {
              "name": "Patch Commit",
              "tags": [
                "patch"
              ],
              "url": "https://github.com/openclaw/clawhub/commit/8c2de6c506bb4efabe3f0c2ffb8370b9e23d4650"
            },
            {
              "name": "VulnCheck Advisory: ClawHub before 8c2de6c506 Quota Exhaustion via Anonymous API",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/clawhub-before-8c2de6c506-quota-exhaustion-via-anonymous-api"
            }
          ],
          "title": "ClawHub before 8c2de6c506 Quota Exhaustion via Anonymous API",
          "x_generator": {
            "engine": "vulncheck-endgame"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-100600",
        "datePublished": "2026-09-26T13:22:45.578Z",
        "dateReserved": "2026-09-26T01:04:47.561Z",
        "dateUpdated": "2026-09-26T13:22:45.578Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-100599 (GCVE-0-2026-100599)

    Vulnerability from nvd – Published: 2026-09-26 02:19 – Updated: 2026-09-28 17:01
    VLAI
    Title
    OpenClaw 2026.5.1 before 2026.7.1 Remote Code Execution via googlemeet.chrome
    Summary
    OpenClaw versions 2026.5.1 through 2026.7.0 fail to apply the configured exec approval path to Google Meet node commands. The googlemeet.chrome command accepts caller-supplied audio command arrays and executes them on a paired node without going through the normal system.run approval flow. In deployments with the Google Meet plugin enabled, a paired Chrome node, and the googlemeet.chrome node command allowed, a tool-enabled agent able to invoke that command can execute attacker-selected processes on the paired node, impacting files, credentials, browser profiles, and availability on that node. The issue is fixed in 2026.7.1; as a workaround, remove googlemeet.chrome from allowed node commands or disable the Google Meet plugin.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-28 17:01 UTC
    CWE
    • CWE-78 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
    References
    Impacted products
    Vendor Product Version
    OpenClaw OpenClaw Affected: 2026.5.1 , < 2026.7.1 (semver)
    Unaffected: 2026.7.1 (semver)
        cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-09-11 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-100599",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-28T17:01:05.340158Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-28T17:01:20.520Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageURL": "pkg:npm/openclaw",
              "product": "OpenClaw",
              "vendor": "OpenClaw",
              "versions": [
                {
                  "lessThan": "2026.7.1",
                  "status": "affected",
                  "version": "2026.5.1",
                  "versionType": "semver"
                },
                {
                  "status": "unaffected",
                  "version": "2026.7.1",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "2026.7.1",
                      "versionStartIncluding": "2026.5.1",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "wwwvwwvwwwwwvwwvw"
            }
          ],
          "datePublic": "2026-09-11T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "OpenClaw versions 2026.5.1 through 2026.7.0 fail to apply the configured exec approval path to Google Meet node commands. The googlemeet.chrome command accepts caller-supplied audio command arrays and executes them on a paired node without going through the normal system.run approval flow. In deployments with the Google Meet plugin enabled, a paired Chrome node, and the googlemeet.chrome node command allowed, a tool-enabled agent able to invoke that command can execute attacker-selected processes on the paired node, impacting files, credentials, browser profiles, and availability on that node. The issue is fixed in 2026.7.1; as a workaround, remove googlemeet.chrome from allowed node commands or disable the Google Meet plugin."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 8.7,
                "baseSeverity": "HIGH",
                "privilegesRequired": "LOW",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH"
              },
              "format": "CVSS"
            },
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 8.8,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-78",
                  "description": "Improper Neutralization of Special Elements used in an OS Command (\u0027OS Command Injection\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-26T02:19:18.983Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "name": "GitHub Security Advisory (GHSA-224w-vfr9-h35c)",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://github.com/openclaw/openclaw/security/advisories/GHSA-224w-vfr9-h35c"
            },
            {
              "name": "VulnCheck Advisory: OpenClaw 2026.5.1 before 2026.7.1 Remote Code Execution via googlemeet.chrome",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/openclaw-2026.5.1-before-2026.7.1-remote-code-execution-via-googlemeet-chrome"
            }
          ],
          "title": "OpenClaw 2026.5.1 before 2026.7.1 Remote Code Execution via googlemeet.chrome",
          "x_generator": {
            "engine": "vulncheck-endgame"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-100599",
        "datePublished": "2026-09-26T02:19:18.983Z",
        "dateReserved": "2026-09-26T01:04:47.561Z",
        "dateUpdated": "2026-09-28T17:01:20.520Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-100598 (GCVE-0-2026-100598)

    Vulnerability from nvd – Published: 2026-09-26 02:19 – Updated: 2026-09-28 19:18
    VLAI
    Title
    OpenClaw before 2026.7.1 Approval Binding Logic Error
    Summary
    OpenClaw (npm package openclaw) before 2026.7.1 incorrectly binds Signal approval reactions. In affected versions, a reaction intended to resolve a structured approval request could instead attach to ordinary outbound text when unrelated outbound messages and a pending approval are present in the same conversation. As a result, an approver's reaction to unrelated text could be interpreted as approving or denying a pending host action; the practical impact depends on the pending request, conversation timing, and the actions available to the OpenClaw process. The issue does not change the authority of correctly identified approvers. This is fixed in version 2026.7.1.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-28 19:17 UTC
    CWE
    • CWE-346 - Origin Validation Error
    References
    Impacted products
    Vendor Product Version
    OpenClaw OpenClaw Affected: 0 , < 2026.7.1 (semver)
    Unaffected: 2026.7.1 (semver)
        cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-09-11 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-100598",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-28T19:17:26.583581Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-28T19:18:21.339Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageURL": "pkg:npm/openclaw",
              "product": "OpenClaw",
              "vendor": "OpenClaw",
              "versions": [
                {
                  "lessThan": "2026.7.1",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "status": "unaffected",
                  "version": "2026.7.1",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "2026.7.1",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "rexpository"
            }
          ],
          "datePublic": "2026-09-11T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "OpenClaw (npm package openclaw) before 2026.7.1 incorrectly binds Signal approval reactions. In affected versions, a reaction intended to resolve a structured approval request could instead attach to ordinary outbound text when unrelated outbound messages and a pending approval are present in the same conversation. As a result, an approver\u0027s reaction to unrelated text could be interpreted as approving or denying a pending host action; the practical impact depends on the pending request, conversation timing, and the actions available to the OpenClaw process. The issue does not change the authority of correctly identified approvers. This is fixed in version 2026.7.1."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "HIGH",
                "attackRequirements": "PRESENT",
                "attackVector": "NETWORK",
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "privilegesRequired": "LOW",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "PASSIVE",
                "vectorString": "CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH"
              },
              "format": "CVSS"
            },
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.1,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-346",
                  "description": "Origin Validation Error",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-26T02:19:18.296Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "name": "GitHub Security Advisory (GHSA-r88x-r7jj-f2cf)",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://github.com/openclaw/openclaw/security/advisories/GHSA-r88x-r7jj-f2cf"
            },
            {
              "name": "VulnCheck Advisory: OpenClaw before 2026.7.1 Approval Binding Logic Error",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/openclaw-before-2026.7.1-approval-binding-logic-error"
            }
          ],
          "title": "OpenClaw before 2026.7.1 Approval Binding Logic Error",
          "x_generator": {
            "engine": "vulncheck-endgame"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-100598",
        "datePublished": "2026-09-26T02:19:18.296Z",
        "dateReserved": "2026-09-26T01:04:47.561Z",
        "dateUpdated": "2026-09-28T19:18:21.339Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-100597 (GCVE-0-2026-100597)

    Vulnerability from nvd – Published: 2026-09-26 02:19 – Updated: 2026-09-30 00:30
    VLAI
    Title
    OpenClaw before 2026.7.1 Path Traversal via Filesystem Race
    Summary
    OpenClaw (npm package 'openclaw') before 2026.7.1 is vulnerable to a time-of-check time-of-use race condition in OpenShell local mirror filesystem mutation operations. The remove, mkdir, and rename operations could act on a different filesystem target after OpenClaw completed its sandbox path-safety check, if the path is changed concurrently. An attacker able to win the race can cause a sandboxed operation to delete, create, or rename a host path outside the intended mirror root with the permissions of the OpenClaw process user. This does not require an operator to have granted host filesystem access outside the sandbox. The issue is fixed in 2026.7.1.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-30 00:30 UTC
    CWE
    • CWE-367 - Time-of-check Time-of-use (TOCTOU) Race Condition
    References
    Impacted products
    Vendor Product Version
    OpenClaw OpenClaw Affected: 0 , < 2026.7.1 (semver)
    Unaffected: 2026.7.1 (semver)
        cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-09-11 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-100597",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-30T00:30:25.759138Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-30T00:30:35.989Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageURL": "pkg:npm/openclaw",
              "product": "OpenClaw",
              "vendor": "OpenClaw",
              "versions": [
                {
                  "lessThan": "2026.7.1",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "status": "unaffected",
                  "version": "2026.7.1",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "2026.7.1",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "gal1ium"
            },
            {
              "lang": "en",
              "type": "reporter",
              "value": "chluo1997"
            }
          ],
          "datePublic": "2026-09-11T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "OpenClaw (npm package \u0027openclaw\u0027) before 2026.7.1 is vulnerable to a time-of-check time-of-use race condition in OpenShell local mirror filesystem mutation operations. The remove, mkdir, and rename operations could act on a different filesystem target after OpenClaw completed its sandbox path-safety check, if the path is changed concurrently. An attacker able to win the race can cause a sandboxed operation to delete, create, or rename a host path outside the intended mirror root with the permissions of the OpenClaw process user. This does not require an operator to have granted host filesystem access outside the sandbox. The issue is fixed in 2026.7.1."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "HIGH",
                "attackRequirements": "PRESENT",
                "attackVector": "LOCAL",
                "baseScore": 8.8,
                "baseSeverity": "HIGH",
                "privilegesRequired": "LOW",
                "subAvailabilityImpact": "HIGH",
                "subConfidentialityImpact": "HIGH",
                "subIntegrityImpact": "HIGH",
                "userInteraction": "NONE",
                "vectorString": "CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH"
              },
              "format": "CVSS"
            },
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "LOCAL",
                "availabilityImpact": "HIGH",
                "baseScore": 7.8,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "CHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-367",
                  "description": "Time-of-check Time-of-use (TOCTOU) Race Condition",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-26T02:19:17.613Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "name": "GitHub Security Advisory (GHSA-crg9-c62w-j2p5)",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://github.com/openclaw/openclaw/security/advisories/GHSA-crg9-c62w-j2p5"
            },
            {
              "name": "VulnCheck Advisory: OpenClaw before 2026.7.1 Path Traversal via Filesystem Race",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/openclaw-before-2026.7.1-path-traversal-via-filesystem-race"
            }
          ],
          "title": "OpenClaw before 2026.7.1 Path Traversal via Filesystem Race",
          "x_generator": {
            "engine": "vulncheck-endgame"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-100597",
        "datePublished": "2026-09-26T02:19:17.613Z",
        "dateReserved": "2026-09-26T01:04:47.561Z",
        "dateUpdated": "2026-09-30T00:30:35.989Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-100596 (GCVE-0-2026-100596)

    Vulnerability from nvd – Published: 2026-09-26 02:19 – Updated: 2026-09-26 02:19
    VLAI
    Title
    OpenClaw before 2026.7.1 Authorization Bypass via MCP Configuration
    Summary
    OpenClaw versions before 2026.7.1 fail to properly authorize non-owner users executing MCP configuration changes through /mcp set and /mcp unset commands. Attackers can persist arbitrary stdio MCP commands that execute with OpenClaw process privileges when configuration loads, compromising host confidentiality, integrity, and availability.
    CWE
    References
    Impacted products
    Vendor Product Version
    OpenClaw OpenClaw Affected: 0 , < 2026.7.1 (semver)
    Unaffected: 2026.7.1 (semver)
        cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-09-11 00:00
    Credits
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageURL": "pkg:npm/openclaw",
              "product": "OpenClaw",
              "vendor": "OpenClaw",
              "versions": [
                {
                  "lessThan": "2026.7.1",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "status": "unaffected",
                  "version": "2026.7.1",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "2026.7.1",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "yetval"
            }
          ],
          "datePublic": "2026-09-11T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "OpenClaw versions before 2026.7.1 fail to properly authorize non-owner users executing MCP configuration changes through /mcp set and /mcp unset commands. Attackers can persist arbitrary stdio MCP commands that execute with OpenClaw process privileges when configuration loads, compromising host confidentiality, integrity, and availability."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 8.7,
                "baseSeverity": "HIGH",
                "privilegesRequired": "LOW",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH"
              },
              "format": "CVSS"
            },
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 8.8,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-862",
                  "description": "Missing Authorization",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-26T02:19:16.957Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "name": "GitHub Security Advisory (GHSA-wwx7-573h-pqwc)",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://github.com/openclaw/openclaw/security/advisories/GHSA-wwx7-573h-pqwc"
            },
            {
              "name": "VulnCheck Advisory: OpenClaw before 2026.7.1 Authorization Bypass via MCP Configuration",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/openclaw-before-2026.7.1-authorization-bypass-via-mcp-configuration"
            }
          ],
          "title": "OpenClaw before 2026.7.1 Authorization Bypass via MCP Configuration",
          "x_generator": {
            "engine": "vulncheck-endgame"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-100596",
        "datePublished": "2026-09-26T02:19:16.957Z",
        "dateReserved": "2026-09-26T01:04:47.561Z",
        "dateUpdated": "2026-09-26T02:19:16.957Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-101884 (GCVE-0-2026-101884)

    Vulnerability from cvelistv5 – Published: 2026-09-30 19:16 – Updated: 2026-09-30 19:33
    VLAI
    Title
    OpenClaw Windows Node before 2026.7.1 Remote Code Execution via Environment Override
    Summary
    OpenClaw Windows Node before 2026.7.1 contains an incomplete environment-variable sanitizer in system.run that fails to block GIT_CONFIG_*, DOTNET_STARTUP_HOOKS, and JAVA_TOOL_OPTIONS variables. Attackers with gateway or agent access can supply these variables to allowlisted tools like git, dotnet, or java to load attacker-controlled code and achieve arbitrary code execution.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-30 19:33 UTC
    CWE
    • CWE-184 - Incomplete List of Disallowed Inputs
    Impacted products
    Vendor Product Version
    OpenClaw OpenClaw Windows Node Affected: 0 , < 2026.7.1 (custom)
    Create a notification for this product.
    Date Public
    2026-09-03 05:32
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-101884",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-30T19:33:07.973543Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-30T19:33:24.196Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "exploit"
                ],
                "url": "https://github.com/openclaw/openclaw-windows-node/security/advisories/GHSA-39cf-qcfw-g8pg"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "OpenClaw Windows Node",
              "repo": "https://github.com/openclaw/openclaw-windows-node",
              "vendor": "OpenClaw",
              "versions": [
                {
                  "lessThan": "2026.7.1",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Cameron Beeley (anagnorisis2peripeteia)"
            }
          ],
          "datePublic": "2026-09-03T05:32:25.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "OpenClaw Windows Node before 2026.7.1 contains an incomplete environment-variable sanitizer in system.run that fails to block GIT_CONFIG_*, DOTNET_STARTUP_HOOKS, and JAVA_TOOL_OPTIONS variables. Attackers with gateway or agent access can supply these variables to allowlisted tools like git, dotnet, or java to load attacker-controlled code and achieve arbitrary code execution."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "LOW",
                "attackRequirements": "PRESENT",
                "attackVector": "NETWORK",
                "baseScore": 7.7,
                "baseSeverity": "HIGH",
                "privilegesRequired": "LOW",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH"
              },
              "format": "CVSS"
            },
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-184",
                  "description": "Incomplete List of Disallowed Inputs",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-30T19:16:04.686Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "name": "GitHub Security Advisory (GHSA-39cf-qcfw-g8pg)",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://github.com/openclaw/openclaw-windows-node/security/advisories/GHSA-39cf-qcfw-g8pg"
            },
            {
              "tags": [
                "patch"
              ],
              "url": "https://github.com/openclaw/openclaw-windows-node/commit/261ba11aaad671834ad141bb85101b50cf1a38f6"
            },
            {
              "name": "OpenClaw Windows Node v2026.7.1 Release Notes",
              "tags": [
                "release-notes"
              ],
              "url": "https://github.com/openclaw/openclaw-windows-node/releases/tag/v2026.7.1"
            },
            {
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/openclaw/openclaw-windows-node/blob/v0.6.12/src/OpenClaw.Shared/ExecEnvSanitizer.cs#L15-L50"
            },
            {
              "name": "VulnCheck Advisory: OpenClaw Windows Node before 2026.7.1 Remote Code Execution via Environment Override",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/openclaw-windows-node-before-2026.7.1-remote-code-execution-via-environment-override"
            }
          ],
          "title": "OpenClaw Windows Node before 2026.7.1 Remote Code Execution via Environment Override",
          "x_generator": {
            "engine": "vulncheck-endgame"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-101884",
        "datePublished": "2026-09-30T19:16:04.686Z",
        "dateReserved": "2026-09-28T15:44:45.389Z",
        "dateUpdated": "2026-09-30T19:33:24.196Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-101883 (GCVE-0-2026-101883)

    Vulnerability from cvelistv5 – Published: 2026-09-30 19:16 – Updated: 2026-09-30 19:16
    VLAI
    Title
    OpenClaw Windows Node through 2026.9.4 SSRF via canvas.present
    Summary
    OpenClaw Windows Node through 2026.9.4 contains a server-side request forgery vulnerability in the canvas.present capability that bypasses URL risk evaluation enforced by canvas.navigate. Attackers with gateway or agent access can issue canvas.present to make the node's WebView send requests to localhost, private networks, or tailnet services from the user's machine.
    CWE
    • CWE-918 - Server-Side Request Forgery (SSRF)
    Impacted products
    Vendor Product Version
    OpenClaw OpenClaw Windows Node Affected: 0 , ≤ 2026.9.4 (custom)
    Create a notification for this product.
    Date Public
    2026-09-03 05:32
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "OpenClaw Windows Node",
              "repo": "https://github.com/openclaw/openclaw-windows-node",
              "vendor": "OpenClaw",
              "versions": [
                {
                  "lessThanOrEqual": "2026.9.4",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Cameron Beeley (anagnorisis2peripeteia)"
            }
          ],
          "datePublic": "2026-09-03T05:32:23.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "OpenClaw Windows Node through 2026.9.4 contains a server-side request forgery vulnerability in the canvas.present capability that bypasses URL risk evaluation enforced by canvas.navigate. Attackers with gateway or agent access can issue canvas.present to make the node\u0027s WebView send requests to localhost, private networks, or tailnet services from the user\u0027s machine."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "privilegesRequired": "LOW",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "LOW",
                "vulnIntegrityImpact": "LOW"
              },
              "format": "CVSS"
            },
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 5.4,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "LOW",
                "integrityImpact": "LOW",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-918",
                  "description": "Server-Side Request Forgery (SSRF)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-30T19:16:03.985Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "name": "GitHub Security Advisory (GHSA-7vch-pmw9-3g4q)",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://github.com/openclaw/openclaw-windows-node/security/advisories/GHSA-7vch-pmw9-3g4q"
            },
            {
              "tags": [
                "patch"
              ],
              "url": "https://github.com/openclaw/openclaw-windows-node/commit/16528aadaa45d7bc6718b07ccf8b01f3eb033ad1"
            },
            {
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/openclaw/openclaw-windows-node/blob/v2026.9.4/src/OpenClaw.Tray.WinUI/Services/NodeService.cs#L1244-L1270"
            },
            {
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/openclaw/openclaw-windows-node/blob/v0.6.12/src/OpenClaw.Tray.WinUI/Windows/CanvasWindow.xaml.cs#L77-L109"
            },
            {
              "name": "VulnCheck Advisory: OpenClaw Windows Node through 2026.9.4 SSRF via canvas.present",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/openclaw-windows-node-through-2026.9.4-ssrf-via-canvas-present"
            }
          ],
          "title": "OpenClaw Windows Node through 2026.9.4 SSRF via canvas.present",
          "x_generator": {
            "engine": "vulncheck-endgame"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-101883",
        "datePublished": "2026-09-30T19:16:03.985Z",
        "dateReserved": "2026-09-28T15:44:45.389Z",
        "dateUpdated": "2026-09-30T19:16:03.985Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-101882 (GCVE-0-2026-101882)

    Vulnerability from cvelistv5 – Published: 2026-09-30 19:16 – Updated: 2026-10-01 15:29
    VLAI
    Title
    OpenClaw Windows Node before 2026.7.1 Remote Code Execution via system.execApprovals.set
    Summary
    OpenClaw Windows Node before 2026.7.1 contains an incomplete validation vulnerability in system.execApprovals.set that accepts wildcard-executable rules and abusable system binaries like mshta, rundll32, and certutil. Remote callers can add broad allow rules to execute arbitrary commands on the Windows host through system.run without operator checks or user prompts.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-10-01 15:28 UTC
    CWE
    • CWE-184 - Incomplete List of Disallowed Inputs
    Impacted products
    Vendor Product Version
    OpenClaw OpenClaw Windows Node Affected: 0 , < 2026.7.1 (custom)
    Create a notification for this product.
    Date Public
    2026-09-03 05:32
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-101882",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-10-01T15:28:47.813494Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-10-01T15:29:01.764Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "exploit"
                ],
                "url": "https://github.com/openclaw/openclaw-windows-node/security/advisories/GHSA-f32j-8759-w2fp"
              },
              {
                "tags": [
                  "exploit"
                ],
                "url": "https://github.com/openclaw/openclaw-windows-node/security/advisories/GHSA-g95v-c9r6-2hmq"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "OpenClaw Windows Node",
              "repo": "https://github.com/openclaw/openclaw-windows-node",
              "vendor": "OpenClaw",
              "versions": [
                {
                  "lessThan": "2026.7.1",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Cameron Beeley (anagnorisis2peripeteia)"
            }
          ],
          "datePublic": "2026-09-03T05:32:21.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "OpenClaw Windows Node before 2026.7.1 contains an incomplete validation vulnerability in system.execApprovals.set that accepts wildcard-executable rules and abusable system binaries like mshta, rundll32, and certutil. Remote callers can add broad allow rules to execute arbitrary commands on the Windows host through system.run without operator checks or user prompts."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 8.7,
                "baseSeverity": "HIGH",
                "privilegesRequired": "LOW",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH"
              },
              "format": "CVSS"
            },
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 8.8,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-184",
                  "description": "Incomplete List of Disallowed Inputs",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-30T19:16:03.309Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "name": "GitHub Security Advisory (GHSA-f32j-8759-w2fp)",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://github.com/openclaw/openclaw-windows-node/security/advisories/GHSA-f32j-8759-w2fp"
            },
            {
              "name": "GitHub Security Advisory (GHSA-g95v-c9r6-2hmq)",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://github.com/openclaw/openclaw-windows-node/security/advisories/GHSA-g95v-c9r6-2hmq"
            },
            {
              "tags": [
                "patch"
              ],
              "url": "https://github.com/openclaw/openclaw-windows-node/commit/8f07ad92beb28376bc228c0b07093173a043a656"
            },
            {
              "tags": [
                "patch"
              ],
              "url": "https://github.com/openclaw/openclaw-windows-node/commit/988df5badc84ab5efd5b4e291766a1fa5e7e268a"
            },
            {
              "name": "OpenClaw Windows Node v2026.7.1 Release Notes",
              "tags": [
                "release-notes"
              ],
              "url": "https://github.com/openclaw/openclaw-windows-node/releases/tag/v2026.7.1"
            },
            {
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/openclaw/openclaw-windows-node/blob/v0.6.12/src/OpenClaw.Shared/Capabilities/SystemCapability.cs#L791-L853"
            },
            {
              "name": "VulnCheck Advisory: OpenClaw Windows Node before 2026.7.1 Remote Code Execution via system.execApprovals.set",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/openclaw-windows-node-before-2026.7.1-remote-code-execution-via-system-execapprovals-set"
            }
          ],
          "title": "OpenClaw Windows Node before 2026.7.1 Remote Code Execution via system.execApprovals.set",
          "x_generator": {
            "engine": "vulncheck-endgame"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-101882",
        "datePublished": "2026-09-30T19:16:03.309Z",
        "dateReserved": "2026-09-28T15:44:45.389Z",
        "dateUpdated": "2026-10-01T15:29:01.764Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-101881 (GCVE-0-2026-101881)

    Vulnerability from cvelistv5 – Published: 2026-09-30 19:16 – Updated: 2026-09-30 19:53
    VLAI
    Title
    OpenClaw Windows Node before 2026.7.1 Denial of Service
    Summary
    OpenClaw Windows Node before 2026.7.1 contains an allocation of resources without limits vulnerability in the gateway WebSocket transport that allows connected gateways to exhaust node memory. Attackers can send an unending sequence of WebSocket continuation frames without EndOfMessage to cause unbounded memory growth until the node process crashes.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-30 19:53 UTC
    CWE
    • CWE-770 - Allocation of Resources Without Limits or Throttling
    Impacted products
    Vendor Product Version
    OpenClaw OpenClaw Windows Node Affected: 0 , < 2026.7.1 (custom)
    Create a notification for this product.
    Date Public
    2026-09-03 05:32
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-101881",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-30T19:53:03.562709Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-30T19:53:47.897Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "exploit"
                ],
                "url": "https://github.com/openclaw/openclaw-windows-node/security/advisories/GHSA-xxr2-xm56-9cw5"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "OpenClaw Windows Node",
              "repo": "https://github.com/openclaw/openclaw-windows-node",
              "vendor": "OpenClaw",
              "versions": [
                {
                  "lessThan": "2026.7.1",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Cameron Beeley (anagnorisis2peripeteia)"
            }
          ],
          "datePublic": "2026-09-03T05:32:19.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "OpenClaw Windows Node before 2026.7.1 contains an allocation of resources without limits vulnerability in the gateway WebSocket transport that allows connected gateways to exhaust node memory. Attackers can send an unending sequence of WebSocket continuation frames without EndOfMessage to cause unbounded memory growth until the node process crashes."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 7.1,
                "baseSeverity": "HIGH",
                "privilegesRequired": "LOW",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "NONE",
                "vulnIntegrityImpact": "NONE"
              },
              "format": "CVSS"
            },
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 6.5,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-770",
                  "description": "Allocation of Resources Without Limits or Throttling",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-30T19:16:02.477Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "name": "GitHub Security Advisory (GHSA-xxr2-xm56-9cw5)",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://github.com/openclaw/openclaw-windows-node/security/advisories/GHSA-xxr2-xm56-9cw5"
            },
            {
              "tags": [
                "patch"
              ],
              "url": "https://github.com/openclaw/openclaw-windows-node/commit/1810e357aa0d0639099b347f31c746ba7d31512a"
            },
            {
              "name": "OpenClaw Windows Node v2026.7.1 Release Notes",
              "tags": [
                "release-notes"
              ],
              "url": "https://github.com/openclaw/openclaw-windows-node/releases/tag/v2026.7.1"
            },
            {
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/openclaw/openclaw-windows-node/blob/v0.6.12/src/OpenClaw.Shared/WebSocketClientBase.cs#L217-L263"
            },
            {
              "name": "VulnCheck Advisory: OpenClaw Windows Node before 2026.7.1 Denial of Service",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/openclaw-windows-node-before-2026.7.1-denial-of-service"
            }
          ],
          "title": "OpenClaw Windows Node before 2026.7.1 Denial of Service",
          "x_generator": {
            "engine": "vulncheck-endgame"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-101881",
        "datePublished": "2026-09-30T19:16:02.477Z",
        "dateReserved": "2026-09-28T15:44:45.389Z",
        "dateUpdated": "2026-09-30T19:53:47.897Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-101880 (GCVE-0-2026-101880)

    Vulnerability from cvelistv5 – Published: 2026-09-30 19:16 – Updated: 2026-09-30 19:34
    VLAI
    Title
    OpenClaw Windows Node before 2026.7.1 Authorization Bypass
    Summary
    OpenClaw Windows Node before 2026.7.1 contains an incorrect authorization vulnerability in the system.run exec-approval policy where ExecShellWrapperParser fails to split commands on pipe operators or extract command substitutions. Connected gateways or agents can bypass approval rules by placing denied commands behind allowed prefixes using pipe operators or command substitution syntax, achieving arbitrary command execution on Windows hosts.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-30 19:33 UTC
    CWE
    • CWE-863 - Incorrect Authorization
    Impacted products
    Vendor Product Version
    OpenClaw OpenClaw Windows Node Affected: 0 , < 2026.7.1 (custom)
    Create a notification for this product.
    Date Public
    2026-09-03 05:32
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-101880",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-30T19:33:47.048317Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-30T19:34:05.680Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "exploit"
                ],
                "url": "https://github.com/openclaw/openclaw-windows-node/security/advisories/GHSA-r3x2-vf2f-vvj8"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "OpenClaw Windows Node",
              "repo": "https://github.com/openclaw/openclaw-windows-node",
              "vendor": "OpenClaw",
              "versions": [
                {
                  "lessThan": "2026.7.1",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Cameron Beeley (anagnorisis2peripeteia)"
            }
          ],
          "datePublic": "2026-09-03T05:32:07.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "OpenClaw Windows Node before 2026.7.1 contains an incorrect authorization vulnerability in the system.run exec-approval policy where ExecShellWrapperParser fails to split commands on pipe operators or extract command substitutions. Connected gateways or agents can bypass approval rules by placing denied commands behind allowed prefixes using pipe operators or command substitution syntax, achieving arbitrary command execution on Windows hosts."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 8.7,
                "baseSeverity": "HIGH",
                "privilegesRequired": "LOW",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH"
              },
              "format": "CVSS"
            },
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 8.8,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-863",
                  "description": "Incorrect Authorization",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-30T19:16:01.717Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "name": "GitHub Security Advisory (GHSA-r3x2-vf2f-vvj8)",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://github.com/openclaw/openclaw-windows-node/security/advisories/GHSA-r3x2-vf2f-vvj8"
            },
            {
              "name": "GitHub Security Advisory (GHSA-vg38-vjq2-vgvh)",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://github.com/openclaw/openclaw-windows-node/security/advisories/GHSA-vg38-vjq2-vgvh"
            },
            {
              "tags": [
                "patch"
              ],
              "url": "https://github.com/openclaw/openclaw-windows-node/commit/2077aa3e7159101bddcee2f4efcb9d604a81619e"
            },
            {
              "name": "OpenClaw Windows Node v2026.7.1 Release Notes",
              "tags": [
                "release-notes"
              ],
              "url": "https://github.com/openclaw/openclaw-windows-node/releases/tag/v2026.7.1"
            },
            {
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/openclaw/openclaw-windows-node/blob/v0.6.12/src/OpenClaw.Shared/ExecShellWrapperParser.cs#L253"
            },
            {
              "name": "VulnCheck Advisory: OpenClaw Windows Node before 2026.7.1 Authorization Bypass",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/openclaw-windows-node-before-2026.7.1-authorization-bypass"
            }
          ],
          "title": "OpenClaw Windows Node before 2026.7.1 Authorization Bypass",
          "x_generator": {
            "engine": "vulncheck-endgame"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-101880",
        "datePublished": "2026-09-30T19:16:01.717Z",
        "dateReserved": "2026-09-28T15:44:45.389Z",
        "dateUpdated": "2026-09-30T19:34:05.680Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-101879 (GCVE-0-2026-101879)

    Vulnerability from cvelistv5 – Published: 2026-09-30 19:16 – Updated: 2026-09-30 19:16
    VLAI
    Title
    OpenClaw Windows Node before 2026.7.1-3 Missing Authorization
    Summary
    OpenClaw Windows Node before 2026.7.1-3 contains a missing authorization vulnerability in NodeService capture handlers that allows connected gateways or agents to perform screen snapshots, camera snaps, and location captures without consent prompts. Attackers can invoke screen.snapshot, camera.snap, and location.get over the node WebSocket to silently capture screenshots, photograph users through webcams, and obtain device geolocation without user interaction.
    CWE
    Impacted products
    Vendor Product Version
    OpenClaw OpenClaw Windows Node Affected: 0 , < 2026.7.1-3 (custom)
    Create a notification for this product.
    Date Public
    2026-09-03 05:31
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "OpenClaw Windows Node",
              "repo": "https://github.com/openclaw/openclaw-windows-node",
              "vendor": "OpenClaw",
              "versions": [
                {
                  "lessThan": "2026.7.1-3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Cameron Beeley (anagnorisis2peripeteia)"
            }
          ],
          "datePublic": "2026-09-03T05:31:51.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "OpenClaw Windows Node before 2026.7.1-3 contains a missing authorization vulnerability in NodeService capture handlers that allows connected gateways or agents to perform screen snapshots, camera snaps, and location captures without consent prompts. Attackers can invoke screen.snapshot, camera.snap, and location.get over the node WebSocket to silently capture screenshots, photograph users through webcams, and obtain device geolocation without user interaction."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 7.1,
                "baseSeverity": "HIGH",
                "privilegesRequired": "LOW",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "NONE"
              },
              "format": "CVSS"
            },
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 6.5,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "NONE",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-862",
                  "description": "Missing Authorization",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-30T19:16:01.014Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "name": "GitHub Security Advisory (GHSA-fxch-cgcp-4v5h)",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://github.com/openclaw/openclaw-windows-node/security/advisories/GHSA-fxch-cgcp-4v5h"
            },
            {
              "tags": [
                "patch"
              ],
              "url": "https://github.com/openclaw/openclaw-windows-node/commit/31a8c6557df740232898079b21f0eb677a4119cf"
            },
            {
              "tags": [
                "patch"
              ],
              "url": "https://github.com/openclaw/openclaw-windows-node/commit/16cb6897941fa7832ce2811e9d550caed9a49b4b"
            },
            {
              "name": "OpenClaw Windows Node v2026.7.1-3 Release Notes",
              "tags": [
                "release-notes"
              ],
              "url": "https://github.com/openclaw/openclaw-windows-node/releases/tag/v2026.7.1-3"
            },
            {
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/openclaw/openclaw-windows-node/blob/v2026.7.1-2/src/OpenClaw.Tray.WinUI/Services/NodeService.cs#L1891-L1913"
            },
            {
              "name": "VulnCheck Advisory: OpenClaw Windows Node before 2026.7.1-3 Missing Authorization",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/openclaw-windows-node-before-2026.7.1-3-missing-authorization"
            }
          ],
          "title": "OpenClaw Windows Node before 2026.7.1-3 Missing Authorization",
          "x_generator": {
            "engine": "vulncheck-endgame"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-101879",
        "datePublished": "2026-09-30T19:16:01.014Z",
        "dateReserved": "2026-09-28T15:44:45.389Z",
        "dateUpdated": "2026-09-30T19:16:01.014Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-102807 (GCVE-0-2026-102807)

    Vulnerability from cvelistv5 – Published: 2026-09-29 17:22 – Updated: 2026-09-29 17:58
    VLAI
    Title
    OpenClaw before 2026.9.4 Authorization Bypass via MCP App Standalone Ticket
    Summary
    OpenClaw before 2026.9.4 contains an incorrect authorization vulnerability in the mcp.app.view method that allows read-scoped operators to execute MCP App tools requiring operator.write scope. Attackers with operator.read tokens can obtain a standalone ticket from mcp.app.view and redeem it at the MCP app view endpoint to invoke state-changing tools without proper authorization checks.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-29 17:58 UTC
    CWE
    • CWE-863 - Incorrect Authorization
    Impacted products
    Vendor Product Version
    OpenClaw OpenClaw Affected: 0 , < 2026.9.4 (semver)
    Unaffected: 2026.9.4 (semver)
        cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-09-09 00:00
    Credits
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-102807",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-29T17:58:34.738470Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-29T17:58:40.914Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageURL": "pkg:npm/openclaw",
              "product": "OpenClaw",
              "vendor": "OpenClaw",
              "versions": [
                {
                  "lessThan": "2026.9.4",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "status": "unaffected",
                  "version": "2026.9.4",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "2026.9.4",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Wentao He"
            }
          ],
          "datePublic": "2026-09-09T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "OpenClaw before 2026.9.4 contains an incorrect authorization vulnerability in the mcp.app.view method that allows read-scoped operators to execute MCP App tools requiring operator.write scope. Attackers with operator.read tokens can obtain a standalone ticket from mcp.app.view and redeem it at the MCP app view endpoint to invoke state-changing tools without proper authorization checks."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "LOW",
                "attackRequirements": "PRESENT",
                "attackVector": "NETWORK",
                "baseScore": 6,
                "baseSeverity": "MEDIUM",
                "privilegesRequired": "LOW",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "NONE",
                "vulnIntegrityImpact": "HIGH"
              },
              "format": "CVSS"
            },
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-863",
                  "description": "Incorrect Authorization",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-29T17:22:40.440Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "name": "Pull Request #142661",
              "tags": [
                "issue-tracking",
                "patch"
              ],
              "url": "https://github.com/openclaw/openclaw/pull/142661"
            },
            {
              "name": "Patch Commit",
              "tags": [
                "patch"
              ],
              "url": "https://github.com/openclaw/openclaw/commit/3bd8ec2b39b5f9e80aef0973f7d17eadc745b8f8"
            },
            {
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/openclaw/openclaw/blob/1391f7cd2d40ab5bbcf2f5f831d3a64f520e72d7/src/gateway/mcp-app-standalone.ts#L209-L215"
            },
            {
              "tags": [
                "release-notes"
              ],
              "url": "https://docs.openclaw.ai/releases/2026.9.4"
            },
            {
              "tags": [
                "product"
              ],
              "url": "https://github.com/openclaw/openclaw"
            },
            {
              "name": "VulnCheck Advisory: OpenClaw before 2026.9.4 Authorization Bypass via MCP App Standalone Ticket",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/openclaw-before-2026.9.4-authorization-bypass-via-mcp-app-standalone-ticket"
            }
          ],
          "title": "OpenClaw before 2026.9.4 Authorization Bypass via MCP App Standalone Ticket",
          "x_generator": {
            "engine": "vulncheck-endgame"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-102807",
        "datePublished": "2026-09-29T17:22:40.440Z",
        "dateReserved": "2026-09-29T17:11:35.367Z",
        "dateUpdated": "2026-09-29T17:58:40.914Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-102806 (GCVE-0-2026-102806)

    Vulnerability from cvelistv5 – Published: 2026-09-29 17:22 – Updated: 2026-09-29 19:55
    VLAI
    Title
    OpenClaw before 2026.9.5 Sandbox Isolation Bypass via Media Pipelines
    Summary
    OpenClaw before 2026.9.5 contains an incorrect authorization vulnerability in the Gateway's local media root allowlist that breaks filesystem isolation between sandboxed sessions. Sandboxed sessions or untrusted content can cause the Gateway to read files from sibling session sandboxes or shared workspace directories through media pipeline functions that fail to restrict reads to the active session.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-29 19:55 UTC
    CWE
    • CWE-863 - Incorrect Authorization
    Impacted products
    Vendor Product Version
    OpenClaw OpenClaw Affected: 0 , < 2026.9.5 (semver)
    Unaffected: 2026.9.5 (semver)
        cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-09-17 00:00
    Credits
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-102806",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-29T19:55:26.822879Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-29T19:55:47.830Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageURL": "pkg:npm/openclaw",
              "product": "OpenClaw",
              "vendor": "OpenClaw",
              "versions": [
                {
                  "lessThan": "2026.9.5",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "status": "unaffected",
                  "version": "2026.9.5",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "2026.9.5",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Wentao He"
            }
          ],
          "datePublic": "2026-09-17T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "OpenClaw before 2026.9.5 contains an incorrect authorization vulnerability in the Gateway\u0027s local media root allowlist that breaks filesystem isolation between sandboxed sessions. Sandboxed sessions or untrusted content can cause the Gateway to read files from sibling session sandboxes or shared workspace directories through media pipeline functions that fail to restrict reads to the active session."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "LOW",
                "attackRequirements": "PRESENT",
                "attackVector": "NETWORK",
                "baseScore": 6,
                "baseSeverity": "MEDIUM",
                "privilegesRequired": "LOW",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "NONE"
              },
              "format": "CVSS"
            },
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 6.3,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "NONE",
                "privilegesRequired": "LOW",
                "scope": "CHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-863",
                  "description": "Incorrect Authorization",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-29T17:22:39.784Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "name": "Pull Request #144347",
              "tags": [
                "issue-tracking",
                "patch"
              ],
              "url": "https://github.com/openclaw/openclaw/pull/144347"
            },
            {
              "name": "Patch Commit",
              "tags": [
                "patch"
              ],
              "url": "https://github.com/openclaw/openclaw/commit/fca04893b5b337d2eb70a6ba41f03fc8e33eff83"
            },
            {
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/openclaw/openclaw/blob/3a9d69db306cd7f081e06254cb89c4bcc14a7107/src/media/local-roots.ts#L33-L60"
            },
            {
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/openclaw/openclaw/blob/3a9d69db306cd7f081e06254cb89c4bcc14a7107/src/media-understanding/runner.attachments.ts#L40-L50"
            },
            {
              "tags": [
                "release-notes"
              ],
              "url": "https://docs.openclaw.ai/releases/2026.9.5"
            },
            {
              "tags": [
                "product"
              ],
              "url": "https://github.com/openclaw/openclaw"
            },
            {
              "name": "VulnCheck Advisory: OpenClaw before 2026.9.5 Sandbox Isolation Bypass via Media Pipelines",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/openclaw-before-2026.9.5-sandbox-isolation-bypass-via-media-pipelines"
            }
          ],
          "title": "OpenClaw before 2026.9.5 Sandbox Isolation Bypass via Media Pipelines",
          "x_generator": {
            "engine": "vulncheck-endgame"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-102806",
        "datePublished": "2026-09-29T17:22:39.784Z",
        "dateReserved": "2026-09-29T17:11:26.586Z",
        "dateUpdated": "2026-09-29T19:55:47.830Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-100604 (GCVE-0-2026-100604)

    Vulnerability from cvelistv5 – Published: 2026-09-26 13:22 – Updated: 2026-09-26 13:22
    VLAI
    Title
    ClawHub Authentication Bypass via Former Publisher Skill Control
    Summary
    ClawHub (openclaw/clawhub) contains an incorrect authorization vulnerability in the ClawHub application/backend: an organization-owned skill retains the ownerUserId of its original publisher, and transfer and lifecycle authorization checks trust that historical user before requiring current organization privileges. An authenticated user who originally published an organization skill can therefore transfer, delete, or restore that skill — taking control of its trusted name and history — even after their organization privileges have been revoked or downgraded. The issue was confirmed at revision cbfee7343ddc867316dd9b3de6fa8856730f9f41; the complete historical affected range was not established. It is fixed by PR #3680, included in revision 8c2de6c506bb4efabe3f0c2ffb8370b9e23d4650, which was deployed to clawhub.ai on 2026-09-11; self-hosted deployments should update to that revision or a later descendant. The npm CLI and OpenClaw runtime are separate products and are not affected.
    CWE
    • CWE-863 - Incorrect Authorization
    Impacted products
    Vendor Product Version
    openclaw clawhub Affected: 0 , < 8c2de6c506bb4efabe3f0c2ffb8370b9e23d4650 (git)
    Unaffected: 8c2de6c506bb4efabe3f0c2ffb8370b9e23d4650 (git)
    Create a notification for this product.
    Date Public
    2026-09-11 00:00
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "clawhub",
              "vendor": "openclaw",
              "versions": [
                {
                  "lessThan": "8c2de6c506bb4efabe3f0c2ffb8370b9e23d4650",
                  "status": "affected",
                  "version": "0",
                  "versionType": "git"
                },
                {
                  "status": "unaffected",
                  "version": "8c2de6c506bb4efabe3f0c2ffb8370b9e23d4650",
                  "versionType": "git"
                }
              ]
            }
          ],
          "datePublic": "2026-09-11T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "ClawHub (openclaw/clawhub) contains an incorrect authorization vulnerability in the ClawHub application/backend: an organization-owned skill retains the ownerUserId of its original publisher, and transfer and lifecycle authorization checks trust that historical user before requiring current organization privileges. An authenticated user who originally published an organization skill can therefore transfer, delete, or restore that skill \u2014 taking control of its trusted name and history \u2014 even after their organization privileges have been revoked or downgraded. The issue was confirmed at revision cbfee7343ddc867316dd9b3de6fa8856730f9f41; the complete historical affected range was not established. It is fixed by PR #3680, included in revision 8c2de6c506bb4efabe3f0c2ffb8370b9e23d4650, which was deployed to clawhub.ai on 2026-09-11; self-hosted deployments should update to that revision or a later descendant. The npm CLI and OpenClaw runtime are separate products and are not affected."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "LOW",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "LOW",
                "vulnConfidentialityImpact": "NONE",
                "vulnIntegrityImpact": "LOW",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS"
            },
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "LOW",
                "baseScore": 5.4,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "LOW",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-863",
                  "description": "Incorrect Authorization",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-26T13:22:48.436Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "name": "GitHub Security Advisory (GHSA-9558-q4f9-324f)",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://github.com/openclaw/clawhub/security/advisories/GHSA-9558-q4f9-324f"
            },
            {
              "name": "Patch Commit",
              "tags": [
                "patch"
              ],
              "url": "https://github.com/openclaw/clawhub/commit/8c2de6c506bb4efabe3f0c2ffb8370b9e23d4650"
            },
            {
              "name": "VulnCheck Advisory: ClawHub Authentication Bypass via Former Publisher Skill Control",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/clawhub-authentication-bypass-via-former-publisher-skill-control"
            }
          ],
          "title": "ClawHub Authentication Bypass via Former Publisher Skill Control",
          "x_generator": {
            "engine": "vulncheck-endgame"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-100604",
        "datePublished": "2026-09-26T13:22:48.436Z",
        "dateReserved": "2026-09-26T01:04:47.562Z",
        "dateUpdated": "2026-09-26T13:22:48.436Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-100603 (GCVE-0-2026-100603)

    Vulnerability from cvelistv5 – Published: 2026-09-26 13:22 – Updated: 2026-09-28 17:05
    VLAI
    Title
    ClawHub before 8c2de6c506 Skill Hiding via Coordinated Reports
    Summary
    ClawHub (openclaw/clawhub) application/backend contains a flaw in the skill report moderation flow: four distinct ordinary authenticated accounts can report a visible skill and trigger automatic hiding (moderationStatus: hidden) of that skill from the catalog without any moderator decision. Because the reporter quota counts only reports filed against visible targets, the same accounts can repeat the process against additional skills; official skills are not exempt. The issue was confirmed at revision cbfee7343ddc867316dd9b3de6fa8856730f9f41; the complete historical affected range was not established. The fix (PR #3681) is included in revision 8c2de6c506bb4efabe3f0c2ffb8370b9e23d4650; self-hosted deployments should update to that revision or a later descendant. The npm CLI and OpenClaw runtime are separate products and are not affected.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-28 17:05 UTC
    CWE
    • CWE-799 - Improper Control of Interaction Frequency
    Impacted products
    Vendor Product Version
    openclaw clawhub Affected: 0 , < 8c2de6c506bb4efabe3f0c2ffb8370b9e23d4650 (git)
    Unaffected: 8c2de6c506bb4efabe3f0c2ffb8370b9e23d4650 (git)
    Create a notification for this product.
    Date Public
    2026-09-11 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-100603",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-28T17:05:07.198454Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-28T17:05:43.542Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "clawhub",
              "vendor": "openclaw",
              "versions": [
                {
                  "lessThan": "8c2de6c506bb4efabe3f0c2ffb8370b9e23d4650",
                  "status": "affected",
                  "version": "0",
                  "versionType": "git"
                },
                {
                  "status": "unaffected",
                  "version": "8c2de6c506bb4efabe3f0c2ffb8370b9e23d4650",
                  "versionType": "git"
                }
              ]
            }
          ],
          "datePublic": "2026-09-11T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "ClawHub (openclaw/clawhub) application/backend contains a flaw in the skill report moderation flow: four distinct ordinary authenticated accounts can report a visible skill and trigger automatic hiding (moderationStatus: hidden) of that skill from the catalog without any moderator decision. Because the reporter quota counts only reports filed against visible targets, the same accounts can repeat the process against additional skills; official skills are not exempt. The issue was confirmed at revision cbfee7343ddc867316dd9b3de6fa8856730f9f41; the complete historical affected range was not established. The fix (PR #3681) is included in revision 8c2de6c506bb4efabe3f0c2ffb8370b9e23d4650; self-hosted deployments should update to that revision or a later descendant. The npm CLI and OpenClaw runtime are separate products and are not affected."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 8.7,
                "baseSeverity": "HIGH",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "LOW",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS"
            },
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "LOW",
                "baseScore": 5.4,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "LOW",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-799",
                  "description": "Improper Control of Interaction Frequency",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-26T13:22:47.730Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "name": "GitHub Security Advisory (GHSA-5jj4-m8c9-gwcq)",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://github.com/openclaw/clawhub/security/advisories/GHSA-5jj4-m8c9-gwcq"
            },
            {
              "name": "Patch Commit",
              "tags": [
                "patch"
              ],
              "url": "https://github.com/openclaw/clawhub/commit/8c2de6c506bb4efabe3f0c2ffb8370b9e23d4650"
            },
            {
              "name": "VulnCheck Advisory: ClawHub before 8c2de6c506 Skill Hiding via Coordinated Reports",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/clawhub-before-8c2de6c506-skill-hiding-via-coordinated-reports"
            }
          ],
          "title": "ClawHub before 8c2de6c506 Skill Hiding via Coordinated Reports",
          "x_generator": {
            "engine": "vulncheck-endgame"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-100603",
        "datePublished": "2026-09-26T13:22:47.730Z",
        "dateReserved": "2026-09-26T01:04:47.561Z",
        "dateUpdated": "2026-09-28T17:05:43.542Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-100602 (GCVE-0-2026-100602)

    Vulnerability from cvelistv5 – Published: 2026-09-26 13:22 – Updated: 2026-09-28 19:13
    VLAI
    Title
    ClawHub Changelog Preview Information Disclosure via Authorization Bypass
    Summary
    ClawHub (openclaw/clawhub application/backend) contains a missing authorization check in the changelog preview feature. A signed-in caller can invoke the public skills:generateChangelogPreview action for a skill they are not authorized to access; the previous version is read without the file-read authorization enforced on normal content access, and up to 8,000 characters of quarantined content may be submitted to the AI provider and reflected in the preview returned to the caller, disclosing restricted skill content. The issue was confirmed at revision cbfee7343ddc867316dd9b3de6fa8856730f9f41; the complete historical affected range was not established. It is fixed by PR #3682, included in revision 8c2de6c506bb4efabe3f0c2ffb8370b9e23d4650, which was deployed to clawhub.ai on 2026-09-11; self-hosted deployments should update to that revision or a later descendant. The npm CLI and OpenClaw runtime are separate products and are not affected.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-28 19:13 UTC
    CWE
    Impacted products
    Vendor Product Version
    openclaw clawhub Affected: 0 , < 8c2de6c506bb4efabe3f0c2ffb8370b9e23d4650 (git)
    Unaffected: 8c2de6c506bb4efabe3f0c2ffb8370b9e23d4650 (git)
    Create a notification for this product.
    Date Public
    2026-09-11 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-100602",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-28T19:13:10.079746Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-28T19:13:23.012Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "clawhub",
              "vendor": "openclaw",
              "versions": [
                {
                  "lessThan": "8c2de6c506bb4efabe3f0c2ffb8370b9e23d4650",
                  "status": "affected",
                  "version": "0",
                  "versionType": "git"
                },
                {
                  "status": "unaffected",
                  "version": "8c2de6c506bb4efabe3f0c2ffb8370b9e23d4650",
                  "versionType": "git"
                }
              ]
            }
          ],
          "datePublic": "2026-09-11T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "ClawHub (openclaw/clawhub application/backend) contains a missing authorization check in the changelog preview feature. A signed-in caller can invoke the public skills:generateChangelogPreview action for a skill they are not authorized to access; the previous version is read without the file-read authorization enforced on normal content access, and up to 8,000 characters of quarantined content may be submitted to the AI provider and reflected in the preview returned to the caller, disclosing restricted skill content. The issue was confirmed at revision cbfee7343ddc867316dd9b3de6fa8856730f9f41; the complete historical affected range was not established. It is fixed by PR #3682, included in revision 8c2de6c506bb4efabe3f0c2ffb8370b9e23d4650, which was deployed to clawhub.ai on 2026-09-11; self-hosted deployments should update to that revision or a later descendant. The npm CLI and OpenClaw runtime are separate products and are not affected."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 7.1,
                "baseSeverity": "HIGH",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "LOW",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "NONE",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS"
            },
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 6.5,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "NONE",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-862",
                  "description": "Missing Authorization",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-26T13:22:47.020Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "name": "GitHub Security Advisory (GHSA-g3jp-jj55-jrcr)",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://github.com/openclaw/clawhub/security/advisories/GHSA-g3jp-jj55-jrcr"
            },
            {
              "name": "Patch Commit",
              "tags": [
                "patch"
              ],
              "url": "https://github.com/openclaw/clawhub/commit/8c2de6c506bb4efabe3f0c2ffb8370b9e23d4650"
            },
            {
              "name": "VulnCheck Advisory: ClawHub Changelog Preview Information Disclosure via Authorization Bypass",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/clawhub-changelog-preview-information-disclosure-via-authorization-bypass"
            }
          ],
          "title": "ClawHub Changelog Preview Information Disclosure via Authorization Bypass",
          "x_generator": {
            "engine": "vulncheck-endgame"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-100602",
        "datePublished": "2026-09-26T13:22:47.020Z",
        "dateReserved": "2026-09-26T01:04:47.561Z",
        "dateUpdated": "2026-09-28T19:13:23.012Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-100601 (GCVE-0-2026-100601)

    Vulnerability from cvelistv5 – Published: 2026-09-26 13:22 – Updated: 2026-09-30 12:47
    VLAI
    Title
    ClawHub SSRF via Unchecked DNS Resolution in Profile Image
    Summary
    ClawHub (openclaw/clawhub) application/backend contains a server-side request forgery vulnerability in the public profile preview's image fetching. The preview accepts a user-supplied image URL and checks the textual hostname against private-address patterns, but does not validate or pin the resolved network destination, so a public-looking hostname can resolve to an internal address or change resolution between validation and connection (DNS rebinding). A maintainer-run local harness demonstrated an outbound connection to an owner-controlled loopback listener; access to production internal services, credential disclosure, and code execution were not demonstrated. The issue was confirmed at revision cbfee7343ddc867316dd9b3de6fa8856730f9f41; the complete historical affected range was not established. Fixed by PR #3683, included in revision 8c2de6c506bb4efabe3f0c2ffb8370b9e23d4650, which was deployed to clawhub.ai on 2026-09-11; self-hosted deployments should update to that revision or a later descendant. The npm CLI and OpenClaw runtime are separate products and are not affected.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-30 12:47 UTC
    CWE
    • CWE-918 - Server-Side Request Forgery (SSRF)
    Impacted products
    Vendor Product Version
    openclaw clawhub Affected: 0 , < 8c2de6c506bb4efabe3f0c2ffb8370b9e23d4650 (git)
    Unaffected: 8c2de6c506bb4efabe3f0c2ffb8370b9e23d4650 (git)
    Create a notification for this product.
    Date Public
    2026-09-11 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-100601",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-30T12:47:07.077181Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-30T12:47:18.560Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "clawhub",
              "vendor": "openclaw",
              "versions": [
                {
                  "lessThan": "8c2de6c506bb4efabe3f0c2ffb8370b9e23d4650",
                  "status": "affected",
                  "version": "0",
                  "versionType": "git"
                },
                {
                  "status": "unaffected",
                  "version": "8c2de6c506bb4efabe3f0c2ffb8370b9e23d4650",
                  "versionType": "git"
                }
              ]
            }
          ],
          "datePublic": "2026-09-11T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "ClawHub (openclaw/clawhub) application/backend contains a server-side request forgery vulnerability in the public profile preview\u0027s image fetching. The preview accepts a user-supplied image URL and checks the textual hostname against private-address patterns, but does not validate or pin the resolved network destination, so a public-looking hostname can resolve to an internal address or change resolution between validation and connection (DNS rebinding). A maintainer-run local harness demonstrated an outbound connection to an owner-controlled loopback listener; access to production internal services, credential disclosure, and code execution were not demonstrated. The issue was confirmed at revision cbfee7343ddc867316dd9b3de6fa8856730f9f41; the complete historical affected range was not established. Fixed by PR #3683, included in revision 8c2de6c506bb4efabe3f0c2ffb8370b9e23d4650, which was deployed to clawhub.ai on 2026-09-11; self-hosted deployments should update to that revision or a later descendant. The npm CLI and OpenClaw runtime are separate products and are not affected."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 6.9,
                "baseSeverity": "MEDIUM",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "NONE",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "LOW",
                "subConfidentialityImpact": "LOW",
                "subIntegrityImpact": "LOW",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:L/SI:L/SA:L",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "NONE",
                "vulnIntegrityImpact": "LOW",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS"
            },
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "LOW",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-918",
                  "description": "Server-Side Request Forgery (SSRF)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-26T13:22:46.283Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "name": "GitHub Security Advisory (GHSA-48gp-hx8w-wjvm)",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://github.com/openclaw/clawhub/security/advisories/GHSA-48gp-hx8w-wjvm"
            },
            {
              "name": "Patch Commit",
              "tags": [
                "patch"
              ],
              "url": "https://github.com/openclaw/clawhub/commit/8c2de6c506bb4efabe3f0c2ffb8370b9e23d4650"
            },
            {
              "name": "VulnCheck Advisory: ClawHub SSRF via Unchecked DNS Resolution in Profile Image",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/clawhub-ssrf-via-unchecked-dns-resolution-in-profile-image"
            }
          ],
          "title": "ClawHub SSRF via Unchecked DNS Resolution in Profile Image",
          "x_generator": {
            "engine": "vulncheck-endgame"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-100601",
        "datePublished": "2026-09-26T13:22:46.283Z",
        "dateReserved": "2026-09-26T01:04:47.561Z",
        "dateUpdated": "2026-09-30T12:47:18.560Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-100600 (GCVE-0-2026-100600)

    Vulnerability from cvelistv5 – Published: 2026-09-26 13:22 – Updated: 2026-09-26 13:22
    VLAI
    Title
    ClawHub before 8c2de6c506 Quota Exhaustion via Anonymous API
    Summary
    ClawHub (the openclaw/clawhub application/backend) does not bind anonymous HTTP API requests to a trusted caller identity, so all direct anonymous API requests share a single default quota allowance. A remote, unauthenticated caller can drain that shared allowance and thereby deny or degrade API access for unrelated visitors. In addition, when the TRUST_FORWARDED_IPS option is enabled without an authenticated edge/proxy, clients can supply arbitrary forwarded IP headers to select quota identities of their choosing and evade rate limiting. The issue was confirmed at revision cbfee7343ddc867316dd9b3de6fa8856730f9f41; the complete historical affected range was not established. It is fixed in revision 8c2de6c506bb4efabe3f0c2ffb8370b9e23d4650 (PR #3684), where direct anonymous calls are redirected to the public API origin without consuming quota and forged identity assertions return HTTP 401. The npm CLI and OpenClaw runtime are separate products and are not affected.
    CWE
    • CWE-770 - Allocation of Resources Without Limits or Throttling
    Impacted products
    Vendor Product Version
    openclaw clawhub Affected: 0 , < 8c2de6c506bb4efabe3f0c2ffb8370b9e23d4650 (git)
    Unaffected: 8c2de6c506bb4efabe3f0c2ffb8370b9e23d4650 (git)
    Create a notification for this product.
    Date Public
    2026-09-11 00:00
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "clawhub",
              "vendor": "openclaw",
              "versions": [
                {
                  "lessThan": "8c2de6c506bb4efabe3f0c2ffb8370b9e23d4650",
                  "status": "affected",
                  "version": "0",
                  "versionType": "git"
                },
                {
                  "status": "unaffected",
                  "version": "8c2de6c506bb4efabe3f0c2ffb8370b9e23d4650",
                  "versionType": "git"
                }
              ]
            }
          ],
          "datePublic": "2026-09-11T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "ClawHub (the openclaw/clawhub application/backend) does not bind anonymous HTTP API requests to a trusted caller identity, so all direct anonymous API requests share a single default quota allowance. A remote, unauthenticated caller can drain that shared allowance and thereby deny or degrade API access for unrelated visitors. In addition, when the TRUST_FORWARDED_IPS option is enabled without an authenticated edge/proxy, clients can supply arbitrary forwarded IP headers to select quota identities of their choosing and evade rate limiting. The issue was confirmed at revision cbfee7343ddc867316dd9b3de6fa8856730f9f41; the complete historical affected range was not established. It is fixed in revision 8c2de6c506bb4efabe3f0c2ffb8370b9e23d4650 (PR #3684), where direct anonymous calls are redirected to the public API origin without consuming quota and forged identity assertions return HTTP 401. The npm CLI and OpenClaw runtime are separate products and are not affected."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 6.9,
                "baseSeverity": "MEDIUM",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "NONE",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "LOW",
                "vulnConfidentialityImpact": "NONE",
                "vulnIntegrityImpact": "NONE",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS"
            },
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "LOW",
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-770",
                  "description": "Allocation of Resources Without Limits or Throttling",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-26T13:22:45.578Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "name": "GitHub Security Advisory (GHSA-4c7q-g7xf-5628)",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://github.com/openclaw/clawhub/security/advisories/GHSA-4c7q-g7xf-5628"
            },
            {
              "name": "Patch Commit",
              "tags": [
                "patch"
              ],
              "url": "https://github.com/openclaw/clawhub/commit/8c2de6c506bb4efabe3f0c2ffb8370b9e23d4650"
            },
            {
              "name": "VulnCheck Advisory: ClawHub before 8c2de6c506 Quota Exhaustion via Anonymous API",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/clawhub-before-8c2de6c506-quota-exhaustion-via-anonymous-api"
            }
          ],
          "title": "ClawHub before 8c2de6c506 Quota Exhaustion via Anonymous API",
          "x_generator": {
            "engine": "vulncheck-endgame"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-100600",
        "datePublished": "2026-09-26T13:22:45.578Z",
        "dateReserved": "2026-09-26T01:04:47.561Z",
        "dateUpdated": "2026-09-26T13:22:45.578Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }