openclaw vulnerabilities

Direct Vulnerabilities

Known vulnerabilities in the openclaw package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • L
GHSA-jq3f-vjww-8rq7

<2026.3.13.1-r0
  • L
GHSA-g2f6-pwvx-r275

<2026.3.13.1-r0
  • L
GHSA-63f5-hhc7-cx6p

<2026.3.13.1-r0
  • L
GHSA-xwcj-hwhf-h378

<2026.3.13.1-r0
  • L
GHSA-vr7j-g7jv-h5mp

<2026.2.17-r0
  • L
GHSA-m69h-jm2f-2pv8

<2026.3.13.1-r0
  • L
CVE-2026-2229

<2026.3.13.1-r0
  • L
GHSA-5m9r-p9g7-679c

<2026.3.13.1-r0
  • L
GHSA-r7vr-gr74-94p8

<2026.3.13.1-r0
  • L
GHSA-7h7g-x2px-94hj

<2026.3.13.1-r0
  • L
CVE-2026-1528

<2026.3.13.1-r0
  • L
CVE-2026-2581

<2026.3.13.1-r0
  • L
GHSA-g353-mgv3-8pcj

<2026.3.13.1-r0
  • L
Improper Handling of Highly Compressed Data (Data Amplification)

<2026.3.13.1-r0
  • L
CVE-2026-1527

<2026.3.13.1-r0
  • L
GHSA-rqpp-rjj8-7wv8

<2026.3.13.1-r0
  • L
CVE-2026-1526

<2026.3.13.1-r0
  • C
CVE-2026-1525

<2026.3.13.1-r0
  • L
GHSA-99qw-6mr3-36qr

<2026.3.13.1-r0
  • L
GHSA-f5mf-3r52-r83w

<2026.3.13.1-r0
  • L
GHSA-xvx8-77m6-gwg6

<2026.3.12-r0
  • L
GHSA-vmhq-cqm9-6p7q

<2026.3.12-r0
  • L
GHSA-xf99-j42q-5w5p

<2026.3.12-r0
  • L
GHSA-4jpw-hj22-2xmc

<2026.3.12-r0
  • L
GHSA-9vvh-2768-c8vp

<2026.3.12-r0
  • L
GHSA-qvr7-g57c-mrc7

<2026.3.12-r0
  • L
GHSA-qc36-x95h-7j53

<2026.3.12-r0
  • L
GHSA-jf6w-m8jw-jfxc

<2026.3.12-r0
  • L
GHSA-f8r2-vg7x-gh8m

<2026.3.12-r0
  • L
GHSA-4w7m-58cg-cmff

<2026.3.12-r0
  • L
GHSA-rw39-5899-8mxp

<2026.3.12-r0
  • L
GHSA-wcxr-59v9-rxr8

<2026.3.12-r0
  • L
GHSA-8jhh-jcqg-mj5p

<2026.3.12-r0
  • L
GHSA-xw77-45gv-p728

<2026.3.12-r0
  • L
GHSA-mj4p-rc52-m843

<2026.3.12-r0
  • L
GHSA-2rqg-gjgv-84jm

<2026.3.12-r0
  • L
GHSA-vhwf-4x96-vqx2

<2026.3.11-r0
  • L
Origin Validation Error

<2026.3.12-r0
  • L
GHSA-gp3q-wpq4-5c5h

<2026.3.2-r0
  • L
GHSA-v8cg-4474-49v8

<2026.3.2-r0
  • L
GHSA-g7cr-9h7q-4qxq

<2026.3.11-r0
  • L
GHSA-8g75-q649-6pv6

<2026.3.11-r0
  • L
GHSA-qcc4-p59m-p54m

<2026.3.2-r0
  • L
GHSA-mgrq-9f93-wpp5

<2026.3.2-r0
  • L
GHSA-8j2w-6fmm-m587

<2026.3.2-r0
  • M
Directory Traversal

<2026.3.11-r0
  • L
Loop with Unreachable Exit Condition ('Infinite Loop')

<2026.3.11-r0
  • L
GHSA-v8w9-8mx6-g223

<2026.3.11-r0
  • L
GHSA-r6qf-8968-wj9q

<2026.3.11-r0
  • L
GHSA-3h2q-j2v4-6w5r

<2026.3.11-r0
  • L
GHSA-9q2p-vc84-2rwm

<2026.3.11-r0
  • L
GHSA-rchv-x836-w7xp

<2026.3.11-r0
  • L
GHSA-6rmx-gvvg-vh6j

<2026.3.11-r0
  • L
GHSA-hfpr-jhpq-x4rm

<2026.3.11-r0
  • L
GHSA-9q36-67vc-rrwg

<2026.3.11-r0
  • L
GHSA-pjvx-rx66-r3fg

<2026.3.11-r0
  • L
GHSA-6mgf-v5j7-45cr

<2026.3.11-r0
  • L
GHSA-j425-whc4-4jgc

<2026.3.11-r0
  • L
OS Command Injection

<2026.2.26-r0
  • L
GHSA-474h-prjg-mmw3

<2026.3.7-r0
  • L
GHSA-cfvj-7rx7-fc7c

<2026.3.7-r0
  • L
Arbitrary Code Injection

<2026.3.7-r0
  • L
GHSA-3pxq-f3cp-jmxp

<2026.3.7-r0
  • L
GHSA-2858-xg23-26fp

<2026.3.7-r0
  • C
Improper Handling of URL Encoding (Hex Encoding)

<2026.3.7-r0
  • L
GHSA-77hf-7fqf-f227

<2026.3.7-r0
  • L
GHSA-wpg9-4g4v-f9rc

<2026.3.7-r0
  • L
GHSA-8mvx-p2r9-r375

<2026.3.7-r0
  • L
GHSA-h3rm-6x7g-882f

<2026.3.7-r0
  • L
GHSA-r54r-wmmq-mh84

<2026.3.7-r0
  • L
GHSA-x4vp-4235-65hg

<2026.3.7-r0
  • M
Directory Traversal

<2026.3.7-r0
  • L
Incorrect Authorization

<2026.3.7-r0
  • L
Inappropriate Comment Style

<2026.3.7-r0
  • M
Cross-site Scripting (XSS)

<2026.3.7-r0
  • L
GHSA-v865-p3gq-hw6m

<2026.3.7-r0
  • L
GHSA-3jx4-q2m7-r496

<2026.3.2-r0
  • L
GHSA-x2ff-j5c2-ggpr

<2026.3.2-r0
  • L
GHSA-q6qf-4p5j-r25g

<2026.2.23-r0
  • L
GHSA-jwf4-8wf4-jf2m

<2026.2.23-r0
  • L
GHSA-vjp8-wprm-2jw9

<2026.3.2-r0
  • L
GHSA-f6h3-846h-2r8w

<2026.2.23-r0
  • L
GHSA-4rqq-w8v4-7p47

<2026.2.23-r0
  • L
GHSA-8cp7-rp8r-mg77

<2026.2.19-r0
  • L
GHSA-jjgj-cpp9-cvpv

<2026.2.21-r0
  • L
GHSA-9mph-4f7v-fmvh

<2026.2.23-r0
  • L
GHSA-vvjh-f6p9-5vcf

<2026.2.19-r0
  • L
GHSA-25gx-x37c-7pph

<2026.2.21-r0
  • L
GHSA-qhrr-grqp-6x2g

<2026.2.23-r0
  • L
GHSA-xmv6-r34m-62p4

<2026.3.2-r0
  • L
GHSA-5847-rm3g-23mw

<2026.2.23-r0
  • L
GHSA-rm2p-j3r7-4x4j

<2026.3.2-r0
  • L
GHSA-cjv3-m589-v3rx

<2026.2.21-r0
  • L
GHSA-534w-2vm4-89xr

<2026.2.25-r0
  • L
GHSA-h656-5vcf-cm23

<2026.2.25-r0
  • L
GHSA-8fmp-37rc-p5g7

<2026.2.21-r0
  • L
GHSA-25pw-4h6w-qwvm

<2026.3.2-r0
  • L
GHSA-vj3g-5px3-gr46

<2026.2.19-r0
  • L
GHSA-48wf-g7cp-gr3m

<2026.2.23-r0
  • L
GHSA-h9xm-j4qg-fvpg

<2026.2.23-r0
  • L
GHSA-gw85-xp4q-5gp9

<2026.2.25-r0
  • L
GHSA-2ww6-868g-2c56

<2026.2.23-r0
  • L
GHSA-jj82-76v6-933r

<2026.2.23-r0
  • L
GHSA-9868-vxmx-w862

<2026.2.23-r0
  • L
GHSA-5h2c-8v84-qpvr

<2026.2.23-r0
  • L
GHSA-w7j5-j98m-w679

<2026.2.21-r0
  • L
GHSA-vvgp-4c28-m3jm

<2026.3.2-r0
  • L
GHSA-mqr9-vqhq-3jxw

<2026.2.19-r0
  • L
GHSA-2ch6-x3g4-7759

<2026.2.23-r0
  • L
GHSA-45cg-2683-gfmq

<2026.2.21-r0
  • L
GHSA-pj5x-38rw-6fph

<2026.2.19-r0
  • L
GHSA-pfv7-rr5m-qmv6

<2026.2.19-r0
  • L
GHSA-vqx8-9xxw-f2m7

<2026.2.23-r0
  • L
GHSA-jxrq-8fm4-9p58

<2026.2.23-r0
  • L
GHSA-w9cg-v44m-4qv8

<2026.2.21-r0
  • L
GHSA-f8mp-vj46-cq8v

<2026.2.23-r0
  • L
GHSA-vmqr-rc7x-3446

<2026.2.23-r0
  • L
GHSA-jv6r-27ww-4gw4

<2026.3.2-r0
  • L
GHSA-7fcc-cw49-xm78

<2026.2.19-r0
  • L
GHSA-9p38-94jf-hgjj

<2026.2.23-r0
  • L
GHSA-2rgf-hm63-5qph

<2026.2.19-r0
  • L
GHSA-7f4q-9rqh-x36p

<2026.2.23-r0
  • L
GHSA-3cvx-236h-m9fj

<2026.2.19-r0
  • L
GHSA-62f6-mrcj-v8h5

<2026.2.21-r0
  • L
GHSA-jmmg-jqc7-5qf4

<2026.3.2-r0
  • L
GHSA-qj22-xqjr-v83v

<2026.3.2-r0
  • L
GHSA-r9q5-c7qc-p26w

<2026.3.2-r0
  • L
GHSA-fg3m-vhrr-8gj6

<2026.2.19-r0
  • L
GHSA-4gc7-qcvf-38wg

<2026.2.21-r0
  • L
GHSA-2fgq-7j6h-9rm4

<2026.2.23-r0
  • L
GHSA-wpph-cjgr-7c39

<2026.2.23-r0
  • L
GHSA-ccg8-46r6-9qgj

<2026.2.25-r0
  • L
GHSA-g75x-8qqm-2vxp

<2026.2.19-r0
  • L
GHSA-3c6h-g97w-fg78

<2026.2.23-r0
  • L
GHSA-r65x-2hqr-j5hf

<2026.3.2-r0
  • L
GHSA-6g25-pc82-vfwp

<2026.3.2-r0
  • L
GHSA-43x4-g22p-3hrq

<2026.2.21-r0
  • L
GHSA-mwxv-35wr-4vvj

<2026.3.2-r0
  • L
GHSA-8mf7-vv8w-hjr2

<2026.2.23-r0
  • L
GHSA-3xfw-4pmr-4xc5

<2026.2.21-r0
  • L
GHSA-2mc2-g238-722j

<2026.2.19-r0
  • L
GHSA-hff7-ccv5-52f8

<2026.2.21-r0
  • L
GHSA-mwcg-wfq3-4gjc

<2026.3.2-r0
  • L
GHSA-2hm8-rqrm-xfjq

<2026.2.19-r0
  • L
GHSA-553v-f69r-656j

<2026.3.2-r0
  • L
GHSA-6rcp-vxwf-3mfp

<2026.2.25-r0
  • L
GHSA-gcj7-r3hg-m7w6

<2026.3.2-r0
  • L
GHSA-ff98-w8hj-qrxf

<2026.2.19-r0
  • L
GHSA-v3j7-34xh-6g3w

<2026.2.21-r0
  • L
GHSA-7ff8-xjh3-mgh6

<2026.2.23-r0
  • L
GHSA-27cr-4p5m-74rj

<2026.2.25-r0
  • L
GHSA-j4xf-96qf-rx69

<2026.2.23-r0
  • L
GHSA-3x3x-h76w-hp98

<2026.2.19-r0
  • L
GHSA-354r-7mfh-7rh2

<2026.3.2-r0
  • L
GHSA-rv2q-f2h5-6xmg

<2026.2.23-r0
  • L
GHSA-4cqv-h74h-93j4

<2026.2.21-r0
  • L
GHSA-vffc-f7r7-rx2w

<2026.2.19-r0
  • L
GHSA-j26j-7qc4-3mrf

<2026.3.2-r0
  • L
GHSA-h97f-6pqj-q452

<2026.3.2-r0
  • L
GHSA-659f-22xc-98f2

<2026.2.21-r0
  • L
GHSA-33hm-cq8r-wc49

<2026.2.25-r0
  • L
GHSA-r294-2894-92j3

<2026.2.23-r0
  • L
GHSA-m8v2-6wwh-r4gc

<2026.2.25-r0
  • L
GHSA-w76h-8m22-hpgh

<2026.2.23-r0
  • L
GHSA-xgf2-vxv2-rrmg

<2026.2.23-r0
  • L
GHSA-v6x2-2qvm-6gv8

<2026.2.21-r0
  • L
GHSA-792q-qw95-f446

<2026.3.2-r0
  • L
GHSA-7qf6-h84j-8fq4

<2026.3.2-r0
  • L
GHSA-gq83-8q7q-9hfx

<2026.2.19-r0
  • L
GHSA-9f72-qcpw-2hxc

<2026.2.25-r0
  • L
GHSA-x9cf-3w63-rpq9

<2026.2.19-r0
  • L
GHSA-5gj7-jf77-q2q2

<2026.2.25-r0
  • L
GHSA-796m-2973-wc5q

<2026.2.23-r0
  • L
GHSA-56pc-6hvp-4gv4

<2026.2.17-r0
  • L
GHSA-5ghc-98wh-gwwf

<2026.2.23-r0
  • L
GHSA-wm8r-w8pf-2v6w

<2026.3.2-r0
  • L
GHSA-fqcm-97m6-w7rm

<2026.2.25-r0
  • L
GHSA-g99v-8hwm-g76g

<2026.3.2-r0
  • L
GHSA-8m9v-xpgf-g99m

<2026.3.2-r0
  • L
GHSA-jq4x-98m3-ggq6

<2026.2.21-r0
  • L
GHSA-gwqp-86q6-w47g

<2026.2.23-r0
  • L
GHSA-vpj2-69hf-rppw

<2026.3.2-r0
  • L
GHSA-x82f-27x3-q89c

<2026.3.2-r0
  • L
GHSA-5v6x-rfc3-7qfr

<2026.2.21-r0
  • L
GHSA-rx3g-mvc3-qfjf

<2026.2.23-r0
  • L
GHSA-hjvp-qhm6-wrh2

<2026.3.2-r0
  • L
GHSA-6j27-pc5c-m8w8

<2026.2.23-r0
  • L
GHSA-6x2m-hqfw-hvpj

<2026.2.23-r0
  • L
GHSA-wr6m-jg37-68xh

<2026.3.2-r0
  • L
GHSA-q399-23r3-hfx4

<2026.3.2-r0
  • L
GHSA-mfg5-7q5g-f37j

<2026.2.23-r0
  • L
GHSA-c6hr-w26q-c636

<2026.2.19-r0
  • L
GHSA-392f-ggf5-fp3c

<2026.3.2-r0
  • L
GHSA-p7gr-f84w-hqg5

<2026.3.2-r0
  • L
GHSA-f7ww-2725-qvw2

<2026.3.2-r0
  • L
GHSA-36h3-7c54-j27r

<2026.3.2-r0
  • L
GHSA-7xmq-g46g-f8pv

<2026.3.2-r0
  • L
GHSA-jr6x-2q95-fh2g

<2026.3.2-r0
  • L
GHSA-6f6j-wx9w-ff4j

<2026.3.2-r0
  • L
GHSA-fgvx-58p6-gjwc

<2026.3.2-r0
  • L
GHSA-ww6v-v748-x7g9

<2026.2.25-r0
  • L
GHSA-hwpq-rrpf-pgcq

<2026.3.2-r0
  • L
GHSA-5f9p-f3w2-fwch

<2026.2.23-r0
  • L
GHSA-rxxp-482v-7mrh

<2026.2.23-r0
  • H
Buffer Overflow

<2026.3.7-r0
  • H
Incomplete Blacklist

<2026.2.23-r0
  • L
GHSA-82g8-464f-2mv7

<2026.2.21-r0
  • L
GHSA-7jx5-9fjg-hp4m

<2026.2.23-r0
  • L
Algorithmic Complexity

<2026.2.26-r0
  • L
Inefficient Regular Expression Complexity

<2026.2.26-r0
  • C
Directory Traversal

<2026.2.22-r0
  • C
Directory Traversal

<2026.2.24-r0
  • M
Resource Exhaustion

<2026.2.19-r0
  • L
GHSA-gq3j-xvxp-8hrf

<2026.2.21-r0
  • M
Missing Authorization

<2026.2.19-r0
  • L
Incorrect Regular Expression

<2026.2.19-r0
  • H
Server-Side Request Forgery (SSRF)

<2026.2.19-r0
  • M
Symlink Following

<2026.2.19-r0
  • L
GHSA-6c9j-x93c-rw6j

<2026.2.19-r0
  • L
GHSA-4685-c5cp-vp95

<2026.2.19-r0
  • M
Directory Traversal

<2026.2.17-r1
  • L
Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion')

<2026.2.19-r0
  • M
Server-Side Request Forgery (SSRF)

<2026.2.19-r0
  • H
Directory Traversal

<2026.2.17-r1
  • H
Inefficient Regular Expression Complexity

<2026.2.19-r0
  • M
Improper Handling of Unicode Encoding

<2026.2.17-r1
  • L
Inefficient Regular Expression Complexity

<2026.2.19-r0
  • L
Directory Traversal

<2026.2.17-r1