SB2026052906 - Multiple vulnerabilities in OpenClaw
Published: May 29, 2026 Updated: June 30, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 8 vulnerabilities.
1) Incomplete List of Disallowed Inputs (CVE-ID: N/A)
CWE-ID: CWE-184 - Incomplete List of Disallowed Inputs
CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to influence a Node.js child process or coverage output path.
The vulnerability exists due to incomplete list of disallowed inputs in the host environment sanitizer when processing lower-trust environment sources. A remote user can supply crafted environment variables through a workspace .env, tool environment override, or skill environment block to influence a Node.js child process or coverage output path.
Only instances where the affected feature is enabled and reachable are vulnerable, and practical impact depends on whether lower-trust input can reach the accepted environment path.
2) Incomplete List of Disallowed Inputs (CVE-ID: N/A)
CWE-ID: CWE-184 - Incomplete List of Disallowed Inputs
CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to trigger unintended wrapper-level side effects.
The vulnerability exists due to incomplete neutralization of special elements in the exec allowlist path when processing command requests through transparent command wrappers. A remote user can submit a crafted command request to trigger unintended wrapper-level side effects.
Exploitation requires the affected feature to be enabled and reachable, and practical impact depends on whether lower-trust input can reach that path.
3) Server-Side Request Forgery (SSRF) (CVE-ID: N/A)
CWE-ID: CWE-918 - Server-Side Request Forgery (SSRF)
CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to perform server-side request forgery.
The vulnerability exists due to improper input validation in hostname policy checks for model- or workspace-derived URLs when handling a hostname presented with a trailing dot. A remote user can supply a URL using a trailing-dot hostname to perform server-side request forgery.
Exploitation requires the affected feature to be enabled and reachable, and practical impact depends on whether lower-trust input can reach the affected request path.
4) Improper access control (CVE-ID: N/A)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to regain revoked node token authority.
The vulnerability exists due to improper access control in the device session handling logic when processing a surviving pairing-scoped session after node token revocation. A remote user can maintain a same-device pairing-scoped session to regain revoked node token authority.
The issue affects deployments where an already paired device retains a same-device session with pairing-related scope after its node token is revoked.
5) Incorrect authorization (CVE-ID: N/A)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to bypass authorization checks.
The vulnerability exists due to improper access control in hooks allowedAgentIds handling when processing blank agent IDs. A remote user can supply a blank agent ID to bypass authorization checks.
Only the named feature and configuration are affected, and practical impact depends on whether lower-trust input can reach the vulnerable path.
6) Improper Restriction of Excessive Authentication Attempts (CVE-ID: N/A)
CWE-ID: CWE-307 - Improper Restriction of Excessive Authentication Attempts
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper restriction of excessive authentication attempts in the WebSocket authentication feature when handling authentication attempts over reachable WebSocket paths. A remote attacker can send repeated authentication attempts to cause a denial of service.
Exploitation requires the affected feature to be enabled and reachable, and practical impact depends on whether lower-trust input can reach that path.
7) Incorrect authorization (CVE-ID: N/A)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to bypass intended authorization controls.
The vulnerability exists due to improper access control in ClickClack allowFrom when processing lower-trust caller or configured input paths. A remote user can invoke non-allowlisted commands to bypass intended authorization controls.
Only instances where the affected feature is enabled and reachable are vulnerable.
8) Server-Side Request Forgery (SSRF) (CVE-ID: N/A)
CWE-ID: CWE-918 - Server-Side Request Forgery (SSRF)
CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N]
The vulnerability allows a remote user to access network destinations that should have been blocked by OpenClaw policy.
The vulnerability exists due to server-side request forgery (SSRF) in browser snapshot routes when processing post-navigation requests. A remote user can supply a crafted input path to access network destinations that should have been blocked by OpenClaw policy.
Only instances with the affected feature enabled and reachable are vulnerable, and practical impact depends on whether lower-trust input can reach that path.
Remediation
Install update from vendor's website.
References
- https://github.com/openclaw/openclaw/security/advisories/GHSA-ccwh-wwpp-6wg5
- https://github.com/openclaw/openclaw/security/advisories/GHSA-cwpp-5962-q4f6
- https://github.com/openclaw/openclaw/security/advisories/GHSA-gxg4-2rrr-jhc7
- https://github.com/openclaw/openclaw/security/advisories/GHSA-q99w-vh6v-q3v7
- https://github.com/openclaw/openclaw/security/advisories/GHSA-724r-v4wf-mqc5
- https://github.com/openclaw/openclaw/security/advisories/GHSA-5p6w-wmh3-frfr
- https://github.com/openclaw/openclaw/security/advisories/GHSA-fh8v-vgcv-pwh4
- https://github.com/openclaw/openclaw/security/advisories/GHSA-2x93-h3hg-2xfp