| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-32019 | OpenClaw < 2026.2.22 - Incomplete IPv4 Special-Use Range Blocking in SSRF Guard | OpenClaw | OpenClaw | High | 7.4 | 2026-03-19 22:06:56 | Deep Dive |
| CVE-2026-32017 | OpenClaw < 2026.2.19 - Arbitrary File Write via Short-Option Bypass in exec Allowlist | OpenClaw | OpenClaw | High | 7.1 | 2026-03-19 22:06:55 | Deep Dive |
| CVE-2026-32016 | OpenClaw < 2026.2.22 - Path Traversal via Basename-Only Allowlist Matching on macOS | OpenClaw | OpenClaw | High | 7.8 | 2026-03-19 22:06:54 | Deep Dive |
| CVE-2026-32015 | OpenClaw 2026.1.21 < 2026.2.19 - PATH Hijacking Bypass in tools.exec.safeBins Allowlist Validation | OpenClaw | OpenClaw | High | 7.8 | 2026-03-19 22:06:53 | Deep Dive |
| CVE-2026-32014 | OpenClaw < 2026.2.26 - Node Reconnect Metadata Spoofing via Unsigned Platform Fields | OpenClaw | OpenClaw | High | 8.0 | 2026-03-19 22:06:52 | Deep Dive |
| CVE-2026-32011 | OpenClaw < 2026.3.2 - Slow-Request Denial of Service via Pre-Auth Webhook Body Parsing | OpenClaw | OpenClaw | High | 7.5 | 2026-03-19 22:06:51 | Deep Dive |
| CVE-2026-32013 | OpenClaw < 2026.2.25 - Symlink Traversal in agents.files Methods | OpenClaw | OpenClaw | High | 8.8 | 2026-03-19 22:06:51 | Deep Dive |
| CVE-2026-32010 | OpenClaw < 2026.2.22 - Allowlist Bypass via sort --compress-program Parameter | OpenClaw | OpenClaw | Medium | 6.3 | 2026-03-19 22:06:50 | Deep Dive |
| CVE-2026-32009 | OpenClaw < 2026.2.24 - Binary Hijacking via Static Default Trusted Directories in safeBins | OpenClaw | OpenClaw | Medium | 5.7 | 2026-03-19 22:06:49 | Deep Dive |
| CVE-2026-32008 | OpenClaw < 2026.2.21 - Arbitrary Local File Read via Browser Navigation Guard | OpenClaw | OpenClaw | Medium | 6.5 | 2026-03-19 22:06:48 | Deep Dive |
| CVE-2026-32007 | OpenClaw < 2026.2.23 - Sandbox Bypass in apply_patch Tool via Workspace-Only Check Bypass | OpenClaw | OpenClaw | Medium | 6.8 | 2026-03-19 22:06:47 | Deep Dive |
| CVE-2026-32005 | OpenClaw < 2026.2.25 - Authorization Bypass in Interactive Callbacks via Sender Check Skip | OpenClaw | OpenClaw | Medium | 6.8 | 2026-03-19 22:06:46 | Deep Dive |
| CVE-2026-32006 | OpenClaw < 2026.2.26 - Authorization Bypass via DM Pairing-Store Fallback in Group Allowlist | OpenClaw | OpenClaw | Low | 3.1 | 2026-03-19 22:06:46 | Deep Dive |
| CVE-2026-32004 | OpenClaw < 2026.3.2 - Authentication Bypass via Encoded Path in /api/channels Route | OpenClaw | OpenClaw | Medium | 6.5 | 2026-03-19 22:06:45 | Deep Dive |
| CVE-2026-32003 | OpenClaw < 2026.2.22 - Remote Code Execution via SHELLOPTS/PS4 Environment Injection in system.run | OpenClaw | OpenClaw | Medium | 6.6 | 2026-03-19 22:06:44 | Deep Dive |
| CVE-2026-32002 | OpenClaw < 2026.2.23 - Sandbox Boundary Bypass via Image Tool workspaceOnly Bypass | OpenClaw | OpenClaw | Medium | 5.3 | 2026-03-19 22:06:43 | Deep Dive |
| CVE-2026-32001 | OpenClaw < 2026.2.22 - Node Role Device-Identity Bypass via WebSocket Authentication | OpenClaw | OpenClaw | Medium | 5.4 | 2026-03-19 22:06:42 | Deep Dive |
| CVE-2026-32000 | OpenClaw < 2026.2.19 - Command Injection via Windows Shell Fallback in Lobster Tool Execution | OpenClaw | OpenClaw | High | 7.1 | 2026-03-19 01:00:57 | Deep Dive |
| CVE-2026-31998 | OpenClaw 2026.2.22 < 2026.2.24 - Authorization Bypass in Synology Chat Plugin via Empty allowedUserIds | OpenClaw | OpenClaw | High | 8.6 | 2026-03-19 01:00:56 | Deep Dive |
| CVE-2026-31999 | OpenClaw 2026.2.26 < 2026.3.1 - Current Working Directory Injection via Windows Wrapper Resolution Fallback | OpenClaw | OpenClaw | Medium | 6.3 | 2026-03-19 01:00:56 | Deep Dive |