https://advisories.gitlab.com/npm/openclaw/CVE-2026-33577/
OpenClaw: node.pair.approve missing callerScopes validation allows low-privilege operator to...
CVE-2026-33577 OpenClaw: node.pair.approve missing callerScopes validation allows low-privilege operator to approve malicious nodes: The node pairing approval...
openclaw node
https://advisories.gitlab.com/npm/openclaw/CVE-2026-42431/
OpenClaw `node.invoke(browser.proxy)` bypasses `browser.request` persistent profile-mutation guard...
CVE-2026-42431 OpenClaw `node.invoke(browser.proxy)` bypasses `browser.request` persistent profile-mutation guard: OpenClaw node.invoke(browser.proxy) bypasses...
openclaw nodeinvokebrowserproxy
https://advisories.gitlab.com/npm/openclaw/CVE-2026-32058/
OpenClaw Node system.run approval context-binding weakness in approval-enabled host=node flows |...
CVE-2026-32058 OpenClaw Node system.run approval context-binding weakness in approval-enabled host=node flows: In approval-enabled host=node workflows,...
openclaw node
https://advisories.gitlab.com/npm/openclaw/GHSA-r65x-2hqr-j5hf/
OpenClaw: Node reconnect metadata spoofing could bypass platform-based node command policy | GitLab...
GHSA-r65x-2hqr-j5hf OpenClaw: Node reconnect metadata spoofing could bypass platform-based node command policy: A paired node device could reconnect with...
openclaw node
https://advisories.gitlab.com/npm/openclaw/GHSA-cmfr-9m2r-xwhq/
OpenClaw `node.invoke(browser.proxy)` bypasses `browser.request` persistent profile-mutation guard...
GHSA-cmfr-9m2r-xwhq OpenClaw `node.invoke(browser.proxy)` bypasses `browser.request` persistent profile-mutation guard: OpenClaw node.invoke(browser.proxy)...
openclaw nodeinvokebrowserproxy
https://advisories.gitlab.com/npm/openclaw/GHSA-h5hg-h7rr-gpf3/
OpenClaw: Node browser proxy `allowProfiles` bypass through persistent profile mutation and runtime...
GHSA-h5hg-h7rr-gpf3 OpenClaw: Node browser proxy `allowProfiles` bypass through persistent profile mutation and runtime profile selection: Node browser proxy...
openclaw node
https://advisories.gitlab.com/npm/openclaw/GHSA-jqpq-mgvm-f9r6/
OpenClaw: Command hijacking via unsafe PATH handling (bootstrapping + node-host PATH overrides) |...
GHSA-jqpq-mgvm-f9r6 OpenClaw: Command hijacking via unsafe PATH handling (bootstrapping + node-host PATH overrides): OpenClaw previously accepted untrusted...
openclawcommandhijackingviaunsafe
https://advisories.gitlab.com/npm/openclaw/CVE-2026-32043/
OpenClaw's system.run approval TOCTOU via mutable symlink cwd target on node host | GitLab Advisory...
CVE-2026-32043 OpenClaw's system.run approval TOCTOU via mutable symlink cwd target on node host: In openclaw@2026.2.24, approval-bound system.run on node...
https://advisories.gitlab.com/npm/openclaw/GHSA-6x2m-hqfw-hvpj/
OpenClaw: Node exec approvals could be replayed across nodes | GitLab Advisory Database (GLAD)
GHSA-6x2m-hqfw-hvpj OpenClaw: Node exec approvals could be replayed across nodes: exec.approval requests for host=node were not explicitly bound to the target...
https://advisories.gitlab.com/npm/openclaw/GHSA-67mf-f936-ppxf/
OpenClaw `node.pair.approve` placed in `operator.write` scope instead of `operator.pairing` allows...
GHSA-67mf-f936-ppxf OpenClaw `node.pair.approve` placed in `operator.write` scope instead of `operator.pairing` allows unprivileged pairing approval: OpenClaw...
https://advisories.gitlab.com/npm/openclaw/CVE-2026-35648/
OpenClaw may have stale policy enforcement for queued node actions | GitLab Advisory Database (GLAD)
CVE-2026-35648 OpenClaw may have stale policy enforcement for queued node actions: Queued node actions were not revalidated against current command policy when...
https://advisories.gitlab.com/npm/openclaw/GHSA-vvgp-4c28-m3jm/
OpenClaw has a Trusted-proxy Control UI pairing bypass which allows unpaired node sessions | GitLab...
GHSA-vvgp-4c28-m3jm OpenClaw has a Trusted-proxy Control UI pairing bypass which allows unpaired node sessions: A trusted-proxy Control UI pairing bypass...
https://advisories.gitlab.com/npm/openclaw/GHSA-f7ww-2725-qvw2/
OpenClaw: Node system.run approval bypass via parent-symlink cwd rebind | GitLab Advisory Database...
GHSA-f7ww-2725-qvw2 OpenClaw: Node system.run approval bypass via parent-symlink cwd rebind: For host=node executions, approval context could be bypassed after...