Robuta

https://advisories.gitlab.com/npm/openclaw/CVE-2026-33577/ OpenClaw: node.pair.approve missing callerScopes validation allows low-privilege operator to... CVE-2026-33577 OpenClaw: node.pair.approve missing callerScopes validation allows low-privilege operator to approve malicious nodes: The node pairing approval... openclaw node https://advisories.gitlab.com/npm/openclaw/CVE-2026-42431/ OpenClaw `node.invoke(browser.proxy)` bypasses `browser.request` persistent profile-mutation guard... CVE-2026-42431 OpenClaw `node.invoke(browser.proxy)` bypasses `browser.request` persistent profile-mutation guard: OpenClaw node.invoke(browser.proxy) bypasses... openclaw nodeinvokebrowserproxy https://advisories.gitlab.com/npm/openclaw/CVE-2026-32058/ OpenClaw Node system.run approval context-binding weakness in approval-enabled host=node flows |... CVE-2026-32058 OpenClaw Node system.run approval context-binding weakness in approval-enabled host=node flows: In approval-enabled host=node workflows,... openclaw node https://advisories.gitlab.com/npm/openclaw/GHSA-r65x-2hqr-j5hf/ OpenClaw: Node reconnect metadata spoofing could bypass platform-based node command policy | GitLab... GHSA-r65x-2hqr-j5hf OpenClaw: Node reconnect metadata spoofing could bypass platform-based node command policy: A paired node device could reconnect with... openclaw node https://advisories.gitlab.com/npm/openclaw/GHSA-cmfr-9m2r-xwhq/ OpenClaw `node.invoke(browser.proxy)` bypasses `browser.request` persistent profile-mutation guard... GHSA-cmfr-9m2r-xwhq OpenClaw `node.invoke(browser.proxy)` bypasses `browser.request` persistent profile-mutation guard: OpenClaw node.invoke(browser.proxy)... openclaw nodeinvokebrowserproxy https://advisories.gitlab.com/npm/openclaw/GHSA-h5hg-h7rr-gpf3/ OpenClaw: Node browser proxy `allowProfiles` bypass through persistent profile mutation and runtime... GHSA-h5hg-h7rr-gpf3 OpenClaw: Node browser proxy `allowProfiles` bypass through persistent profile mutation and runtime profile selection: Node browser proxy... openclaw node https://advisories.gitlab.com/npm/openclaw/GHSA-jqpq-mgvm-f9r6/ OpenClaw: Command hijacking via unsafe PATH handling (bootstrapping + node-host PATH overrides) |... GHSA-jqpq-mgvm-f9r6 OpenClaw: Command hijacking via unsafe PATH handling (bootstrapping + node-host PATH overrides): OpenClaw previously accepted untrusted... openclawcommandhijackingviaunsafe https://advisories.gitlab.com/npm/openclaw/CVE-2026-32043/ OpenClaw's system.run approval TOCTOU via mutable symlink cwd target on node host | GitLab Advisory... CVE-2026-32043 OpenClaw's system.run approval TOCTOU via mutable symlink cwd target on node host: In openclaw@2026.2.24, approval-bound system.run on node... https://advisories.gitlab.com/npm/openclaw/GHSA-6x2m-hqfw-hvpj/ OpenClaw: Node exec approvals could be replayed across nodes | GitLab Advisory Database (GLAD) GHSA-6x2m-hqfw-hvpj OpenClaw: Node exec approvals could be replayed across nodes: exec.approval requests for host=node were not explicitly bound to the target... https://advisories.gitlab.com/npm/openclaw/GHSA-67mf-f936-ppxf/ OpenClaw `node.pair.approve` placed in `operator.write` scope instead of `operator.pairing` allows... GHSA-67mf-f936-ppxf OpenClaw `node.pair.approve` placed in `operator.write` scope instead of `operator.pairing` allows unprivileged pairing approval: OpenClaw... https://advisories.gitlab.com/npm/openclaw/CVE-2026-35648/ OpenClaw may have stale policy enforcement for queued node actions | GitLab Advisory Database (GLAD) CVE-2026-35648 OpenClaw may have stale policy enforcement for queued node actions: Queued node actions were not revalidated against current command policy when... https://advisories.gitlab.com/npm/openclaw/GHSA-vvgp-4c28-m3jm/ OpenClaw has a Trusted-proxy Control UI pairing bypass which allows unpaired node sessions | GitLab... GHSA-vvgp-4c28-m3jm OpenClaw has a Trusted-proxy Control UI pairing bypass which allows unpaired node sessions: A trusted-proxy Control UI pairing bypass... https://advisories.gitlab.com/npm/openclaw/GHSA-f7ww-2725-qvw2/ OpenClaw: Node system.run approval bypass via parent-symlink cwd rebind | GitLab Advisory Database... GHSA-f7ww-2725-qvw2 OpenClaw: Node system.run approval bypass via parent-symlink cwd rebind: For host=node executions, approval context could be bypassed after...