Openclaw Windows Node vulnerabilities
6 known vulnerabilities affecting openclaw/openclaw_windows_node.
Total CVEs
6
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH3MEDIUM3
Vulnerabilities
Page 1 of 1
CVE-2026-101880P2HIGHCVSS 8.8fixed in 2026.7.12026-09-30
CVE-2026-101880 [HIGH] CWE-863 CVE-2026-101880: OpenClaw Windows Node before 2026.7.1 contains an incorrect authorization vulnerability in the syste
OpenClaw Windows Node before 2026.7.1 contains an incorrect authorization vulnerability in the system.run exec-approval policy where ExecShellWrapperParser fails to split commands on pipe operators or extract command substitutions. Connected gateways or agents can bypass approval rules by placing denied commands behind allowed prefixes using pipe op
nvd
CVE-2026-101882P2HIGHCVSS 8.8fixed in 2026.7.12026-09-30
CVE-2026-101882 [HIGH] CWE-184 CVE-2026-101882: OpenClaw Windows Node before 2026.7.1 contains an incomplete validation vulnerability in system.exec
OpenClaw Windows Node before 2026.7.1 contains an incomplete validation vulnerability in system.execApprovals.set that accepts wildcard-executable rules and abusable system binaries like mshta, rundll32, and certutil. Remote callers can add broad allow rules to execute arbitrary commands on the Windows host through system.run without operator checks
nvd
CVE-2026-101884P3HIGHCVSS 7.5fixed in 2026.7.12026-09-30
CVE-2026-101884 [HIGH] CWE-184 CVE-2026-101884: OpenClaw Windows Node before 2026.7.1 contains an incomplete environment-variable sanitizer in syste
OpenClaw Windows Node before 2026.7.1 contains an incomplete environment-variable sanitizer in system.run that fails to block GIT_CONFIG_*, DOTNET_STARTUP_HOOKS, and JAVA_TOOL_OPTIONS variables. Attackers with gateway or agent access can supply these variables to allowlisted tools like git, dotnet, or java to load attacker-controlled code and achiev
nvd
CVE-2026-101879P3MEDIUMCVSS 6.5fixed in 2026.7.1-32026-09-30
CVE-2026-101879 [MEDIUM] CWE-862 CVE-2026-101879: OpenClaw Windows Node before 2026.7.1-3 contains a missing authorization vulnerability in NodeServic
OpenClaw Windows Node before 2026.7.1-3 contains a missing authorization vulnerability in NodeService capture handlers that allows connected gateways or agents to perform screen snapshots, camera snaps, and location captures without consent prompts. Attackers can invoke screen.snapshot, camera.snap, and location.get over the node WebSocket to sile
nvd
CVE-2026-101881P3MEDIUMCVSS 6.5fixed in 2026.7.12026-09-30
CVE-2026-101881 [MEDIUM] CWE-770 CVE-2026-101881: OpenClaw Windows Node before 2026.7.1 contains an allocation of resources without limits vulnerabili
OpenClaw Windows Node before 2026.7.1 contains an allocation of resources without limits vulnerability in the gateway WebSocket transport that allows connected gateways to exhaust node memory. Attackers can send an unending sequence of WebSocket continuation frames without EndOfMessage to cause unbounded memory growth until the node process crashe
nvd
CVE-2026-101883P4MEDIUMCVSS 5.4≤ 2026.9.42026-09-30
CVE-2026-101883 [MEDIUM] CWE-918 CVE-2026-101883: OpenClaw Windows Node through 2026.9.4 contains a server-side request forgery vulnerability in the c
OpenClaw Windows Node through 2026.9.4 contains a server-side request forgery vulnerability in the canvas.present capability that bypasses URL risk evaluation enforced by canvas.navigate. Attackers with gateway or agent access can issue canvas.present to make the node's WebView send requests to localhost, private networks, or tailnet services from
nvd