openclaw
467 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
download skill installation allowed targetDir valuesnormalizeForHash in src/agents/sandbox/config-hash.ts recursigroupPolicy=allowlist, group authorization couldlanHost, `tailnetDnskills.status could disclose secrets to operator.read clientsrawCommand and command[] in the node hostgatewayUrl wopenclaw:// URL scheme. For openclaw://agent