2026 CVE Vulnerabilities
65,619 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-100541 | HIGH | 7.5 | 0.3% | Sep 26, 2026 | OpenClaw's Matrix integration (npm package @openclaw/matrix) versions >= 2026.2.2 and < 2026.8.1 lowercase complete Matr... |
| CVE-2026-100540 | MEDIUM | 6.8 | — | Sep 26, 2026 | OpenClaw Feishu before 2026.8.1 fails to validate whether a configured default account is disabled before selecting it f... |
| CVE-2026-100539 | LOW | 2.6 | — | Sep 26, 2026 | OpenClaw (npm package 'openclaw') before 2026.8.1 fails to revoke memory tool access when an operator hot-disables memor... |
| CVE-2026-100538 | MEDIUM | 6.5 | — | Sep 26, 2026 | OpenClaw (npm package 'openclaw') before 2026.8.1 does not apply the originating sender's global or per-agent toolsBySen... |
| CVE-2026-100537 | LOW | 3.1 | 0.2% | Sep 26, 2026 | OpenClaw (npm package 'openclaw') before 2026.8.1 fails to apply the originating requester's effective tool policy durin... |
| CVE-2026-100536 | MEDIUM | 6.5 | — | Sep 26, 2026 | OpenClaw versions before 2026.8.1 fail to validate all source fields in structured message attachments, allowing attacke... |
| CVE-2026-100535 | HIGH | 7.5 | — | Sep 26, 2026 | OpenClaw (npm package 'openclaw') versions >= 2026.4.5 and < 2026.8.1 can lose the originating requester's restrictions ... |
| CVE-2026-100534 | LOW | 3.1 | — | Sep 26, 2026 | OpenClaw versions before 2026.8.1 contain an authorization bypass vulnerability in webhook TaskFlow cancellation that al... |
| CVE-2026-100533 | MEDIUM | 5.3 | 0.3% | Sep 26, 2026 | OpenClaw versions before 2026.8.1 contain a path traversal vulnerability in the tools.fs.workspaceOnly feature where Uni... |
| CVE-2026-100532 | HIGH | 8.1 | — | Sep 26, 2026 | @openclaw/whatsapp (npm) before 2026.8.1 exposes the WhatsApp login tool through the generic channel-tool path without p... |
| CVE-2026-100531 | MEDIUM | 6.5 | — | Sep 26, 2026 | The @openclaw/slack npm package before 2026.8.1 contains an authorization flaw in its Slack download-file handler: when ... |
| CVE-2026-100530 | HIGH | 7.3 | — | Sep 26, 2026 | OpenClaw versions before 2026.8.1 fail to bind working directory context to reusable exec approvals, allowing approved c... |
| CVE-2026-100529 | MEDIUM | 6.4 | 0.2% | Sep 26, 2026 | OpenClaw versions before 2026.8.1 contain an authorization scope widening vulnerability in file-transfer allow-always ap... |
| CVE-2026-100528 | MEDIUM | 5.4 | — | Sep 26, 2026 | OpenClaw (npm package 'openclaw') before 2026.8.1 could send third-party provider credentials to the wrong endpoint. In ... |
| CVE-2026-100527 | MEDIUM | 5.3 | — | Sep 26, 2026 | OpenClaw before 2026.8.2 contains a denial of service vulnerability in the Browser extension relay that allows unauthent... |
| CVE-2026-100526 | MEDIUM | 5.3 | — | Sep 26, 2026 | OpenClaw's Discord integration (npm package @openclaw/discord) before version 2026.9.3 could lose the sender-scoped medi... |
| CVE-2026-100525 | MEDIUM | 4.3 | 0.2% | Sep 26, 2026 | The OpenClaw Prometheus diagnostics plugin (@openclaw/diagnostics-prometheus) before version 2026.9.3 does not enforce t... |
| CVE-2026-100524 | MEDIUM | 5.4 | — | Sep 26, 2026 | Cotonti through 1.0.0 contains a cross-site request forgery vulnerability in the extensions manager that allows attacker... |
| CVE-2026-100523 | MEDIUM | 6.1 | — | Sep 26, 2026 | Cotonti through 1.0.0 contains an open redirect vulnerability in message.php that base64-decodes the redirect parameter ... |
| CVE-2026-100522 | MEDIUM | 6.1 | — | Sep 26, 2026 | Cotonti through 1.0.0 contains a reflected cross-site scripting vulnerability in message.php where the lng parameter is ... |
| CVE-2026-100521 | MEDIUM | 6.1 | 0.2% | Sep 26, 2026 | Cotonti through 1.0.0 contains a reflected cross-site scripting vulnerability in the search plugin highlight parameter t... |
| CVE-2026-100520 | HIGH | 8.8 | — | Sep 26, 2026 | Laranode versions before 1.2.1 contain a path traversal vulnerability in the POST /filemanager/upload-file endpoint that... |
| CVE-2026-100505 | MEDIUM | 4.4 | — | Sep 26, 2026 | Ghidra versions 9.2 through 12.1.4 contain a heap out-of-bounds read vulnerability in StringManager::getCodepoint when d... |
| CVE-2026-100504 | HIGH | 7 | — | Sep 26, 2026 | Ghidra versions through 12.1.4 contain a stack-based out-of-bounds write vulnerability in the decompiler's leftshift128 ... |
| CVE-2026-100503 | LOW | 3.3 | 0.1% | Sep 26, 2026 | Ghidra versions through 12.1.4 contain a heap use-after-free vulnerability in the decompiler's Funcdata::opInsertAfter f... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now