Multi-channel AI gateway with extensible messaging integrations
74%
Total Score
80
100
100
1
88
| Title | Versions | Severity |
|---|---|---|
CVE-2026-43570 openclaw is vulnerable to UNIX Symbolic Link (Symlink) Following in versions 2026.3.22 - 2026.4.5. | 2026.3.22 - 2026.4.5 | Medium |
CVE-2026-45005 openclaw is vulnerable to Insufficient Session Expiration in versions 0.0.0 - 2026.4.23. | 0.0.0 - 2026.4.23 | Medium |
CVE-2026-45004 openclaw is vulnerable to Improper Control of Generation of Code ('Code Injection') in versions 0.0.0 - 2026.4.23. | 0.0.0 - 2026.4.23 | High |
CVE-2026-41358 openclaw is vulnerable to Origin Validation Error in versions 0.0.0 - 2026.4.1. | 0.0.0 - 2026.4.1 | Medium |
CVE-2026-44112 openclaw is vulnerable to Time-of-check Time-of-use (TOCTOU) Race Condition in versions 0.0.0 - 2026.4.21. | 0.0.0 - 2026.4.21 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
ws Version 8.21.0 | — | — |
tar Version 7.5.15 | — | — |
zod Version 4.4.3 | — | — |
jiti Version 2.7.0 | — | — |
yaml Version 2.9.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant