๐Ÿ›ก๏ธ OpenClaw CVE & Security Advisory Tracker

August 10, 2026 ยท View on GitHub

Total Advisories All-CNA CVEs Project CVEs Assigned CVEs Published Reserved
Critical High Medium Low Awaiting CVE

An automated tracker that continuously monitors OpenClaw security advisories across the GitHub Advisory Database, repo-level security advisories, and a full scan of the CVE V5 (cvelistV5) registry covering every CVE affecting OpenClaw regardless of which CNA assigned it. On each run it pulls the latest data, reconciles GHSA โ†’ CVE publication state, breaks the totals down by assigning CNA, and regenerates this dashboard so you always have an up-to-date picture of the project's vulnerability landscape.

Last updated: 2026-08-10 02:04 UTC ยท MIT License ยท Full Advisory List ยท Security Policy ยท Data: cvelistV5 + Advisory DB ยท Updates every 6h


All CVEs by CNA ยท Published CVEs ยท Pipeline ยท Advisories ยท Categories ยท Insights ยท Identity


๐Ÿ—๏ธ Project Identity

FieldValue
Current NameOpenClaw
Previous NamesMoltbot (second name), Clawdbot (original name)
Repositoryopenclaw/openclaw
npm Packageopenclaw (formerly clawdbot)
AuthorPeter Steinberger (steipete)
Search terms for CVE discovery

To find all CVEs, search for: openclaw, clawdbot, moltbot, clawhub, pkg:npm/clawdbot, pkg:npm/openclaw


๐ŸŒ All OpenClaw CVEs by Assigning CNA (CVE List V5)

The sections lower down track CVEs that have an OpenClaw GitHub Security Advisory โ€” i.e. CVEs the project issued itself. That is only part of the picture. A direct scan of the authoritative CVE List V5 registry finds 543 CVEs that name OpenClaw as an affected product, the large majority assigned by third-party researchers rather than the project. Earlier versions of this tracker reported only the ~51 project-issued (GHSA-linked) CVEs and were blind to this external stream.

Count
Total OpenClaw CVEs (all CNAs)543
Project-issued (GitHub as CNA)34
Third-party-issued (VulnCheck, ZDI, MITRE, โ€ฆ)509

By Assigning CNA

CNACVEsShare
VulnCheck50092.1%
GitHub_M346.3%
VulDB40.7%
zdi30.6%
mitre20.4%

2026 Monthly Publish Trend

The steady third-party (VulnCheck-led) disclosure cadence across 2026:

MonthCVEs
2026-0235โ–ˆโ–ˆโ–ˆโ–ˆ
2026-03198โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆ
2026-04174โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆ
2026-0575โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆ
2026-0661โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆ

Methodology: generated by reconcile_cnas.py, which scans every record in CVEProject/cvelistV5 and selects those whose containers.cna.affected[].vendor or .product is openclaw (case-insensitive), or that reference github.com/openclaw/openclaw. REJECTED records are excluded. VulnCheck is by far the dominant CNA โ€” its researchers drive the bulk of OpenClaw disclosures. The GHSA-based sections below cover the project's own advisories and are unchanged. Full reconciled set: openclaw-cves-all.json ยท aggregates: cna-breakdown.json.


๐Ÿš€ CVEs Published in cvelistV5 (51)

These CVEs have full records in the CVEProject/cvelistV5 repository:

CVE IDSeverityCVSSTitleCWEPublished
CVE-2026-22172Critical9.4OpenClaw < 2026.3.12 - Scope Elevation in WebSocket Shared-Auth ConnectionsCWE-8622026-03-20
CVE-2026-28446Critical9.2OpenClaw < 2026.2.1 - Inbound Allowlist Policy Bypass in voice-call Extension via Empty Caller ID and Suffix MatchingCWE-3032026-03-05
CVE-2026-32918Critical9.2OpenClaw < 2026.3.11 - Session Sandbox Escape via session_status ToolCWE-8632026-03-29
CVE-2026-43533High8.9OpenClaw < 2026.4.10 - Arbitrary Local File Read via QQBot Media TagsCWE-232026-05-05
CVE-2026-22171High8.8OpenClaw < 2026.2.19 - Path Traversal in Feishu Media Temporary File NamingCWE-222026-03-18
CVE-2026-24763High8.8OpenClaw/Clawdbot Docker Execution has Authenticated Command Injection via PATH Environment VariableCWE-782026-02-02
CVE-2026-25253High8.8OpenClaw/Clawdbot has 1-Click RCE via Authentication Token Exfiltration From gatewayUrlCWE-6692026-02-01
CVE-2026-28462High8.7OpenClaw < 2026.2.13 - Path Traversal in Trace and Download Output PathsCWE-222026-03-05
CVE-2026-28478High8.7OpenClaw affected by denial of service via unbounded webhook request body bufferingCWE-7702026-03-05
CVE-2026-32042High8.7OpenClaw < 2026.2.25 - Privilege Escalation via Unpaired Device Identity in Shared Gateway AuthenticationCWE-8632026-03-21
CVE-2026-32049High8.7OpenClaw < 2026.2.22 - Denial of Service via Inbound Media Download Byte Limit BypassCWE-7702026-03-21
CVE-2026-32060High8.7OpenClaw < 2026.2.14 - Path Traversal in apply_patch via Crafted PathsCWE-222026-03-11
CVE-2026-32846High8.7OpenClaw Media Parsing Path Traversal to Arbitrary File ReadCWE-222026-03-26
CVE-2026-35639High8.7OpenClaw < 2026.3.22 - Privilege Escalation via device.pair.approve Scope ValidationCWE-6482026-04-09
CVE-2026-35663High8.7OpenClaw < 2026.3.25 - Privilege Escalation via Backend Reconnect Scope Self-ClaimCWE-6482026-04-10
CVE-2026-41349High8.7OpenClaw < 2026.3.28 - Agentic Consent Bypass via config.patchCWE-8622026-04-23
CVE-2026-53814High8.7OpenClaw: Hook-triggered CLI runs could receive owner MCP tool authorityCWE-2662026-06-11
CVE-2026-53817High8.7OpenClaw < 2026.5.22 - Control UI Locality Spoofing in Device PairingCWE-2902026-06-11
CVE-2026-53819High8.7OpenClaw: Workspace .env could override Homebrew executable selection for skill install flowsCWE-4262026-06-11
CVE-2026-53843High8.7OpenClaw: Pairing-scoped device session could restore revoked node token authorityCWE-6132026-06-16
CVE-2026-62196High8.7OpenClaw 2026.3.22 < 2026.6.6 Authorization Bypass via WhatsApp Group IDsCWE-8632026-07-13
CVE-2026-26323High8.6OpenClaw has a command injection in maintainer clawtributors updaterCWE-782026-02-19
CVE-2026-53816High8.6OpenClaw < 2026.5.18 - Exec Lifecycle Event Forgery via Paired NodeCWE-8622026-06-11
CVE-2026-53849High8.6OpenClaw: Discord allowFrom could bind to mutable display namesCWE-2902026-06-16
CVE-2026-53857High8.6OpenClaw < 2026.5.3 - Mutable Display Name Binding in Zalo allowFrom PolicyCWE-2902026-06-16
CVE-2026-41396High8.5OpenClaw < 2026.3.31 - Environment Variable Override of Plugin Trust RootCWE-8292026-04-28
CVE-2026-53829High8.5OpenClaw < 2026.5.18 - Command Truncation in Exec Approval DisplayCWE-4512026-06-12
CVE-2026-28482High8.4OpenClaw < 2026.2.12 - Path Traversal via Unsanitized sessionId and sessionFile ParametersCWE-222026-03-05
CVE-2026-28393High8.3OpenClaw 2.0.0-beta3 < 2026.2.14 - Arbitrary JavaScript Module Loading via Hook Transform Path TraversalCWE-4272026-03-05
CVE-2026-28469High8.2OpenClaw Google Chat shared-path webhook target ambiguity allowed cross-account policy-context misroutingCWE-6392026-03-05
CVE-2026-35630High8OpenClaw: QQBot native approval buttons did not enforce configured approver identityCWE-8622026-05-29
CVE-2026-25157High7.8OpenClaw/Clawdbot has OS Command Injection via Project Root Path in sshNodeCommandCWE-782026-02-04
CVE-2026-27002High7.7OpenClaw: Docker container escape via unvalidated bind mount config injectionCWE-2502026-02-19
CVE-2026-32048High7.7OpenClaw < 2026.3.1 - Sandbox Escape via Cross-Agent sessions_spawnCWE-7322026-03-21
CVE-2026-42422High7.7OpenClaw < 2026.4.8 - Role Bypass in device.token.rotate FunctionCWE-8632026-04-28
CVE-2026-53806High7.7OpenClaw < 2026.5.12 - Shell Option Parsing Bypass in Exec RevalidationCWE-3672026-06-11
CVE-2026-53811High7.7OpenClaw: Matrix allowFrom could bind to mutable display namesCWE-2902026-06-11
CVE-2026-53810High7.7OpenClaw's marketplace runtime extension metadata could point at unscanned payloadsCWE-8292026-06-11
CVE-2026-53853High7.6OpenClaw: Linux and macOS exec allowlists skipped configured argument patternsCWE-693, CWE-8632026-06-16
CVE-2026-53855High7.6OpenClaw < 2026.4.2 - Shell Positional Parameters Bypass in Inline-Eval ChecksCWE-184, CWE-8632026-06-16
CVE-2026-53864High7.6OpenClaw: Host environment sanitizer missed two Node.js control variablesCWE-1842026-06-16
CVE-2026-53866High7.6OpenClaw < 2026.5.12 - Allowlist Bypass in Shell Inline-Command ParsingCWE-8622026-06-16
CVE-2026-42428High7.5OpenClaw < 2026.4.8 - Missing Integrity Verification in Package DownloadsCWE-3532026-04-28
CVE-2026-28458High7.4OpenClaw's Browser Relay /cdp websocket is missing auth which could allow cross-tab cookie accessCWE-3062026-03-05
CVE-2026-53833High7.4QQBot for OpenClaw < 2026.4.29 - Authorization Bypass via QQBot Streaming CommandCWE-2902026-06-12
CVE-2026-42432High7.3OpenClaw < 2026.4.8 - Command Escalation via Node Pairing Reconnect BypassCWE-8632026-04-28
CVE-2026-53813High7.3OpenClaw: Fake package roots could influence memory-core artifact loadingCWE-4272026-06-11
CVE-2026-34512High7.2OpenClaw < 2026.3.25 - Improper Access Control in /sessions/:sessionKey/kill EndpointCWE-8632026-04-09
CVE-2026-41364High7.2OpenClaw < 2026.3.31 - Arbitrary File Write via Symlink Following in SSH Sandbox Tar UploadCWE-592026-04-27
CVE-2026-53865High7.2OpenClaw: Workspace-derived service PATH could influence trash command selectionCWE-4262026-06-16
CVE-2026-26317High7.1OpenClaw affected by cross-site request forgery (CSRF) through loopback browser mutation endpointsCWE-3522026-02-19
CVE-2026-22169High7.1OpenClaw < 2026.2.22 - Allowlist Bypass via sort Configuration in safeBinsCWE-782026-03-18
CVE-2026-35621High7.1OpenClaw < 2026.3.24 - Privilege Escalation via chat.send to Allowlist PersistenceCWE-8622026-04-10
CVE-2026-35636High7.1OpenClaw 2026.3.11 < 2026.3.25 - Session Isolation Bypass via sessionId ResolutionCWE-6962026-04-09
CVE-2026-41299High7.1OpenClaw < 2026.3.28 - Client Identity Spoofing in chat.send Gateway Provenance GuardCWE-8072026-04-20
CVE-2026-41359High7.1OpenClaw < 2026.3.28 - Privilege Escalation via operator.write to Admin-Class Telegram Config and Cron PersistenceCWE-2692026-04-23
CVE-2026-41375High7.1OpenClaw < 2026.3.28 - Authorization Bypass in /phone arm and /phone disarm EndpointsCWE-8632026-04-28
CVE-2026-53815High7.1OpenClaw < 2026.5.19 - Channel Allowlist Bypass in Message Read ActionsCWE-8622026-06-11
CVE-2026-43531High7OpenClaw < 2026.4.9 - Environment Variable Injection via Workspace .env FileCWE-152026-05-05
CVE-2026-53842High7OpenClaw: Workspace .env CLOUDSDK_PYTHON could influence Gmail setup gcloud executionCWE-4262026-06-16
CVE-2026-53846High7OpenClaw: Workspace .env npm_execpath could influence bundled runtime dependency installCWE-4262026-06-16
CVE-2026-53858High7OpenClaw: Workspace .env STATE_DIRECTORY could influence bundled runtime dependency rootsCWE-4262026-06-16
CVE-2026-27545Medium6.9OpenClaw < 2026.2.26 - Approval Bypass via Parent Symlink Current Working Directory RebindCWE-3672026-03-18
CVE-2026-27523Medium6.9OpenClaw < 2026.2.24 - Sandbox Bind Validation Bypass via Symlink-Parent Missing-Leaf PathsCWE-222026-03-18
CVE-2026-27004Medium6.9OpenClaw session tool visibility hardening and Telegram webhook secret fallbackCWE-209, CWE-3462026-02-19
CVE-2026-28480Medium6.9OpenClaw Telegram allowlist authorization accepted mutable usernamesCWE-2902026-03-05
CVE-2026-32919Medium6.9OpenClaw < 2026.3.11 - Unauthorized Session Reset via agent Slash CommandsCWE-8632026-03-29
CVE-2026-35652Medium6.9OpenClaw < 2026.3.22 - Unauthorized Action Execution via Callback DispatchCWE-6962026-04-10
CVE-2026-41301Medium6.9OpenClaw 2026.3.22 < 2026.3.31 - Forged Nostr DM Pairing State Creation via Signature Verification BypassCWE-3472026-04-20
CVE-2026-41343Medium6.9OpenClaw < 2026.3.31 - Denial of Service via LINE Webhook Handler Pre-Auth ConcurrencyCWE-7992026-04-23
CVE-2026-41335Medium6.9OpenClaw < 2026.3.31 - Information Disclosure via Control UI Bootstrap JSONCWE-4972026-04-23
CVE-2026-41372Medium6.9OpenClaw < 2026.4.2 - Loopback Protection Bypass via Trailing-Dot Localhost in CDP DiscoveryCWE-6392026-04-27
CVE-2026-53818Medium6.9OpenClaw < 2026.4.24 - Owner-Only Tool Policy Bypass via MCP LoopbackCWE-8622026-06-11
CVE-2026-29612Medium6.8OpenClaw < 2026.2.14 - Denial of Service via Large Base64 Media File DecodingCWE-7702026-03-05
CVE-2026-45224Medium6.8Crabbox < 0.9.0 Path Traversal via Islo Provider Workspace ResolutionCWE-222026-05-11
CVE-2026-53850Medium6.8OpenClaw < 2026.4.25 - Control Scope Enforcement Bypass in Focus CommandCWE-8622026-06-16
CVE-2026-28452Medium6.7OpenClaw affected by denial of service through unguarded archive extraction allowing high expansion/resource abuse (ZIP/TAR)CWE-7702026-03-05
CVE-2026-32044Medium6.7OpenClaw < 2026.3.2 - Tar Archive Safety Bypass in Skills InstallationCWE-4092026-03-21
CVE-2026-26328Medium6.5OpenClaw iMessage group allowlist authorization inherited DM pairing-store identitiesCWE-284, CWE-8632026-02-19
CVE-2026-35673Medium6.5OpenClaw < 2026.4.29 - SSRF Policy Bypass via Browser Debug/Export RoutesCWE-8632026-05-29
CVE-2026-28448Medium6.3OpenClaw 2026.1.29 < 2026.2.1 - Authorization Bypass in Twitch Plugin allowFrom Access ControlCWE-2852026-03-05
CVE-2026-28471Medium6.3OpenClaw 2026.1.14-1 < 2026.2.2 - Allowlist Bypass via displayName and Cross-Homeserver localpart Matching in Matrix PluginCWE-2872026-03-05
CVE-2026-33580Medium6.3OpenClaw < 2026.3.28 - Brute Force Attack via Missing Rate Limiting on Webhook Shared Secret AuthenticationCWE-3072026-03-31
CVE-2026-35649Medium6.3OpenClaw < 2026.3.22 - Settings Reconciliation Bypass via Empty AllowlistCWE-1832026-04-10
CVE-2026-35656Medium6.3OpenClaw < 2026.3.22 - XFF Loopback Spoofing Bypass in Canvas Authentication and Rate LimiterCWE-2902026-04-10
CVE-2026-53851Medium6.3OpenClaw < 2026.5.12 - Slack Reaction Event Notification BypassCWE-8622026-06-16
CVE-2026-62220Medium6.3OpenClaw 2026.2.25 < 2026.5.26 WebSocket Rate Limit BypassCWE-3072026-07-17
CVE-2026-41366Medium6OpenClaw < 2026.3.31 - Arbitrary Host File Read via appendLocalMediaParentRoots Self-WhitelistingCWE-7322026-04-27
CVE-2026-45001Medium6OpenClaw < 2026.4.20 - Gateway Config Mutation Guard Bypass via Agent Tool AccessCWE-8622026-05-11
CVE-2026-53840Medium6OpenClaw: MCP Streamable HTTP redirects could forward configured custom headers to another originCWE-5222026-06-16
CVE-2026-53844Medium6OpenClaw < 2026.4.29 - Session Visibility Check Bypass in Shared Memory SearchCWE-8622026-06-16
CVE-2026-53854Medium6OpenClaw: Internal/webchat command auth could inherit ownerAllowFrom wildcard stateCWE-8632026-06-16
CVE-2026-53859Medium6OpenClaw < 2026.5.26 - Hostname Validation Bypass via Trailing-Dot InconsistencyCWE-1023, CWE-9182026-06-16
CVE-2026-53863Medium6OpenClaw < 2026.4.25 - Unvalidated Group ID Acceptance in Tool Group PolicyCWE-6392026-06-16
CVE-2026-62205Medium6OpenClaw 2026.4.12-beta.1 < 2026.6.6 Authorization Bypass via message actionsCWE-8622026-07-17
CVE-2026-62210Medium6OpenClaw < 2026.6.1 Denial of Service via Remote Media URLsCWE-7702026-07-17
CVE-2026-32054Medium5.9OpenClaw < 2026.2.25 - Symlink Traversal in Browser Trace/Download Path HandlingCWE-592026-03-21
CVE-2026-41393Medium5.9OpenClaw < 2026.3.31 - Arbitrary DNS Authority Acceptance and Credential Exfiltration via Wide-Area DiscoveryCWE-3462026-04-28
CVE-2026-27646Medium5.8OpenClaw < 2026.3.7 - Sandbox Escape via /acp spawn CommandCWE-8632026-03-23
CVE-2026-32035Medium5.8OpenClaw < 2026.3.2 - Missing Owner Flag Validation in Discord Voice Transcript HandlerCWE-8632026-03-19
CVE-2026-31995Medium5.8OpenClaw 2026.1.21 < 2026.2.19 - Command Injection via Windows Shell Fallback in Lobster ExtensionCWE-782026-03-19
CVE-2026-32977Medium5.8OpenClaw < 2026.3.11 - Sandbox Boundary Bypass via Unanchored writeFile Commit PathCWE-3672026-03-31
CVE-2026-32988Medium5.8OpenClaw < 2026.3.11 - Sandbox Boundary Bypass via Unvalidated Temporary File CreationCWE-3672026-03-31
CVE-2026-53856Medium5.7OpenClaw: Config recovery could restore openclaw.json with broad file permissionsCWE-7322026-06-16
CVE-2026-28457Medium5.6OpenClaw < 2026.2.14 - Path Traversal in Sandbox Skill Mirroring via Name ParameterCWE-222026-03-05
CVE-2026-33578Medium5.3OpenClaw < 2026.3.28 - Sender Policy Allowlist Bypass via Policy Downgrade in Google Chat and Zalouser ExtensionsCWE-8632026-03-31
CVE-2026-34425Medium5.3OpenClaw - Shell-Bleed Protection Preflight Validation BypassCWE-1842026-04-02
CVE-2026-41367Medium5.3OpenClaw 2026.2.14 < 2026.3.28 - Policy Enforcement Bypass in Discord Component InteractionsCWE-8632026-04-27
CVE-2026-53847Medium5.3OpenClaw < 2026.5.6 - Privilege Escalation via Active Memory Write ScopeCWE-2662026-06-16
CVE-2026-53861Medium5.3OpenClaw < 2026.5.6 - Allowlist Bypass via Combined POSIX Inline Flags on macOSCWE-1842026-06-16
CVE-2026-53812Medium4.9OpenClaw's browser act interactions could bypass private-network navigation checksCWE-9182026-06-11
CVE-2026-62201Medium4.9OpenClaw < 2026.6.6 Network Policy Bypass via exec-serverCWE-9182026-07-17
CVE-2026-15193Medium4.8AidanPark openclaw-android Android WebView Bridge JsBridge.kt os command injectionCWE-78, CWE-772026-07-09
CVE-2026-22180Medium4.8OpenClaw < 2026.3.2 - Path Confinement Bypass in Browser Output and File Write OperationsCWE-592026-03-18
CVE-2026-32020Medium4.8OpenClaw < 2026.2.22 - Arbitrary File Read via Symlink Following in Static File HandlerCWE-592026-03-19
CVE-2026-53809Medium4.8OpenClaw < 2026.4.25 - Provider Alias Confusion in Embedded Runner PolicyCWE-8632026-06-11
CVE-2026-41338Medium4.3OpenClaw < 2026.3.31 - Time-of-Check-Time-of-Use (TOCTOU) Vulnerability in Sandbox File OperationsCWE-3672026-04-23
CVE-2026-24764Low3.7OpenClaw has Remote Code Execution via System Prompt Injection in Slack Channel DescriptionsCWE-74, CWE-942026-02-19
CVE-2026-32906Low2.3OpenClaw < 2026.5.12 - Privilege Escalation in Slack Plugin Approvals via Exec Approver GateCWE-8632026-05-29
CVE-2026-35624Low2.3OpenClaw < 2026.3.22 - Policy Confusion via Room Name Collision in Nextcloud TalkCWE-8072026-04-09
CVE-2026-34507Low2.3OpenClaw < 2026.4.29 - Policy Bypass in QQBot Admin Commands via DM-only and allowFrom ChecksCWE-8632026-05-29
CVE-2026-35617Low2.3OpenClaw < 2026.3.25 - Authorization Bypass via Group Policy Rebinding with Mutable Space displayNameCWE-8072026-04-09
CVE-2026-41402Low2.3OpenClaw < 2026.3.31 - Webhook Replay Cache Cross-Target messageId Scope BypassCWE-7062026-04-28
CVE-2026-41408Low2.3OpenClaw < 2026.3.31 - Disk Exhaustion via Media Download BypassCWE-7702026-04-28
CVE-2026-41916Low2.3OpenClaw < 2026.4.8 - Stale Authentication State via Config ReloadCWE-6132026-04-28
CVE-2026-44991Low2.3OpenClaw < 2026.4.21 - Authorization Bypass in Owner-Enforced Commands via Wildcard Channel SendersCWE-8632026-05-11
CVE-2026-44993Low2.3OpenClaw < 2026.4.20 - Direct Message Misclassification in Feishu Card ActionsCWE-1842026-05-11
CVE-2026-53845Low2.3OpenClaw: Skill-command dispatch could skip before-tool-call hooksCWE-6932026-06-16
CVE-2026-53848Low2.3OpenClaw < 2026.5.26 - Exec Allowlist Bypass via Transparent Command WrappersCWE-1842026-06-16
CVE-2026-53852Low2.3OpenClaw < 2026.4.25 - Scope Bypass via Empty-Scope Device Re-pairingCWE-6362026-06-16
CVE-2026-53860Low2.3OpenClaw: BlueBubbles sender policy could match mutable conversation identifiersCWE-807, CWE-8632026-06-16
CVE-2026-53862Low2.3OpenClaw < 2026.5.12 - Bootstrap Token Replay via Pending Pairing Scope WideningCWE-266, CWE-3452026-06-16
CVE-2026-62221Low2.3OpenClaw 2026.5.12 < 2026.5.26 Authorization Bypass via allowFromCWE-8632026-07-17
CVE-2026-53841Low2.1OpenClaw: Exported session HTML could keep unsafe markdown linksCWE-832026-06-16
CVE-2026-30741NoneA remote code execution (RCE) vulnerability in OpenClaw Agent Platform v2026.2.62026-03-11
๐Ÿ“– Detailed CVE Analysis (click to expand)

CVE-2026-22172 โ€” OpenClaw < 2026.3.12 - Scope Elevation in WebSocket Shared-Auth Connections

FieldDetail
CVSS9.4 (CRITICAL) โ€” CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
CWECWE-862 (CWE-862 Missing Authorization)
Affected< 2026.3.12
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-rqpp-rjj8-7wv8

OpenClaw versions prior to 2026.3.12 contain an authorization bypass vulnerability in the WebSocket connect path that allows shared-token or password-authenticated connections to self-declare elevated scopes without server-side binding. Attackers can exploit this logic flaw to present unauthorized scopes such as operator.admin and perform admin-only gateway operations.

References:


CVE-2026-28446 โ€” OpenClaw < 2026.2.1 - Inbound Allowlist Policy Bypass in voice-call Extension via Empty Caller ID and Suffix Matching

FieldDetail
CVSS9.2 (CRITICAL) โ€” CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N
CWECWE-303 (Incorrect Implementation of Authentication Algorithm)
Affected< 2026.2.1
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-4rj2-gpmh-qq5x

OpenClaw versions prior to 2026.2.1 with the voice-call extension installed and enabled contain an authentication bypass vulnerability in inbound allowlist policy validation that accepts empty caller IDs and uses suffix-based matching instead of strict equality. Remote attackers can bypass inbound access controls by placing calls with missing caller IDs or numbers ending with allowlisted digits to reach the voice-call agent and execute tools.

References:


CVE-2026-32918 โ€” OpenClaw < 2026.3.11 - Session Sandbox Escape via session_status Tool

FieldDetail
CVSS9.2 (CRITICAL) โ€” CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N
CWECWE-863 (Incorrect Authorization)
Affected< 2026.3.11
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-wcxr-59v9-rxr8

OpenClaw before 2026.3.11 contains a session sandbox escape vulnerability in the session_status tool that allows sandboxed subagents to access parent or sibling session state. Attackers can supply arbitrary sessionKey values to read or modify session data outside their sandbox scope, including persisted model overrides.

References:


CVE-2026-43533 โ€” OpenClaw < 2026.4.10 - Arbitrary Local File Read via QQBot Media Tags

FieldDetail
CVSS8.9 (HIGH) โ€” CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N
CWECWE-23 (CWE-23: Relative Path Traversal)
Affected< 2026.4.10
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-66r7-m7xm-v49h

OpenClaw before 2026.4.10 contains an arbitrary file read vulnerability in QQBot media tags that allows attackers to reference host-local paths outside the intended media storage boundary. Attackers can craft malicious reply text containing media tags to disclose arbitrary local files through outbound media handling.

References:


CVE-2026-22171 โ€” OpenClaw < 2026.2.19 - Path Traversal in Feishu Media Temporary File Naming

FieldDetail
CVSS8.8 (HIGH) โ€” CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N
CWECWE-22 (CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'))
Affected< 2026.2.19
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-vj3g-5px3-gr46

OpenClaw versions prior to 2026.2.19 contain a path traversal vulnerability in the Feishu media download flow where untrusted media keys are interpolated directly into temporary file paths in extensions/feishu/src/media.ts. An attacker who can control Feishu media key values returned to the client can use traversal segments to escape os.tmpdir() and write arbitrary files within the OpenClaw process permissions.

References:


CVE-2026-24763 โ€” OpenClaw/Clawdbot Docker Execution has Authenticated Command Injection via PATH Environment Variable

FieldDetail
CVSS8.8 (HIGH) โ€” CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWECWE-78 (CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'))
Affected< 2026.1.29
Vendor/Productclawdbot / clawdbot
AdvisoryGHSA-mc68-q9jw-2h3v

OpenClaw (formerly Clawdbot) is a personal AI assistant you run on your own devices. Prior to 2026.1.29, a command injection vulnerability existed in OpenClawโ€™s Docker sandbox execution mechanism due to unsafe handling of the PATH environment variable when constructing shell commands. An authenticated user able to control environment variables could influence command execution within the container context. This vulnerability is fixed in 2026.1.29.

Naming note: Uses old name clawdbot/clawdbot as vendor/product. References:


CVE-2026-25253 โ€” OpenClaw/Clawdbot has 1-Click RCE via Authentication Token Exfiltration From gatewayUrl

FieldDetail
CVSS8.8 (HIGH) โ€” CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CWECWE-669 (CWE-669 Incorrect Resource Transfer Between Spheres)
Affected< 2026.1.29
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-g8p2-7wf7-98mq

OpenClaw (aka clawdbot or Moltbot) before 2026.1.29 obtains a gatewayUrl value from a query string and automatically makes a WebSocket connection without prompting, sending a token value.

Naming note: Uses all three names in description. packageURL still references pkg:npm/clawdbot. References:


CVE-2026-28462 โ€” OpenClaw < 2026.2.13 - Path Traversal in Trace and Download Output Paths

FieldDetail
CVSS8.7 (HIGH) โ€” CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
CWECWE-22 (Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'))
Affected< 2026.2.13
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-gq9c-wg68-gwj2

OpenClaw versions prior to 2026.2.13 contain a vulnerability in the browser control API in which it accepts user-supplied output paths for trace and download files without consistently constraining writes to temporary directories. Attackers with API access can exploit path traversal in POST /trace/stop, POST /wait/download, and POST /download endpoints to write files outside intended temp roots.

References:


CVE-2026-28478 โ€” OpenClaw affected by denial of service via unbounded webhook request body buffering

FieldDetail
CVSS8.7 (HIGH) โ€” CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
CWECWE-770 (Allocation of Resources Without Limits or Throttling)
Affected< 2026.2.13
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-q447-rj3r-2cgh

OpenClaw versions prior to 2026.2.13 contain a denial of service vulnerability in webhook handlers that buffer request bodies without strict byte or time limits. Remote unauthenticated attackers can send oversized JSON payloads or slow uploads to webhook endpoints causing memory pressure and availability degradation.

References:


CVE-2026-32042 โ€” OpenClaw < 2026.2.25 - Privilege Escalation via Unpaired Device Identity in Shared Gateway Authentication

FieldDetail
CVSS8.7 (HIGH) โ€” CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CWECWE-863 (CWE-863: Incorrect Authorization)
Affected< 2026.2.25
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-553v-f69r-656j

OpenClaw versions 2026.2.22 prior to 2026.2.25 contain a privilege escalation vulnerability allowing unpaired device identities to bypass operator pairing requirements and self-assign elevated operator scopes including operator.admin. Attackers with valid shared gateway authentication can present a self-signed unpaired device identity to request and obtain higher operator scopes before pairing approval is granted.

References:


CVE-2026-32049 โ€” OpenClaw < 2026.2.22 - Denial of Service via Inbound Media Download Byte Limit Bypass

FieldDetail
CVSS8.7 (HIGH) โ€” CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
CWECWE-770 (CWE-770: Allocation of Resources Without Limits or Throttling)
Affected< 2026.2.22
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-rxxp-482v-7mrh

OpenClaw versions prior to 2026.2.22 fail to consistently enforce configured inbound media byte limits before buffering remote media across multiple channel ingestion paths. Remote attackers can send oversized media payloads to trigger elevated memory usage and potential process instability.

References:


CVE-2026-32060 โ€” OpenClaw < 2026.2.14 - Path Traversal in apply_patch via Crafted Paths

FieldDetail
CVSS8.7 (HIGH) โ€” CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CWECWE-22 (Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'))
Affected< 2026.2.14
Vendor/Productopenclaw / openclaw
AdvisoryGHSA-r5fq-947m-xm57

OpenClaw versions prior to 2026.2.14 contain a path traversal vulnerability in apply_patch that allows attackers to write or delete files outside the configured workspace directory. When apply_patch is enabled without filesystem sandbox containment, attackers can exploit crafted paths including directory traversal sequences or absolute paths to escape workspace boundaries and modify arbitrary files.

References:


CVE-2026-32846 โ€” OpenClaw Media Parsing Path Traversal to Arbitrary File Read

FieldDetail
CVSS8.7 (HIGH) โ€” CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
CWECWE-22 (CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'))
Affected< 4797bbc5b96e2cca5532e43b58915c051746fe37
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-f6pf-4gjx-c94r

OpenClaw through 2026.3.23 (fixed in commit 4797bbc) contains a path traversal vulnerability in media parsing that allows attackers to read arbitrary files by bypassing path validation in the isLikelyLocalPath() and isValidMedia() functions. Attackers can exploit incomplete validation and the allowBareFilename bypass to reference files outside the intended application sandbox, resulting in disclosure of sensitive information including system files, environment files, and SSH keys.

References:


CVE-2026-35639 โ€” OpenClaw < 2026.3.22 - Privilege Escalation via device.pair.approve Scope Validation

FieldDetail
CVSS8.7 (HIGH) โ€” CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CWECWE-648 (CWE-648: Incorrect Use of Privileged APIs)
Affected< 2026.3.22
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-hf68-49fm-59cq

OpenClaw before 2026.3.22 contains a privilege escalation vulnerability in the device.pair.approve method that allows an operator.pairing approver to approve pending device requests with broader operator scopes than the approver actually holds. Attackers can exploit insufficient scope validation to escalate privileges to operator.admin and achieve remote code execution on the Node infrastructure.

References:


CVE-2026-35663 โ€” OpenClaw < 2026.3.25 - Privilege Escalation via Backend Reconnect Scope Self-Claim

FieldDetail
CVSS8.7 (HIGH) โ€” CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CWECWE-648 (CWE-648: Incorrect Use of Privileged APIs)
Affected< 2026.3.25
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-9hjh-fr4f-gxc4

OpenClaw before 2026.3.25 contains a privilege escalation vulnerability allowing non-admin operators to self-request broader scopes during backend reconnect. Attackers can bypass pairing requirements to reconnect as operator.admin, gaining unauthorized administrative privileges.

References:


FieldDetail
CVSS8.7 (HIGH) โ€” CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CWECWE-862 (CWE-862 Missing Authorization)
Affected< 2026.3.28
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-v3qc-wrwx-j3pw

OpenClaw before 2026.3.28 contains an agentic consent bypass vulnerability allowing LLM agents to silently disable execution approval via config.patch parameter. Remote attackers can exploit this to bypass security controls and execute unauthorized operations without user consent.

References:


CVE-2026-53814 โ€” OpenClaw: Hook-triggered CLI runs could receive owner MCP tool authority

FieldDetail
CVSS8.7 (HIGH) โ€” CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N
CWECWE-266 (Incorrect Privilege Assignment)
Affected< 2026.5.20
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-6fvr-66p3-3qj4

OpenClaw before 2026.5.20 contains a privilege escalation vulnerability where hook-triggered agent runs incorrectly receive owner-scoped MCP loopback authority instead of hook-appropriate scope. Attackers with a valid hook token can exploit the /hooks/agent endpoint to cause spawned CLI runtimes to access or invoke owner-only MCP tools, potentially executing privileged actions like persistent cron state modifications.

References:


CVE-2026-53817 โ€” OpenClaw < 2026.5.22 - Control UI Locality Spoofing in Device Pairing

FieldDetail
CVSS8.7 (HIGH) โ€” CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CWECWE-290 (Authentication Bypass by Spoofing)
Affected< 2026.5.22
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-chr9-m4q2-76hw

OpenClaw before 2026.5.22 contains a locality validation vulnerability in Control UI pairing that allows attackers with network access to spoof locality information and obtain durable admin-capable device tokens. Attackers can exploit insufficient locality-derived trust validation to convert temporary shared access into persistent administrative credentials that survive token rotation.

References:


CVE-2026-53819 โ€” OpenClaw: Workspace .env could override Homebrew executable selection for skill install flows

FieldDetail
CVSS8.7 (HIGH) โ€” CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CWECWE-426 (Untrusted Search Path)
Affected< 2026.5.27
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-8wg3-5mcm-fjq8

OpenClaw before 2026.5.27 contains an arbitrary code execution vulnerability in skill install flows where workspace .env files can override the Homebrew executable selection. Attackers with access to trusted operator workspaces can execute unintended Homebrew-compatible executables during skill setup to compromise the system.

References:


CVE-2026-53843 โ€” OpenClaw: Pairing-scoped device session could restore revoked node token authority

FieldDetail
CVSS8.7 (HIGH) โ€” CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CWECWE-613 (Insufficient Session Expiration)
Affected< 2026.5.26
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-q99w-vh6v-q3v7

OpenClaw before 2026.5.26 contains an authorization bypass vulnerability where a surviving pairing-scoped device session can re-establish node token authority after revocation. Attackers with a paired device can regain WebSocket node-level access without renewed approval, weakening revocation controls and maintaining unauthorized access longer than intended.

References:


CVE-2026-62196 โ€” OpenClaw 2026.3.22 < 2026.6.6 Authorization Bypass via WhatsApp Group IDs

FieldDetail
CVSS8.7 (HIGH) โ€” CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N
CWECWE-863 (Incorrect Authorization)
Affected< 2026.6.6
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-fh38-965w-f6c3

OpenClaw versions 2026.3.22 before 2026.6.6 contain an authorization bypass vulnerability where WhatsApp group IDs can satisfy elevated sender allowlists. Attackers with lower-trust access can perform actions requiring stronger authorization by leveraging group ID validation in the affected feature.

References:


CVE-2026-26323 โ€” OpenClaw has a command injection in maintainer clawtributors updater

FieldDetail
CVSS8.6 (HIGH) โ€” CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
CWECWE-78 (CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'))
Affected< >= 2026.1.8, < 2026.2.14
Vendor/Productopenclaw / openclaw
AdvisoryGHSA-m7x8-2w3w-pr42

OpenClaw is a personal AI assistant. Versions 2026.1.8 through 2026.2.13 have a command injection in the maintainer/dev script scripts/update-clawtributors.ts. The issue affects contributors/maintainers (or CI) who run bun scripts/update-clawtributors.ts in a source checkout that contains a malicious commit author email (e.g. crafted @users[.]noreply[.]github[.]com values). Normal CLI usage is not affected (npm i -g openclaw): this script is not part of the shipped CLI and is not executed during routine operation. The script derived a GitHub login from git log author metadata and interpolated it into a shell command (via execSync). A malicious commit record could inject shell metacharacters and execute arbitrary commands when the script is run. Version 2026.2.14 contains a patch.

References:


CVE-2026-53816 โ€” OpenClaw < 2026.5.18 - Exec Lifecycle Event Forgery via Paired Node

FieldDetail
CVSS8.6 (HIGH) โ€” CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CWECWE-862 (Missing Authorization)
Affected< 2026.5.18
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-3c6j-hq33-3jv4

OpenClaw before 2026.5.18 contains an insufficient provenance validation vulnerability in node event handling that allows paired nodes to forge exec lifecycle events without system.run authorization. A malicious or compromised paired node can send crafted node.event messages to the gateway, steering target sessions into exec-event paths that expose capabilities the reduced node surface should not provide.

References:


CVE-2026-53849 โ€” OpenClaw: Discord allowFrom could bind to mutable display names

FieldDetail
CVSS8.6 (HIGH) โ€” CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
CWECWE-290 (Authentication Bypass by Spoofing)
Affected< 2026.5.7
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-cw4q-gqg5-g38h

OpenClaw before 2026.5.7 contains a privilege escalation vulnerability where the allowFrom feature improperly validates Discord account identity using mutable display names instead of immutable user IDs. Attackers with Discord accounts can change their display name to match a policy entry and gain unauthorized agent access intended for another Discord identity.

References:


CVE-2026-53857 โ€” OpenClaw < 2026.5.3 - Mutable Display Name Binding in Zalo allowFrom Policy

FieldDetail
CVSS8.6 (HIGH) โ€” CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
CWECWE-290 (Authentication Bypass by Spoofing)
Affected< 2026.5.3
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-8c59-hr4w-qg69

OpenClaw before 2026.5.3 contains a policy enforcement vulnerability where Zalo contacts with mutable display metadata could match allowFrom policy entries through display name changes. Attackers with mutable display names could receive agent responses intended for different Zalo identities when the feature is enabled.

References:


CVE-2026-41396 โ€” OpenClaw < 2026.3.31 - Environment Variable Override of Plugin Trust Root

FieldDetail
CVSS8.5 (HIGH) โ€” CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CWECWE-829 (CWE-829: Inclusion of Functionality from Untrusted Control Sphere)
Affected< 2026.3.31
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-qcj9-wwgw-6gm8

OpenClaw before 2026.3.31 allows workspace .env files to override the OPENCLAW_BUNDLED_PLUGINS_DIR environment variable, compromising plugin trust verification. Attackers with control over workspace configuration can inject malicious plugins by overriding the bundled plugin trust root directory.

References:


CVE-2026-53829 โ€” OpenClaw < 2026.5.18 - Command Truncation in Exec Approval Display

FieldDetail
CVSS8.5 (HIGH) โ€” CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CWECWE-451 (User Interface (UI) Misrepresentation of Critical Information)
Affected< 2026.5.18
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-xww8-gqvh-92x9

OpenClaw before 2026.5.18 contains an approval display truncation vulnerability allowing authenticated users to hide command suffixes from approvers. Attackers can submit oversized exec commands with benign prefixes and malicious suffixes to execute unauthorized operations after approval.

References:


CVE-2026-28482 โ€” OpenClaw < 2026.2.12 - Path Traversal via Unsanitized sessionId and sessionFile Parameters

FieldDetail
CVSS8.4 (HIGH) โ€” CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
CWECWE-22 (Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'))
Affected< 2026.2.12
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-5xfq-5mr7-426q

OpenClaw versions prior to 2026.2.12 construct transcript file paths using unsanitized sessionId parameters and sessionFile paths without enforcing directory containment. Authenticated attackers can exploit path traversal sequences like ../../etc/passwd in sessionId or sessionFile parameters to read or write arbitrary files outside the agent sessions directory.

References:


CVE-2026-28393 โ€” OpenClaw 2.0.0-beta3 < 2026.2.14 - Arbitrary JavaScript Module Loading via Hook Transform Path Traversal

FieldDetail
CVSS8.3 (HIGH) โ€” CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
CWECWE-427 (Uncontrolled Search Path Element)
Affected< 2026.2.14
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-7xhj-55q9-pc3m

OpenClaw versions 2.0.0-beta3 prior to 2026.2.14 contain a path traversal vulnerability in hook transform module loading that allows arbitrary JavaScript execution. The hooks.mappings[].transform.module parameter accepts absolute paths and traversal sequences, enabling attackers with configuration write access to load and execute malicious modules with gateway process privileges.

References:


CVE-2026-28469 โ€” OpenClaw Google Chat shared-path webhook target ambiguity allowed cross-account policy-context misrouting

FieldDetail
CVSS8.2 (HIGH) โ€” CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
CWECWE-639 (Authorization Bypass Through User-Controlled Key)
Affected< 2026.2.14
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-rq6g-px6m-c248

OpenClaw versions prior to 2026.2.14 contain a webhook routing vulnerability in the Google Chat monitor component that allows cross-account policy context misrouting when multiple webhook targets share the same HTTP path. Attackers can exploit first-match request verification semantics to process inbound webhook events under incorrect account contexts, bypassing intended allowlists and session policies.

References:


CVE-2026-35630 โ€” OpenClaw: QQBot native approval buttons did not enforce configured approver identity

FieldDetail
CVSS8 (HIGH) โ€” CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
CWECWE-862 (Missing Authorization)
Affected< 2026.5.18
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-mgq6-vr84-7m2j

OpenClaw before 2026.5.18 contains an authorization bypass vulnerability in QQBot native approval buttons that fails to enforce configured approver identity. Non-approver users can click approval buttons to resolve pending exec or plugin approval requests without proper authorization.

References:


CVE-2026-25157 โ€” OpenClaw/Clawdbot has OS Command Injection via Project Root Path in sshNodeCommand

FieldDetail
CVSS7.8 (HIGH) โ€” CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
CWECWE-78 (CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'))
Affected< 2026.1.29
Vendor/Productopenclaw / openclaw
AdvisoryGHSA-q284-4pvr-m585

OpenClaw is a personal AI assistant. Prior to version 2026.1.29, there is an OS command injection vulnerability via the Project Root Path in sshNodeCommand. The sshNodeCommand function constructed a shell script without properly escaping the user-supplied project path in an error message. When the cd command failed, the unescaped path was interpolated directly into an echo statement, allowing arbitrary command execution on the remote SSH host. The parseSSHTarget function did not validate that SSH target strings could not begin with a dash. An attacker-supplied target like -oProxyCommand=... would be interpreted as an SSH configuration flag rather than a hostname, allowing arbitrary command execution on the local machine. This issue has been patched in version 2026.1.29.


CVE-2026-27002 โ€” OpenClaw: Docker container escape via unvalidated bind mount config injection

FieldDetail
CVSS7.7 (HIGH) โ€” CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CWECWE-250 (CWE-250: Execution with Unnecessary Privileges)
Affected< 2026.2.15
Vendor/Productopenclaw / openclaw
AdvisoryGHSA-w235-x559-36mg

OpenClaw is a personal AI assistant. Prior to version 2026.2.15, a configuration injection issue in the Docker tool sandbox could allow dangerous Docker options (bind mounts, host networking, unconfined profiles) to be applied, enabling container escape or host data access. OpenClaw 2026.2.15 blocks dangerous sandbox Docker settings and includes runtime enforcement when building docker create args; config-schema validation for network=host, seccompProfile=unconfined, apparmorProfile=unconfined; and security audit findings to surface dangerous sandbox docker config. As a workaround, do not configure agents.*.sandbox.docker.binds to mount system directories or Docker socket paths, keep agents.*.sandbox.docker.network at none (default) or bridge, and do not use unconfined for seccomp/AppArmor profiles.

References:


CVE-2026-32048 โ€” OpenClaw < 2026.3.1 - Sandbox Escape via Cross-Agent sessions_spawn

FieldDetail
CVSS7.7 (HIGH) โ€” CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CWECWE-732 (CWE-732: Incorrect Permission Assignment for Critical Resource)
Affected< 2026.3.1
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-p7gr-f84w-hqg5

OpenClaw versions prior to 2026.3.1 fail to enforce sandbox inheritance during cross-agent sessions_spawn operations, allowing sandboxed sessions to create child processes under unsandboxed agents. An attacker with a sandboxed session can exploit this to spawn child runtimes with sandbox.mode set to off, bypassing runtime confinement restrictions.

References:


CVE-2026-42422 โ€” OpenClaw < 2026.4.8 - Role Bypass in device.token.rotate Function

FieldDetail
CVSS7.7 (HIGH) โ€” CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CWECWE-863 (CWE-863: Incorrect Authorization)
Affected< 2026.4.8
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-whf9-3hcx-gq54

OpenClaw before 2026.4.8 contains a role bypass vulnerability in the device.token.rotate function that allows minting tokens for unapproved roles. Attackers can bypass device role-upgrade pairing to preserve or mint roles and scopes that had not undergone intended approval.

References:


CVE-2026-53806 โ€” OpenClaw < 2026.5.12 - Shell Option Parsing Bypass in Exec Revalidation

FieldDetail
CVSS7.7 (HIGH) โ€” CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CWECWE-367 (Time-of-check Time-of-use (TOCTOU) Race Condition)
Affected< 2026.5.12
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-vxx3-6hc9-7cc3

OpenClaw before 2026.5.12 contains a shell option parsing vulnerability that allows combined POSIX shell flags to bypass exec revalidation checks. Attackers can exploit this by using combined shell options to execute inline shell content without intended allowlist validation, potentially enabling unauthorized command execution when the affected feature is enabled.

References:


CVE-2026-53811 โ€” OpenClaw: Matrix allowFrom could bind to mutable display names

FieldDetail
CVSS7.7 (HIGH) โ€” CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CWECWE-290 (Authentication Bypass by Spoofing)
Affected< 2026.5.7
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-7hxm-f538-3xp6

OpenClaw before 2026.5.7 contains a privilege escalation vulnerability in the Matrix allowFrom feature that allows authenticated accounts to match policy entries through mutable display name metadata. Attackers with the ability to change display names can receive agent access intended for another Matrix identity, potentially gaining unauthorized permissions depending on operator configuration.

References:


CVE-2026-53810 โ€” OpenClaw's marketplace runtime extension metadata could point at unscanned payloads

FieldDetail
CVSS7.7 (HIGH) โ€” CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CWECWE-829 (Inclusion of Functionality from Untrusted Control Sphere)
Affected< 2026.5.18
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-v6r2-jh58-xx6w

OpenClaw before 2026.5.18 contains a code execution vulnerability where marketplace runtime extension metadata can redirect loading toward unscanned package payloads. Attackers with trusted operator access can manipulate extension metadata to load plugin code outside reviewed package entry points, bypassing security scanning.

References:


CVE-2026-53853 โ€” OpenClaw: Linux and macOS exec allowlists skipped configured argument patterns

FieldDetail
CVSS7.6 (HIGH) โ€” CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N
CWECWE-693 (Protection Mechanism Failure), CWE-863 (Incorrect Authorization)
Affected< 2026.5.12
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-v2ww-5rh7-2h5v

OpenClaw before 2026.5.12 contains an argument pattern validation bypass in the exec allowlist that allows attackers to execute disallowed arguments for allowlisted executables on Linux and macOS systems. Attackers can bypass configured argPattern restrictions by directly invoking allowlisted executables with unrestricted arguments, potentially enabling unauthorized file access, network access, or command execution.

References:


CVE-2026-53855 โ€” OpenClaw < 2026.4.2 - Shell Positional Parameters Bypass in Inline-Eval Checks

FieldDetail
CVSS7.6 (HIGH) โ€” CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
CWECWE-184 (Incomplete List of Disallowed Inputs), CWE-863 (Incorrect Authorization)
Affected< 2026.4.2
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-5cj2-3jr2-5h77

OpenClaw before 2026.4.2 contains an inline-eval bypass vulnerability allowing authenticated operators to weaken strict allowlist checks via shell positional parameters. Attackers can combine allowlisted tools with shell positional arguments to place inline-eval content in shell carriers outside intended allowlist rules, enabling execution of unapproved shell-provided content.

References:


CVE-2026-53864 โ€” OpenClaw: Host environment sanitizer missed two Node.js control variables

FieldDetail
CVSS7.6 (HIGH) โ€” CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
CWECWE-184 (Incomplete List of Disallowed Inputs)
Affected< 2026.5.26
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-ccwh-wwpp-6wg5

OpenClaw before 2026.5.26 contains an insufficient sanitization vulnerability in the host environment sanitizer that allows Node.js control variables to bypass validation. Attackers with access to workspace .env files, tool environment overrides, or skill environment blocks can pass malicious Node.js control variables to influence child processes or coverage output paths.

References:


CVE-2026-53866 โ€” OpenClaw < 2026.5.12 - Allowlist Bypass in Shell Inline-Command Parsing

FieldDetail
CVSS7.6 (HIGH) โ€” CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
CWECWE-862 (Missing Authorization)
Affected< 2026.5.12
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-f397-5vjw-v2c2

OpenClaw before 2026.5.12 contains an allowlist bypass vulnerability in shell inline-command parsing that allows authenticated operators to execute unapproved commands. A command request using shell inline-command forms could route through a parser case missing the expected allowlist decision, enabling shell content execution without intended approval prompts.

References:


CVE-2026-42428 โ€” OpenClaw < 2026.4.8 - Missing Integrity Verification in Package Downloads

FieldDetail
CVSS7.5 (HIGH) โ€” CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CWECWE-353 (CWE-353 Missing Support for Integrity Check)
Affected< 2026.4.8
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-3vvq-q2qc-7rmp

OpenClaw versions before 2026.4.8 fail to enforce integrity verification on downloaded plugin archives. Attackers can install malicious or tampered plugin packages without detection, compromising the local assistant environment.

References:


FieldDetail
CVSS7.4 (HIGH) โ€” CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
CWECWE-306 (Missing Authentication for Critical Function)
Affected< 2026.2.1
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-mr32-vwc2-5j6h

OpenClaw version 2026.1.20 prior to 2026.2.1 contains a vulnerability in the Browser Relay (extension must be installed and enabled) /cdp WebSocket endpoint in which it does not require authentication tokens, allowing websites to connect via loopback and access sensitive data. Attackers can exploit this by connecting to ws://127.0.0.1:18792/cdp to steal session cookies and execute JavaScript in other browser tabs.

References:


CVE-2026-53833 โ€” QQBot for OpenClaw < 2026.4.29 - Authorization Bypass via QQBot Streaming Command

FieldDetail
CVSS7.4 (HIGH) โ€” CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
CWECWE-290 (Authentication Bypass by Spoofing)
Affected< 2026.4.29
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-jvm4-4j77-39p6

OpenClaw before 2026.4.29 contains an authorization bypass vulnerability in the QQBot streaming command that allows authenticated senders to mutate configuration without explicit allowFrom restrictions. Attackers can modify QQBot streaming configuration outside intended admin policy by reaching the affected command without non-wildcard allowlist entry requirements.

References:


CVE-2026-42432 โ€” OpenClaw < 2026.4.8 - Command Escalation via Node Pairing Reconnect Bypass

FieldDetail
CVSS7.3 (HIGH) โ€” CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CWECWE-863 (CWE-863: Incorrect Authorization)
Affected< 2026.4.8
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-5wj5-87vq-39xm

OpenClaw before 2026.4.8 contains a privilege escalation vulnerability allowing previously paired nodes to reconnect with exec-capable commands without operator.admin scope requirement. Attackers can bypass re-pairing authentication to execute privileged commands on the local assistant system.

References:


CVE-2026-53813 โ€” OpenClaw: Fake package roots could influence memory-core artifact loading

FieldDetail
CVSS7.3 (HIGH) โ€” CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CWECWE-427 (Uncontrolled Search Path Element)
Affected< 2026.4.25
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-v8cx-933x-r976

OpenClaw before 2026.4.25 contains a path traversal vulnerability in memory-core artifact loading where workspace state influences local package root resolution. Attackers with access to affected workspaces can load memory-core artifacts from unintended local locations, potentially executing malicious code or accessing sensitive data.

References:


CVE-2026-34512 โ€” OpenClaw < 2026.3.25 - Improper Access Control in /sessions/:sessionKey/kill Endpoint

FieldDetail
CVSS7.2 (HIGH) โ€” CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N
CWECWE-863 (CWE-863: Incorrect Authorization)
Affected< 2026.3.25
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-9p93-7j67-5pc2

OpenClaw before 2026.3.25 contains an improper access control vulnerability in the HTTP /sessions/:sessionKey/kill route that allows any bearer-authenticated user to invoke admin-level session termination functions without proper scope validation. Attackers can exploit this by sending authenticated requests to kill arbitrary subagent sessions via the killSubagentRunAdmin function, bypassing ownership and operator scope restrictions.

References:


FieldDetail
CVSS7.2 (HIGH) โ€” CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N
CWECWE-59 (CWE-59: Improper Link Resolution Before File Access ('Link Following'))
Affected< 2026.3.31
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-fv94-qvg8-xqpw

OpenClaw before 2026.3.31 contains a symlink following vulnerability in SSH sandbox tar upload that allows remote attackers to write arbitrary files. Attackers can exploit this by uploading tar archives containing symlinks to escape the sandbox and overwrite files on the remote host.

References:


CVE-2026-53865 โ€” OpenClaw: Workspace-derived service PATH could influence trash command selection

FieldDetail
CVSS7.2 (HIGH) โ€” CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
CWECWE-426 (Untrusted Search Path)
Affected< 2026.5.2
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-rx78-29qr-5hq8

OpenClaw before 2026.5.2 contains a path traversal vulnerability in maintenance task execution that allows workspace-derived service paths to influence trash command selection. Attackers can execute unintended local executables from operator-unintended paths during maintenance operations by manipulating workspace-derived environment paths.

References:


CVE-2026-26317 โ€” OpenClaw affected by cross-site request forgery (CSRF) through loopback browser mutation endpoints

FieldDetail
CVSS7.1 (HIGH) โ€” CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L
CWECWE-352 (CWE-352: Cross-Site Request Forgery (CSRF))
Affected<= 2026.1.24-3
Vendor/Productopenclaw / clawdbot
AdvisoryGHSA-3fqr-4cg8-h96q

OpenClaw is a personal AI assistant. Prior to 2026.2.14, browser-facing localhost mutation routes accepted cross-origin browser requests without explicit Origin/Referer validation. Loopback binding reduces remote exposure but does not prevent browser-initiated requests from malicious origins. A malicious website can trigger unauthorized state changes against a victim's local OpenClaw browser control plane (for example opening tabs, starting/stopping the browser, mutating storage/cookies) if the browser control service is reachable on loopback in the victim's browser context. Starting in version 2026.2.14, mutating HTTP methods (POST/PUT/PATCH/DELETE) are rejected when the request indicates a non-loopback Origin/Referer (or Sec-Fetch-Site: cross-site). Other mitigations include enabling browser control auth (token/password) and avoid running with auth disabled.

Naming note: Uses old name openclaw/clawdbot as vendor/product. References:


CVE-2026-22169 โ€” OpenClaw < 2026.2.22 - Allowlist Bypass via sort Configuration in safeBins

FieldDetail
CVSS7.1 (HIGH) โ€” CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CWECWE-78 (Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78))
Affected< 2026.2.22
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-vmqr-rc7x-3446

OpenClaw versions prior to 2026.2.22 contain an allowlist bypass vulnerability in the safeBins configuration that allows attackers to invoke external helpers through the compress-program option. When sort is explicitly added to tools.exec.safeBins, remote attackers can bypass intended safe-bin approval constraints by leveraging the compress-program parameter to execute unauthorized external programs.

References:


CVE-2026-35621 โ€” OpenClaw < 2026.3.24 - Privilege Escalation via chat.send to Allowlist Persistence

FieldDetail
CVSS7.1 (HIGH) โ€” CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
CWECWE-862 (CWE-862 Missing Authorization)
Affected< 2026.3.24
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-94pw-c6m8-p9p9

OpenClaw before 2026.3.24 contains a privilege escalation vulnerability where the /allowlist command fails to re-validate gateway client scopes for internal callers, allowing operator.write-scoped clients to mutate channel authorization policy. Attackers can exploit chat.send to build an internal command-authorized context and persist channel allowFrom and groupAllowFrom policy changes reserved for operator.admin scope.

References:


CVE-2026-35636 โ€” OpenClaw 2026.3.11 < 2026.3.25 - Session Isolation Bypass via sessionId Resolution

FieldDetail
CVSS7.1 (HIGH) โ€” CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
CWECWE-696 (CWE-696: Incorrect Behavior Order)
Affected< *
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-q2qc-744p-66r2

OpenClaw versions 2026.3.11 through 2026.3.24 contain a session isolation bypass vulnerability where session_status resolves sessionId to canonical session keys before enforcing visibility checks. Sandboxed child sessions can exploit this to access parent or sibling sessions that should be blocked by explicit sessionKey restrictions.

References:


CVE-2026-41299 โ€” OpenClaw < 2026.3.28 - Client Identity Spoofing in chat.send Gateway Provenance Guard

FieldDetail
CVSS7.1 (HIGH) โ€” CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N
CWECWE-807 (CWE-807 Reliance on Untrusted Inputs in a Security Decision)
Affected< 2026.3.28
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-6xg4-82hv-cp6f

OpenClaw before 2026.3.28 contains an authorization bypass vulnerability in the chat.send gateway method where ACP-only provenance fields are gated by self-declared client metadata from WebSocket handshake rather than verified authorization state. Authenticated operator clients can spoof ACP identity labels and inject reserved provenance fields intended only for the ACP bridge by manipulating client metadata during connection.

References:


CVE-2026-41359 โ€” OpenClaw < 2026.3.28 - Privilege Escalation via operator.write to Admin-Class Telegram Config and Cron Persistence

FieldDetail
CVSS7.1 (HIGH) โ€” CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N
CWECWE-269 (CWE-269 Improper Privilege Management)
Affected< 2026.3.28
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-767m-xrhc-fxm7

OpenClaw before 2026.3.28 contains a privilege escalation vulnerability allowing authenticated operators with write permissions to access admin-class Telegram configuration and cron persistence settings via the send endpoint. Attackers with operator.write credentials can exploit insufficient access controls to reach sensitive administrative functionality and modify persistence mechanisms.

References:


CVE-2026-41375 โ€” OpenClaw < 2026.3.28 - Authorization Bypass in /phone arm and /phone disarm Endpoints

FieldDetail
CVSS7.1 (HIGH) โ€” CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
CWECWE-863 (CWE-863: Incorrect Authorization)
Affected< 2026.3.28
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-h2v7-xc88-xx8c

OpenClaw before 2026.3.28 contains an authorization bypass vulnerability in the /phone arm and /phone disarm endpoints that fails to properly enforce operator.admin scope checks for external channels. Attackers can bypass authentication restrictions to arm or disarm phone channels without proper administrative privileges.

References:


CVE-2026-53815 โ€” OpenClaw < 2026.5.19 - Channel Allowlist Bypass in Message Read Actions

FieldDetail
CVSS7.1 (HIGH) โ€” CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
CWECWE-862 (Missing Authorization)
Affected< 2026.5.19
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-q7q8-3mgw-q67r

OpenClaw before 2026.5.19 contains an authorization bypass vulnerability in message read actions that skips channel allowlist checks. Lower-trust callers can request messages from channels not intended for them by exploiting insufficient validation in the affected feature, potentially exposing sensitive channel messages.

References:


CVE-2026-43531 โ€” OpenClaw < 2026.4.9 - Environment Variable Injection via Workspace .env File

FieldDetail
CVSS7 (HIGH) โ€” CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CWECWE-15 (CWE-15: External Control of System or Configuration Setting)
Affected< 2026.4.9
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-7wv4-cc7p-jhxc

OpenClaw before 2026.4.9 contains an environment variable injection vulnerability allowing malicious workspace .env files to set runtime-control variables. Attackers can inject variables affecting update sources, gateway URLs, ClawHub resolution, and browser executable paths to compromise application behavior.

References:


CVE-2026-53842 โ€” OpenClaw: Workspace .env CLOUDSDK_PYTHON could influence Gmail setup gcloud execution

FieldDetail
CVSS7 (HIGH) โ€” CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
CWECWE-426 (Untrusted Search Path)
Affected< 2026.5.2
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-fq9j-vw4w-fr6v

OpenClaw before 2026.5.2 contains an environment variable injection vulnerability allowing workspace .env files to influence Python runtime selection through CLOUDSDK_PYTHON during Gmail setup gcloud execution. Attackers with repository access can manipulate the CLOUDSDK_PYTHON variable to execute setup through unintended local Python paths, potentially enabling arbitrary code execution.

References:


CVE-2026-53846 โ€” OpenClaw: Workspace .env npm_execpath could influence bundled runtime dependency install

FieldDetail
CVSS7 (HIGH) โ€” CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
CWECWE-426 (Untrusted Search Path)
Affected< 2026.4.29
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-24vr-rprv-67rf

OpenClaw before 2026.4.29 contains a path traversal vulnerability in the install helper that allows workspace .env files to override the npm_execpath configuration used for bundled runtime dependency installation. Attackers with workspace access can execute unintended local package-manager executables during dependency setup to compromise the build environment.

References:


CVE-2026-53858 โ€” OpenClaw: Workspace .env STATE_DIRECTORY could influence bundled runtime dependency roots

FieldDetail
CVSS7 (HIGH) โ€” CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
CWECWE-426 (Untrusted Search Path)
Affected< 2026.5.2
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-wc84-j36w-pw4x

OpenClaw before 2026.5.2 contains an environment variable injection vulnerability where workspace .env STATE_DIRECTORY could influence bundled runtime dependency roots. Attackers can manipulate the STATE_DIRECTORY variable to load runtime dependencies from unintended local paths, potentially executing malicious code during dependency resolution.

References:


FieldDetail
CVSS6.9 (MEDIUM) โ€” CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N
CWECWE-367 (CWE-367: Time-of-check Time-of-use (TOCTOU) Race Condition)
Affected< 2026.2.26
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-f7ww-2725-qvw2

OpenClaw versions prior to 2026.2.26 contain an approval bypass vulnerability in system.run execution that allows attackers to execute commands from unintended filesystem locations by rebinding writable parent symlinks in the current working directory after approval. An attacker can modify mutable parent symlink path components between approval and execution time to redirect command execution to a different location while preserving the visible working directory string.

References:


FieldDetail
CVSS6.9 (MEDIUM) โ€” CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N
CWECWE-22 (CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'))
Affected< 2026.2.24
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-m8v2-6wwh-r4gc

OpenClaw versions prior to 2026.2.24 contain a sandbox bind validation vulnerability allowing attackers to bypass allowed-root and blocked-path checks via symlinked parent directories with non-existent leaf paths. Attackers can craft bind source paths that appear within allowed roots but resolve outside sandbox boundaries once missing leaf components are created, weakening bind-source isolation enforcement.

References:


CVE-2026-27004 โ€” OpenClaw session tool visibility hardening and Telegram webhook secret fallback

FieldDetail
CVSS6.9 (MEDIUM) โ€” CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
CWECWE-209 (CWE-209: Generation of Error Message Containing Sensitive Information), CWE-346 (CWE-346: Origin Validation Error)
Affected< 2026.2.15
Vendor/Productopenclaw / openclaw
AdvisoryGHSA-6hf3-mhgc-cm65

OpenClaw is a personal AI assistant. Prior to version 2026.2.15, in some shared-agent deployments, OpenClaw session tools (sessions_list, sessions_history, sessions_send) allowed broader session targeting than some operators intended. This is primarily a configuration/visibility-scoping issue in multi-user environments where peers are not equally trusted. In Telegram webhook mode, monitor startup also did not fall back to per-account webhookSecret when only the account-level secret was configured. In shared-agent, multi-user, less-trusted environments: session-tool access could expose transcript content across peer sessions. In single-agent or trusted environments, practical impact is limited. In Telegram webhook mode, account-level secret wiring could be missed unless an explicit monitor webhook secret override was provided. Version 2026.2.15 fixes the issue.

References:


CVE-2026-28480 โ€” OpenClaw Telegram allowlist authorization accepted mutable usernames

FieldDetail
CVSS6.9 (MEDIUM) โ€” CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
CWECWE-290 (Authentication Bypass by Spoofing)
Affected< 2026.2.14
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-mj5r-hh7j-4gxf

OpenClaw versions prior to 2026.2.14 contain an authorization bypass vulnerability where Telegram allowlist matching accepts mutable usernames instead of immutable numeric sender IDs. Attackers can spoof identity by obtaining recycled usernames to bypass allowlist restrictions and interact with bots as unauthorized senders.

References:


CVE-2026-32919 โ€” OpenClaw < 2026.3.11 - Unauthorized Session Reset via agent Slash Commands

FieldDetail
CVSS6.9 (MEDIUM) โ€” CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N
CWECWE-863 (Incorrect Authorization)
Affected< 2026.3.11
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-jf6w-m8jw-jfxc

OpenClaw before 2026.3.11 contains an authorization bypass vulnerability allowing write-scoped callers to reach admin-only session reset logic. Attackers with operator.write scope can issue agent requests containing /new or /reset slash commands to reset targeted conversation state without holding operator.admin privileges.

References:


CVE-2026-35652 โ€” OpenClaw < 2026.3.22 - Unauthorized Action Execution via Callback Dispatch

FieldDetail
CVSS6.9 (MEDIUM) โ€” CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N
CWECWE-696 (CWE-696: Incorrect Behavior Order)
Affected< 2026.3.22
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-8883-9w57-vwv6

OpenClaw before 2026.3.22 contains an authorization bypass vulnerability in interactive callback dispatch that allows non-allowlisted senders to execute action handlers. Attackers can bypass sender authorization checks by dispatching callbacks before normal security validation completes, enabling unauthorized actions.

References:


CVE-2026-41301 โ€” OpenClaw 2026.3.22 < 2026.3.31 - Forged Nostr DM Pairing State Creation via Signature Verification Bypass

FieldDetail
CVSS6.9 (MEDIUM) โ€” CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
CWECWE-347 (CWE-347: Improper Verification of Cryptographic Signature)
Affected< 2026.3.31
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-h43v-27wg-5mf9

OpenClaw versions 2026.3.22 before 2026.3.31 contain a signature verification bypass vulnerability in the Nostr DM ingress path that allows pairing challenges to be issued before event signature validation. An unauthenticated remote attacker can send forged direct messages to create pending pairing entries and trigger pairing-reply attempts, consuming shared pairing capacity and triggering bounded relay and logging work on the Nostr channel.

References:


CVE-2026-41343 โ€” OpenClaw < 2026.3.31 - Denial of Service via LINE Webhook Handler Pre-Auth Concurrency

FieldDetail
CVSS6.9 (MEDIUM) โ€” CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
CWECWE-799 (Improper Control of Interaction Frequency)
Affected< 2026.3.31
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-qcc3-jqwp-5vh2

OpenClaw before 2026.3.31 lacks a shared pre-auth concurrency budget on the public LINE webhook path, allowing attackers to cause transient availability loss. Remote attackers can flood the webhook endpoint with concurrent requests before signature verification to exhaust resources and degrade service availability.

References:


CVE-2026-41335 โ€” OpenClaw < 2026.3.31 - Information Disclosure via Control UI Bootstrap JSON

FieldDetail
CVSS6.9 (MEDIUM) โ€” CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
CWECWE-497 (CWE-497: Exposure of Sensitive System Information to an Unauthorized Control Sphere)
Affected< 2026.3.31
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-hr8g-2q7x-3f4w

OpenClaw before 2026.3.31 contains an information disclosure vulnerability in the Control Interface bootstrap JSON that exposes version and assistant agent identifiers. Attackers can extract sensitive fingerprinting information from the Control UI bootstrap payload to identify system versions and agent configurations.

References:


CVE-2026-41372 โ€” OpenClaw < 2026.4.2 - Loopback Protection Bypass via Trailing-Dot Localhost in CDP Discovery

FieldDetail
CVSS6.9 (MEDIUM) โ€” CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N
CWECWE-639 (CWE-639 Authorization Bypass Through User-Controlled Key)
Affected< 2026.4.2
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-fh32-73r9-rgh5

OpenClaw before 2026.4.2 fails to normalize trailing-dot localhost hosts in remote CDP discovery responses, allowing bypass of loopback protections. Attackers can craft hostile discovery responses returning localhost. to retarget authenticated browser control toward localhost endpoints and expose browser state.

References:


CVE-2026-53818 โ€” OpenClaw < 2026.4.24 - Owner-Only Tool Policy Bypass via MCP Loopback

FieldDetail
CVSS6.9 (MEDIUM) โ€” CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N
CWECWE-862 (Missing Authorization)
Affected< 2026.4.24
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-rj6p-xmxr-qj4h

OpenClaw before 2026.4.24 contains an authorization bypass vulnerability in the MCP loopback feature that allows non-owner callers to skip owner-only tool policies and before-tool-call hooks. Attackers can invoke owner-only behavior through the affected loopback path to execute restricted tools when the feature is enabled and reachable.

References:


CVE-2026-29612 โ€” OpenClaw < 2026.2.14 - Denial of Service via Large Base64 Media File Decoding

FieldDetail
CVSS6.8 (MEDIUM) โ€” CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
CWECWE-770 (Allocation of Resources Without Limits or Throttling)
Affected< 2026.2.14
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-w2cg-vxx6-5xjg

OpenClaw versions prior to 2026.2.14 decode base64-backed media inputs into buffers before enforcing decoded-size budget limits, allowing attackers to trigger large memory allocations. Remote attackers can supply oversized base64 payloads to cause memory pressure and denial of service.

References:


CVE-2026-45224 โ€” Crabbox < 0.9.0 Path Traversal via Islo Provider Workspace Resolution

FieldDetail
CVSS6.8 (MEDIUM) โ€” CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N
CWECWE-22 (Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'))
Affected< 0.9.0
Vendor/Productopenclaw / crabbox
Advisory

Crabbox before 0.9.0 contains a path traversal vulnerability in the Islo provider's workspace path resolution that allows attackers to supply absolute or relative paths that resolve outside the intended /workspace directory. Attackers can craft a malicious .crabbox.yaml or crabbox.yaml file with traversal sequences to cause arbitrary file deletion and overwrite when sync.delete is enabled, as the workspace preparation logic executes rm -rf and mkdir -p operations on the resolved path without proper validation.

References:


CVE-2026-53850 โ€” OpenClaw < 2026.4.25 - Control Scope Enforcement Bypass in Focus Command

FieldDetail
CVSS6.8 (MEDIUM) โ€” CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
CWECWE-862 (Missing Authorization)
Affected< 2026.4.25
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-mpc8-jxjh-qpgh

OpenClaw before 2026.4.25 contains a control scope enforcement bypass vulnerability in the focus command that allows authenticated callers to execute the command without proper authorization checks. Attackers can trigger the focus command to change focus state outside intended caller authority, potentially enabling unauthorized operations depending on gateway configuration and input trust levels.

References:


CVE-2026-28452 โ€” OpenClaw affected by denial of service through unguarded archive extraction allowing high expansion/resource abuse (ZIP/TAR)

FieldDetail
CVSS6.7 (MEDIUM) โ€” CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
CWECWE-770 (Allocation of Resources Without Limits or Throttling)
Affected< 2026.2.14
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-h89v-j3x9-8wqj

OpenClaw versions prior to 2026.2.14 contain a denial of service vulnerability in the extractArchive function within src/infra/archive.ts that allows attackers to consume excessive CPU, memory, and disk resources through high-expansion ZIP and TAR archives. Remote attackers can trigger resource exhaustion by providing maliciously crafted archive files during install or update operations, causing service degradation or system unavailability.

References:


CVE-2026-32044 โ€” OpenClaw < 2026.3.2 - Tar Archive Safety Bypass in Skills Installation

FieldDetail
CVSS6.7 (MEDIUM) โ€” CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
CWECWE-409 (CWE-409 Improper Handling of Highly Compressed Data (Data Amplification))
Affected< 2026.3.2
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-77hf-7fqf-f227

OpenClaw versions prior to 2026.3.2 contain an archive extraction vulnerability in the tar.bz2 installer path that bypasses safety checks enforced on other archive formats. Attackers can craft malicious tar.bz2 skill archives to bypass special-entry blocking and extracted-size guardrails, causing local denial of service during skill installation.

References:


CVE-2026-26328 โ€” OpenClaw iMessage group allowlist authorization inherited DM pairing-store identities

FieldDetail
CVSS6.5 (MEDIUM) โ€” CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
CWECWE-284 (CWE-284: Improper Access Control), CWE-863 (CWE-863: Incorrect Authorization)
Affected<= 2026.1.24-3
Vendor/Productopenclaw / clawdbot
AdvisoryGHSA-g34w-4xqq-h79m

OpenClaw is a personal AI assistant. Prior to version 2026.2.14, under iMessage groupPolicy=allowlist, group authorization could be satisfied by sender identities coming from the DM pairing store, broadening DM trust into group contexts. Version 2026.2.14 fixes the issue.

Naming note: Uses old name openclaw/clawdbot as vendor/product. References:


CVE-2026-35673 โ€” OpenClaw < 2026.4.29 - SSRF Policy Bypass via Browser Debug/Export Routes

FieldDetail
CVSS6.5 (MEDIUM) โ€” CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:L/A:N
CWECWE-863 (Incorrect Authorization)
Affected< 2026.4.29
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-hcm3-8f6r-6xwg

OpenClaw before 2026.4.29 contains an SSRF policy bypass vulnerability in browser debug and export routes that allows reuse of already-open blocked tabs. Attackers with access to these routes can bypass private-network SSRF policies by reusing blocked tabs to export or inspect content that should remain protected.

References:


CVE-2026-28448 โ€” OpenClaw 2026.1.29 < 2026.2.1 - Authorization Bypass in Twitch Plugin allowFrom Access Control

FieldDetail
CVSS6.3 (MEDIUM) โ€” CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
CWECWE-285 (Improper Authorization)
Affected< 2026.2.1
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-33rq-m5x2-fvgf

OpenClaw versions 2026.1.29 prior to 2026.2.1 contain a vulnerability in the Twitch plugin (must be installed and enabled) in which it fails to enforce the allowFrom allowlist when allowedRoles is unset or empty, allowing unauthorized Twitch users to trigger agent dispatch. Remote attackers can mention the bot in Twitch chat to bypass access control and invoke the agent pipeline, potentially causing unintended actions or resource exhaustion.

References:


CVE-2026-28471 โ€” OpenClaw 2026.1.14-1 < 2026.2.2 - Allowlist Bypass via displayName and Cross-Homeserver localpart Matching in Matrix Plugin

FieldDetail
CVSS6.3 (MEDIUM) โ€” CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
CWECWE-287 (Improper Authentication)
Affected< 2026.2.2
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-rmxw-jxxx-4cpc

OpenClaw version 2026.1.14-1 prior to 2026.2.2, with the Matrix plugin installed and enabled, contain a vulnerability in which DM allowlist matching could be bypassed by exact-matching against sender display names and localparts without homeserver validation. Remote Matrix users can impersonate allowed identities by using attacker-controlled display names or matching localparts from different homeservers to reach the routing and agent pipeline.

References:


CVE-2026-33580 โ€” OpenClaw < 2026.3.28 - Brute Force Attack via Missing Rate Limiting on Webhook Shared Secret Authentication

FieldDetail
CVSS6.3 (MEDIUM) โ€” CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
CWECWE-307 (CWE-307 Improper Restriction of Excessive Authentication Attempts)
Affected< 2026.3.28
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-9528-x887-j2fp

OpenClaw before 2026.3.28 contains a missing rate limiting vulnerability in the Nextcloud Talk webhook authentication that allows attackers to brute-force weak shared secrets. Attackers who can reach the webhook endpoint can exploit this to forge inbound webhook events by repeatedly attempting authentication without throttling.

References:


CVE-2026-35649 โ€” OpenClaw < 2026.3.22 - Settings Reconciliation Bypass via Empty Allowlist

FieldDetail
CVSS6.3 (MEDIUM) โ€” CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
CWECWE-183 (CWE-183: Permissive List of Allowed Inputs)
Affected< 2026.3.22
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-pw7h-9g6p-c378

OpenClaw before 2026.3.22 contains a settings reconciliation vulnerability that allows attackers to bypass intended deny-all revocations by exploiting empty allowlist handling. The vulnerability treats explicit empty allowlists as unset during reconciliation, silently undoing intended access control denials and restoring previously revoked permissions.

References:


CVE-2026-35656 โ€” OpenClaw < 2026.3.22 - XFF Loopback Spoofing Bypass in Canvas Authentication and Rate Limiter

FieldDetail
CVSS6.3 (MEDIUM) โ€” CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
CWECWE-290 (CWE-290: Authentication Bypass by Spoofing)
Affected< 2026.3.22
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-844j-xrrq-wgh4

OpenClaw before 2026.3.22 contains an authentication bypass vulnerability in the X-Forwarded-For header processing when trustedProxies is configured, allowing attackers to spoof loopback hops. Remote attackers can inject forged forwarding headers to bypass canvas authentication and rate-limiting protections by masquerading as loopback clients.

References:


CVE-2026-53851 โ€” OpenClaw < 2026.5.12 - Slack Reaction Event Notification Bypass

FieldDetail
CVSS6.3 (MEDIUM) โ€” CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
CWECWE-862 (Missing Authorization)
Affected< 2026.5.12
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-fcvx-5cxc-v5p8

OpenClaw before 2026.5.12 contains a notification bypass vulnerability allowing Slack reaction events to enter the agent pipeline despite disabled reaction notifications. Attackers can trigger unintended agent processing by sending reaction events when the feature is enabled, potentially leading to unauthorized processing of lower-trust input.

References:


CVE-2026-62220 โ€” OpenClaw 2026.2.25 < 2026.5.26 WebSocket Rate Limit Bypass

FieldDetail
CVSS6.3 (MEDIUM) โ€” CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
CWECWE-307 (Improper Restriction of Excessive Authentication Attempts)
Affected< 2026.5.26
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-5p6w-wmh3-frfr

OpenClaw 2026.2.25 before 2026.5.26 allow a lower-trust caller or configured input path to bypass non-browser rate limits on WebSocket authentication attempts. When the affected feature is enabled and reachable by lower-trust input, this can consume gateway resources and reduce service availability.

References:


CVE-2026-41366 โ€” OpenClaw < 2026.3.31 - Arbitrary Host File Read via appendLocalMediaParentRoots Self-Whitelisting

FieldDetail
CVSS6 (MEDIUM) โ€” CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
CWECWE-732 (CWE-732: Incorrect Permission Assignment for Critical Resource)
Affected< 2026.3.31
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-57gh-m6rq-54cf

OpenClaw before 2026.3.31 contains a local roots self-whitelisting vulnerability in appendLocalMediaParentRoots that allows model-initiated arbitrary host file read. Attackers can exploit improper media parent directory validation to exfiltrate credentials and access sensitive files.

References:


CVE-2026-45001 โ€” OpenClaw < 2026.4.20 - Gateway Config Mutation Guard Bypass via Agent Tool Access

FieldDetail
CVSS6 (MEDIUM) โ€” CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N
CWECWE-862 (Missing Authorization)
Affected< 2026.4.20
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-7jm2-g593-4qrc

OpenClaw before 2026.4.20 contains a guard bypass vulnerability in the agent-facing gateway config.patch and config.apply endpoints that fails to protect operator-trusted settings including sandbox policy, plugin enablement, gateway auth/TLS, hook routing, MCP server configuration, SSRF policy, and filesystem hardening. A prompt-injected model with access to the owner-only gateway tool can persist unauthorized changes to protected operator settings.

References:


CVE-2026-53840 โ€” OpenClaw: MCP Streamable HTTP redirects could forward configured custom headers to another origin

FieldDetail
CVSS6 (MEDIUM) โ€” CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N
CWECWE-522 (Insufficiently Protected Credentials)
Affected< 2026.5.12
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-rjxq-qqhf-8hwh

OpenClaw before 2026.5.12 contains an information disclosure vulnerability in streamable-http MCP servers that forwards operator-configured custom headers during cross-origin redirects. Attackers controlling or compromising an MCP endpoint can redirect requests to exfiltrate sensitive headers like API keys or tenant-routing credentials to attacker-controlled origins.

References:


FieldDetail
CVSS6 (MEDIUM) โ€” CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
CWECWE-862 (Missing Authorization)
Affected< 2026.4.29
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-72fw-cqh5-f324

OpenClaw before 2026.4.29 contains a session visibility check bypass vulnerability in shared memory search that allows authenticated callers to access memory entries without proper authorization. Attackers can skip session visibility guards on the search path to retrieve memory entries that should not be visible to their session.

References:


CVE-2026-53854 โ€” OpenClaw: Internal/webchat command auth could inherit ownerAllowFrom wildcard state

FieldDetail
CVSS6 (MEDIUM) โ€” CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
CWECWE-863 (Incorrect Authorization)
Affected< 2026.4.25
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-4hpg-mp64-x7xq

OpenClaw before 2026.4.25 contains a privilege escalation vulnerability in internal and webchat command authentication that allows senders to inherit wildcard ownerAllowFrom state across channel boundaries. Attackers can exploit this by sending commands on affected internal or webchat paths to execute owner-style command behavior outside intended channel scope, potentially bypassing access controls.

References:


CVE-2026-53859 โ€” OpenClaw < 2026.5.26 - Hostname Validation Bypass via Trailing-Dot Inconsistency

FieldDetail
CVSS6 (MEDIUM) โ€” CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
CWECWE-1023 (Incomplete Comparison with Missing Factors), CWE-918 (Server-Side Request Forgery (SSRF))
Affected< 2026.5.26
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-gxg4-2rrr-jhc7

OpenClaw before 2026.5.26 contains a hostname validation vulnerability allowing attackers to bypass blocklist comparisons using trailing-dot notation in model or workspace-derived URLs. Attackers can exploit inconsistent hostname checks to reach destinations that operators intended to block through hostname policies.

References:


CVE-2026-53863 โ€” OpenClaw < 2026.4.25 - Unvalidated Group ID Acceptance in Tool Group Policy

FieldDetail
CVSS6 (MEDIUM) โ€” CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N
CWECWE-639 (Authorization Bypass Through User-Controlled Key)
Affected< 2026.4.25
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-985f-72mj-8gf7

OpenClaw before 2026.4.25 contains an input validation vulnerability in tool group policy callers that accept unvalidated group IDs. Attackers who can supply a group ID to the policy resolver could trigger incorrect group-policy decisions for tool invocations, potentially bypassing intended access controls.

References:


CVE-2026-62205 โ€” OpenClaw 2026.4.12-beta.1 < 2026.6.6 Authorization Bypass via message actions

FieldDetail
CVSS6 (MEDIUM) โ€” CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N
CWECWE-862 (Missing Authorization)
Affected< 2026.6.6
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-p5xh-frrh-cmgj

OpenClaw versions 2026.4.12-beta.1 before 2026.6.6 contain a missing-authorization vulnerability in the MS Teams message actions feature. When the affected feature is enabled and reachable, a lower-trust caller or a configured input path can perform actions that should have required a stronger authorization or policy check. Practical impact depends on the operator's configuration and whether lower-trust input can reach that path. The issue is fixed in 2026.6.6.

References:


CVE-2026-62210 โ€” OpenClaw < 2026.6.1 Denial of Service via Remote Media URLs

FieldDetail
CVSS6 (MEDIUM) โ€” CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
CWECWE-770 (Allocation of Resources Without Limits or Throttling)
Affected< 2026.6.1
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-4xwj-mcc7-x7x5

OpenClaw versions before 2026.6.1 contain a denial of service vulnerability where remote media URLs can trigger slow-read attacks that exhaust gateway worker resources. Attackers with access to configured input paths can supply remote media URLs that consume gateway resources and reduce availability.

References:


FieldDetail
CVSS5.9 (MEDIUM) โ€” CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N
CWECWE-59 (CWE-59: Improper Link Resolution Before File Access ('Link Following'))
Affected< 2026.2.25
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-36h3-7c54-j27r

OpenClaw versions prior to 2026.2.25 contain a symlink traversal vulnerability in browser trace and download output path handling that allows local attackers to escape the managed temp root directory. An attacker with local access can create symlinks to route file writes outside the intended temp directory, enabling arbitrary file overwrite on the affected system.

References:


CVE-2026-41393 โ€” OpenClaw < 2026.3.31 - Arbitrary DNS Authority Acceptance and Credential Exfiltration via Wide-Area Discovery

FieldDetail
CVSS5.9 (MEDIUM) โ€” CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
CWECWE-346 (CWE-346: Origin Validation Error)
Affected< 2026.3.31
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-q9w8-cf67-r238

OpenClaw before 2026.3.31 contains a wide-area discovery vulnerability allowing arbitrary tailnet peers to be accepted as DNS authorities. Attackers with same-tailnet position and CA-trusted endpoint access can exfiltrate operator credentials through DNS steering manipulation.

References:


CVE-2026-27646 โ€” OpenClaw < 2026.3.7 - Sandbox Escape via /acp spawn Command

FieldDetail
CVSS5.8 (MEDIUM) โ€” CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N
CWECWE-863 (CWE-863: Incorrect Authorization)
Affected< 2026.3.7
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-9q36-67vc-rrwg

OpenClaw versions prior to 2026.3.7 contain a sandbox escape vulnerability in the /acp spawn command that allows authorized sandboxed sessions to initialize host-side ACP runtime. Attackers can bypass sandbox restrictions by invoking the /acp spawn slash-command to cross from sandboxed chat context into host-side ACP session initialization when ACP is enabled.

References:


CVE-2026-32035 โ€” OpenClaw < 2026.3.2 - Missing Owner Flag Validation in Discord Voice Transcript Handler

FieldDetail
CVSS5.8 (MEDIUM) โ€” CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:A/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N
CWECWE-863 (CWE-863: Incorrect Authorization)
Affected< 2026.3.2
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-wpg9-4g4v-f9rc

OpenClaw versions prior to 2026.3.2 fail to pass the senderIsOwner flag when processing Discord voice transcripts in agentCommand, causing the flag to default to true. Non-owner voice participants can exploit this omission to access owner-only tools including gateway and cron functionality in mixed-trust channels.

References:


CVE-2026-31995 โ€” OpenClaw 2026.1.21 < 2026.2.19 - Command Injection via Windows Shell Fallback in Lobster Extension

FieldDetail
CVSS5.8 (MEDIUM) โ€” CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N
CWECWE-78 (Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78))
Affected< 2026.2.19
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-fg3m-vhrr-8gj6

OpenClaw versions 2026.1.21 prior to 2026.2.19 contain a command injection vulnerability in the Lobster extension's Windows shell fallback mechanism that allows attackers to inject arbitrary commands through tool-provided arguments. When spawn failures trigger shell fallback with shell: true, attackers can exploit cmd.exe command interpretation to execute malicious commands by controlling workflow arguments.

References:


CVE-2026-32977 โ€” OpenClaw < 2026.3.11 - Sandbox Boundary Bypass via Unanchored writeFile Commit Path

FieldDetail
CVSS5.8 (MEDIUM) โ€” CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N
CWECWE-367 (Time-of-check Time-of-use (TOCTOU) Race Condition)
Affected< 2026.3.11
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-xvx8-77m6-gwg6

OpenClaw before 2026.3.11 contains a sandbox boundary bypass vulnerability in the fs-bridge writeFile commit step that uses an unanchored container path during the final move operation. An attacker can exploit a time-of-check-time-of-use race condition by modifying parent paths inside the sandbox to redirect committed files outside the validated writable path within the container mount namespace.

References:


CVE-2026-32988 โ€” OpenClaw < 2026.3.11 - Sandbox Boundary Bypass via Unvalidated Temporary File Creation

FieldDetail
CVSS5.8 (MEDIUM) โ€” CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N
CWECWE-367 (Time-of-check Time-of-use (TOCTOU) Race Condition)
Affected< 2026.3.11
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-mj4p-rc52-m843

OpenClaw before 2026.3.11 contains a sandbox boundary bypass vulnerability in fs-bridge staged writes where temporary file creation and population are not pinned to a verified parent directory. Attackers can exploit a race condition in parent-path alias changes to write attacker-controlled bytes outside the intended validated path before the final guarded replace step executes.

References:


CVE-2026-53856 โ€” OpenClaw: Config recovery could restore openclaw.json with broad file permissions

FieldDetail
CVSS5.7 (MEDIUM) โ€” CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
CWECWE-732 (Incorrect Permission Assignment for Critical Resource)
Affected< 2026.4.24
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-rwp6-7w3q-75fq

OpenClaw 2026.4.23 before 2026.4.24 contains an insecure file permissions vulnerability in config recovery that restores OpenClaw.json with overly broad permissions. Local attackers on shared hosts can read sensitive configuration data by exploiting the recovery path to access the restored config file.

References:


CVE-2026-28457 โ€” OpenClaw < 2026.2.14 - Path Traversal in Sandbox Skill Mirroring via Name Parameter

FieldDetail
CVSS5.6 (MEDIUM) โ€” CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N
CWECWE-22 (Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'))
Affected< 2026.2.14
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-xw4p-pw82-hqr7

OpenClaw versions prior to 2026.2.14 contain a path traversal vulnerability in sandbox skill mirroring (must be enabled) that uses the skill frontmatter name parameter unsanitized when copying skills into the sandbox workspace. Attackers who provide a crafted skill package with traversal sequences like ../ or absolute paths in the name field can write files outside the sandbox workspace root directory.

References:


CVE-2026-33578 โ€” OpenClaw < 2026.3.28 - Sender Policy Allowlist Bypass via Policy Downgrade in Google Chat and Zalouser Extensions

FieldDetail
CVSS5.3 (MEDIUM) โ€” CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
CWECWE-863 (CWE-863 Incorrect Authorization)
Affected< 2026.3.28
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-63mg-xp9j-jfcm

OpenClaw before 2026.3.28 contains a sender policy bypass vulnerability in the Google Chat and Zalouser extensions where route-level group allowlist policies silently downgrade to open policy. Attackers can exploit this policy resolution flaw to bypass sender restrictions and interact with bots despite configured allowlist restrictions.

References:


CVE-2026-34425 โ€” OpenClaw - Shell-Bleed Protection Preflight Validation Bypass

FieldDetail
CVSS5.3 (MEDIUM) โ€” CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
CWECWE-184 (CWE-184 Incomplete List of Disallowed Inputs)
Affected< 8aceaf5d0f0ec552b75a792f7f0a3bfa5b091513
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-fvx6-pj3r-5q4q

OpenClaw versions prior to commit 8aceaf5 contain a preflight validation bypass vulnerability in shell-bleed protection that allows attackers to execute blocked script content by using piped or complex command forms that the parser fails to recognize. Attackers can craft commands such as piped execution, command substitution, or subshell invocation to bypass the validateScriptFileForShellBleed() validation checks and execute arbitrary script content that would otherwise be blocked.

References:


CVE-2026-41367 โ€” OpenClaw 2026.2.14 < 2026.3.28 - Policy Enforcement Bypass in Discord Component Interactions

FieldDetail
CVSS5.3 (MEDIUM) โ€” CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N
CWECWE-863 (CWE-863: Incorrect Authorization)
Affected< *
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-jp4j-q5fc-58gv

OpenClaw versions 2026.2.14 through 2026.3.24 fail to consistently apply guild and channel policy gates to Discord button and component interactions. Attackers can trigger privileged component actions from blocked contexts by bypassing channel policy enforcement.

References:


CVE-2026-53847 โ€” OpenClaw < 2026.5.6 - Privilege Escalation via Active Memory Write Scope

FieldDetail
CVSS5.3 (MEDIUM) โ€” CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N
CWECWE-266 (Incorrect Privilege Assignment)
Affected< 2026.5.6
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-x629-46cc-7xgw

OpenClaw before 2026.5.6 contains a privilege escalation vulnerability in the Active Memory write scope that allows Gateway operators with operator.write access to modify global configuration without requiring operator.admin privileges. Attackers with operator.write access can exploit insufficient scope validation to apply unauthorized configuration changes beyond the intended write scope.

References:


CVE-2026-53861 โ€” OpenClaw < 2026.5.6 - Allowlist Bypass via Combined POSIX Inline Flags on macOS

FieldDetail
CVSS5.3 (MEDIUM) โ€” CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
CWECWE-184 (Incomplete List of Disallowed Inputs)
Affected< 2026.5.6
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-c226-q6fx-6j6c

OpenClaw before 2026.5.6 contains an allowlist bypass vulnerability in the macOS Swift exec feature that misses combined POSIX inline-command flags. Attackers can execute shell content outside the intended allowlist check by using combined flag forms, potentially allowing unauthorized command execution depending on operator configuration.

References:


CVE-2026-53812 โ€” OpenClaw's browser act interactions could bypass private-network navigation checks

FieldDetail
CVSS4.9 (MEDIUM) โ€” CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N
CWECWE-918 (Server-Side Request Forgery (SSRF))
Affected< 2026.5.18
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-2hfg-4fh4-qp7f

OpenClaw before 2026.5.18 contains a server-side request forgery vulnerability in browser control that allows authenticated users to bypass private-network navigation checks through Playwright act interactions. Attackers can trigger navigation to private-network targets via action-triggered redirects and subsequently read restricted page content using browser evaluation capabilities.

References:


CVE-2026-62201 โ€” OpenClaw < 2026.6.6 Network Policy Bypass via exec-server

FieldDetail
CVSS4.9 (MEDIUM) โ€” CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N
CWECWE-918 (Server-Side Request Forgery (SSRF))
Affected< 2026.6.6
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-mgvr-6gvw-3rgr

OpenClaw versions before 2026.6.6 contain a network policy bypass vulnerability in the sandbox exec-server that allows lower-trust callers to reach internal network destinations blocked by OpenClaw policy. Attackers can send HTTP requests through the exec-server to access network resources that should have been restricted by configured policies.

References:


CVE-2026-15193 โ€” AidanPark openclaw-android Android WebView Bridge JsBridge.kt os command injection

FieldDetail
CVSS4.8 (MEDIUM) โ€” CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
CWECWE-78 (OS Command Injection), CWE-77 (Command Injection)
Affected< 0.4.0
Vendor/ProductAidanPark / openclaw-android
Advisory

A vulnerability was determined in AidanPark openclaw-android up to 0.4.0. The affected element is an unknown function of the file android/app/src/main/java/com/openclaw/android/JsBridge.kt of the component Android WebView Bridge. This manipulation causes os command injection. The attack can only be executed locally. The exploit has been publicly disclosed and may be utilized. The pull request to fix this issue awaits acceptance.

References:


CVE-2026-22180 โ€” OpenClaw < 2026.3.2 - Path Confinement Bypass in Browser Output and File Write Operations

FieldDetail
CVSS4.8 (MEDIUM) โ€” CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
CWECWE-59 (CWE-59: Improper Link Resolution Before File Access ('Link Following'))
Affected< 2026.3.2
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-3pxq-f3cp-jmxp

OpenClaw versions prior to 2026.3.2 contain a path-confinement bypass vulnerability in browser output handling that allows writes outside intended root directories. Attackers can exploit insufficient canonical path-boundary validation in file write operations to escape root-bound restrictions and write files to arbitrary locations.

References:


FieldDetail
CVSS4.8 (MEDIUM) โ€” CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
CWECWE-59 (CWE-59: Improper Link Resolution Before File Access ('Link Following'))
Affected< 2026.2.22
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-5ghc-98wh-gwwf

OpenClaw versions prior to 2026.2.22 contain a path traversal vulnerability in the static file handler that follows symbolic links, allowing out-of-root file reads. Attackers can place symlinks under the Control UI root directory to bypass directory confinement checks and read arbitrary files outside the intended root.

References:


CVE-2026-53809 โ€” OpenClaw < 2026.4.25 - Provider Alias Confusion in Embedded Runner Policy

FieldDetail
CVSS4.8 (MEDIUM) โ€” CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N
CWECWE-863 (Incorrect Authorization)
Affected< 2026.4.25
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-p39j-x9h5-q66m

OpenClaw before 2026.4.25 contains a policy bypass vulnerability in embedded runner policy that allows requests using provider aliases to compare against aliases instead of canonical provider identities. Attackers can exploit this confusion to select bundled tool access outside intended provider policy restrictions when the affected feature is enabled.

References:


CVE-2026-41338 โ€” OpenClaw < 2026.3.31 - Time-of-Check-Time-of-Use (TOCTOU) Vulnerability in Sandbox File Operations

FieldDetail
CVSS4.3 (MEDIUM) โ€” CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:P/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N
CWECWE-367 (CWE-367: Time-of-check Time-of-use (TOCTOU) Race Condition)
Affected< 2026.3.31
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-rm5c-4rmf-vvhw

OpenClaw before 2026.3.31 contains a time-of-check-time-of-use vulnerability in sandbox file operations that allows attackers to bypass fd-based defenses. Attackers can exploit check-then-act patterns in apply_patch, remove, and mkdir operations to manipulate files between validation and execution.

References:


CVE-2026-24764 โ€” OpenClaw has Remote Code Execution via System Prompt Injection in Slack Channel Descriptions

FieldDetail
CVSS3.7 (LOW) โ€” CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N
CWECWE-74 (CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')), CWE-94 (CWE-94: Improper Control of Generation of Code ('Code Injection'))
Affected< 2026.2.3
Vendor/Productclawdbot / clawdbot
AdvisoryGHSA-782p-5fr5-7fj8

OpenClaw (formerly Clawdbot) is a personal AI assistant users run on their own devices. In versions 2026.2.2 and below, when the Slack integration is enabled, channel metadata (topic/description) can be incorporated into the model's system prompt. Prompt injection is a documented risk for LLM-driven systems. This issue increases the injection surface by allowing untrusted Slack channel metadata to be treated as higher-trust system input. This issue has been fixed in version 2026.2.3.

Naming note: Uses old name clawdbot/clawdbot as vendor/product. References:


CVE-2026-32906 โ€” OpenClaw < 2026.5.12 - Privilege Escalation in Slack Plugin Approvals via Exec Approver Gate

FieldDetail
CVSS2.3 (LOW) โ€” CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
CWECWE-863 (Incorrect Authorization)
Affected< 2026.5.12
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-wv26-j37q-2g7p

OpenClaw before 2026.5.12 contains a privilege escalation vulnerability in Slack plugin approvals that allows exec-authorized users to resolve plugin approvals through the exec approver gate. Attackers with limited exec approval permissions can bypass intended approval splits to approve plugin actions outside operator configuration.

References:


CVE-2026-35624 โ€” OpenClaw < 2026.3.22 - Policy Confusion via Room Name Collision in Nextcloud Talk

FieldDetail
CVSS2.3 (LOW) โ€” CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
CWECWE-807 (CWE-807 Reliance on Untrusted Inputs in a Security Decision)
Affected< 2026.3.22
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-xhq5-45pm-2gjr

OpenClaw before 2026.3.22 contains a policy confusion vulnerability in room authorization that matches colliding room names instead of stable room tokens. Attackers can exploit similarly named rooms to bypass allowlist policies and gain unauthorized access to protected Nextcloud Talk rooms.

References:


CVE-2026-34507 โ€” OpenClaw < 2026.4.29 - Policy Bypass in QQBot Admin Commands via DM-only and allowFrom Checks

FieldDetail
CVSS2.3 (LOW) โ€” CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
CWECWE-863 (Incorrect Authorization)
Affected< 2026.4.29
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-w4v6-g3wm-w36c

OpenClaw before 2026.4.29 contains a policy bypass vulnerability in QQBot admin commands that allows authenticated senders to skip DM-only and allowFrom policy checks. Attackers can route admin commands from unauthorized senders or contexts to execute restricted behavior that policy should have blocked.

References:


CVE-2026-35617 โ€” OpenClaw < 2026.3.25 - Authorization Bypass via Group Policy Rebinding with Mutable Space displayName

FieldDetail
CVSS2.3 (LOW) โ€” CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
CWECWE-807 (CWE-807 Reliance on Untrusted Inputs in a Security Decision)
Affected< 2026.3.25
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-52q4-3xjc-6778

OpenClaw before 2026.3.25 contains an authorization bypass vulnerability in Google Chat group policy enforcement that relies on mutable space display names. Attackers can rebind group policies by changing or colliding space display names to gain unauthorized access to protected resources.

References:


CVE-2026-41402 โ€” OpenClaw < 2026.3.31 - Webhook Replay Cache Cross-Target messageId Scope Bypass

FieldDetail
CVSS2.3 (LOW) โ€” CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
CWECWE-706 (CWE-706: Use of Incorrectly-Resolved Name or Reference)
Affected< 2026.3.31
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-hhq4-97c2-p447

OpenClaw before 2026.3.31 contains a scope bypass vulnerability in webhook replay cache deduplication that allows authenticated attackers to replay messages across sibling targets using the same messageId. Attackers can exploit overly broad cache keying to bypass replay protection and deliver duplicate webhook messages to unintended targets.

References:


CVE-2026-41408 โ€” OpenClaw < 2026.3.31 - Disk Exhaustion via Media Download Bypass

FieldDetail
CVSS2.3 (LOW) โ€” CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
CWECWE-770 (CWE-770: Allocation of Resources Without Limits or Throttling)
Affected< 2026.3.31
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-4g5x-2jfc-xm98

OpenClaw before 2026.3.31 contains a resource exhaustion vulnerability in media downloads that bypasses core safety limits for file size, count, and cleanup operations. Attackers can exhaust disk space by downloading media files without triggering intended safety restrictions, causing availability impact.

References:


CVE-2026-41916 โ€” OpenClaw < 2026.4.8 - Stale Authentication State via Config Reload

FieldDetail
CVSS2.3 (LOW) โ€” CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
CWECWE-613 (CWE-613: Insufficient Session Expiration)
Affected< 2026.4.8
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-68x5-xx89-w9mm

OpenClaw before 2026.4.8 contains an authentication state management vulnerability where the resolvedAuth closure becomes stale after configuration reload. Newly accepted gateway connections continue using outdated resolved auth state, allowing attackers to bypass authentication controls through config reload operations.

References:


CVE-2026-44991 โ€” OpenClaw < 2026.4.21 - Authorization Bypass in Owner-Enforced Commands via Wildcard Channel Senders

FieldDetail
CVSS2.3 (LOW) โ€” CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
CWECWE-863 (Incorrect Authorization)
Affected< 2026.4.21
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-c28g-vh7m-fm7v

OpenClaw before 2026.4.21 contains an authorization bypass vulnerability in command-auth.ts that allows non-owner senders to execute owner-enforced slash commands when wildcard inbound senders are configured without explicit owner allowFrom settings. Attackers can exploit this by sending commands like /send, /config, or /debug on affected channels to bypass owner-only command authorization checks.

References:


CVE-2026-44993 โ€” OpenClaw < 2026.4.20 - Direct Message Misclassification in Feishu Card Actions

FieldDetail
CVSS2.3 (LOW) โ€” CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
CWECWE-184 (Incomplete List of Disallowed Inputs)
Affected< 2026.4.20
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-72q8-jcmc-97wx

OpenClaw before 2026.4.20 contains a message classification vulnerability in Feishu card-action callbacks that misclassifies direct messages as group conversations. Attackers can bypass dmPolicy enforcement by triggering card-action flows in direct message conversations that should have been blocked by restrictive policies.

References:


CVE-2026-53845 โ€” OpenClaw: Skill-command dispatch could skip before-tool-call hooks

FieldDetail
CVSS2.3 (LOW) โ€” CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
CWECWE-693 (Protection Mechanism Failure)
Affected< 2026.5.6
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-68xw-r643-9p5w

OpenClaw before 2026.5.6 contains a hook bypass vulnerability where skill commands routed through the affected dispatch path skip before-tool-call hook coverage. Attackers can exploit this by sending skill commands through the vulnerable dispatch path to bypass hook-based auditing and policy enforcement mechanisms.

References:


CVE-2026-53848 โ€” OpenClaw < 2026.5.26 - Exec Allowlist Bypass via Transparent Command Wrappers

FieldDetail
CVSS2.3 (LOW) โ€” CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
CWECWE-184 (Incomplete List of Disallowed Inputs)
Affected< 2026.5.26
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-cwpp-5962-q4f6

OpenClaw before 2026.5.26 contains an exec allowlist bypass vulnerability allowing authenticated operators to execute wrapper-level side effects outside allowlisted command intent. Attackers can craft command requests that bypass allowlist validation by leveraging transparent command wrappers to perform unintended operations.

References:


CVE-2026-53852 โ€” OpenClaw < 2026.4.25 - Scope Bypass via Empty-Scope Device Re-pairing

FieldDetail
CVSS2.3 (LOW) โ€” CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
CWECWE-636 (Not Failing Securely ('Failing Open'))
Affected< 2026.4.25
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-8mg9-j9cf-54cj

OpenClaw before 2026.4.25 contains a scope containment bypass vulnerability in device re-pairing that allows authenticated operators to restore broader scopes than intended by submitting empty-scope re-pairing requests. Attackers can exploit this by sending re-pairing requests with empty scope sets to skip containment guards and retain unauthorized device access.

References:


CVE-2026-53860 โ€” OpenClaw: BlueBubbles sender policy could match mutable conversation identifiers

FieldDetail
CVSS2.3 (LOW) โ€” CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
CWECWE-807 (Reliance on Untrusted Inputs in a Security Decision), CWE-863 (Incorrect Authorization)
Affected< 2026.5.7
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-8j37-5w68-wj2g

OpenClaw before 2026.5.7 contains a sender policy bypass vulnerability in BlueBubbles that allows participants to match allowlist entries through conversation metadata rather than stable sender identity. Attackers can influence conversation-level identifiers to receive agent responses intended for configured senders, potentially bypassing access controls.

References:


CVE-2026-53862 โ€” OpenClaw < 2026.5.12 - Bootstrap Token Replay via Pending Pairing Scope Widening

FieldDetail
CVSS2.3 (LOW) โ€” CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
CWECWE-266 (Incorrect Privilege Assignment), CWE-345 (Insufficient Verification of Data Authenticity)
Affected< 2026.5.12
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-9v8j-9c9g-w66c

OpenClaw before 2026.5.12 contains a bootstrap token replay vulnerability allowing callers with pending token access to reuse tokens with broader requested scopes. Attackers can replay bootstrap tokens before approval to escalate pairing authority beyond intended scope limits.

References:


CVE-2026-62221 โ€” OpenClaw 2026.5.12 < 2026.5.26 Authorization Bypass via allowFrom

FieldDetail
CVSS2.3 (LOW) โ€” CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
CWECWE-863 (Incorrect Authorization)
Affected< 2026.5.26
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-fh8v-vgcv-pwh4

OpenClaw 2026.5.12 before 2026.5.26 contain an incorrect authorization vulnerability in the ClickClack allowFrom feature. When the affected feature is enabled and reachable, a lower-trust caller or configured input path could execute or persist actions beyond the caller's intended authorization, including running non-allowlisted commands.

References:


FieldDetail
CVSS2.1 (LOW) โ€” CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
CWECWE-83 (Improper Neutralization of Script in Attributes in a Web Page)
Affected< 2026.5.12
Vendor/ProductOpenClaw / OpenClaw
AdvisoryGHSA-w9hf-3pp7-pvxv

OpenClaw before 2026.5.12 contains a cross-site scripting vulnerability in exported session HTML that preserves unsafe javascript: and data: links in generated content. Attackers can execute browser-side scripts if a trusted operator opens the exported file and activates a malicious link.

References:


CVE-2026-30741 โ€” A remote code execution (RCE) vulnerability in OpenClaw Agent Platform v2026.2.6

FieldDetail
CVSSNone () โ€” ``
CWE
Affected< n/a
Vendor/Productn/a / n/a
Advisory

A remote code execution (RCE) vulnerability in OpenClaw Agent Platform v2026.2.6 allows attackers to execute arbitrary code via a Request-Side prompt injection attack.

References:



โณ CVE Publication Pipeline

Of 51 GHSAs with CVE IDs, 51 are fully published and 0 remain RESERVED.

graph LR
    A["1๏ธโƒฃ GitHub Reserves<br/>CVE ID<br/><b>RESERVED</b>"] --> B["2๏ธโƒฃ GHSA Goes Public<br/>with CVE ID Shown"]
    B --> C["3๏ธโƒฃ CNA Submits<br/>CVE Record via<br/>CVE Services<br/><b>PUBLISHED</b>"]
    C --> D["4๏ธโƒฃ cvelistV5 Bot<br/>Commits JSON File"]

    style A fill:#fee,stroke:#c33,color:#333
    style B fill:#fff3cd,stroke:#856404,color:#333
    style C fill:#d4edda,stroke:#155724,color:#333
    style D fill:#cce5ff,stroke:#004085,color:#333
CVE IDStatecvelistV5GHSA PublishedCNA
CVE-2026-24763โœ… PUBLISHEDโœ…2026-02-02GitHub_M
CVE-2026-25157โœ… PUBLISHEDโœ…2026-02-02GitHub_M
CVE-2026-25253โœ… PUBLISHEDโœ…2026-02-02mitre
CVE-2026-26317โœ… PUBLISHEDโœ…2026-02-18GitHub_M
CVE-2026-26328โœ… PUBLISHEDโœ…2026-02-18GitHub_M
CVE-2026-28452โœ… PUBLISHEDโœ…2026-02-18VulnCheck
CVE-2026-28458โœ… PUBLISHEDโœ…2026-02-17VulnCheck
CVE-2026-28469โœ… PUBLISHEDโœ…2026-02-18VulnCheck
CVE-2026-28478โœ… PUBLISHEDโœ…2026-02-18VulnCheck
CVE-2026-28480โœ… PUBLISHEDโœ…2026-02-18VulnCheck
CVE-2026-29612โœ… PUBLISHEDโœ…2026-02-18VulnCheck
CVE-2026-35630โœ… PUBLISHEDโœ…2026-07-02VulnCheck
CVE-2026-53806โœ… PUBLISHEDโœ…2026-07-02VulnCheck
CVE-2026-53809โœ… PUBLISHEDโœ…2026-07-02VulnCheck
CVE-2026-53810โœ… PUBLISHEDโœ…2026-07-02VulnCheck
CVE-2026-53811โœ… PUBLISHEDโœ…2026-07-02VulnCheck
CVE-2026-53812โœ… PUBLISHEDโœ…2026-07-02VulnCheck
CVE-2026-53813โœ… PUBLISHEDโœ…2026-07-02VulnCheck
CVE-2026-53814โœ… PUBLISHEDโœ…2026-07-02VulnCheck
CVE-2026-53815โœ… PUBLISHEDโœ…2026-07-02VulnCheck
CVE-2026-53816โœ… PUBLISHEDโœ…2026-07-02VulnCheck
CVE-2026-53817โœ… PUBLISHEDโœ…2026-07-02VulnCheck
CVE-2026-53818โœ… PUBLISHEDโœ…2026-07-02VulnCheck
CVE-2026-53819โœ… PUBLISHEDโœ…2026-07-02VulnCheck
CVE-2026-53840โœ… PUBLISHEDโœ…2026-06-17VulnCheck
CVE-2026-53841โœ… PUBLISHEDโœ…2026-06-18VulnCheck
CVE-2026-53842โœ… PUBLISHEDโœ…2026-06-18VulnCheck
CVE-2026-53843โœ… PUBLISHEDโœ…2026-06-18VulnCheck
CVE-2026-53844โœ… PUBLISHEDโœ…2026-06-18VulnCheck
CVE-2026-53845โœ… PUBLISHEDโœ…2026-06-18VulnCheck
CVE-2026-53846โœ… PUBLISHEDโœ…2026-06-18VulnCheck
CVE-2026-53847โœ… PUBLISHEDโœ…2026-06-18VulnCheck
CVE-2026-53848โœ… PUBLISHEDโœ…2026-06-18VulnCheck
CVE-2026-53849โœ… PUBLISHEDโœ…2026-06-18VulnCheck
CVE-2026-53850โœ… PUBLISHEDโœ…2026-06-18VulnCheck
CVE-2026-53851โœ… PUBLISHEDโœ…2026-06-18VulnCheck
CVE-2026-53852โœ… PUBLISHEDโœ…2026-06-18VulnCheck
CVE-2026-53853โœ… PUBLISHEDโœ…2026-06-18VulnCheck
CVE-2026-53854โœ… PUBLISHEDโœ…2026-06-18VulnCheck
CVE-2026-53855โœ… PUBLISHEDโœ…2026-06-18VulnCheck
CVE-2026-53856โœ… PUBLISHEDโœ…2026-06-18VulnCheck
CVE-2026-53857โœ… PUBLISHEDโœ…2026-06-18VulnCheck
CVE-2026-53858โœ… PUBLISHEDโœ…2026-06-18VulnCheck
CVE-2026-53859โœ… PUBLISHEDโœ…2026-06-18VulnCheck
CVE-2026-53860โœ… PUBLISHEDโœ…2026-06-18VulnCheck
CVE-2026-53861โœ… PUBLISHEDโœ…2026-06-18VulnCheck
CVE-2026-53862โœ… PUBLISHEDโœ…2026-06-18VulnCheck
CVE-2026-53863โœ… PUBLISHEDโœ…2026-06-18VulnCheck
CVE-2026-53864โœ… PUBLISHEDโœ…2026-06-18VulnCheck
CVE-2026-53865โœ… PUBLISHEDโœ…2026-06-18VulnCheck
CVE-2026-53866โœ… PUBLISHEDโœ…2026-06-18VulnCheck

๐Ÿ”‘ Key Insights

InsightDetail
Dominant Weakness59% of categorized issues relate to Allowlist Bypass (38/64)
V5 Sync Rate51/51 CVE IDs (100%) have full cvelistV5 records
Advisory Velocity157 security advisories across 2026-02-02 โ†’ 2026-07-02
Top Severity1 Critical + 90 High = 91 high-impact issues (58%)

Vulnerability Categories

CategoryCountExamples
OS Command Injection (CWE-78)12PATH injection, SSH command injection, Docker exec, keychain writes
Path Traversal (CWE-22)1MEDIA: paths, plugin install, browser downloads, Zip Slip, transcript paths
SSRF1Image tool fetch, Feishu extension, attachment/media URLs, IPv6 bypass
Auth Bypass / Missing Auth3WebSocket config.apply, webhook verification, browser relay, sandbox bridge
Allowlist Bypass38Telegram usernames, Matrix displayName, Slack DM, Twitch, voice-call
Injection (XSS/CSRF/Prompt)6XSS in Control UI, prompt injection via Slack/CWD/logs, CSRF
Denial of Service3Unbounded media fetch, webhook body buffering, archive expansion

๐Ÿ“‹ All Security Advisories (157)

Critical & High Severity

GHSACVESeverityTitlePublished
GHSA-7hxm-f538-3xp6CVE-2026-53811HighOpenClaw: Matrix allowFrom could bind to mutable display names2026-07-02
GHSA-3c6j-hq33-3jv4CVE-2026-53816HighOpenClaw: Paired nodes could forge exec lifecycle events without system.run provenance2026-07-02
GHSA-vxx3-6hc9-7cc3CVE-2026-53806HighOpenClaw: Combined POSIX shell options could confuse exec revalidation2026-07-02
GHSA-v8cx-933x-r976CVE-2026-53813HighOpenClaw: Fake package roots could influence memory-core artifact loading2026-07-02
GHSA-8wg3-5mcm-fjq8CVE-2026-53819HighOpenClaw: Workspace .env could override Homebrew executable selection for skill install flows2026-07-02
GHSA-mgq6-vr84-7m2jCVE-2026-35630HighOpenClaw: QQBot native approval buttons did not enforce configured approver identity2026-07-02
GHSA-6fvr-66p3-3qj4CVE-2026-53814HighOpenClaw: Hook-triggered CLI runs could receive owner MCP tool authority2026-07-02
GHSA-chr9-m4q2-76hwCVE-2026-53817HighOpenClaw: Control UI locality spoofing could mint a durable admin device token2026-07-02
GHSA-v6r2-jh58-xx6wCVE-2026-53810HighOpenClaw's marketplace runtime extension metadata could point at unscanned payloads2026-07-02
GHSA-q7q8-3mgw-q67rCVE-2026-53815HighOpenClaw: Message read actions could skip channel allowlist checks2026-07-02
GHSA-p73f-w79w-jqr5โ€”HighOpenClaw: Native command authorization could skip owner-command enforcement2026-07-02
GHSA-j472-gf56-x589โ€”HighOpenClaw: PowerShell encoded-command aliases could miss exec allowlist checks2026-07-02
GHSA-77q5-rr5v-x43qโ€”HighOpenClaw: Trusted retry endpoint checks could match hostname prefixes2026-07-02
GHSA-w5ww-7chg-mxcqโ€”HighOpenClaw: Telegram interactive callbacks could skip commands.allowFrom2026-07-02
GHSA-xr4f-mjxj-w6w5โ€”HighOpenClaw: Non-owner chat senders could issue device-pairing bootstrap codes2026-07-02
GHSA-w4v6-g3wm-w36cโ€”CriticalOpenClaw: QQBot admin commands could skip DM-only and allowFrom policy2026-07-02
GHSA-qjpc-qf9m-xwmrโ€”HighOpenClaw: Trusted-proxy Control UI WebSocket accepted client-declared scopes before pairing2026-07-02
GHSA-c29c-2q9c-pc86โ€”HighOpenClaw: Slack allowFrom could bind to mutable display names2026-07-02
GHSA-jvm4-4j77-39p6โ€”HighOpenClaw: QQBot streaming command could mutate config without explicit allowFrom2026-07-02
GHSA-83w9-h5wv-j9xmโ€”HighOpenClaw: Node pairing reconnection could confuse approval scope state2026-07-02
GHSA-hw9r-h9mr-4jffโ€”HighOpenClaw: Scoped chat.send route inheritance could bypass admin command scope gates2026-07-02
GHSA-mhq8-78pj-5j79โ€”HighOpenClaw's POSIX node system.run safe-bin allowlist could be widened by shell expansion2026-07-02
GHSA-rggc-m335-3wvjโ€”HighOpenClaw: Same-host trusted-proxy deployments could accept local forged identity headers2026-07-02
GHSA-2j8v-hwgc-x698โ€”HighOpenClaw: Shell wrapper argv could change between approval and execution2026-07-02
GHSA-xww8-gqvh-92x9โ€”HighOpenClaw: Exec approval display truncation could hide the command being approved2026-07-02
GHSA-rx78-29qr-5hq8CVE-2026-53865HighOpenClaw: Workspace-derived service PATH could influence trash command selection2026-06-18
GHSA-wc84-j36w-pw4xCVE-2026-53858HighOpenClaw: Workspace .env STATE_DIRECTORY could influence bundled runtime dependency roots2026-06-18
GHSA-cw4q-gqg5-g38hCVE-2026-53849HighOpenClaw: Discord allowFrom could bind to mutable display names2026-06-18
GHSA-24vr-rprv-67rfCVE-2026-53846HighOpenClaw: Workspace .env npm_execpath could influence bundled runtime dependency install2026-06-18
GHSA-v2ww-5rh7-2h5vCVE-2026-53853HighOpenClaw: Linux and macOS exec allowlists skipped configured argument patterns2026-06-18
GHSA-8c59-hr4w-qg69CVE-2026-53857HighOpenClaw: Zalo allowFrom could bind to mutable display names2026-06-18
GHSA-5cj2-3jr2-5h77CVE-2026-53855HighOpenClaw: Shell positional parameters could weaken strict inline-eval checks2026-06-18
GHSA-fq9j-vw4w-fr6vCVE-2026-53842HighOpenClaw: Workspace .env CLOUDSDK_PYTHON could influence Gmail setup gcloud execution2026-06-18
GHSA-f397-5vjw-v2c2CVE-2026-53866HighOpenClaw: Shell inline-command parsing could miss an allowlist check2026-06-18
GHSA-q99w-vh6v-q3v7CVE-2026-53843HighOpenClaw: Pairing-scoped device session could restore revoked node token authority2026-06-18
GHSA-ccwh-wwpp-6wg5CVE-2026-53864HighOpenClaw: Host environment sanitizer missed two Node.js control variables2026-06-18
GHSA-rjxq-qqhf-8hwhCVE-2026-53840HighOpenClaw: MCP Streamable HTTP redirects could forward configured custom headers to another origin2026-06-17
GHSA-2w22-3f6x-3hf4โ€”HighDuplicate Advisory: Workspace-derived service PATH could influence trash command selection2026-06-16
GHSA-vr6h-vxqj-3pjxโ€”HighDuplicate Advisory: Host environment sanitizer missed two Node.js control variables2026-06-16
GHSA-v383-2wgg-v483โ€”HighDuplicate Advisory: Shell inline-command parsing could miss an allowlist check2026-06-16
GHSA-3v3j-737j-7g74โ€”HighDuplicate Advisory: Linux and macOS exec allowlists skipped configured argument patterns2026-06-16
GHSA-4qgr-57jq-93vhโ€”HighDuplicate Advisory: Workspace .env STATE_DIRECTORY could influence bundled runtime dependency roots2026-06-16
GHSA-w7m7-3xcf-mp48โ€”HighDuplicate Advisory: Zalo allowFrom could bind to mutable display names2026-06-16
GHSA-27pq-2ph8-8x25โ€”HighDuplicate Advisory: Shell positional parameters could weaken strict inline-eval checks2026-06-16
GHSA-qp5j-jr73-m2pwโ€”HighDuplicate Advisory: Workspace .env npm_execpath could influence bundled runtime dependency install2026-06-16
GHSA-p44v-rx83-vjp4โ€”HighDuplicate Advisory: Discord allowFrom could bind to mutable display names2026-06-16
GHSA-9fr2-p65v-gqxqโ€”HighDuplicate Advisory: Workspace .env CLOUDSDK_PYTHON could influence Gmail setup gcloud execution2026-06-16
GHSA-wrmq-9fc4-gwwjโ€”HighDuplicate Advisory: Pairing-scoped device session could restore revoked node token authority2026-06-16
GHSA-hx4v-668p-g2qrโ€”HighDuplicate Advisory: OpenClaw: QQBot native approval buttons did not enforce configured approver identity2026-05-29
GHSA-xpr6-2hgm-4wwpโ€”HighDuplicate Advisory: OpenClaw vulnerable to arbitrary code execution via attacker-controlled setup-api.js loaded from cwd during env-key resolution2026-05-11
GHSA-rq6g-px6m-c248CVE-2026-28469HighOpenClaw Google Chat shared-path webhook target ambiguity allowed cross-account policy-context misrouting2026-02-18
GHSA-3fqr-4cg8-h96qCVE-2026-26317HighOpenClaw affected by cross-site request forgery (CSRF) through loopback browser mutation endpoints2026-02-18
GHSA-q447-rj3r-2cghCVE-2026-28478HighOpenClaw affected by denial of service via unbounded webhook request body buffering2026-02-18
GHSA-mr32-vwc2-5j6hCVE-2026-28458HighOpenClaw's Browser Relay /cdp websocket is missing auth which could allow cross-tab cookie access2026-02-17
GHSA-q284-4pvr-m585CVE-2026-25157HighOpenClaw/Clawdbot has OS Command Injection via Project Root Path in sshNodeCommand2026-02-02
GHSA-g8p2-7wf7-98mqCVE-2026-25253HighOpenClaw/Clawdbot has 1-Click RCE via Authentication Token Exfiltration From gatewayUrl2026-02-02
GHSA-mc68-q9jw-2h3vCVE-2026-24763HighOpenClaw/Clawdbot Docker Execution has Authenticated Command Injection via PATH Environment Variable2026-02-02
GHSA-r2c6-8jc8-g32wโ€”HighDuplicate Advisory: 1-Click RCE via Authentication Token Exfiltration From gatewayUrl2026-02-02

Medium Severity

GHSACVESeverityTitlePublished
GHSA-rj6p-xmxr-qj4hCVE-2026-53818MediumOpenClaw: MCP loopback could skip owner-only tool policy for non-owner callers2026-07-02
GHSA-p39j-x9h5-q66mCVE-2026-53809MediumOpenClaw: Embedded runner policy could be confused by provider aliases2026-07-02
GHSA-2hfg-4fh4-qp7fCVE-2026-53812MediumOpenClaw's browser act interactions could bypass private-network navigation checks2026-07-02
GHSA-4m3v-q747-pc6hโ€”MediumOpenClaw: Mattermost slash token revocation could lag until monitor refresh2026-07-02
GHSA-275c-xpvc-jgfwโ€”MediumOpenClaw: Slack and Zalo webhook secrets could remain active after secrets.reload2026-07-02
GHSA-6c4r-g249-wv3cโ€”MediumOpenClaw: Sandboxed session spawn could expose the real workspace path to child prompts2026-07-02
GHSA-77pv-3w4q-vrj5โ€”MediumOpenClaw: QQBot pre-dispatch slash commands could skip allowFrom checks2026-07-02
GHSA-hcm3-8f6r-6xwgโ€”MediumOpenClaw: Browser debug/export routes could reuse already-open blocked tabs2026-07-02
GHSA-grc3-2j34-p6gmโ€”MediumOpenClaw: message.action forwarding could send Gateway credentials to model-supplied loopback URLs2026-07-02
GHSA-gp79-m99v-gjmhโ€”MediumOpenClaw: Mattermost handlers could fall open when channel type was missing2026-07-02
GHSA-cqwv-9qjx-vxw2โ€”MediumOpenClaw: Skill Workshop apply flow could override pending approval2026-07-02
GHSA-wv26-j37q-2g7pโ€”MediumOpenClaw's Slack plugin approvals used the exec approver gate for plugin actions2026-07-02
GHSA-p2fh-f5fc-44hrโ€”MediumOpenClaw: memory-wiki ingest could read local files with operator.write scope2026-07-02
GHSA-qh2f-99mv-mrcfโ€”MediumOpenClaw: Bundle MCP loopback could miss its exec denylist on session spawn2026-07-02
GHSA-9c3v-684m-579cโ€”MediumOpenClaw MCP SSE redirects could forward Authorization headers2026-07-01
GHSA-4hpg-mp64-x7xqCVE-2026-53854MediumOpenClaw: Internal/webchat command auth could inherit ownerAllowFrom wildcard state2026-06-18
GHSA-mpc8-jxjh-qpghCVE-2026-53850MediumOpenClaw: Focus command could miss controlScope enforcement2026-06-18
GHSA-72fw-cqh5-f324CVE-2026-53844MediumOpenClaw: memory-wiki shared search could miss session visibility checks2026-06-18
GHSA-rwp6-7w3q-75fqCVE-2026-53856MediumOpenClaw: Config recovery could restore openclaw.json with broad file permissions2026-06-18
GHSA-x629-46cc-7xgwCVE-2026-53847MediumOpenClaw: Active Memory write scope could mutate global config2026-06-18
GHSA-w9hf-3pp7-pvxvCVE-2026-53841MediumOpenClaw: Exported session HTML could keep unsafe markdown links2026-06-18
GHSA-fcvx-5cxc-v5p8CVE-2026-53851MediumOpenClaw: Slack reaction events could ignore reaction notification settings2026-06-18
GHSA-gxg4-2rrr-jhc7CVE-2026-53859MediumOpenClaw: Hostname checks could treat trailing-dot hosts inconsistently2026-06-18
GHSA-c226-q6fx-6j6cCVE-2026-53861MediumOpenClaw: macOS Swift exec allowlist missed combined POSIX inline flags2026-06-18
GHSA-985f-72mj-8gf7CVE-2026-53863MediumOpenClaw: Tool group policy callers could accept unvalidated group IDs2026-06-18
GHSA-8wmm-344f-mpjgโ€”MediumDuplicate Advisory: Tool group policy callers could accept unvalidated group IDs2026-06-16
GHSA-g796-jqmx-wf9qโ€”MediumDuplicate Advisory: macOS Swift exec allowlist missed combined POSIX inline flags2026-06-16
GHSA-vqx6-6j84-2794โ€”MediumDuplicate Advisory: Hostname checks could treat trailing-dot hosts inconsistently2026-06-16
GHSA-r2fx-hp6p-pgrmโ€”MediumDuplicate Advisory: Internal/webchat command auth could inherit ownerAllowFrom wildcard state2026-06-16
GHSA-vqj9-vhg4-27mgโ€”MediumDuplicate Advisory: Config recovery could restore openclaw.json with broad file permissions2026-06-16
GHSA-c8w7-9w9h-x69qโ€”MediumDuplicate Advisory: Slack reaction events could ignore reaction notification settings2026-06-16
GHSA-gw2c-6hcg-5g52โ€”MediumDuplicate Advisory: Focus command could miss controlScope enforcement2026-06-16
GHSA-58wc-8wrv-xp9jโ€”MediumDuplicate Advisory: Active Memory write scope could mutate global config2026-06-16
GHSA-x7cf-6gp3-q5f8โ€”MediumDuplicate Advisory: MCP Streamable HTTP redirects could forward configured custom headers to another origin2026-06-16
GHSA-6jm4-83g2-35gvโ€”MediumDuplicate Advisory: memory-wiki shared search could miss session visibility checks2026-06-16
GHSA-v8j2-5f9p-fmh4โ€”MediumDuplicate Advisory: OpenClaw's Webhooks SecretRef route secret remains valid after rotation/reload2026-05-11
GHSA-5jgm-f9wr-9qm7โ€”MediumDuplicate Advisory: OpenClaw: Workspace dotenv files cannot override connector endpoint hosts2026-05-11
GHSA-9j32-3m66-mc4mโ€”MediumDuplicate Advisory: OpenClaw: Hook mapping templates could bypass hook session-key opt-in2026-05-11
GHSA-mj5r-hh7j-4gxfCVE-2026-28480MediumOpenClaw Telegram allowlist authorization accepted mutable usernames2026-02-18
GHSA-h89v-j3x9-8wqjCVE-2026-28452MediumOpenClaw affected by denial of service through unguarded archive extraction allowing high expansion/resource abuse (ZIP/TAR)2026-02-18
GHSA-w2cg-vxx6-5xjgCVE-2026-29612MediumOpenClaw: denial of service through large base64 media files allocating large buffers before limit checks2026-02-18
GHSA-g34w-4xqq-h79mCVE-2026-26328MediumOpenClaw iMessage group allowlist authorization inherited DM pairing-store identities2026-02-18

Low Severity

GHSACVESeverityTitlePublished
GHSA-3wqp-prf6-2m72โ€”LowOpenClaw: Feishu dynamic-agent bindings could miss configWrites enforcement2026-07-02
GHSA-8mg9-j9cf-54cjCVE-2026-53852LowOpenClaw: Empty-scope device re-pairing could confuse caller scope containment2026-06-18
GHSA-8j37-5w68-wj2gCVE-2026-53860LowOpenClaw: BlueBubbles sender policy could match mutable conversation identifiers2026-06-18
GHSA-68xw-r643-9p5wCVE-2026-53845LowOpenClaw: Skill-command dispatch could skip before-tool-call hooks2026-06-18
GHSA-9v8j-9c9g-w66cCVE-2026-53862LowOpenClaw: Bootstrap token replay could widen pending pairing scopes2026-06-18
GHSA-cwpp-5962-q4f6CVE-2026-53848LowOpenClaw: Exec allowlist could miss side effects from transparent command wrappers2026-06-18
GHSA-h9h6-pwqv-j9hvโ€”LowDuplicate Advisory: Bootstrap token replay could widen pending pairing scopes2026-06-16
GHSA-8hj2-w4c9-fjfqโ€”LowDuplicate Advisory: BlueBubbles sender policy could match mutable conversation identifiers2026-06-16
GHSA-hc4w-hm59-9w88โ€”LowDuplicate Advisory: Empty-scope device re-pairing could confuse caller scope containment2026-06-16
GHSA-r7vv-6763-m739โ€”LowDuplicate Advisory: Skill-command dispatch could skip before-tool-call hooks2026-06-16
GHSA-wrr6-p5r6-474mโ€”LowDuplicate Advisory: Exec allowlist could miss side effects from transparent command wrappers2026-06-16
GHSA-6xcg-6q43-rj2vโ€”LowDuplicate Advisory: Exported session HTML could keep unsafe markdown links2026-06-16
GHSA-chm2-m3w2-wcxmโ€”LowOpenClaw Google Chat spoofing access with allowlist authorized mutable email principal despite sender-ID mismatch2026-02-17

Repo-Only Advisories (~44 more)

These advisories are listed on the repo security page but not yet indexed in the GitHub Advisory Database. See the full advisory list for details.

Show 44 repo-only advisories
GHSASeverityTitlePublished
GHSA-2q7j-2vhx-56g8HighFeishu tools could ignore per-account disablement2026-06-30
GHSA-2x93-h3hg-2xfpHighBrowser snapshot routes could miss post-navigation SSRF checks2026-06-30
GHSA-34mr-7r3m-gfg7HighExec allowlist glob matching could allow traversal bypasses2026-06-30
GHSA-3fp5-v549-9v66Highflock wrapper could bypass durable exec approval binding2026-06-30
GHSA-3pmr-x9g8-m55rHighDiscord guild actions could skip cross-provider requester authorization2026-06-30
GHSA-3x84-qq85-fj65HighBrowser CDP discovery could accept blocked WebSocket URLs2026-06-30
GHSA-4pqj-3c56-5fqqHighWorkspace dotenv files could override provider credentials2026-06-30
GHSA-52xj-c9p8-78cvHighMCP loopback could expose owner-only tools to non-owner runs2026-06-30
GHSA-575v-8hfq-m3mcHighSandbox bind mounts could bypass parent-directory denylist checks2026-06-30
GHSA-724r-v4wf-mqc5HighHooks allowedAgentIds could be bypassed with blank agent IDs2026-06-30
GHSA-7jx6-764p-fgg9HighQQBot exec approvals could allow non-allowlisted senders2026-06-30
GHSA-7vrr-rp4x-4g76HighPlugin install commands could allow non-owner persistence2026-06-30
GHSA-8f46-3xx3-8c9mHighNode exec approvals could use different gateway and node environments2026-06-30
GHSA-8v95-qqcm-qp9hHighdevice.pair.approve could bypass role-management checks2026-06-30
GHSA-9969-8g9h-rxwmHighHost exec environment filtering could allow Git ext transport2026-06-30
GHSA-cf2p-f286-mphfHighIdentity-bearing HTTP callers could reach admin-scoped tools2026-06-30
GHSA-f6p7-6326-vf7vHighDiscord moderation actions could miss trusted requester checks2026-06-30
GHSA-fh38-965w-f6c3HighWhatsApp group IDs could satisfy elevated sender allowlists2026-06-30
GHSA-hjr6-g723-hmfmHighHost exec environment filtering could miss interpreter startup variables2026-06-30
GHSA-hx85-fgcw-9vrcHighDevice-pair approval could expose node system.run early2026-06-30
GHSA-jhfx-v2j8-x3m6HighOpenAI-compatible HTTP model overrides could miss admin authorization2026-06-30
GHSA-m38g-vpwj-mpg9HighOpenShell mirror sync could follow remote symlink parents2026-06-30
GHSA-mgvr-6gvw-3rgrHighSandbox exec-server HTTP requests could reach internal networks2026-06-30
GHSA-mm9g-83wh-mhwjHighIsolated cron jobs could regain denied exec tools2026-06-30
GHSA-p5xh-frrh-cmgjHighMS Teams message actions could miss requester authorization2026-06-30
GHSA-rh6r-vvfc-86jqHighSetup-mode discovery could load untrusted workspace plugins2026-06-30
GHSA-v7hx-r36p-f68mHighMessage mutations could skip requester authorization2026-06-30
GHSA-vr7j-7684-7gm5HighHTTP Canvas responses could forge trusted A2UI actions2026-06-30
GHSA-w8wf-3qvj-6xqfHighFeishu permission tools could ignore per-account disablement2026-06-30
GHSA-wp73-f3gg-w4vrHighClickClack agent-mode dispatch could ignore toolsAllow2026-06-30
GHSA-wxh3-g47h-q3mcHighHost exec environment filtering could miss rustup startup variables2026-06-30
GHSA-wxm8-ghhq-q688HighMS Teams safeFetch could race DNS rebinding checks2026-06-30
GHSA-x863-pqjw-hmgfHighBrowser act route could miss current-tab URL checks2026-06-30
GHSA-4xwj-mcc7-x7x5MediumRemote media URLs could slow-read exhaust tool workers2026-06-30
GHSA-5p6w-wmh3-frfrMediumWebSocket auth attempts could avoid non-browser rate limits2026-06-30
GHSA-7w4v-g4m6-j88vMedium[AgentGG] MS Teams allowFrom could bind to mutable display names2026-06-30
GHSA-fh8v-vgcv-pwh4MediumClickClack allowFrom could allow non-allowlisted commands2026-06-30
GHSA-fwgr-fpv9-vf5xMediumQQBot media upload could reach untrusted remote URLs2026-06-30
GHSA-j4cx-jvq7-79vmMediumTrajectory export could skip broad credential redaction2026-06-30
GHSA-mhm4-93fw-4qr2MediumSkill command dispatch could skip effective tool policy2026-06-30
GHSA-prwc-c6w5-mmgrMediumBot Framework serviceUrl validation could leak bot tokens2026-06-30
GHSA-v4f6-x5g5-2g4gMediumNative web search could ignore OpenClaw tool policy2026-06-30
GHSA-v54h-q2vx-vgg4MediumMS Teams outbound requests could leak Bot Framework tokens2026-06-30
GHSA-wgq8-x5wm-g4rwMediumPlugin install wrappers could skip install policy2026-06-30

Naming Inconsistencies

The OpenClaw project has been renamed multiple times, causing inconsistencies across CVE records:

CVEvendorproductpackageURLDescription Names
CVE-2026-22172OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-28446OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-32918OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-43533OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-22171OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-24763clawdbotclawdbotโ€”OpenClaw (formerly Clawdbot)
CVE-2026-25253OpenClawOpenClawpkg:npm/clawdbotOpenClaw / clawdbot / Moltbot
CVE-2026-28462OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-28478OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-32042OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-32049OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-32060openclawopenclawpkg:npm/openclawOpenClaw
CVE-2026-32846OpenClawOpenClawโ€”OpenClaw
CVE-2026-35639OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-35663OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-41349OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-53814OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-53817OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-53819OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-53843OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-62196OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-26323openclawopenclawโ€”OpenClaw
CVE-2026-53816OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-53849OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-53857OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-41396OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-53829OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-28482OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-28393OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-28469OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-35630OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-25157openclawopenclawโ€”OpenClaw
CVE-2026-27002openclawopenclawโ€”OpenClaw
CVE-2026-32048OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-42422OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-53806OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-53811OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-53810OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-53853OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-53855OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-53864OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-53866OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-42428OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-28458OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-53833OpenClawOpenClawpkg:npm/openclaw/qqbotOpenClaw
CVE-2026-42432OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-53813OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-34512OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-41364OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-53865OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-26317openclawclawdbotโ€”OpenClaw (formerly Clawdbot)
CVE-2026-22169OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-35621OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-35636OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-41299OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-41359OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-41375OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-53815OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-43531OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-53842OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-53846OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-53858OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-27545OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-27523OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-27004openclawopenclawโ€”OpenClaw
CVE-2026-28480OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-32919OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-35652OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-41301OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-41343OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-41335OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-41372OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-53818OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-29612OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-45224openclawcrabboxโ€”OpenClaw
CVE-2026-53850OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-28452OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-32044OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-26328openclawclawdbotโ€”OpenClaw (formerly Clawdbot)
CVE-2026-35673OpenClawOpenClawpkg:npm/OpenClawOpenClaw
CVE-2026-28448OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-28471OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-33580OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-35649OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-35656OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-53851OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-62220OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-41366OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-45001OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-53840OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-53844OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-53854OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-53859OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-53863OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-62205OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-62210OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-32054OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-41393OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-27646OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-32035OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-31995OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-32977OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-32988OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-53856OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-28457OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-33578OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-34425OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-41367OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-53847OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-53861OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-53812OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-62201OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-15193AidanParkopenclaw-androidโ€”OpenClaw
CVE-2026-22180OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-32020OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-53809OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-41338OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-24764clawdbotclawdbotโ€”OpenClaw (formerly Clawdbot)
CVE-2026-32906OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-35624OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-34507OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-35617OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-41402OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-41408OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-41916OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-44991OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-44993OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-53845OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-53848OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-53852OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-53860OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-53862OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-62221OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-53841OpenClawOpenClawpkg:npm/openclawOpenClaw
CVE-2026-30741n/an/aโ€”OpenClaw

Data Sources

SourceURL
CVE List v5 (full scan, all CNAs)CVEProject/cvelistV5 โ€” every record affecting OpenClaw, any assigner
GitHub Advisory DBgithub.com/advisories
Repo Security Tabopenclaw/openclaw/security
CVE Services APIhttps://cveawg.mitre.org/api/cve-id/{CVE-ID}

Auto-generated by update_readme.py ยท Updated every 6h via GitHub Actions
Data: ghsa-advisories.json ยท cves.json ยท cve-pipeline-status.json

Maintained by Jerry Gamblin ยท OpenClawCVEs