OpenClaw has 128 CVEs on record. Cadence is steady at roughly 47 per quarter. The busiest recent month was June 2026 with 55. The median CVSS is 7.1 (high), with 6 rated critical. None have a confirmed exploitation report. The dominant weakness classes are CWE-863 (30) and CWE-862 (15). Most affected products: openclaw (123), @openclaw/feishu (2), ClawScan (2).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.1
- Publish → KEV
- —
- Last 90 days
- 47 prev 78
Weakness classes
Products
- openclaw 123
- @openclaw/feishu 2
- ClawScan 2
- github.com/openclaw/crabbox 1
Worst active — by depth score
CVE-2026-33579Critical· 9.9OpenClaw before 2026.3.28 contains a privilege escalation vulnerability in the /pair approve command path that fails to forward caller scopes into the core approval check67CVE-2026-32917Critical· 9.8OpenClaw before 2026.3.13 contains a remote command injection vulnerability in the iMessage attachment staging flow that allows attackers to execute arbitrary commands on configured remote hosts54CVE-2026-28474Critical· 9.8OpenClaw's Nextcloud Talk plugin versions prior to 2026.2.6 accept equality matching on the mutable actor.name display name field for allowlist validation, allowing attackers to bypass DM and room allowlists54GHSA-w4v6-g3wm-w36cCriticalOpenClaw: QQBot admin commands could skip DM-only and allowFrom policy52CVE-2026-32916Critical· 9.4OpenClaw versions 2026.3.7 before 2026.3.11 contain an authorization bypass vulnerability where plugin subagent routes execute gateway methods through a synthetic operator client with broad administrative scopes52
OpenClaw vulnerabilities
CVEs affecting OpenClaw, newest first. Open any entry for full detail, references, and exploit status.
128 CVEsRSS
CVE-2026-91836Low· 2.8PoCA flaw has been found in OpenClaw ClawScan up to 0.1.6
A flaw has been found in OpenClaw ClawScan up to 0.1.6. This affects an unknown function of the file internal/runner/static_scanner.go of the component Static Scanner. This manipulation causes incomplete comparison with missing factors. …
CVE-2026-91835Low· 2.8PoCA vulnerability was detected in OpenClaw ClawScan up to 0.1.6
A vulnerability was detected in OpenClaw ClawScan up to 0.1.6. The impacted element is the function IsBinaryFile of the file internal/runner/static_scanner.go of the component File Classifier. The manipulation results in interpretation c…
GHSA-2q7j-2vhx-56g8High· 8.1OpenClaw Feishu tools could ignore per-account disablement
OpenClaw Feishu tools could ignore per-account disablement
GHSA-w8wf-3qvj-6xqfHigh· 8.1OpenClaw Feishu permission tools could ignore per-account disablement
OpenClaw Feishu permission tools could ignore per-account disablement
CVE-2026-62196High· 8.3OpenClaw versions 2026.3.22 before 2026.6.6 contain an authorization bypass vulnerability where WhatsApp group IDs can satisfy elevated sender allowlists
OpenClaw versions 2026.3.22 before 2026.6.6 contain an authorization bypass vulnerability where WhatsApp group IDs can satisfy elevated sender allowlists. Attackers with lower-trust access can perform actions requiring stronger authoriza…
CVE-2026-35630High· 8.0OpenClaw: QQBot native approval buttons did not enforce configured approver identity
OpenClaw: QQBot native approval buttons did not enforce configured approver identity
GHSA-c29c-2q9c-pc86HighOpenClaw: Slack allowFrom could bind to mutable display names
OpenClaw: Slack allowFrom could bind to mutable display names
GHSA-qjpc-qf9m-xwmrHigh· 8.8OpenClaw: Trusted-proxy Control UI WebSocket accepted client-declared scopes before pairing
OpenClaw: Trusted-proxy Control UI WebSocket accepted client-declared scopes before pairing
GHSA-gp79-m99v-gjmhMediumOpenClaw: Mattermost handlers could fall open when channel type was missing
OpenClaw: Mattermost handlers could fall open when channel type was missing
GHSA-w4v6-g3wm-w36cCriticalOpenClaw: QQBot admin commands could skip DM-only and allowFrom policy
OpenClaw: QQBot admin commands could skip DM-only and allowFrom policy
GHSA-grc3-2j34-p6gmMediumOpenClaw: message.action forwarding could send Gateway credentials to model-supplied loopback URLs
OpenClaw: message.action forwarding could send Gateway credentials to model-supplied loopback URLs
GHSA-hcm3-8f6r-6xwgMedium· 6.5OpenClaw: Browser debug/export routes could reuse already-open blocked tabs
OpenClaw: Browser debug/export routes could reuse already-open blocked tabs
GHSA-xr4f-mjxj-w6w5High· 8.3OpenClaw: Non-owner chat senders could issue device-pairing bootstrap codes
OpenClaw: Non-owner chat senders could issue device-pairing bootstrap codes
GHSA-77pv-3w4q-vrj5MediumOpenClaw: QQBot pre-dispatch slash commands could skip allowFrom checks
OpenClaw: QQBot pre-dispatch slash commands could skip allowFrom checks
CVE-2026-53819High· 8.8OpenClaw: Workspace .env could override Homebrew executable selection for skill install flows
OpenClaw: Workspace .env could override Homebrew executable selection for skill install flows
CVE-2026-53813High· 7.8OpenClaw: Fake package roots could influence memory-core artifact loading
OpenClaw: Fake package roots could influence memory-core artifact loading
CVE-2026-53809Medium· 3.8OpenClaw: Embedded runner policy could be confused by provider aliases
OpenClaw: Embedded runner policy could be confused by provider aliases
GHSA-6c4r-g249-wv3cMediumOpenClaw: Sandboxed session spawn could expose the real workspace path to child prompts
OpenClaw: Sandboxed session spawn could expose the real workspace path to child prompts
GHSA-3wqp-prf6-2m72Low· 3.1OpenClaw: Feishu dynamic-agent bindings could miss configWrites enforcement
OpenClaw: Feishu dynamic-agent bindings could miss configWrites enforcement
GHSA-275c-xpvc-jgfwMediumOpenClaw: Slack and Zalo webhook secrets could remain active after secrets.reload
OpenClaw: Slack and Zalo webhook secrets could remain active after secrets.reload
CVE-2026-53818Medium· 6.6OpenClaw: MCP loopback could skip owner-only tool policy for non-owner callers
OpenClaw: MCP loopback could skip owner-only tool policy for non-owner callers
CVE-2026-53806High· 8.8OpenClaw: Combined POSIX shell options could confuse exec revalidation
OpenClaw: Combined POSIX shell options could confuse exec revalidation
CVE-2026-53816High· 7.2OpenClaw: Paired nodes could forge exec lifecycle events without system.run provenance
OpenClaw: Paired nodes could forge exec lifecycle events without system.run provenance
GHSA-4m3v-q747-pc6hMediumOpenClaw: Mattermost slash token revocation could lag until monitor refresh
OpenClaw: Mattermost slash token revocation could lag until monitor refresh
CVE-2026-53811High· 8.8OpenClaw: Matrix allowFrom could bind to mutable display names
OpenClaw: Matrix allowFrom could bind to mutable display names
GHSA-w5ww-7chg-mxcqHighOpenClaw: Telegram interactive callbacks could skip commands.allowFrom
OpenClaw: Telegram interactive callbacks could skip commands.allowFrom
GHSA-77q5-rr5v-x43qHighOpenClaw: Trusted retry endpoint checks could match hostname prefixes
OpenClaw: Trusted retry endpoint checks could match hostname prefixes
GHSA-j472-gf56-x589HighOpenClaw: PowerShell encoded-command aliases could miss exec allowlist checks
OpenClaw: PowerShell encoded-command aliases could miss exec allowlist checks
GHSA-p73f-w79w-jqr5HighOpenClaw: Native command authorization could skip owner-command enforcement
OpenClaw: Native command authorization could skip owner-command enforcement
CVE-2026-53815High· 6.5OpenClaw: Message read actions could skip channel allowlist checks
OpenClaw: Message read actions could skip channel allowlist checks