VulnSea

OpenClaw has 222 CVEs on record. Disclosure cadence is accelerating: 127 in the last 90 days against 71 in the 90 before. The busiest recent month was September 2026 with 84. The median CVSS is 6.6 (medium), with 8 rated critical. None have a confirmed exploitation report. The dominant weakness classes are CWE-863 (51) and CWE-862 (33). Most affected products: OpenClaw (200), clawhub (5), @openclaw/feishu (2).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
6.6
Publish → KEV
—
Last 90 days
127 prev 71

Products

  • OpenClaw 200
  • clawhub 5
  • @openclaw/feishu 2
  • ClawScan 2
  • discord 2
  • slack 2
222
Total CVEs
8
Critical
0
CISA KEV
0
Exploited

OpenClaw vulnerabilities

CVEs affecting OpenClaw, newest first. Open any entry for full detail, references, and exploit status.

222 CVEsRSS

CVE-2026-100543High· 7.5
yesterday

OpenClaw (npm package openclaw) before 2026.8.1 could include deterministic hashes computed over the original, unredacted configuration in redacted configuration responses

OpenClaw (npm package openclaw) before 2026.8.1 could include deterministic hashes computed over the original, unredacted configuration in redacted configuration responses. When the Gateway password had low entropy and the remaining conf…

▾ TwilightOpenClaw · OpenClawvia NVD
CVE-2026-100542Low· 3.1
yesterday

OpenClaw (npm package 'openclaw') versions >= 2026.5.28 and < 2026.8.1 mishandle archive listings in the tar.bz2 skill installer: bounded command-output suffixes were treated as complete listings of the archive

OpenClaw (npm package 'openclaw') versions >= 2026.5.28 and < 2026.8.1 mishandle archive listings in the tar.bz2 skill installer: bounded command-output suffixes were treated as complete listings of the archive. A crafted .tar.bz2/.tbz2 …

▾ SunlitOpenClaw · OpenClawvia NVD
CVE-2026-100541High· 7.5
yesterday

OpenClaw's Matrix integration (npm package @openclaw/matrix) versions >= 2026.2.2 and < 2026.8.1 lowercase complete Matrix user IDs — including historical localparts and the case-sensitive server-name portion — when deriving the OpenClaw…

OpenClaw's Matrix integration (npm package @openclaw/matrix) versions >= 2026.2.2 and < 2026.8.1 lowercase complete Matrix user IDs — including historical localparts and the case-sensitive server-name portion — when deriving the OpenClaw…

▾ Twilightopenclaw · matrixvia NVD
CVE-2026-100540Medium· 6.8
yesterday

OpenClaw Feishu before 2026.8.1 fails to validate whether a configured default account is disabled before selecting it for model tool operations

OpenClaw Feishu before 2026.8.1 fails to validate whether a configured default account is disabled before selecting it for model tool operations. Attackers can exploit multi-account setups where a disabled default account retains credent…

▾ Sunlitopenclaw · feishuvia NVD
CVE-2026-100539Low· 2.6
yesterday

OpenClaw (npm package 'openclaw') before 2026.8.1 fails to revoke memory tool access when an operator hot-disables memory configuration

OpenClaw (npm package 'openclaw') before 2026.8.1 fails to revoke memory tool access when an operator hot-disables memory configuration. Existing memory_search and memory_get tool instances retain the enabled configuration captured at cr…

▾ SunlitOpenClaw · OpenClawvia NVD
CVE-2026-100538Medium· 6.5
yesterday

OpenClaw (npm package 'openclaw') before 2026.8.1 does not apply the originating sender's global or per-agent toolsBySender policy when handling outbound attachments

OpenClaw (npm package 'openclaw') before 2026.8.1 does not apply the originating sender's global or per-agent toolsBySender policy when handling outbound attachments. A sender that has been explicitly denied filesystem read tools can sti…

▾ SunlitOpenClaw · OpenClawvia NVD
CVE-2026-100537Low· 3.1
yesterday

OpenClaw (npm package 'openclaw') before 2026.8.1 fails to apply the originating requester's effective tool policy during Active Memory automatic recall

OpenClaw (npm package 'openclaw') before 2026.8.1 fails to apply the originating requester's effective tool policy during Active Memory automatic recall. In deployments that use Active Memory together with requester-specific tool rules, …

▾ SunlitOpenClaw · OpenClawvia NVD
CVE-2026-100536Medium· 6.5
yesterday

OpenClaw versions before 2026.8.1 fail to validate all source fields in structured message attachments, allowing attackers to hide unvalidated host paths behind allowed attachment sources

OpenClaw versions before 2026.8.1 fail to validate all source fields in structured message attachments, allowing attackers to hide unvalidated host paths behind allowed attachment sources. Attackers can exploit this by providing multiple…

▾ SunlitOpenClaw · OpenClawvia NVD
CVE-2026-100535High· 7.5
yesterday

OpenClaw (npm package 'openclaw') versions >= 2026.4.5 and < 2026.8.1 can lose the originating requester's restrictions and untrusted provenance when session-derived text is persisted to session memory

OpenClaw (npm package 'openclaw') versions >= 2026.4.5 and < 2026.8.1 can lose the originating requester's restrictions and untrusted provenance when session-derived text is persisted to session memory. In deployments where session-memor…

▾ TwilightOpenClaw · OpenClawvia NVD
CVE-2026-100534Low· 3.1
yesterday

OpenClaw versions before 2026.8.1 contain an authorization bypass vulnerability in webhook TaskFlow cancellation that allows attackers to cancel unrelated sessions

OpenClaw versions before 2026.8.1 contain an authorization bypass vulnerability in webhook TaskFlow cancellation that allows attackers to cancel unrelated sessions. An attacker with a webhook route secret can supply an arbitrary child se…

▾ SunlitOpenClaw · OpenClawvia NVD
CVE-2026-100533Medium· 5.3
yesterday

OpenClaw versions before 2026.8.1 contain a path traversal vulnerability in the tools.fs.workspaceOnly feature where Unicode filename fallback can normalize validated parent directory components

OpenClaw versions before 2026.8.1 contain a path traversal vulnerability in the tools.fs.workspaceOnly feature where Unicode filename fallback can normalize validated parent directory components. Admitted requesters can exploit canonical…

▾ SunlitOpenClaw · OpenClawvia NVD
CVE-2026-100532High· 8.1
yesterday

@openclaw/whatsapp (npm) before 2026.8.1 exposes the WhatsApp login tool through the generic channel-tool path without preserving the originating sender's owner status, so the owner-only tool boundary is not enforced

@openclaw/whatsapp (npm) before 2026.8.1 exposes the WhatsApp login tool through the generic channel-tool path without preserving the originating sender's owner status, so the owner-only tool boundary is not enforced. An admitted non-own…

▾ Twilightopenclaw · whatsappvia NVD
CVE-2026-100531Medium· 6.5
yesterday

The @openclaw/slack npm package before 2026.8.1 contains an authorization flaw in its Slack download-file handler: when a file lacks the share metadata used to prove it belongs to the requested conversation, the conversation-authorizatio…

The @openclaw/slack npm package before 2026.8.1 contains an authorization flaw in its Slack download-file handler: when a file lacks the share metadata used to prove it belongs to the requested conversation, the conversation-authorizatio…

▾ Sunlitopenclaw · slackvia NVD
CVE-2026-100530High· 7.3
yesterday

OpenClaw versions before 2026.8.1 fail to bind working directory context to reusable exec approvals, allowing approved commands to execute in different directories

OpenClaw versions before 2026.8.1 fail to bind working directory context to reusable exec approvals, allowing approved commands to execute in different directories. Attackers with an allow-always approval can reuse it to run the same com…

▾ TwilightOpenClaw · OpenClawvia NVD
CVE-2026-100529Medium· 6.4
yesterday

OpenClaw versions before 2026.8.1 contain an authorization scope widening vulnerability in file-transfer allow-always approvals that allows attackers to reuse standing grants for unreviewed paths

OpenClaw versions before 2026.8.1 contain an authorization scope widening vulnerability in file-transfer allow-always approvals that allows attackers to reuse standing grants for unreviewed paths. Attackers can exploit glob metacharacter…

▾ SunlitOpenClaw · OpenClawvia NVD
CVE-2026-100528Medium· 5.4
yesterday

OpenClaw (npm package 'openclaw') before 2026.8.1 could send third-party provider credentials to the wrong endpoint

OpenClaw (npm package 'openclaw') before 2026.8.1 could send third-party provider credentials to the wrong endpoint. In affected versions, when a third-party provider uses an OpenAI-compatible API and the resolved model metadata lacks a …

▾ SunlitOpenClaw · OpenClawvia NVD
CVE-2026-100527Medium· 5.3
yesterday

OpenClaw before 2026.8.2 contains a denial of service vulnerability in the Browser extension relay that allows unauthenticated network sources to exhaust pending-authentication capacity

OpenClaw before 2026.8.2 contains a denial of service vulnerability in the Browser extension relay that allows unauthenticated network sources to exhaust pending-authentication capacity. Attackers can hold every pending slot by maintaini…

▾ SunlitOpenClaw · OpenClawvia NVD
CVE-2026-100526Medium· 5.3
yesterday

OpenClaw's Discord integration (npm package @openclaw/discord) before version 2026.9.3 could lose the sender-scoped media policy in the emoji and sticker upload actions before loading a local file

OpenClaw's Discord integration (npm package @openclaw/discord) before version 2026.9.3 could lose the sender-scoped media policy in the emoji and sticker upload actions before loading a local file. A sender permitted to invoke those acti…

▾ Sunlitopenclaw · discordvia NVD
CVE-2026-100525Medium· 4.3
yesterday

The OpenClaw Prometheus diagnostics plugin (@openclaw/diagnostics-prometheus) before version 2026.9.3 does not enforce the operator.read scope on its authenticated metrics endpoint

The OpenClaw Prometheus diagnostics plugin (@openclaw/diagnostics-prometheus) before version 2026.9.3 does not enforce the operator.read scope on its authenticated metrics endpoint. In deployments using an identity-bearing Gateway authen…

▾ Sunlitopenclaw · diagnostics-prometheusvia NVD
CVE-2026-95815Medium· 6.3
5d ago

OpenClaw iOS before 2026.8.11 logs complete agent deep-link URLs including persistent bearer keys to unified logs as public diagnostic data

OpenClaw iOS before 2026.8.11 logs complete agent deep-link URLs including persistent bearer keys to unified logs as public diagnostic data. Attackers who obtain diagnostic archives can recover unrotated keys and replay them in forged de…

▾ SunlitOpenClaw · OpenClaw iOSEPSS 0.16%via NVD
CVE-2026-91836Low· 2.8PoC
1w ago

A flaw has been found in OpenClaw ClawScan up to 0.1.6

A flaw has been found in OpenClaw ClawScan up to 0.1.6. This affects an unknown function of the file internal/runner/static_scanner.go of the component Static Scanner. This manipulation causes incomplete comparison with missing factors. …

▾ TwilightOpenClaw · ClawScanEPSS 0.33%via NVD
CVE-2026-91835Low· 2.8PoC
1w ago

A vulnerability was detected in OpenClaw ClawScan up to 0.1.6

A vulnerability was detected in OpenClaw ClawScan up to 0.1.6. The impacted element is the function IsBinaryFile of the file internal/runner/static_scanner.go of the component File Classifier. The manipulation results in interpretation c…

▾ TwilightOpenClaw · ClawScanEPSS 0.16%via NVD
GHSA-2q7j-2vhx-56g8High· 8.1
3w ago

OpenClaw Feishu tools could ignore per-account disablement

OpenClaw Feishu tools could ignore per-account disablement

▾ Twilightopenclaw · @openclaw/feishuvia GHSA
GHSA-w8wf-3qvj-6xqfHigh· 8.1
3w ago

OpenClaw Feishu permission tools could ignore per-account disablement

OpenClaw Feishu permission tools could ignore per-account disablement

▾ Twilightopenclaw · @openclaw/feishuvia GHSA
CVE-2026-62196High· 8.3
2mo ago

OpenClaw versions 2026.3.22 before 2026.6.6 contain an authorization bypass vulnerability where WhatsApp group IDs can satisfy elevated sender allowlists

OpenClaw versions 2026.3.22 before 2026.6.6 contain an authorization bypass vulnerability where WhatsApp group IDs can satisfy elevated sender allowlists. Attackers with lower-trust access can perform actions requiring stronger authoriza…

▾ Twilightopenclaw · openclawEPSS 0.40%via NVD
CVE-2026-59261High· 7.1
2mo ago

OpenClaw < 2026.5.28 - Credential Override via Workspace Dotenv Files

OpenClaw before 2026.5.28 contains a credential exposure vulnerability where workspace dotenv files can override provider credentials. Attackers with lower-trust access to configured input paths can expose sensitive data and credentials …

▾ TwilightOpenClaw · OpenClawEPSS 0.27%via CVEORG
GHSA-c29c-2q9c-pc86High
2mo ago

OpenClaw: Slack allowFrom could bind to mutable display names

OpenClaw: Slack allowFrom could bind to mutable display names

▾ Twilightopenclaw · openclawvia GHSA
GHSA-qjpc-qf9m-xwmrHigh· 8.8
2mo ago

OpenClaw: Trusted-proxy Control UI WebSocket accepted client-declared scopes before pairing

OpenClaw: Trusted-proxy Control UI WebSocket accepted client-declared scopes before pairing

▾ Twilightopenclaw · openclawvia GHSA
GHSA-gp79-m99v-gjmhMedium
2mo ago

OpenClaw: Mattermost handlers could fall open when channel type was missing

OpenClaw: Mattermost handlers could fall open when channel type was missing

▾ Sunlitopenclaw · openclawvia GHSA
GHSA-w4v6-g3wm-w36cCritical
2mo ago

OpenClaw: QQBot admin commands could skip DM-only and allowFrom policy

OpenClaw: QQBot admin commands could skip DM-only and allowFrom policy

▾ Midnightopenclaw · openclawvia GHSA
OpenClaw vulnerabilities (CVEs) — page 3 · VulnSea