VulnSea

Openclaw has 222 CVEs on record. Disclosure cadence is accelerating: 127 in the last 90 days against 71 in the 90 before. The busiest recent month was September 2026 with 84. The median CVSS is 6.6 (medium), with 8 rated critical. None have a confirmed exploitation report. The dominant weakness classes are CWE-863 (51) and CWE-862 (33). Most affected products: OpenClaw (200), clawhub (5), @openclaw/feishu (2).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
6.6
Publish → KEV
—
Last 90 days
127 prev 71

Products

  • OpenClaw 200
  • clawhub 5
  • @openclaw/feishu 2
  • ClawScan 2
  • discord 2
  • slack 2
222
Total CVEs
8
Critical
0
CISA KEV
0
Exploited

Openclaw vulnerabilities

CVEs affecting Openclaw, newest first. Open any entry for full detail, references, and exploit status.

222 CVEsRSS

CVE-2026-100603Medium· 5.4
yesterday

ClawHub (openclaw/clawhub) application/backend contains a flaw in the skill report moderation flow: four distinct ordinary authenticated accounts can report a visible skill and trigger automatic hiding (moderationStatus: hidden) of that …

ClawHub (openclaw/clawhub) application/backend contains a flaw in the skill report moderation flow: four distinct ordinary authenticated accounts can report a visible skill and trigger automatic hiding (moderationStatus: hidden) of that …

▾ Sunlitopenclaw · clawhubvia NVD
CVE-2026-100601Medium· 5.3
yesterday

ClawHub (openclaw/clawhub) application/backend contains a server-side request forgery vulnerability in the public profile preview's image fetching

ClawHub (openclaw/clawhub) application/backend contains a server-side request forgery vulnerability in the public profile preview's image fetching. The preview accepts a user-supplied image URL and checks the textual hostname against pri…

▾ Sunlitopenclaw · clawhubvia NVD
CVE-2026-100600Medium· 5.3
yesterday

ClawHub (the openclaw/clawhub application/backend) does not bind anonymous HTTP API requests to a trusted caller identity, so all direct anonymous API requests share a single default quota allowance

ClawHub (the openclaw/clawhub application/backend) does not bind anonymous HTTP API requests to a trusted caller identity, so all direct anonymous API requests share a single default quota allowance. A remote, unauthenticated caller can …

▾ Sunlitopenclaw · clawhubvia NVD
CVE-2026-100604Medium· 5.4
yesterday

ClawHub (openclaw/clawhub) contains an incorrect authorization vulnerability in the ClawHub application/backend: an organization-owned skill retains the ownerUserId of its original publisher, and transfer and lifecycle authorization chec…

ClawHub (openclaw/clawhub) contains an incorrect authorization vulnerability in the ClawHub application/backend: an organization-owned skill retains the ownerUserId of its original publisher, and transfer and lifecycle authorization chec…

▾ Sunlitopenclaw · clawhubvia NVD
CVE-2026-100602Medium· 6.5
yesterday

ClawHub (openclaw/clawhub application/backend) contains a missing authorization check in the changelog preview feature

ClawHub (openclaw/clawhub application/backend) contains a missing authorization check in the changelog preview feature. A signed-in caller can invoke the public skills:generateChangelogPreview action for a skill they are not authorized t…

▾ Sunlitopenclaw · clawhubvia NVD
CVE-2026-100599High· 8.8
yesterday

OpenClaw versions 2026.5.1 through 2026.7.0 fail to apply the configured exec approval path to Google Meet node commands

OpenClaw versions 2026.5.1 through 2026.7.0 fail to apply the configured exec approval path to Google Meet node commands. The googlemeet.chrome command accepts caller-supplied audio command arrays and executes them on a paired node witho…

▾ TwilightOpenClaw · OpenClawEPSS 0.30%via NVD
CVE-2026-100598High· 7.1
yesterday

OpenClaw (npm package openclaw) before 2026.7.1 incorrectly binds Signal approval reactions

OpenClaw (npm package openclaw) before 2026.7.1 incorrectly binds Signal approval reactions. In affected versions, a reaction intended to resolve a structured approval request could instead attach to ordinary outbound text when unrelated…

▾ TwilightOpenClaw · OpenClawEPSS 0.11%via NVD
CVE-2026-100597High· 7.8
yesterday

OpenClaw (npm package 'openclaw') before 2026.7.1 is vulnerable to a time-of-check time-of-use race condition in OpenShell local mirror filesystem mutation operations

OpenClaw (npm package 'openclaw') before 2026.7.1 is vulnerable to a time-of-check time-of-use race condition in OpenShell local mirror filesystem mutation operations. The remove, mkdir, and rename operations could act on a different fil…

▾ TwilightOpenClaw · OpenClawEPSS 0.08%via NVD
CVE-2026-100596High· 8.8
yesterday

OpenClaw versions before 2026.7.1 fail to properly authorize non-owner users executing MCP configuration changes through /mcp set and /mcp unset commands

OpenClaw versions before 2026.7.1 fail to properly authorize non-owner users executing MCP configuration changes through /mcp set and /mcp unset commands. Attackers can persist arbitrary stdio MCP commands that execute with OpenClaw proc…

▾ TwilightOpenClaw · OpenClawEPSS 0.25%via NVD
CVE-2026-100595Medium· 6.5
yesterday

OpenClaw versions before 2026.7.1 contain an authorization bypass vulnerability in the diagnostics export command that allows non-owner channel senders to access owner-only host diagnostic bundles

OpenClaw versions before 2026.7.1 contain an authorization bypass vulnerability in the diagnostics export command that allows non-owner channel senders to access owner-only host diagnostic bundles. Attackers can request and receive diagn…

▾ SunlitOpenClaw · OpenClawEPSS 0.24%via NVD
CVE-2026-100594Medium· 6.5
yesterday

OpenClaw versions before 2026.7.1 contain an authorization bypass vulnerability in the /export-trajectory endpoint that allows non-owner senders to request and receive owner-only trajectory bundles

OpenClaw versions before 2026.7.1 contain an authorization bypass vulnerability in the /export-trajectory endpoint that allows non-owner senders to request and receive owner-only trajectory bundles. Attackers can access prompts, model me…

▾ SunlitOpenClaw · OpenClawEPSS 0.24%via NVD
CVE-2026-100593Medium· 5.4
yesterday

OpenClaw (npm package `openclaw`) before 2026.7.1 does not enforce the documented owner-only requirement for persistent `/activation` policy changes in group channels

OpenClaw (npm package `openclaw`) before 2026.7.1 does not enforce the documented owner-only requirement for persistent `/activation` policy changes in group channels. An authorized non-owner channel sender can change whether the agent r…

▾ SunlitOpenClaw · OpenClawEPSS 0.14%via NVD
CVE-2026-100592Medium· 6.3
yesterday

OpenClaw is an agent gateway distributed via npm

OpenClaw is an agent gateway distributed via npm. In versions >= 2026.4.10 and < 2026.7.1, persistent memory dreaming mutations omit owner permission checks. An authorized but non-owner external-channel sender can issue the persistent '/…

▾ SunlitOpenClaw · OpenClawEPSS 0.16%via NVD
CVE-2026-100591Medium· 6.3
yesterday

OpenClaw is an npm-distributed agent gateway

OpenClaw is an npm-distributed agent gateway. In versions before 2026.7.1, the global Active Memory toggle mutations could omit owner checks. An authorized non-owner external-channel sender could therefore persistently enable or disable …

▾ SunlitOpenClaw · OpenClawEPSS 0.16%via NVD
CVE-2026-100590Medium· 4.3
yesterday

OpenClaw before 2026.7.1 contains an authorization bypass vulnerability in the /voice set command that allows non-owner external-channel senders to persist Gateway voice configuration

OpenClaw before 2026.7.1 contains an authorization bypass vulnerability in the /voice set command that allows non-owner external-channel senders to persist Gateway voice configuration. Attackers with command access can change the voice u…

▾ SunlitOpenClaw · OpenClawEPSS 0.18%via NVD
CVE-2026-100589High· 8.3
yesterday

OpenClaw versions before 2026.7.1 contain a sandbox bypass vulnerability in the browser tool that allows sandboxed sessions to access paired node browser actions despite allowHostControl=false configuration

OpenClaw versions before 2026.7.1 contain a sandbox bypass vulnerability in the browser tool that allows sandboxed sessions to access paired node browser actions despite allowHostControl=false configuration. Attackers with control over s…

▾ TwilightOpenClaw · OpenClawEPSS 0.32%via NVD
CVE-2026-100588High· 8.3
yesterday

OpenClaw (npm package 'openclaw') before 2026.7.1 does not enforce the administrator scope requirement on browser control when it is reached through the node.invoke method, although direct browser.request access requires administrator sc…

OpenClaw (npm package 'openclaw') before 2026.7.1 does not enforce the administrator scope requirement on browser control when it is reached through the node.invoke method, although direct browser.request access requires administrator sc…

▾ TwilightOpenClaw · OpenClawEPSS 0.30%via NVD
CVE-2026-100587High· 8.8
yesterday

OpenClaw versions before 2026.7.1 fail to properly validate owner authorization in the Codex computer-use installation command

OpenClaw versions before 2026.7.1 fail to properly validate owner authorization in the Codex computer-use installation command. Non-owner channel senders can install arbitrary plugins and execute MCP processes with OpenClaw user privileg…

▾ TwilightOpenClaw · OpenClawEPSS 0.25%via NVD
CVE-2026-100586High· 8.8
yesterday

OpenClaw Codex before 2026.7.1 fails to properly enforce owner authorization when creating native conversation bindings

OpenClaw Codex before 2026.7.1 fails to properly enforce owner authorization when creating native conversation bindings. Non-owner channel senders with command access can create bindings to the native Codex runtime and execute host-capab…

▾ TwilightOpenClaw · OpenClawEPSS 0.25%via NVD
CVE-2026-100585High· 8.0
yesterday

OpenClaw (npm package `openclaw`) before 2026.7.1 fails to enforce the owner-only authorization requirement for Claude Code permission prompts delivered through the MCP channel bridge

OpenClaw (npm package `openclaw`) before 2026.7.1 fails to enforce the owner-only authorization requirement for Claude Code permission prompts delivered through the MCP channel bridge. An authorized non-owner channel sender with channel …

▾ TwilightOpenClaw · OpenClawEPSS 0.19%via NVD
CVE-2026-100584Medium· 6.7
yesterday

OpenClaw is an npm-distributed agent runtime

OpenClaw is an npm-distributed agent runtime. In versions >= 2026.2.26 and < 2026.7.1, PowerShell command analysis on Windows hosts running in exec allowlist mode could approve an exact executable resolved from PATH but subsequently exec…

▾ SunlitOpenClaw · OpenClawEPSS 0.10%via NVD
CVE-2026-100583Medium· 4.3
yesterday

OpenClaw Discord versions before 2026.7.1 contain an authorization bypass vulnerability in guild metadata read actions that allows lower-trust senders to retrieve information excluded by channel allowlists

OpenClaw Discord versions before 2026.7.1 contain an authorization bypass vulnerability in guild metadata read actions that allows lower-trust senders to retrieve information excluded by channel allowlists. Attackers can bypass the confi…

▾ Sunlitopenclaw · discordEPSS 0.18%via NVD
CVE-2026-100582Medium· 6.5
yesterday

OpenClaw channel plugins (@openclaw/msteams, @openclaw/feishu, @openclaw/matrix, and @openclaw/googlechat) before 2026.8.1 do not enforce the configured channel read allowlist for caller-supplied explicit read targets in message, reactio…

OpenClaw channel plugins (@openclaw/msteams, @openclaw/feishu, @openclaw/matrix, and @openclaw/googlechat) before 2026.8.1 do not enforce the configured channel read allowlist for caller-supplied explicit read targets in message, reactio…

▾ Sunlitopenclaw · msteamsEPSS 0.21%via NVD
CVE-2026-100581Medium· 5.5
yesterday

OpenClaw for iOS before 2026.8.11 stores Gateway credentials as cleartext JSON in App Group UserDefaults instead of the device Keychain

OpenClaw for iOS before 2026.8.11 stores Gateway credentials as cleartext JSON in App Group UserDefaults instead of the device Keychain. Attackers with access to unencrypted device backups or extracted App Group containers can recover va…

▾ SunlitOpenClaw · OpenClawEPSS 0.08%via NVD
CVE-2026-100580High· 8.8
yesterday

OpenClaw (npm package 'openclaw') before 2026.7.1 improperly handles case sensitivity in the model-facing cron tool: a mixed-case payload kind can pass the agent-facing shell-execution guard and later normalize into a command job

OpenClaw (npm package 'openclaw') before 2026.7.1 improperly handles case sensitivity in the model-facing cron tool: a mixed-case payload kind can pass the agent-facing shell-execution guard and later normalize into a command job. An act…

▾ TwilightOpenClaw · OpenClawEPSS 0.34%via NVD
CVE-2026-100579High· 7.6
yesterday

OpenClaw (npm package 'openclaw') before 2026.7.1 incorrectly trusts requester provenance in message.action

OpenClaw (npm package 'openclaw') before 2026.7.1 incorrectly trusts requester provenance in message.action. In identity-bearing Gateway deployments (authentication modes that honor caller identity and narrower operator scopes), a write-…

▾ TwilightOpenClaw · OpenClawEPSS 0.23%via NVD
CVE-2026-100578High· 7.6
yesterday

OpenClaw (npm package `openclaw`) before 2026.7.1 fails to restrict owner-only infrastructure tools exposed through the chat.send endpoint

OpenClaw (npm package `openclaw`) before 2026.7.1 fails to restrict owner-only infrastructure tools exposed through the chat.send endpoint. In Gateway deployments using authentication modes that honor caller identity and narrower operato…

▾ TwilightOpenClaw · OpenClawEPSS 0.23%via NVD
CVE-2026-100577Medium· 6.3
yesterday

OpenClaw versions before 2026.8.1 fail to validate video asset URLs returned by providers, allowing server-side requests to private destinations

OpenClaw versions before 2026.8.1 fail to validate video asset URLs returned by providers, allowing server-side requests to private destinations. A malicious or compromised provider can return private or loopback URLs to cause the CLI to…

▾ SunlitOpenClaw · OpenClawEPSS 0.14%via NVD
CVE-2026-100576Medium· 5.4
yesterday

OpenClaw versions before 2026.8.1 contain a server-side request forgery vulnerability in browser wait predicates that allows attackers to bypass SSRF protections by reaching blocked destinations

OpenClaw versions before 2026.8.1 contain a server-side request forgery vulnerability in browser wait predicates that allows attackers to bypass SSRF protections by reaching blocked destinations. Attackers can use the wait --fn function …

▾ SunlitOpenClaw · OpenClawEPSS 0.21%via NVD
CVE-2026-100575High· 8.8
yesterday

OpenClaw Slack versions before 2026.8.1 fail to properly enforce sender allowlists in multi-person direct messages

OpenClaw Slack versions before 2026.8.1 fail to properly enforce sender allowlists in multi-person direct messages. Disallowed participants can trigger Slack agents and access tools and data granted to those agents by bypassing configure…

▾ Twilightopenclaw · slackEPSS 0.26%via NVD
Openclaw vulnerabilities (CVEs) · VulnSea