VulnSea

Openclaw has 222 CVEs on record. Disclosure cadence is accelerating: 127 in the last 90 days against 71 in the 90 before. The busiest recent month was September 2026 with 84. The median CVSS is 6.6 (medium), with 8 rated critical. None have a confirmed exploitation report. The dominant weakness classes are CWE-863 (51) and CWE-862 (33). Most affected products: OpenClaw (200), clawhub (5), @openclaw/feishu (2).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
6.6
Publish → KEV
—
Last 90 days
127 prev 71

Products

  • OpenClaw 200
  • clawhub 5
  • @openclaw/feishu 2
  • ClawScan 2
  • discord 2
  • slack 2
222
Total CVEs
8
Critical
0
CISA KEV
0
Exploited

Openclaw vulnerabilities

CVEs affecting Openclaw, newest first. Open any entry for full detail, references, and exploit status.

222 CVEsRSS

CVE-2026-100574Medium· 5.9
yesterday

OpenClaw (npm package 'openclaw') before 2026.8.1 contains a server-side request forgery vulnerability in its trusted-host DNS checks

OpenClaw (npm package 'openclaw') before 2026.8.1 contains a server-side request forgery vulnerability in its trusted-host DNS checks. For fetches that use the trusted-host DNS recheck, a trusted hostname that resolves to an unspecified …

▾ SunlitOpenClaw · OpenClawEPSS 0.23%via NVD
CVE-2026-100573Low· 3.3
yesterday

OpenClaw versions before 2026.8.1 contain a sandbox policy bypass vulnerability in the MCP loopback component that allows sandboxed coding-agent sessions to invoke tools explicitly denied by sandbox.tools.deny policy

OpenClaw versions before 2026.8.1 contain a sandbox policy bypass vulnerability in the MCP loopback component that allows sandboxed coding-agent sessions to invoke tools explicitly denied by sandbox.tools.deny policy. Attackers can list …

▾ SunlitOpenClaw · OpenClawEPSS 0.11%via NVD
CVE-2026-100572Medium· 5.3
yesterday

OpenClaw versions >= 2026.3.25 and < 2026.8.1 apply invalid-token rate limiting for Synology Chat webhooks before authentication and key the limit on the raw proxy socket address

OpenClaw versions >= 2026.3.25 and < 2026.8.1 apply invalid-token rate limiting for Synology Chat webhooks before authentication and key the limit on the raw proxy socket address. In deployments where OpenClaw sits behind a trusted rever…

▾ SunlitOpenClaw · OpenClawEPSS 0.35%via NVD
CVE-2026-100571Medium· 5.3
yesterday

OpenClaw (npm package 'openclaw') versions >= 2026.6.6 and < 2026.8.1 apply the SMS webhook invalid-request rate limit before Twilio signature verification and identify clients only by the raw proxy socket address

OpenClaw (npm package 'openclaw') versions >= 2026.6.6 and < 2026.8.1 apply the SMS webhook invalid-request rate limit before Twilio signature verification and identify clients only by the raw proxy socket address. In deployments where t…

▾ SunlitOpenClaw · OpenClawEPSS 0.35%via NVD
CVE-2026-100570High· 7.8
yesterday

OpenClaw (npm package 'openclaw') versions >= 2026.3.28 and < 2026.8.1 allow an untrusted workspace .env file to set the CLOUDSDK_PYTHON_ARGS environment variable

OpenClaw (npm package 'openclaw') versions >= 2026.3.28 and < 2026.8.1 allow an untrusted workspace .env file to set the CLOUDSDK_PYTHON_ARGS environment variable. When an operator starts OpenClaw in attacker-controlled workspace content…

▾ TwilightOpenClaw · OpenClawEPSS 0.13%via NVD
CVE-2026-100569Medium· 5.5
yesterday

OpenClaw is an npm-distributed application

OpenClaw is an npm-distributed application. In versions >= 2026.4.25 and < 2026.8.1, the workspace environment-variable filter did not block variables ending in `_ENDPOINT`, so an untrusted workspace `.env` file could set AZURE_SPEECH_EN…

▾ SunlitOpenClaw · OpenClawEPSS 0.12%via NVD
CVE-2026-100568High· 8.3
yesterday

OpenClaw versions before 2026.8.1 fail to properly restrict access to operator command cron jobs, allowing model-visible agent callers to read and execute ownerless command jobs

OpenClaw versions before 2026.8.1 fail to properly restrict access to operator command cron jobs, allowing model-visible agent callers to read and execute ownerless command jobs. Attackers can inspect stored environment variables and for…

▾ TwilightOpenClaw · OpenClawEPSS 0.25%via NVD
CVE-2026-100567High· 8.2
yesterday

OpenClaw is an agent gateway distributed as the npm package 'openclaw'

OpenClaw is an agent gateway distributed as the npm package 'openclaw'. In versions >= 2026.4.5 and < 2026.8.1, the Gateway validated a single DNS resolution result for a configured remote Chrome DevTools Protocol (CDP) hostname, but the…

▾ TwilightOpenClaw · OpenClawEPSS 0.25%via NVD
CVE-2026-100566Medium· 6.5
yesterday

OpenClaw LINE versions before 2026.8.1 contain an access control vulnerability where group allowlist mode silently inherits DM allowFrom values when groupAllowFrom is not explicitly configured

OpenClaw LINE versions before 2026.8.1 contain an access control vulnerability where group allowlist mode silently inherits DM allowFrom values when groupAllowFrom is not explicitly configured. Attackers with group participation can trig…

▾ Sunlitopenclaw · lineEPSS 0.20%via NVD
CVE-2026-100564Medium· 5.4
yesterday

OpenClaw versions before 2026.8.1 fail to neutralize spreadsheet formula characters in participant display names within attendance CSV exports

OpenClaw versions before 2026.8.1 fail to neutralize spreadsheet formula characters in participant display names within attendance CSV exports. Attackers can inject formula-like cells that execute with spreadsheet user permissions when t…

▾ SunlitOpenClaw · OpenClawEPSS 0.19%via NVD
CVE-2026-100563Medium· 5.4
yesterday

OpenClaw (npm package `openclaw`) before 2026.8.1 does not neutralize leading characters that spreadsheet applications interpret as formulas when the Control UI exports session data to CSV

OpenClaw (npm package `openclaw`) before 2026.8.1 does not neutralize leading characters that spreadsheet applications interpret as formulas when the Control UI exports session data to CSV. Although session labels were quoted as CSV text…

▾ SunlitOpenClaw · OpenClawEPSS 0.19%via NVD
CVE-2026-100562Medium· 5.4
yesterday

OpenClaw versions before 2026.8.1 contain an authorization bypass vulnerability in the sessions.create endpoint that allows operator.write callers to modify session configurations reserved for operator.admin scope

OpenClaw versions before 2026.8.1 contain an authorization bypass vulnerability in the sessions.create endpoint that allows operator.write callers to modify session configurations reserved for operator.admin scope. Attackers with write-s…

▾ SunlitOpenClaw · OpenClawEPSS 0.19%via NVD
CVE-2026-100561High· 8.0
yesterday

OpenClaw (npm package 'openclaw') versions >= 2026.3.22 and < 2026.8.1 contain an approval-bypass flaw in the exec approval policy: the policy could trust a command-running wrapper without inspecting the command carried in its arguments.…

OpenClaw (npm package 'openclaw') versions >= 2026.3.22 and < 2026.8.1 contain an approval-bypass flaw in the exec approval policy: the policy could trust a command-running wrapper without inspecting the command carried in its arguments.…

▾ TwilightOpenClaw · OpenClawEPSS 0.25%via NVD
CVE-2026-100560High· 7.5
yesterday

OpenClaw versions before 2026.8.1 contain an authorization bypass vulnerability where Allow Always approvals for exact commands persist as path-only grants on macOS and Linux

OpenClaw versions before 2026.8.1 contain an authorization bypass vulnerability where Allow Always approvals for exact commands persist as path-only grants on macOS and Linux. Attackers can reuse the same executable with different argume…

▾ TwilightOpenClaw · OpenClawEPSS 0.58%via NVD
CVE-2026-100559High· 8.0
yesterday

OpenClaw versions before 2026.8.1 contain a command parser vulnerability where escaped newlines confuse exec allowlist parsing, allowing hidden commands to execute

OpenClaw versions before 2026.8.1 contain a command parser vulnerability where escaped newlines confuse exec allowlist parsing, allowing hidden commands to execute. Attackers can craft input with escaped newlines to bypass allowlist vali…

▾ TwilightOpenClaw · OpenClawEPSS 0.25%via NVD
CVE-2026-100558High· 7.5
yesterday

OpenClaw versions before 2026.8.1 contain a resource exhaustion vulnerability in the Gateway listener that allows unauthenticated clients to retain response sockets by sending WebSocket upgrade requests without matching connection semant…

OpenClaw versions before 2026.8.1 contain a resource exhaustion vulnerability in the Gateway listener that allows unauthenticated clients to retain response sockets by sending WebSocket upgrade requests without matching connection semant…

▾ TwilightOpenClaw · OpenClawEPSS 0.28%via NVD
CVE-2026-100557High· 8.3
yesterday

OpenClaw versions before 2026.8.1 contain an authorization bypass vulnerability in skill tool dispatch that fails to carry the sender's owner status

OpenClaw versions before 2026.8.1 contain an authorization bypass vulnerability in skill tool dispatch that fails to carry the sender's owner status. Non-owner senders authorized to invoke skill commands can access owner-only tools and s…

▾ TwilightOpenClaw · OpenClawEPSS 0.24%via NVD
CVE-2026-100556Medium· 6.3
yesterday

OpenClaw (npm package openclaw) versions >= 2026.5.2 and < 2026.8.1 contain an incorrect authorization vulnerability in WhatsApp group handling

OpenClaw (npm package openclaw) versions >= 2026.5.2 and < 2026.8.1 contain an incorrect authorization vulnerability in WhatsApp group handling. A group sender who is admitted for ordinary messages but denied by commands.allowFrom or own…

▾ SunlitOpenClaw · OpenClawEPSS 0.28%via NVD
CVE-2026-100555High· 7.1
yesterday

OpenClaw is an npm-distributed gateway application

OpenClaw is an npm-distributed gateway application. In versions >= 2026.7.1 and < 2026.8.1, Synology Chat attachment delivery could lose DNS pinning: the Gateway validated a single DNS result for a supplied file URL but then passed the o…

▾ TwilightOpenClaw · OpenClawEPSS 0.20%via NVD
CVE-2026-100554Medium· 4.2
yesterday

OpenClaw (npm package 'openclaw') versions >= 2026.5.12 and < 2026.8.1 do not immediately invalidate Canvas HTTP authorization when a paired node is revoked

OpenClaw (npm package 'openclaw') versions >= 2026.5.12 and < 2026.8.1 do not immediately invalidate Canvas HTTP authorization when a paired node is revoked. Node revocation invalidates the WebSocket client, but Canvas HTTP authorization…

▾ SunlitOpenClaw · OpenClawEPSS 0.22%via NVD
CVE-2026-100553Medium· 4.3
yesterday

OpenClaw versions >= 2026.6.9 and < 2026.8.1 do not declare the native chatId parameter as a delivery target in the Feishu unpin feature, so unpin requests can bypass the shared same-provider cross-context target check

OpenClaw versions >= 2026.6.9 and < 2026.8.1 do not declare the native chatId parameter as a delivery target in the Feishu unpin feature, so unpin requests can bypass the shared same-provider cross-context target check. When tools.messag…

▾ SunlitOpenClaw · OpenClawEPSS 0.21%via NVD
CVE-2026-100552High· 8.8
yesterday

OpenClaw (npm package 'openclaw') before 2026.8.1 does not correctly enforce per-chat tool policies for Codex app-server runtime tools

OpenClaw (npm package 'openclaw') before 2026.8.1 does not correctly enforce per-chat tool policies for Codex app-server runtime tools. A conversation-level tools.allow rule filtered OpenClaw tools but did not restrict the shell, process…

▾ TwilightOpenClaw · OpenClawEPSS 0.26%via NVD
CVE-2026-100551High· 8.3
yesterday

OpenClaw for iOS versions >= 2026.7.1 and < 2026.8.11 do not enforce saved Gateway TLS pins in the Control UI

OpenClaw for iOS versions >= 2026.7.1 and < 2026.8.11 do not enforce saved Gateway TLS pins in the Control UI. While native connections enforced the saved Gateway fingerprint, the authenticated Terminal and session Dashboard WebViews omi…

▾ TwilightOpenClaw · OpenClawEPSS 0.17%via NVD
CVE-2026-100550Medium· 5.4
yesterday

OpenClaw (npm package 'openclaw') before 2026.8.1 contains an access-control bypass in the Microsoft Teams integration

OpenClaw (npm package 'openclaw') before 2026.8.1 contains an access-control bypass in the Microsoft Teams integration. When groupPolicy is set to allowlist, a missing or unsupported configured access group produces a denied group-resolu…

▾ SunlitOpenClaw · OpenClawEPSS 0.19%via NVD
CVE-2026-100549Medium· 5.4
yesterday

OpenClaw versions before 2026.8.1 contain a path traversal vulnerability in QQBot voice attachment handling where filenames are decoded twice, allowing encoded traversal segments to reappear after sanitization

OpenClaw versions before 2026.8.1 contain a path traversal vulnerability in QQBot voice attachment handling where filenames are decoded twice, allowing encoded traversal segments to reappear after sanitization. Attackers can supply craft…

▾ SunlitOpenClaw · OpenClawEPSS 0.28%via NVD
CVE-2026-100548Medium· 5.3
yesterday

OpenClaw (npm package 'openclaw') versions >= 2026.3.28 and < 2026.8.1 contain a credential exposure issue in memory embedding failover

OpenClaw (npm package 'openclaw') versions >= 2026.3.28 and < 2026.8.1 contain a credential exposure issue in memory embedding failover. When remote embedding fallback is configured and the primary embedding provider fails, the request c…

▾ SunlitOpenClaw · OpenClawEPSS 0.25%via NVD
CVE-2026-100547Medium· 5.5
yesterday

OpenClaw is a coding agent distributed as the npm package `openclaw`

OpenClaw is a coding agent distributed as the npm package `openclaw`. In affected versions (2026.7.1 through 2026.7.2), alternate but valid `file:` URL spellings supplied over the Agent Client Protocol (ACP) were treated as relative path…

▾ SunlitOpenClaw · OpenClawEPSS 0.13%via NVD
CVE-2026-100546Medium· 6.4
yesterday

OpenClaw (npm package `openclaw`) versions >= 2026.7.2 and < 2026.9.2 contain a race condition in the Discord realtime voice transcript path

OpenClaw (npm package `openclaw`) versions >= 2026.7.2 and < 2026.9.2 contain a race condition in the Discord realtime voice transcript path. Concurrent control-classified voice transcripts could consume speaker context belonging to anot…

▾ SunlitOpenClaw · OpenClawEPSS 0.18%via NVD
CVE-2026-100545Medium· 5.3
yesterday

OpenClaw (npm package `openclaw`) before 2026.8.1 incorrectly enforces sender tool policies during session-memory filename generation

OpenClaw (npm package `openclaw`) before 2026.8.1 incorrectly enforces sender tool policies during session-memory filename generation. In affected versions, filename generation created an embedded helper that retained tools which the ori…

▾ SunlitOpenClaw · OpenClawEPSS 0.21%via NVD
CVE-2026-100544High· 8.8
yesterday

openclaw's @openclaw/voice-call package before 2026.8.1 launches the configured agent for classic inbound voice calls without propagating the caller's identity or non-owner status

openclaw's @openclaw/voice-call package before 2026.8.1 launches the configured agent for classic inbound voice calls without propagating the caller's identity or non-owner status. As a result, owner-only tool filtering can fail open and…

▾ Twilightopenclaw · voice-callEPSS 0.25%via NVD
Openclaw vulnerabilities (CVEs) — page 2 · VulnSea