VulnSea

Openclaw has 222 CVEs on record. Disclosure cadence is accelerating: 127 in the last 90 days against 71 in the 90 before. The busiest recent month was September 2026 with 84. The median CVSS is 6.6 (medium), with 8 rated critical. None have a confirmed exploitation report. The dominant weakness classes are CWE-863 (51) and CWE-862 (33). Most affected products: OpenClaw (200), clawhub (5), @openclaw/feishu (2).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
6.6
Publish → KEV
—
Last 90 days
127 prev 71

Products

  • OpenClaw 200
  • clawhub 5
  • @openclaw/feishu 2
  • ClawScan 2
  • discord 2
  • slack 2
222
Total CVEs
8
Critical
0
CISA KEV
0
Exploited

Openclaw vulnerabilities

CVEs affecting Openclaw, newest first. Open any entry for full detail, references, and exploit status.

222 CVEsRSS

CVE-2026-34504High· 8.3
6mo ago

OpenClaw before 2026.3.28 contains a server-side request forgery vulnerability in the fal provider image-generation-provider.ts component that allows attackers to fetch internal URLs

OpenClaw before 2026.3.28 contains a server-side request forgery vulnerability in the fal provider image-generation-provider.ts component that allows attackers to fetch internal URLs. A malicious or compromised fal relay can exploit ungu…

▾ Twilightopenclaw · openclawEPSS 0.39%via NVD
CVE-2026-34503High· 8.1
6mo ago

OpenClaw before 2026.3.28 fails to disconnect active WebSocket sessions when devices are removed or tokens are revoked

OpenClaw before 2026.3.28 fails to disconnect active WebSocket sessions when devices are removed or tokens are revoked. Attackers with revoked credentials can maintain unauthorized access through existing live sessions until forced recon…

▾ Twilightopenclaw · openclawEPSS 0.45%via NVD
CVE-2026-33581Medium· 6.5
6mo ago

OpenClaw before 2026.3.24 contains a sandbox bypass vulnerability in the message tool that allows attackers to read arbitrary local files by using mediaUrl and fileUrl alias parameters that bypass localRoots validation

OpenClaw before 2026.3.24 contains a sandbox bypass vulnerability in the message tool that allows attackers to read arbitrary local files by using mediaUrl and fileUrl alias parameters that bypass localRoots validation. Remote attackers …

▾ Sunlitopenclaw · openclawEPSS 0.64%via NVD
CVE-2026-33580Medium· 6.5
6mo ago

OpenClaw before 2026.3.28 contains a missing rate limiting vulnerability in the Nextcloud Talk webhook authentication that allows attackers to brute-force weak shared secrets

OpenClaw before 2026.3.28 contains a missing rate limiting vulnerability in the Nextcloud Talk webhook authentication that allows attackers to brute-force weak shared secrets. Attackers who can reach the webhook endpoint can exploit this…

▾ Sunlitopenclaw · openclawEPSS 0.43%via NVD
CVE-2026-33579Critical· 9.9PoC
6mo ago

OpenClaw before 2026.3.28 contains a privilege escalation vulnerability in the /pair approve command path that fails to forward caller scopes into the core approval check

OpenClaw before 2026.3.28 contains a privilege escalation vulnerability in the /pair approve command path that fails to forward caller scopes into the core approval check. A caller with pairing privileges but without admin privileges can…

▾ Abyssalopenclaw · openclawEPSS 0.51%via NVD
CVE-2026-33578Medium· 4.3
6mo ago

OpenClaw before 2026.3.28 contains a sender policy bypass vulnerability in the Google Chat and Zalouser extensions where route-level group allowlist policies silently downgrade to open policy

OpenClaw before 2026.3.28 contains a sender policy bypass vulnerability in the Google Chat and Zalouser extensions where route-level group allowlist policies silently downgrade to open policy. Attackers can exploit this policy resolution…

▾ Sunlitopenclaw · openclawEPSS 0.31%via NVD
CVE-2026-33577High· 8.1
6mo ago

OpenClaw before 2026.3.28 contains an insufficient scope validation vulnerability in the node pairing approval path that allows low-privilege operators to approve nodes with broader scopes

OpenClaw before 2026.3.28 contains an insufficient scope validation vulnerability in the node pairing approval path that allows low-privilege operators to approve nodes with broader scopes. Attackers can exploit missing callerScopes vali…

▾ Twilightopenclaw · openclawEPSS 0.42%via NVD
CVE-2026-33576Medium· 6.5
6mo ago

OpenClaw before 2026.3.28 downloads and stores inbound media from Zalo channels before validating sender authorization

OpenClaw before 2026.3.28 downloads and stores inbound media from Zalo channels before validating sender authorization. Unauthorized senders can force network fetches and disk writes to the media store by sending messages that are subseq…

▾ Sunlitopenclaw · openclawEPSS 0.43%via NVD
CVE-2026-32896Medium· 4.8
6mo ago

The BlueBubbles webhook handler in OpenClaw versions prior to 2026.2.21 contains a passwordless fallback authentication path that allows unauthenticated webhook events in certain reverse-proxy or local routing configurations

The BlueBubbles webhook handler in OpenClaw versions prior to 2026.2.21 contains a passwordless fallback authentication path that allows unauthenticated webhook events in certain reverse-proxy or local routing configurations. Attackers c…

▾ Sunlitopenclaw · openclawEPSS 0.43%via NVD
CVE-2026-22172Critical· 9.9
6mo ago

OpenClaw < 2026.3.12 - Scope Elevation in WebSocket Shared-Auth Connections

OpenClaw versions prior to 2026.3.12 contain an authorization bypass vulnerability in the WebSocket connect path that allows shared-token or password-authenticated connections to self-declare elevated scopes without server-side binding. …

▾ MidnightOpenClaw · OpenClawEPSS 0.56%via CVEORG
CVE-2026-28474Critical· 9.8
6mo ago

OpenClaw's Nextcloud Talk plugin versions prior to 2026.2.6 accept equality matching on the mutable actor.name display name field for allowlist validation, allowing attackers to bypass DM and room allowlists

OpenClaw's Nextcloud Talk plugin versions prior to 2026.2.6 accept equality matching on the mutable actor.name display name field for allowlist validation, allowing attackers to bypass DM and room allowlists. An attacker can change their…

▾ Midnightopenclaw · openclawEPSS 0.84%via NVD
CVE-2026-28465Medium· 5.9
6mo ago

OpenClaw's voice-call plugin versions before 2026.2.3 contain an improper authentication vulnerability in webhook verification that allows remote attackers to bypass verification by supplying untrusted forwarded headers

OpenClaw's voice-call plugin versions before 2026.2.3 contain an improper authentication vulnerability in webhook verification that allows remote attackers to bypass verification by supplying untrusted forwarded headers. Attackers can sp…

▾ Sunlitopenclaw · openclawEPSS 0.68%via NVD
Openclaw vulnerabilities (CVEs) — page 8 · VulnSea