VulnSea

openclaw has 128 CVEs on record. Cadence is steady at roughly 47 per quarter. The busiest recent month was June 2026 with 55. The median CVSS is 7.1 (high), with 6 rated critical. None have a confirmed exploitation report. The dominant weakness classes are CWE-863 (30) and CWE-862 (15). Most affected products: openclaw (123), @openclaw/feishu (2), ClawScan (2).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
7.1
Publish → KEV
Last 90 days
47 prev 78

Products

  • openclaw 123
  • @openclaw/feishu 2
  • ClawScan 2
  • github.com/openclaw/crabbox 1
128
Total CVEs
6
Critical
0
CISA KEV
0
Exploited

openclaw vulnerabilities

CVEs affecting openclaw, newest first. Open any entry for full detail, references, and exploit status.

128 CVEsRSS

CVE-2026-91836Low· 2.8PoC
6d ago

A flaw has been found in OpenClaw ClawScan up to 0.1.6

A flaw has been found in OpenClaw ClawScan up to 0.1.6. This affects an unknown function of the file internal/runner/static_scanner.go of the component Static Scanner. This manipulation causes incomplete comparison with missing factors. …

TwilightOpenClaw · ClawScanEPSS 0.31%via NVD
CVE-2026-91835Low· 2.8PoC
6d ago

A vulnerability was detected in OpenClaw ClawScan up to 0.1.6

A vulnerability was detected in OpenClaw ClawScan up to 0.1.6. The impacted element is the function IsBinaryFile of the file internal/runner/static_scanner.go of the component File Classifier. The manipulation results in interpretation c…

TwilightOpenClaw · ClawScanEPSS 0.11%via NVD
GHSA-2q7j-2vhx-56g8High· 8.1
2w ago

OpenClaw Feishu tools could ignore per-account disablement

OpenClaw Feishu tools could ignore per-account disablement

Twilightopenclaw · @openclaw/feishuvia GHSA
GHSA-w8wf-3qvj-6xqfHigh· 8.1
2w ago

OpenClaw Feishu permission tools could ignore per-account disablement

OpenClaw Feishu permission tools could ignore per-account disablement

Twilightopenclaw · @openclaw/feishuvia GHSA
CVE-2026-62196High· 8.3
2mo ago

OpenClaw versions 2026.3.22 before 2026.6.6 contain an authorization bypass vulnerability where WhatsApp group IDs can satisfy elevated sender allowlists

OpenClaw versions 2026.3.22 before 2026.6.6 contain an authorization bypass vulnerability where WhatsApp group IDs can satisfy elevated sender allowlists. Attackers with lower-trust access can perform actions requiring stronger authoriza…

Twilightopenclaw · openclawEPSS 0.40%via NVD
CVE-2026-35630High· 8.0
2mo ago

OpenClaw: QQBot native approval buttons did not enforce configured approver identity

OpenClaw: QQBot native approval buttons did not enforce configured approver identity

Twilightopenclaw · openclawEPSS 0.21%via GHSA
GHSA-c29c-2q9c-pc86High
2mo ago

OpenClaw: Slack allowFrom could bind to mutable display names

OpenClaw: Slack allowFrom could bind to mutable display names

Twilightopenclaw · openclawvia GHSA
GHSA-qjpc-qf9m-xwmrHigh· 8.8
2mo ago

OpenClaw: Trusted-proxy Control UI WebSocket accepted client-declared scopes before pairing

OpenClaw: Trusted-proxy Control UI WebSocket accepted client-declared scopes before pairing

Twilightopenclaw · openclawvia GHSA
GHSA-gp79-m99v-gjmhMedium
2mo ago

OpenClaw: Mattermost handlers could fall open when channel type was missing

OpenClaw: Mattermost handlers could fall open when channel type was missing

Sunlitopenclaw · openclawvia GHSA
GHSA-w4v6-g3wm-w36cCritical
2mo ago

OpenClaw: QQBot admin commands could skip DM-only and allowFrom policy

OpenClaw: QQBot admin commands could skip DM-only and allowFrom policy

Midnightopenclaw · openclawvia GHSA
GHSA-grc3-2j34-p6gmMedium
2mo ago

OpenClaw: message.action forwarding could send Gateway credentials to model-supplied loopback URLs

OpenClaw: message.action forwarding could send Gateway credentials to model-supplied loopback URLs

Sunlitopenclaw · openclawvia GHSA
GHSA-hcm3-8f6r-6xwgMedium· 6.5
2mo ago

OpenClaw: Browser debug/export routes could reuse already-open blocked tabs

OpenClaw: Browser debug/export routes could reuse already-open blocked tabs

Sunlitopenclaw · openclawvia GHSA
GHSA-xr4f-mjxj-w6w5High· 8.3
2mo ago

OpenClaw: Non-owner chat senders could issue device-pairing bootstrap codes

OpenClaw: Non-owner chat senders could issue device-pairing bootstrap codes

Twilightopenclaw · openclawvia GHSA
GHSA-77pv-3w4q-vrj5Medium
2mo ago

OpenClaw: QQBot pre-dispatch slash commands could skip allowFrom checks

OpenClaw: QQBot pre-dispatch slash commands could skip allowFrom checks

Sunlitopenclaw · openclawvia GHSA
CVE-2026-53819High· 8.8
2mo ago

OpenClaw: Workspace .env could override Homebrew executable selection for skill install flows

OpenClaw: Workspace .env could override Homebrew executable selection for skill install flows

Twilightopenclaw · openclawEPSS 0.30%via GHSA
CVE-2026-53813High· 7.8
2mo ago

OpenClaw: Fake package roots could influence memory-core artifact loading

OpenClaw: Fake package roots could influence memory-core artifact loading

Twilightopenclaw · openclawEPSS 0.11%via GHSA
CVE-2026-53809Medium· 3.8
2mo ago

OpenClaw: Embedded runner policy could be confused by provider aliases

OpenClaw: Embedded runner policy could be confused by provider aliases

Sunlitopenclaw · openclawEPSS 0.09%via GHSA
GHSA-6c4r-g249-wv3cMedium
2mo ago

OpenClaw: Sandboxed session spawn could expose the real workspace path to child prompts

OpenClaw: Sandboxed session spawn could expose the real workspace path to child prompts

Sunlitopenclaw · openclawvia GHSA
GHSA-3wqp-prf6-2m72Low· 3.1
2mo ago

OpenClaw: Feishu dynamic-agent bindings could miss configWrites enforcement

OpenClaw: Feishu dynamic-agent bindings could miss configWrites enforcement

Sunlitopenclaw · openclawvia GHSA
GHSA-275c-xpvc-jgfwMedium
2mo ago

OpenClaw: Slack and Zalo webhook secrets could remain active after secrets.reload

OpenClaw: Slack and Zalo webhook secrets could remain active after secrets.reload

Sunlitopenclaw · openclawvia GHSA
CVE-2026-53818Medium· 6.6
2mo ago

OpenClaw: MCP loopback could skip owner-only tool policy for non-owner callers

OpenClaw: MCP loopback could skip owner-only tool policy for non-owner callers

Sunlitopenclaw · openclawEPSS 0.10%via GHSA
CVE-2026-53806High· 8.8
2mo ago

OpenClaw: Combined POSIX shell options could confuse exec revalidation

OpenClaw: Combined POSIX shell options could confuse exec revalidation

Twilightopenclaw · openclawEPSS 0.42%via GHSA
CVE-2026-53816High· 7.2
2mo ago

OpenClaw: Paired nodes could forge exec lifecycle events without system.run provenance

OpenClaw: Paired nodes could forge exec lifecycle events without system.run provenance

Twilightopenclaw · openclawEPSS 0.34%via GHSA
GHSA-4m3v-q747-pc6hMedium
2mo ago

OpenClaw: Mattermost slash token revocation could lag until monitor refresh

OpenClaw: Mattermost slash token revocation could lag until monitor refresh

Sunlitopenclaw · openclawvia GHSA
CVE-2026-53811High· 8.8
2mo ago

OpenClaw: Matrix allowFrom could bind to mutable display names

OpenClaw: Matrix allowFrom could bind to mutable display names

Twilightopenclaw · openclawEPSS 0.31%via GHSA
GHSA-w5ww-7chg-mxcqHigh
2mo ago

OpenClaw: Telegram interactive callbacks could skip commands.allowFrom

OpenClaw: Telegram interactive callbacks could skip commands.allowFrom

Twilightopenclaw · openclawvia GHSA
GHSA-77q5-rr5v-x43qHigh
2mo ago

OpenClaw: Trusted retry endpoint checks could match hostname prefixes

OpenClaw: Trusted retry endpoint checks could match hostname prefixes

Twilightopenclaw · openclawvia GHSA
GHSA-j472-gf56-x589High
2mo ago

OpenClaw: PowerShell encoded-command aliases could miss exec allowlist checks

OpenClaw: PowerShell encoded-command aliases could miss exec allowlist checks

Twilightopenclaw · openclawvia GHSA
GHSA-p73f-w79w-jqr5High
2mo ago

OpenClaw: Native command authorization could skip owner-command enforcement

OpenClaw: Native command authorization could skip owner-command enforcement

Twilightopenclaw · openclawvia GHSA
CVE-2026-53815High· 6.5
2mo ago

OpenClaw: Message read actions could skip channel allowlist checks

OpenClaw: Message read actions could skip channel allowlist checks

Twilightopenclaw · openclawEPSS 0.21%via GHSA
openclaw vulnerabilities (CVEs) · VulnSea