VulnSea

openclaw has 128 CVEs on record. Cadence is steady at roughly 47 per quarter. The busiest recent month was June 2026 with 55. The median CVSS is 7.1 (high), with 6 rated critical. None have a confirmed exploitation report. The dominant weakness classes are CWE-863 (30) and CWE-862 (15). Most affected products: openclaw (123), @openclaw/feishu (2), ClawScan (2).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
7.1
Publish → KEV
Last 90 days
47 prev 78

Products

  • openclaw 123
  • @openclaw/feishu 2
  • ClawScan 2
  • github.com/openclaw/crabbox 1
128
Total CVEs
6
Critical
0
CISA KEV
0
Exploited

openclaw vulnerabilities

CVEs affecting openclaw, newest first. Open any entry for full detail, references, and exploit status.

128 CVEsRSS

GHSA-xww8-gqvh-92x9High· 8.0
2mo ago

OpenClaw: Exec approval display truncation could hide the command being approved

OpenClaw: Exec approval display truncation could hide the command being approved

Twilightopenclaw · openclawvia GHSA
GHSA-qh2f-99mv-mrcfMedium
2mo ago

OpenClaw: Bundle MCP loopback could miss its exec denylist on session spawn

OpenClaw: Bundle MCP loopback could miss its exec denylist on session spawn

Sunlitopenclaw · openclawvia GHSA
GHSA-2j8v-hwgc-x698High
2mo ago

OpenClaw: Shell wrapper argv could change between approval and execution

OpenClaw: Shell wrapper argv could change between approval and execution

TwilightOpenclaw · Openclawvia GHSA
CVE-2026-53812Medium· 7.7
2mo ago

OpenClaw's browser act interactions could bypass private-network navigation checks

OpenClaw's browser act interactions could bypass private-network navigation checks

Sunlitopenclaw · openclawEPSS 0.25%via GHSA
CVE-2026-53810High· 8.8
2mo ago

OpenClaw's marketplace runtime extension metadata could point at unscanned payloads

OpenClaw's marketplace runtime extension metadata could point at unscanned payloads

Twilightopenclaw · openclawEPSS 0.42%via GHSA
GHSA-rggc-m335-3wvjHigh
2mo ago

OpenClaw: Same-host trusted-proxy deployments could accept local forged identity headers

OpenClaw: Same-host trusted-proxy deployments could accept local forged identity headers

Twilightopenclaw · openclawvia GHSA
CVE-2026-53817High· 8.0
2mo ago

OpenClaw: Control UI locality spoofing could mint a durable admin device token

OpenClaw: Control UI locality spoofing could mint a durable admin device token

Twilightopenclaw · openclawEPSS 0.31%via GHSA
CVE-2026-53814High· 8.4
2mo ago

OpenClaw: Hook-triggered CLI runs could receive owner MCP tool authority

OpenClaw: Hook-triggered CLI runs could receive owner MCP tool authority

Twilightopenclaw · openclawEPSS 0.28%via GHSA
GHSA-mgq6-vr84-7m2jHigh· 8.0
2mo ago

OpenClaw: QQBot native approval buttons did not enforce configured approver identity

OpenClaw: QQBot native approval buttons did not enforce configured approver identity

Twilightopenclaw · openclawvia GHSA
GHSA-mhq8-78pj-5j79High· 7.1
2mo ago

OpenClaw's POSIX node system.run safe-bin allowlist could be widened by shell expansion

OpenClaw's POSIX node system.run safe-bin allowlist could be widened by shell expansion

Twilightopenclaw · openclawvia GHSA
GHSA-hw9r-h9mr-4jffHigh· 8.8
2mo ago

OpenClaw: Scoped chat.send route inheritance could bypass admin command scope gates

OpenClaw: Scoped chat.send route inheritance could bypass admin command scope gates

Twilightopenclaw · openclawvia GHSA
GHSA-p2fh-f5fc-44hrMedium· 6.5
2mo ago

OpenClaw: memory-wiki ingest could read local files with operator.write scope

OpenClaw: memory-wiki ingest could read local files with operator.write scope

Sunlitopenclaw · openclawvia GHSA
GHSA-wv26-j37q-2g7pMedium
2mo ago

OpenClaw's Slack plugin approvals used the exec approver gate for plugin actions

OpenClaw's Slack plugin approvals used the exec approver gate for plugin actions

Sunlitopenclaw · openclawvia GHSA
GHSA-83w9-h5wv-j9xmHigh
2mo ago

OpenClaw: Node pairing reconnection could confuse approval scope state

OpenClaw: Node pairing reconnection could confuse approval scope state

Twilightopenclaw · openclawvia GHSA
GHSA-jvm4-4j77-39p6High
2mo ago

OpenClaw: QQBot streaming command could mutate config without explicit allowFrom

OpenClaw: QQBot streaming command could mutate config without explicit allowFrom

Twilightopenclaw · openclawvia GHSA
GHSA-cqwv-9qjx-vxw2Medium· 5.3
2mo ago

OpenClaw: Skill Workshop apply flow could override pending approval

OpenClaw: Skill Workshop apply flow could override pending approval

Sunlitopenclaw · openclawvia GHSA
GHSA-9c3v-684m-579cMedium· 6.5
2mo ago

OpenClaw MCP SSE redirects could forward Authorization headers

OpenClaw MCP SSE redirects could forward Authorization headers

Sunlitopenclaw · openclawvia GHSA
CVE-2026-53864High· 8.1
3mo ago

OpenClaw: Host environment sanitizer missed two Node.js control variables

OpenClaw: Host environment sanitizer missed two Node.js control variables

Twilightopenclaw · openclawEPSS 0.25%via GHSA
CVE-2026-53843High· 8.8
3mo ago

OpenClaw: Pairing-scoped device session could restore revoked node token authority

OpenClaw: Pairing-scoped device session could restore revoked node token authority

Twilightopenclaw · openclawEPSS 0.27%via GHSA
CVE-2026-53866High· 8.1
3mo ago

OpenClaw: Shell inline-command parsing could miss an allowlist check

OpenClaw: Shell inline-command parsing could miss an allowlist check

Twilightopenclaw · openclawEPSS 0.27%via GHSA
CVE-2026-53842High· 7.1
3mo ago

OpenClaw: Workspace .env CLOUDSDK_PYTHON could influence Gmail setup gcloud execution

OpenClaw: Workspace .env CLOUDSDK_PYTHON could influence Gmail setup gcloud execution

Twilightopenclaw · openclawEPSS 0.13%via GHSA
CVE-2026-53863Medium
3mo ago

OpenClaw: Tool group policy callers could accept unvalidated group IDs

OpenClaw: Tool group policy callers could accept unvalidated group IDs

Sunlitopenclaw · openclawEPSS 0.17%via GHSA
CVE-2026-53861Medium· 6.6
3mo ago

OpenClaw: macOS Swift exec allowlist missed combined POSIX inline flags

OpenClaw: macOS Swift exec allowlist missed combined POSIX inline flags

Sunlitopenclaw · openclawEPSS 0.25%via GHSA
CVE-2026-53848Low· 4.3
3mo ago

OpenClaw: Exec allowlist could miss side effects from transparent command wrappers

OpenClaw: Exec allowlist could miss side effects from transparent command wrappers

Sunlitopenclaw · openclawEPSS 0.18%via GHSA
CVE-2026-53859Medium· 6.5
3mo ago

OpenClaw: Hostname checks could treat trailing-dot hosts inconsistently

OpenClaw: Hostname checks could treat trailing-dot hosts inconsistently

Sunlitopenclaw · openclawEPSS 0.21%via GHSA
CVE-2026-53855High· 8.1
3mo ago

OpenClaw: Shell positional parameters could weaken strict inline-eval checks

OpenClaw: Shell positional parameters could weaken strict inline-eval checks

Twilightopenclaw · openclawEPSS 0.26%via GHSA
CVE-2026-53862Low· 4.2
3mo ago

OpenClaw: Bootstrap token replay could widen pending pairing scopes

OpenClaw: Bootstrap token replay could widen pending pairing scopes

Sunlitopenclaw · openclawEPSS 0.09%via GHSA
CVE-2026-53851Medium· 5.3
3mo ago

OpenClaw: Slack reaction events could ignore reaction notification settings

OpenClaw: Slack reaction events could ignore reaction notification settings

Sunlitopenclaw · openclawEPSS 0.19%via GHSA
CVE-2026-53841Medium· 6.1
3mo ago

OpenClaw: Exported session HTML could keep unsafe markdown links

OpenClaw: Exported session HTML could keep unsafe markdown links

Sunlitopenclaw · openclawEPSS 0.19%via GHSA
CVE-2026-53847Medium
3mo ago

OpenClaw: Active Memory write scope could mutate global config

OpenClaw: Active Memory write scope could mutate global config

Sunlitopenclaw · openclawEPSS 0.18%via GHSA
openclaw vulnerabilities (CVEs) — page 2 · VulnSea