openclaw has 128 CVEs on record. Cadence is steady at roughly 47 per quarter. The busiest recent month was June 2026 with 55. The median CVSS is 7.1 (high), with 6 rated critical. None have a confirmed exploitation report. The dominant weakness classes are CWE-863 (30) and CWE-862 (15). Most affected products: openclaw (123), @openclaw/feishu (2), ClawScan (2).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.1
- Publish → KEV
- —
- Last 90 days
- 47 prev 78
Weakness classes
Products
- openclaw 123
- @openclaw/feishu 2
- ClawScan 2
- github.com/openclaw/crabbox 1
Worst active — by depth score
CVE-2026-33579Critical· 9.9OpenClaw before 2026.3.28 contains a privilege escalation vulnerability in the /pair approve command path that fails to forward caller scopes into the core approval check67CVE-2026-32917Critical· 9.8OpenClaw before 2026.3.13 contains a remote command injection vulnerability in the iMessage attachment staging flow that allows attackers to execute arbitrary commands on configured remote hosts54CVE-2026-28474Critical· 9.8OpenClaw's Nextcloud Talk plugin versions prior to 2026.2.6 accept equality matching on the mutable actor.name display name field for allowlist validation, allowing attackers to bypass DM and room allowlists54GHSA-w4v6-g3wm-w36cCriticalOpenClaw: QQBot admin commands could skip DM-only and allowFrom policy52CVE-2026-32916Critical· 9.4OpenClaw versions 2026.3.7 before 2026.3.11 contain an authorization bypass vulnerability where plugin subagent routes execute gateway methods through a synthetic operator client with broad administrative scopes52
openclaw vulnerabilities
CVEs affecting openclaw, newest first. Open any entry for full detail, references, and exploit status.
128 CVEsRSS
GHSA-xww8-gqvh-92x9High· 8.0OpenClaw: Exec approval display truncation could hide the command being approved
OpenClaw: Exec approval display truncation could hide the command being approved
GHSA-qh2f-99mv-mrcfMediumOpenClaw: Bundle MCP loopback could miss its exec denylist on session spawn
OpenClaw: Bundle MCP loopback could miss its exec denylist on session spawn
GHSA-2j8v-hwgc-x698HighOpenClaw: Shell wrapper argv could change between approval and execution
OpenClaw: Shell wrapper argv could change between approval and execution
CVE-2026-53812Medium· 7.7OpenClaw's browser act interactions could bypass private-network navigation checks
OpenClaw's browser act interactions could bypass private-network navigation checks
CVE-2026-53810High· 8.8OpenClaw's marketplace runtime extension metadata could point at unscanned payloads
OpenClaw's marketplace runtime extension metadata could point at unscanned payloads
GHSA-rggc-m335-3wvjHighOpenClaw: Same-host trusted-proxy deployments could accept local forged identity headers
OpenClaw: Same-host trusted-proxy deployments could accept local forged identity headers
CVE-2026-53817High· 8.0OpenClaw: Control UI locality spoofing could mint a durable admin device token
OpenClaw: Control UI locality spoofing could mint a durable admin device token
CVE-2026-53814High· 8.4OpenClaw: Hook-triggered CLI runs could receive owner MCP tool authority
OpenClaw: Hook-triggered CLI runs could receive owner MCP tool authority
GHSA-mgq6-vr84-7m2jHigh· 8.0OpenClaw: QQBot native approval buttons did not enforce configured approver identity
OpenClaw: QQBot native approval buttons did not enforce configured approver identity
GHSA-mhq8-78pj-5j79High· 7.1OpenClaw's POSIX node system.run safe-bin allowlist could be widened by shell expansion
OpenClaw's POSIX node system.run safe-bin allowlist could be widened by shell expansion
GHSA-hw9r-h9mr-4jffHigh· 8.8OpenClaw: Scoped chat.send route inheritance could bypass admin command scope gates
OpenClaw: Scoped chat.send route inheritance could bypass admin command scope gates
GHSA-p2fh-f5fc-44hrMedium· 6.5OpenClaw: memory-wiki ingest could read local files with operator.write scope
OpenClaw: memory-wiki ingest could read local files with operator.write scope
GHSA-wv26-j37q-2g7pMediumOpenClaw's Slack plugin approvals used the exec approver gate for plugin actions
OpenClaw's Slack plugin approvals used the exec approver gate for plugin actions
GHSA-83w9-h5wv-j9xmHighOpenClaw: Node pairing reconnection could confuse approval scope state
OpenClaw: Node pairing reconnection could confuse approval scope state
GHSA-jvm4-4j77-39p6HighOpenClaw: QQBot streaming command could mutate config without explicit allowFrom
OpenClaw: QQBot streaming command could mutate config without explicit allowFrom
GHSA-cqwv-9qjx-vxw2Medium· 5.3OpenClaw: Skill Workshop apply flow could override pending approval
OpenClaw: Skill Workshop apply flow could override pending approval
GHSA-9c3v-684m-579cMedium· 6.5OpenClaw MCP SSE redirects could forward Authorization headers
OpenClaw MCP SSE redirects could forward Authorization headers
CVE-2026-53864High· 8.1OpenClaw: Host environment sanitizer missed two Node.js control variables
OpenClaw: Host environment sanitizer missed two Node.js control variables
CVE-2026-53843High· 8.8OpenClaw: Pairing-scoped device session could restore revoked node token authority
OpenClaw: Pairing-scoped device session could restore revoked node token authority
CVE-2026-53866High· 8.1OpenClaw: Shell inline-command parsing could miss an allowlist check
OpenClaw: Shell inline-command parsing could miss an allowlist check
CVE-2026-53842High· 7.1OpenClaw: Workspace .env CLOUDSDK_PYTHON could influence Gmail setup gcloud execution
OpenClaw: Workspace .env CLOUDSDK_PYTHON could influence Gmail setup gcloud execution
CVE-2026-53863MediumOpenClaw: Tool group policy callers could accept unvalidated group IDs
OpenClaw: Tool group policy callers could accept unvalidated group IDs
CVE-2026-53861Medium· 6.6OpenClaw: macOS Swift exec allowlist missed combined POSIX inline flags
OpenClaw: macOS Swift exec allowlist missed combined POSIX inline flags
CVE-2026-53848Low· 4.3OpenClaw: Exec allowlist could miss side effects from transparent command wrappers
OpenClaw: Exec allowlist could miss side effects from transparent command wrappers
CVE-2026-53859Medium· 6.5OpenClaw: Hostname checks could treat trailing-dot hosts inconsistently
OpenClaw: Hostname checks could treat trailing-dot hosts inconsistently
CVE-2026-53855High· 8.1OpenClaw: Shell positional parameters could weaken strict inline-eval checks
OpenClaw: Shell positional parameters could weaken strict inline-eval checks
CVE-2026-53862Low· 4.2OpenClaw: Bootstrap token replay could widen pending pairing scopes
OpenClaw: Bootstrap token replay could widen pending pairing scopes
CVE-2026-53851Medium· 5.3OpenClaw: Slack reaction events could ignore reaction notification settings
OpenClaw: Slack reaction events could ignore reaction notification settings
CVE-2026-53841Medium· 6.1OpenClaw: Exported session HTML could keep unsafe markdown links
OpenClaw: Exported session HTML could keep unsafe markdown links
CVE-2026-53847MediumOpenClaw: Active Memory write scope could mutate global config
OpenClaw: Active Memory write scope could mutate global config