openclaw has 128 CVEs on record. Cadence is steady at roughly 47 per quarter. The busiest recent month was June 2026 with 55. The median CVSS is 7.1 (high), with 6 rated critical. None have a confirmed exploitation report. The dominant weakness classes are CWE-863 (30) and CWE-862 (15). Most affected products: openclaw (123), @openclaw/feishu (2), ClawScan (2).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.1
- Publish → KEV
- —
- Last 90 days
- 47 prev 78
Weakness classes
Products
- openclaw 123
- @openclaw/feishu 2
- ClawScan 2
- github.com/openclaw/crabbox 1
Worst active — by depth score
CVE-2026-33579Critical· 9.9OpenClaw before 2026.3.28 contains a privilege escalation vulnerability in the /pair approve command path that fails to forward caller scopes into the core approval check67CVE-2026-32917Critical· 9.8OpenClaw before 2026.3.13 contains a remote command injection vulnerability in the iMessage attachment staging flow that allows attackers to execute arbitrary commands on configured remote hosts54CVE-2026-28474Critical· 9.8OpenClaw's Nextcloud Talk plugin versions prior to 2026.2.6 accept equality matching on the mutable actor.name display name field for allowlist validation, allowing attackers to bypass DM and room allowlists54GHSA-w4v6-g3wm-w36cCriticalOpenClaw: QQBot admin commands could skip DM-only and allowFrom policy52CVE-2026-32916Critical· 9.4OpenClaw versions 2026.3.7 before 2026.3.11 contain an authorization bypass vulnerability where plugin subagent routes execute gateway methods through a synthetic operator client with broad administrative scopes52
openclaw vulnerabilities
CVEs affecting openclaw, newest first. Open any entry for full detail, references, and exploit status.
128 CVEsRSS
CVE-2026-53845Low· 4.3OpenClaw: Skill-command dispatch could skip before-tool-call hooks
OpenClaw: Skill-command dispatch could skip before-tool-call hooks
CVE-2026-53857High· 8.1OpenClaw: Zalo allowFrom could bind to mutable display names
OpenClaw: Zalo allowFrom could bind to mutable display names
CVE-2026-53856Medium· 5.5OpenClaw: Config recovery could restore openclaw.json with broad file permissions
OpenClaw: Config recovery could restore openclaw.json with broad file permissions
CVE-2026-53844Medium· 6.5OpenClaw: memory-wiki shared search could miss session visibility checks
OpenClaw: memory-wiki shared search could miss session visibility checks
CVE-2026-53860Low· 4.2OpenClaw: BlueBubbles sender policy could match mutable conversation identifiers
OpenClaw: BlueBubbles sender policy could match mutable conversation identifiers
CVE-2026-53853High· 7.1OpenClaw: Linux and macOS exec allowlists skipped configured argument patterns
OpenClaw: Linux and macOS exec allowlists skipped configured argument patterns
CVE-2026-53846High· 7.1OpenClaw: Workspace .env npm_execpath could influence bundled runtime dependency install
OpenClaw: Workspace .env npm_execpath could influence bundled runtime dependency install
CVE-2026-53850MediumOpenClaw: Focus command could miss controlScope enforcement
OpenClaw: Focus command could miss controlScope enforcement
CVE-2026-53858High· 7.1OpenClaw: Workspace .env STATE_DIRECTORY could influence bundled runtime dependency roots
OpenClaw: Workspace .env STATE_DIRECTORY could influence bundled runtime dependency roots
CVE-2026-53849High· 8.1OpenClaw: Discord allowFrom could bind to mutable display names
OpenClaw: Discord allowFrom could bind to mutable display names
CVE-2026-53865High· 7.1OpenClaw: Workspace-derived service PATH could influence trash command selection
OpenClaw: Workspace-derived service PATH could influence trash command selection
CVE-2026-53852Low· 5.4OpenClaw: Empty-scope device re-pairing could confuse caller scope containment
OpenClaw: Empty-scope device re-pairing could confuse caller scope containment
CVE-2026-53854MediumOpenClaw: Internal/webchat command auth could inherit ownerAllowFrom wildcard state
OpenClaw: Internal/webchat command auth could inherit ownerAllowFrom wildcard state
CVE-2026-53840High· 7.1OpenClaw: MCP Streamable HTTP redirects could forward configured custom headers to another origin
OpenClaw: MCP Streamable HTTP redirects could forward configured custom headers to another origin
GHSA-6xcg-6q43-rj2vLow· 6.1Duplicate Advisory: Exported session HTML could keep unsafe markdown links
Duplicate Advisory: Exported session HTML could keep unsafe markdown links
GHSA-6jm4-83g2-35gvMedium· 6.5Duplicate Advisory: memory-wiki shared search could miss session visibility checks
Duplicate Advisory: memory-wiki shared search could miss session visibility checks
GHSA-x7cf-6gp3-q5f8Medium· 7.1Duplicate Advisory: MCP Streamable HTTP redirects could forward configured custom headers to another origin
Duplicate Advisory: MCP Streamable HTTP redirects could forward configured custom headers to another origin
GHSA-wrmq-9fc4-gwwjHigh· 8.8Duplicate Advisory: Pairing-scoped device session could restore revoked node token authority
Duplicate Advisory: Pairing-scoped device session could restore revoked node token authority
GHSA-9fr2-p65v-gqxqHigh· 7.1Duplicate Advisory: Workspace .env CLOUDSDK_PYTHON could influence Gmail setup gcloud execution
Duplicate Advisory: Workspace .env CLOUDSDK_PYTHON could influence Gmail setup gcloud execution
GHSA-58wc-8wrv-xp9jMedium· 5.4Duplicate Advisory: Active Memory write scope could mutate global config
Duplicate Advisory: Active Memory write scope could mutate global config
GHSA-wrr6-p5r6-474mLow· 4.3Duplicate Advisory: Exec allowlist could miss side effects from transparent command wrappers
Duplicate Advisory: Exec allowlist could miss side effects from transparent command wrappers
GHSA-gw2c-6hcg-5g52Medium· 5.5Duplicate Advisory: Focus command could miss controlScope enforcement
Duplicate Advisory: Focus command could miss controlScope enforcement
GHSA-p44v-rx83-vjp4High· 8.1Duplicate Advisory: Discord allowFrom could bind to mutable display names
Duplicate Advisory: Discord allowFrom could bind to mutable display names
GHSA-c8w7-9w9h-x69qMedium· 5.3Duplicate Advisory: Slack reaction events could ignore reaction notification settings
Duplicate Advisory: Slack reaction events could ignore reaction notification settings
GHSA-r7vv-6763-m739Low· 4.3Duplicate Advisory: Skill-command dispatch could skip before-tool-call hooks
Duplicate Advisory: Skill-command dispatch could skip before-tool-call hooks
GHSA-qp5j-jr73-m2pwHigh· 7.1Duplicate Advisory: Workspace .env npm_execpath could influence bundled runtime dependency install
Duplicate Advisory: Workspace .env npm_execpath could influence bundled runtime dependency install
GHSA-27pq-2ph8-8x25High· 8.1Duplicate Advisory: Shell positional parameters could weaken strict inline-eval checks
Duplicate Advisory: Shell positional parameters could weaken strict inline-eval checks
GHSA-w7m7-3xcf-mp48High· 8.1Duplicate Advisory: Zalo allowFrom could bind to mutable display names
Duplicate Advisory: Zalo allowFrom could bind to mutable display names
GHSA-vqj9-vhg4-27mgMedium· 5.5Duplicate Advisory: Config recovery could restore openclaw.json with broad file permissions
Duplicate Advisory: Config recovery could restore openclaw.json with broad file permissions
GHSA-4qgr-57jq-93vhHigh· 7.1Duplicate Advisory: Workspace .env STATE_DIRECTORY could influence bundled runtime dependency roots
Duplicate Advisory: Workspace .env STATE_DIRECTORY could influence bundled runtime dependency roots