OpenClaw has 222 CVEs on record. Disclosure cadence is accelerating: 127 in the last 90 days against 71 in the 90 before. The busiest recent month was September 2026 with 84. The median CVSS is 6.6 (medium), with 8 rated critical. None have a confirmed exploitation report. The dominant weakness classes are CWE-863 (51) and CWE-862 (33). Most affected products: OpenClaw (200), clawhub (5), @openclaw/feishu (2).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 6.6
- Publish → KEV
- —
- Last 90 days
- 127 prev 71
Weakness classes
Products
- OpenClaw 200
- clawhub 5
- @openclaw/feishu 2
- ClawScan 2
- discord 2
- slack 2
Worst active — by depth score
CVE-2026-33579Critical· 9.9OpenClaw before 2026.3.28 contains a privilege escalation vulnerability in the /pair approve command path that fails to forward caller scopes into the core approval check67CVE-2026-32917Critical· 9.8OpenClaw before 2026.3.13 contains a remote command injection vulnerability in the iMessage attachment staging flow that allows attackers to execute arbitrary commands on configured remote hosts55CVE-2026-22172Critical· 9.9OpenClaw < 2026.3.12 - Scope Elevation in WebSocket Shared-Auth Connections55CVE-2026-28474Critical· 9.8OpenClaw's Nextcloud Talk plugin versions prior to 2026.2.6 accept equality matching on the mutable actor.name display name field for allowlist validation, allowing attackers to bypass DM and room allowlists54CVE-2026-44112Critical· 9.6OpenClaw < 2026.4.22 - Symlink Swap Race Condition in OpenShell FS Bridge Writes53
openclaw vulnerabilities
CVEs affecting openclaw, newest first. Open any entry for full detail, references, and exploit status.
222 CVEsRSS
GHSA-grc3-2j34-p6gmMediumOpenClaw: message.action forwarding could send Gateway credentials to model-supplied loopback URLs
OpenClaw: message.action forwarding could send Gateway credentials to model-supplied loopback URLs
GHSA-hcm3-8f6r-6xwgMedium· 6.5OpenClaw: Browser debug/export routes could reuse already-open blocked tabs
OpenClaw: Browser debug/export routes could reuse already-open blocked tabs
GHSA-xr4f-mjxj-w6w5High· 8.3OpenClaw: Non-owner chat senders could issue device-pairing bootstrap codes
OpenClaw: Non-owner chat senders could issue device-pairing bootstrap codes
GHSA-77pv-3w4q-vrj5MediumOpenClaw: QQBot pre-dispatch slash commands could skip allowFrom checks
OpenClaw: QQBot pre-dispatch slash commands could skip allowFrom checks
CVE-2026-53819High· 8.8OpenClaw: Workspace .env could override Homebrew executable selection for skill install flows
OpenClaw: Workspace .env could override Homebrew executable selection for skill install flows
CVE-2026-53813High· 7.8OpenClaw: Fake package roots could influence memory-core artifact loading
OpenClaw: Fake package roots could influence memory-core artifact loading
CVE-2026-53809Medium· 3.8OpenClaw: Embedded runner policy could be confused by provider aliases
OpenClaw: Embedded runner policy could be confused by provider aliases
GHSA-6c4r-g249-wv3cMediumOpenClaw: Sandboxed session spawn could expose the real workspace path to child prompts
OpenClaw: Sandboxed session spawn could expose the real workspace path to child prompts
GHSA-3wqp-prf6-2m72Low· 3.1OpenClaw: Feishu dynamic-agent bindings could miss configWrites enforcement
OpenClaw: Feishu dynamic-agent bindings could miss configWrites enforcement
GHSA-275c-xpvc-jgfwMediumOpenClaw: Slack and Zalo webhook secrets could remain active after secrets.reload
OpenClaw: Slack and Zalo webhook secrets could remain active after secrets.reload
CVE-2026-53818Medium· 6.6OpenClaw: MCP loopback could skip owner-only tool policy for non-owner callers
OpenClaw: MCP loopback could skip owner-only tool policy for non-owner callers
CVE-2026-53806High· 8.8OpenClaw: Combined POSIX shell options could confuse exec revalidation
OpenClaw: Combined POSIX shell options could confuse exec revalidation
CVE-2026-53816High· 7.2OpenClaw: Paired nodes could forge exec lifecycle events without system.run provenance
OpenClaw: Paired nodes could forge exec lifecycle events without system.run provenance
GHSA-4m3v-q747-pc6hMediumOpenClaw: Mattermost slash token revocation could lag until monitor refresh
OpenClaw: Mattermost slash token revocation could lag until monitor refresh
CVE-2026-53811High· 8.8OpenClaw: Matrix allowFrom could bind to mutable display names
OpenClaw: Matrix allowFrom could bind to mutable display names
GHSA-w5ww-7chg-mxcqHighOpenClaw: Telegram interactive callbacks could skip commands.allowFrom
OpenClaw: Telegram interactive callbacks could skip commands.allowFrom
GHSA-77q5-rr5v-x43qHighOpenClaw: Trusted retry endpoint checks could match hostname prefixes
OpenClaw: Trusted retry endpoint checks could match hostname prefixes
GHSA-j472-gf56-x589HighOpenClaw: PowerShell encoded-command aliases could miss exec allowlist checks
OpenClaw: PowerShell encoded-command aliases could miss exec allowlist checks
GHSA-p73f-w79w-jqr5HighOpenClaw: Native command authorization could skip owner-command enforcement
OpenClaw: Native command authorization could skip owner-command enforcement
CVE-2026-53815High· 6.5OpenClaw: Message read actions could skip channel allowlist checks
OpenClaw: Message read actions could skip channel allowlist checks
GHSA-xww8-gqvh-92x9High· 8.0OpenClaw: Exec approval display truncation could hide the command being approved
OpenClaw: Exec approval display truncation could hide the command being approved
GHSA-qh2f-99mv-mrcfMediumOpenClaw: Bundle MCP loopback could miss its exec denylist on session spawn
OpenClaw: Bundle MCP loopback could miss its exec denylist on session spawn
GHSA-2j8v-hwgc-x698HighOpenClaw: Shell wrapper argv could change between approval and execution
OpenClaw: Shell wrapper argv could change between approval and execution
CVE-2026-53812Medium· 7.7OpenClaw's browser act interactions could bypass private-network navigation checks
OpenClaw's browser act interactions could bypass private-network navigation checks
CVE-2026-53810High· 8.8OpenClaw's marketplace runtime extension metadata could point at unscanned payloads
OpenClaw's marketplace runtime extension metadata could point at unscanned payloads
GHSA-rggc-m335-3wvjHighOpenClaw: Same-host trusted-proxy deployments could accept local forged identity headers
OpenClaw: Same-host trusted-proxy deployments could accept local forged identity headers
CVE-2026-53817High· 8.0OpenClaw: Control UI locality spoofing could mint a durable admin device token
OpenClaw: Control UI locality spoofing could mint a durable admin device token
CVE-2026-53814High· 8.4OpenClaw: Hook-triggered CLI runs could receive owner MCP tool authority
OpenClaw: Hook-triggered CLI runs could receive owner MCP tool authority
GHSA-mgq6-vr84-7m2jHigh· 8.0OpenClaw: QQBot native approval buttons did not enforce configured approver identity
OpenClaw: QQBot native approval buttons did not enforce configured approver identity
GHSA-mhq8-78pj-5j79High· 7.1OpenClaw's POSIX node system.run safe-bin allowlist could be widened by shell expansion
OpenClaw's POSIX node system.run safe-bin allowlist could be widened by shell expansion