openclaw has 222 CVEs on record. Disclosure cadence is accelerating: 127 in the last 90 days against 71 in the 90 before. The busiest recent month was September 2026 with 84. The median CVSS is 6.6 (medium), with 8 rated critical. None have a confirmed exploitation report. The dominant weakness classes are CWE-863 (51) and CWE-862 (33). Most affected products: OpenClaw (200), clawhub (5), @openclaw/feishu (2).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 6.6
- Publish → KEV
- —
- Last 90 days
- 127 prev 71
Weakness classes
Products
- OpenClaw 200
- clawhub 5
- @openclaw/feishu 2
- ClawScan 2
- discord 2
- slack 2
Worst active — by depth score
CVE-2026-33579Critical· 9.9OpenClaw before 2026.3.28 contains a privilege escalation vulnerability in the /pair approve command path that fails to forward caller scopes into the core approval check67CVE-2026-32917Critical· 9.8OpenClaw before 2026.3.13 contains a remote command injection vulnerability in the iMessage attachment staging flow that allows attackers to execute arbitrary commands on configured remote hosts55CVE-2026-22172Critical· 9.9OpenClaw < 2026.3.12 - Scope Elevation in WebSocket Shared-Auth Connections55CVE-2026-28474Critical· 9.8OpenClaw's Nextcloud Talk plugin versions prior to 2026.2.6 accept equality matching on the mutable actor.name display name field for allowlist validation, allowing attackers to bypass DM and room allowlists54CVE-2026-44112Critical· 9.6OpenClaw < 2026.4.22 - Symlink Swap Race Condition in OpenShell FS Bridge Writes53
openclaw vulnerabilities
CVEs affecting openclaw, newest first. Open any entry for full detail, references, and exploit status.
222 CVEsRSS
GHSA-hw9r-h9mr-4jffHigh· 8.8OpenClaw: Scoped chat.send route inheritance could bypass admin command scope gates
OpenClaw: Scoped chat.send route inheritance could bypass admin command scope gates
GHSA-p2fh-f5fc-44hrMedium· 6.5OpenClaw: memory-wiki ingest could read local files with operator.write scope
OpenClaw: memory-wiki ingest could read local files with operator.write scope
GHSA-wv26-j37q-2g7pMediumOpenClaw's Slack plugin approvals used the exec approver gate for plugin actions
OpenClaw's Slack plugin approvals used the exec approver gate for plugin actions
GHSA-83w9-h5wv-j9xmHighOpenClaw: Node pairing reconnection could confuse approval scope state
OpenClaw: Node pairing reconnection could confuse approval scope state
GHSA-jvm4-4j77-39p6HighOpenClaw: QQBot streaming command could mutate config without explicit allowFrom
OpenClaw: QQBot streaming command could mutate config without explicit allowFrom
GHSA-cqwv-9qjx-vxw2Medium· 5.3OpenClaw: Skill Workshop apply flow could override pending approval
OpenClaw: Skill Workshop apply flow could override pending approval
GHSA-9c3v-684m-579cMedium· 6.5OpenClaw MCP SSE redirects could forward Authorization headers
OpenClaw MCP SSE redirects could forward Authorization headers
CVE-2026-53864High· 8.1OpenClaw: Host environment sanitizer missed two Node.js control variables
OpenClaw: Host environment sanitizer missed two Node.js control variables
CVE-2026-53843High· 8.8OpenClaw: Pairing-scoped device session could restore revoked node token authority
OpenClaw: Pairing-scoped device session could restore revoked node token authority
CVE-2026-53866High· 8.1OpenClaw: Shell inline-command parsing could miss an allowlist check
OpenClaw: Shell inline-command parsing could miss an allowlist check
CVE-2026-53842High· 7.1OpenClaw: Workspace .env CLOUDSDK_PYTHON could influence Gmail setup gcloud execution
OpenClaw: Workspace .env CLOUDSDK_PYTHON could influence Gmail setup gcloud execution
CVE-2026-53863MediumOpenClaw: Tool group policy callers could accept unvalidated group IDs
OpenClaw: Tool group policy callers could accept unvalidated group IDs
CVE-2026-53861Medium· 6.6OpenClaw: macOS Swift exec allowlist missed combined POSIX inline flags
OpenClaw: macOS Swift exec allowlist missed combined POSIX inline flags
CVE-2026-53848Low· 4.3OpenClaw: Exec allowlist could miss side effects from transparent command wrappers
OpenClaw: Exec allowlist could miss side effects from transparent command wrappers
CVE-2026-53859Medium· 6.5OpenClaw: Hostname checks could treat trailing-dot hosts inconsistently
OpenClaw: Hostname checks could treat trailing-dot hosts inconsistently
CVE-2026-53855High· 8.1OpenClaw: Shell positional parameters could weaken strict inline-eval checks
OpenClaw: Shell positional parameters could weaken strict inline-eval checks
CVE-2026-53862Low· 4.2OpenClaw: Bootstrap token replay could widen pending pairing scopes
OpenClaw: Bootstrap token replay could widen pending pairing scopes
CVE-2026-53851Medium· 5.3OpenClaw: Slack reaction events could ignore reaction notification settings
OpenClaw: Slack reaction events could ignore reaction notification settings
CVE-2026-53841Medium· 6.1OpenClaw: Exported session HTML could keep unsafe markdown links
OpenClaw: Exported session HTML could keep unsafe markdown links
CVE-2026-53847MediumOpenClaw: Active Memory write scope could mutate global config
OpenClaw: Active Memory write scope could mutate global config
CVE-2026-53845Low· 4.3OpenClaw: Skill-command dispatch could skip before-tool-call hooks
OpenClaw: Skill-command dispatch could skip before-tool-call hooks
CVE-2026-53857High· 8.1OpenClaw: Zalo allowFrom could bind to mutable display names
OpenClaw: Zalo allowFrom could bind to mutable display names
CVE-2026-53856Medium· 5.5OpenClaw: Config recovery could restore openclaw.json with broad file permissions
OpenClaw: Config recovery could restore openclaw.json with broad file permissions
CVE-2026-53844Medium· 6.5OpenClaw: memory-wiki shared search could miss session visibility checks
OpenClaw: memory-wiki shared search could miss session visibility checks
CVE-2026-53860Low· 4.2OpenClaw: BlueBubbles sender policy could match mutable conversation identifiers
OpenClaw: BlueBubbles sender policy could match mutable conversation identifiers
CVE-2026-53853High· 7.1OpenClaw: Linux and macOS exec allowlists skipped configured argument patterns
OpenClaw: Linux and macOS exec allowlists skipped configured argument patterns
CVE-2026-53846High· 7.1OpenClaw: Workspace .env npm_execpath could influence bundled runtime dependency install
OpenClaw: Workspace .env npm_execpath could influence bundled runtime dependency install
CVE-2026-53850MediumOpenClaw: Focus command could miss controlScope enforcement
OpenClaw: Focus command could miss controlScope enforcement
CVE-2026-53858High· 7.1OpenClaw: Workspace .env STATE_DIRECTORY could influence bundled runtime dependency roots
OpenClaw: Workspace .env STATE_DIRECTORY could influence bundled runtime dependency roots
CVE-2026-53849High· 8.1OpenClaw: Discord allowFrom could bind to mutable display names
OpenClaw: Discord allowFrom could bind to mutable display names