VulnSea

openclaw has 222 CVEs on record. Disclosure cadence is accelerating: 127 in the last 90 days against 71 in the 90 before. The busiest recent month was September 2026 with 84. The median CVSS is 6.6 (medium), with 8 rated critical. None have a confirmed exploitation report. The dominant weakness classes are CWE-863 (51) and CWE-862 (33). Most affected products: OpenClaw (200), clawhub (5), @openclaw/feishu (2).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
6.6
Publish → KEV
—
Last 90 days
127 prev 71

Products

  • OpenClaw 200
  • clawhub 5
  • @openclaw/feishu 2
  • ClawScan 2
  • discord 2
  • slack 2
222
Total CVEs
8
Critical
0
CISA KEV
0
Exploited

openclaw vulnerabilities

CVEs affecting openclaw, newest first. Open any entry for full detail, references, and exploit status.

222 CVEsRSS

GHSA-2w22-3f6x-3hf4High· 7.1
3mo ago

Duplicate Advisory: Workspace-derived service PATH could influence trash command selection

Duplicate Advisory: Workspace-derived service PATH could influence trash command selection

▾ Twilightopenclaw · openclawvia GHSA
CVE-2026-53822High· 8.8
3mo ago

OpenClaw < 2026.5.18 - Command Argument Modification via Shell Wrapper Between Approval and Execution

OpenClaw before 2026.5.18 contains a command injection vulnerability where shell wrapper argv could change between approval and execution. Attackers can rebuild command arguments after allowlist approval to execute unapproved command sha…

▾ TwilightOpenClaw · OpenClawEPSS 2.0%via CVEORG
CVE-2026-32905High· 8.3
4mo ago

OpenClaw < 2026.5.4 - Unauthorized Device-Pairing Bootstrap Code Issuance via Chat Command

OpenClaw before 2026.5.4 contains an authorization bypass vulnerability in the bundled device-pair plugin that allows non-owner authorized chat senders to issue device-pairing bootstrap codes without proper scope validation. Attackers wi…

▾ TwilightOpenClaw · OpenClawEPSS 0.40%via CVEORG
CVE-2026-34507Medium· 5.4
4mo ago

OpenClaw < 2026.4.29 - Policy Bypass in QQBot Admin Commands via DM-only and allowFrom Checks

OpenClaw before 2026.4.29 contains a policy bypass vulnerability in QQBot admin commands that allows authenticated senders to skip DM-only and allowFrom policy checks. Attackers can route admin commands from unauthorized senders or conte…

▾ SunlitOpenClaw · OpenClawEPSS 0.25%via CVEORG
CVE-2026-35674High· 8.8
4mo ago

OpenClaw < 2026.5.18 - Scope Bypass via Inherited chat.send Route

OpenClaw before 2026.5.18 contains a scope bypass vulnerability in the Gateway chat.send route that allows scoped clients to execute privileged commands. Attackers with operator.write scope can deliver commands through inherited external…

▾ TwilightOpenClaw · OpenClawEPSS 0.45%via CVEORG
CVE-2026-35673Medium· 6.5
4mo ago

OpenClaw < 2026.4.29 - SSRF Policy Bypass via Browser Debug/Export Routes

OpenClaw before 2026.4.29 contains an SSRF policy bypass vulnerability in browser debug and export routes that allows reuse of already-open blocked tabs. Attackers with access to these routes can bypass private-network SSRF policies by r…

▾ SunlitOpenClaw · OpenClawEPSS 0.26%via CVEORG
CVE-2026-35630High· 8.0
4mo ago

OpenClaw < 2026.5.18 - QQBot Missing Approver Identity Enforcement in Native Approval Buttons

OpenClaw before 2026.5.18 contains an authorization bypass vulnerability in QQBot native approval buttons that fails to enforce configured approver identity. Non-approver users can click approval buttons to resolve pending exec or plugin…

▾ TwilightOpenClaw · OpenClawEPSS 0.36%via CVEORG
CVE-2026-8634Critical· 9.1
4mo ago

Crabbox: environment variable exposure vulnerability

Crabbox: environment variable exposure vulnerability

▾ Midnightopenclaw · github.com/openclaw/crabboxEPSS 1.0%via OSV
CVE-2026-44113High· 7.7
4mo ago

OpenClaw < 2026.4.22 - Time-of-Check/Time-of-Use Race Condition in OpenShell FS Bridge

OpenClaw before 2026.4.22 contains a time-of-check/time-of-use race condition in the OpenShell filesystem bridge that allows attackers to read files outside the intended mount root. Attackers can exploit symlink swaps during filesystem o…

▾ TwilightOpenClaw · OpenClawEPSS 0.34%via CVEORG
CVE-2026-44117Medium· 5.8
4mo ago

OpenClaw < 2026.4.20 - Server-Side Request Forgery in QQBot Direct Media Upload

OpenClaw before 2026.4.20 contains a server-side request forgery vulnerability in QQBot direct media upload that skips URL validation. Attackers can bypass SSRF protections by sending crafted image URLs to uploadC2CMedia and uploadGroupM…

▾ SunlitOpenClaw · OpenClawEPSS 0.40%via CVEORG
CVE-2026-44115High· 8.8
4mo ago

OpenClaw < 2026.4.22 - Shell Expansion Bypass in Unquoted Heredocs via Exec Allowlist

OpenClaw before 2026.4.22 contains an exec allowlist analysis vulnerability allowing shell expansion hiding in unquoted heredoc bodies. Attackers can bypass allowlist validation by embedding shell expansion tokens in heredoc bodies to ex…

▾ TwilightOpenClaw · OpenClawEPSS 0.61%via CVEORG
CVE-2026-44114High· 7.8
4mo ago

OpenClaw < 2026.4.20 - Environment Variable Namespace Collision via Workspace dotenv

OpenClaw before 2026.4.20 fails to properly reserve the OPENCLAW_ runtime-control environment namespace in workspace dotenv files, allowing attackers to override critical runtime variables. Malicious workspaces can set variables like OPE…

▾ TwilightOpenClaw · OpenClawEPSS 0.19%via CVEORG
CVE-2026-44112Critical· 9.6
4mo ago

OpenClaw < 2026.4.22 - Symlink Swap Race Condition in OpenShell FS Bridge Writes

OpenClaw before 2026.4.22 contains a time-of-check/time-of-use race condition in OpenShell sandbox filesystem writes that allows attackers to redirect writes outside the intended mount root. Attackers can exploit symlink swaps during fil…

▾ MidnightOpenClaw · OpenClawEPSS 0.39%via CVEORG
CVE-2026-44118High· 7.8
4mo ago

OpenClaw < 2026.4.22 - Owner Context Spoofing via Bearer Token Header

OpenClaw before 2026.4.22 derives loopback MCP owner context from spoofable server-issued bearer tokens in request headers. Non-owner loopback clients can present themselves as owner to bypass owner-gated operations by manipulating the s…

▾ TwilightOpenClaw · OpenClawEPSS 0.16%via CVEORG
CVE-2026-44116High· 8.6
4mo ago

OpenClaw < 2026.4.22 - Server-Side Request Forgery in Zalo Photo URL Validation

OpenClaw before 2026.4.22 contains a server-side request forgery vulnerability in the Zalo plugin's sendPhoto function that fails to validate outbound photo URLs through the SSRF guard. Attackers can bypass SSRF protection by providing m…

▾ TwilightOpenClaw · OpenClawEPSS 0.47%via CVEORG
CVE-2026-40037Medium· 6.5
5mo ago

OpenClaw < 2026.3.31 - Unsafe Request Body Replay via fetchWithSsrFGuard Cross-Origin Redirects

OpenClaw before 2026.3.31 (patched in 2026.4.8) contains a request body replay vulnerability in fetchWithSsrFGuard that allows unsafe request bodies to be resent across cross-origin redirects. Attackers can exploit this by triggering red…

▾ SunlitOpenClaw · OpenClawEPSS 0.55%via CVEORG
CVE-2026-34511Medium· 5.3
5mo ago

OpenClaw before 2026.4.2 reuses the PKCE verifier as the OAuth state parameter in the Gemini OAuth flow, exposing it through the redirect URL

OpenClaw before 2026.4.2 reuses the PKCE verifier as the OAuth state parameter in the Gemini OAuth flow, exposing it through the redirect URL. Attackers who capture the redirect URL can obtain both the authorization code and PKCE verifie…

▾ Sunlitopenclaw · openclawEPSS 0.43%via NVD
CVE-2026-34510Medium· 5.3
5mo ago

OpenClaw < 2026.3.22 - Remote File URL Acceptance in Windows Media Loaders

OpenClaw before 2026.3.22 contains a path traversal vulnerability in Windows media loaders that accepts remote-host file URLs and UNC-style paths before local-path validation. Attackers can exploit this by providing network-hosted file t…

▾ SunlitOpenClaw · OpenClawEPSS 0.46%via CVEORG
CVE-2026-32988High· 7.5
6mo ago

OpenClaw before 2026.3.11 contains a sandbox boundary bypass vulnerability in fs-bridge staged writes where temporary file creation and population are not pinned to a verified parent directory

OpenClaw before 2026.3.11 contains a sandbox boundary bypass vulnerability in fs-bridge staged writes where temporary file creation and population are not pinned to a verified parent directory. Attackers can exploit a race condition in p…

▾ Twilightopenclaw · openclawEPSS 0.11%via NVD
CVE-2026-32982High· 7.5
6mo ago

OpenClaw before 2026.3.13 contains an information disclosure vulnerability in the fetchRemoteMedia function that exposes Telegram bot tokens in error messages

OpenClaw before 2026.3.13 contains an information disclosure vulnerability in the fetchRemoteMedia function that exposes Telegram bot tokens in error messages. When media downloads fail, the original Telegram file URLs containing bot tok…

▾ Twilightopenclaw · openclawEPSS 0.51%via NVD
CVE-2026-32977Medium· 6.3
6mo ago

OpenClaw before 2026.3.11 contains a sandbox boundary bypass vulnerability in the fs-bridge writeFile commit step that uses an unanchored container path during the final move operation

OpenClaw before 2026.3.11 contains a sandbox boundary bypass vulnerability in the fs-bridge writeFile commit step that uses an unanchored container path during the final move operation. An attacker can exploit a time-of-check-time-of-use…

▾ Sunlitopenclaw · openclawEPSS 0.11%via NVD
CVE-2026-32976Medium· 6.5
6mo ago

OpenClaw before 2026.3.11 contains an authorization bypass vulnerability allowing channel commands to mutate protected sibling-account configuration despite configWrites restrictions

OpenClaw before 2026.3.11 contains an authorization bypass vulnerability allowing channel commands to mutate protected sibling-account configuration despite configWrites restrictions. Attackers with authorized access on one account can e…

▾ Sunlitopenclaw · openclawEPSS 0.33%via NVD
CVE-2026-32971High· 7.1
6mo ago

OpenClaw before 2026.3.11 contains an approval-integrity vulnerability in node-host system.run approvals that displays extracted shell payloads instead of the executed argv

OpenClaw before 2026.3.11 contains an approval-integrity vulnerability in node-host system.run approvals that displays extracted shell payloads instead of the executed argv. Attackers can place wrapper binaries and induce wrapper-shaped …

▾ Twilightopenclaw · openclawEPSS 0.38%via NVD
CVE-2026-32970Low· 2.5
6mo ago

OpenClaw before 2026.3.11 contains a credential fallback vulnerability where unavailable local gateway.auth.token and gateway.auth.password SecretRefs are treated as unset, allowing fallback to remote credentials in local mode

OpenClaw before 2026.3.11 contains a credential fallback vulnerability where unavailable local gateway.auth.token and gateway.auth.password SecretRefs are treated as unset, allowing fallback to remote credentials in local mode. Attackers…

▾ Sunlitopenclaw · openclawEPSS 0.15%via NVD
CVE-2026-32921Medium· 6.3
6mo ago

OpenClaw before 2026.3.8 contains an approval bypass vulnerability in system.run where mutable script operands are not bound across approval and execution phases

OpenClaw before 2026.3.8 contains an approval bypass vulnerability in system.run where mutable script operands are not bound across approval and execution phases. Attackers can obtain approval for script execution, modify the approved sc…

▾ Sunlitopenclaw · openclawEPSS 0.33%via NVD
CVE-2026-32920High· 8.4
6mo ago

OpenClaw before 2026.3.12 automatically discovers and loads plugins from .OpenClaw/extensions/ without explicit trust verification, allowing arbitrary code execution

OpenClaw before 2026.3.12 automatically discovers and loads plugins from .OpenClaw/extensions/ without explicit trust verification, allowing arbitrary code execution. Attackers can execute malicious code by including crafted workspace pl…

▾ Twilightopenclaw · openclawEPSS 0.41%via NVD
CVE-2026-32917Critical· 9.8
6mo ago

OpenClaw before 2026.3.13 contains a remote command injection vulnerability in the iMessage attachment staging flow that allows attackers to execute arbitrary commands on configured remote hosts

OpenClaw before 2026.3.13 contains a remote command injection vulnerability in the iMessage attachment staging flow that allows attackers to execute arbitrary commands on configured remote hosts. The vulnerability exists because unsaniti…

▾ Midnightopenclaw · openclawEPSS 3.2%via NVD
CVE-2026-32916Critical· 9.4
6mo ago

OpenClaw versions 2026.3.7 before 2026.3.11 contain an authorization bypass vulnerability where plugin subagent routes execute gateway methods through a synthetic operator client with broad administrative scopes

OpenClaw versions 2026.3.7 before 2026.3.11 contain an authorization bypass vulnerability where plugin subagent routes execute gateway methods through a synthetic operator client with broad administrative scopes. Remote unauthenticated r…

▾ Midnightopenclaw · openclawEPSS 0.63%via NVD
CVE-2026-34506Medium· 4.3
6mo ago

OpenClaw before 2026.3.8 contains a sender allowlist bypass vulnerability in its Microsoft Teams plugin that allows unauthorized senders to bypass intended authorization checks

OpenClaw before 2026.3.8 contains a sender allowlist bypass vulnerability in its Microsoft Teams plugin that allows unauthorized senders to bypass intended authorization checks. When a team/channel route allowlist is configured with an e…

▾ Sunlitopenclaw · openclawEPSS 0.34%via NVD
CVE-2026-34505Medium· 6.5
6mo ago

OpenClaw before 2026.3.12 applies rate limiting only after successful webhook authentication, allowing attackers to bypass rate limits and brute-force webhook secrets

OpenClaw before 2026.3.12 applies rate limiting only after successful webhook authentication, allowing attackers to bypass rate limits and brute-force webhook secrets. Attackers can submit repeated authentication requests with invalid se…

▾ Sunlitopenclaw · openclawEPSS 0.36%via NVD
openclaw vulnerabilities (CVEs) — page 7 · VulnSea