Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

OpenClaw — Vulnerabilities & Security Advisories 639

All 639 CVE vulnerabilities found in OpenClaw, with AI-generated Chinese analysis, references, and POCs.

This page aggregates known security vulnerabilities affecting OpenClaw, a software product, categorized by specific weakness types. It collects publicly disclosed security flaws, including buffer overflows, injection issues, and authentication bypasses, spanning the period from the product's initial release through the latest available advisories. Visitors can track the vendor's published security notices, analyze patterns within a specific weakness class, and review the complete historical record of vulnerabilities identified in OpenClaw. The data is organized to facilitate trend analysis and risk assessment, allowing security teams to identify recurring defect classes and evaluate the severity distribution over time. All entries are sourced from public vulnerability databases and official vendor bulletins, ensuring traceability and consistency in reporting standards. Users can filter results by date range, impact score, or component module to focus on relevant subsets of findings. The collection serves as a centralized reference for tracking how OpenClaw's security posture has evolved, supporting maintenance planning and compliance reporting without relying on scattered external sources.

Vendor: OpenClaw

CVE ID Title CVSS Severity Published
CVE-2026-102806 OpenClaw before 2026.9.5 Sandbox Isolation Bypass via Media Pipelines CWE-863 6.3 Medium 2026-09-29
CVE-2026-102807 OpenClaw before 2026.9.4 Authorization Bypass via MCP App Standalone Ticket CWE-863 5.3 Medium 2026-09-29
CVE-2026-100599 OpenClaw 2026.5.1 before 2026.7.1 Remote Code Execution via googlemeet.chrome CWE-78 8.8 High 2026-09-26
CVE-2026-100597 OpenClaw before 2026.7.1 Path Traversal via Filesystem Race CWE-367 7.8 High 2026-09-26
CVE-2026-100598 OpenClaw before 2026.7.1 Approval Binding Logic Error CWE-346 7.1 High 2026-09-26
CVE-2026-100596 OpenClaw before 2026.7.1 Authorization Bypass via MCP Configuration CWE-862 8.8 High 2026-09-26
CVE-2026-100594 OpenClaw before 2026.7.1 Authorization Bypass via trajectory export CWE-200 6.5 Medium 2026-09-26
CVE-2026-100595 OpenClaw before 2026.7.1 Authorization Bypass via diagnostics CWE-200 6.5 Medium 2026-09-26
CVE-2026-100593 OpenClaw before 2026.7.1 Authentication Bypass via activation CWE-862 5.4 Medium 2026-09-26
CVE-2026-100592 OpenClaw before 2026.7.1 Authentication Bypass via Memory Dreaming CWE-862 6.3 Medium 2026-09-26
CVE-2026-100591 OpenClaw before 2026.7.1 Authentication Bypass via Active Memory CWE-862 6.3 Medium 2026-09-26
CVE-2026-100590 OpenClaw before 2026.7.1 Authorization Bypass via voice set CWE-863 4.3 Medium 2026-09-26
CVE-2026-100588 OpenClaw before 2026.7.1 Authentication Bypass via node.invoke CWE-863 8.3 High 2026-09-26
CVE-2026-100589 OpenClaw before 2026.7.1 Sandbox Bypass via Browser Node CWE-863 8.3 High 2026-09-26
CVE-2026-100587 OpenClaw before 2026.7.1 Authorization Bypass via Codex Install CWE-862 8.8 High 2026-09-26
CVE-2026-100585 OpenClaw before 2026.7.1 Authentication Bypass via MCP Channel CWE-862 8.0 High 2026-09-26
CVE-2026-100586 OpenClaw Codex before 2026.7.1 Authorization Bypass via Bind CWE-269 8.8 High 2026-09-26
CVE-2026-100584 OpenClaw before 2026.7.1 Allowlist Bypass via Workspace Shadows CWE-426 6.7 Medium 2026-09-26
CVE-2026-100581 OpenClaw iOS before 2026.8.11 Credential Storage via Share Extension CWE-312 5.5 Medium 2026-09-26
CVE-2026-100580 OpenClaw before 2026.7.1 Remote Code Execution via cron tool CWE-178 8.8 High 2026-09-26
CVE-2026-100578 OpenClaw before 2026.7.1 Authorization Bypass via chat.send CWE-269 7.6 High 2026-09-26
CVE-2026-100579 OpenClaw before 2026.7.1 Authentication Bypass via Spoofed Requester CWE-639 7.6 High 2026-09-26
CVE-2026-100577 OpenClaw before 2026.8.1 Server-Side Request Forgery via Video Asset CWE-918 6.3 Medium 2026-09-26
CVE-2026-100576 OpenClaw before 2026.8.1 SSRF via Browser Wait Predicates CWE-918 5.4 Medium 2026-09-26
CVE-2026-100573 OpenClaw before 2026.8.1 Sandbox Policy Bypass via MCP Loopback CWE-862 3.3 Low 2026-09-26
CVE-2026-100574 OpenClaw before 2026.8.1 SSRF via Trusted-Host DNS CWE-918 5.9 Medium 2026-09-26
CVE-2026-100572 OpenClaw before 2026.8.1 Denial of Service via Rate Limit CWE-400 5.3 Medium 2026-09-26
CVE-2026-100571 OpenClaw before 2026.8.1 SMS Webhook Rate Limit Bypass CWE-400 5.3 Medium 2026-09-26
CVE-2026-100570 OpenClaw before 2026.8.1 Remote Code Execution via CLOUDSDK_PYTHON_ARGS CWE-88 7.8 High 2026-09-26
CVE-2026-100569 OpenClaw before 2026.8.1 Credential Exposure via Endpoint Override CWE-522 5.5 Medium 2026-09-26

All 639 known CVE vulnerabilities affecting OpenClaw with full Chinese analysis, references, and POCs where available.