Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

OpenClaw — Vulnerabilities & Security Advisories 639

All 639 CVE vulnerabilities found in OpenClaw, with AI-generated Chinese analysis, references, and POCs.

This page aggregates known security vulnerabilities affecting OpenClaw, a software product, categorized by specific weakness types. It collects publicly disclosed security flaws, including buffer overflows, injection issues, and authentication bypasses, spanning the period from the product's initial release through the latest available advisories. Visitors can track the vendor's published security notices, analyze patterns within a specific weakness class, and review the complete historical record of vulnerabilities identified in OpenClaw. The data is organized to facilitate trend analysis and risk assessment, allowing security teams to identify recurring defect classes and evaluate the severity distribution over time. All entries are sourced from public vulnerability databases and official vendor bulletins, ensuring traceability and consistency in reporting standards. Users can filter results by date range, impact score, or component module to focus on relevant subsets of findings. The collection serves as a centralized reference for tracking how OpenClaw's security posture has evolved, supporting maintenance planning and compliance reporting without relying on scattered external sources.

Vendor: OpenClaw

CVE ID Title CVSS Severity Published
CVE-2026-35661 OpenClaw < 2026.3.25 - Telegram DM-Scoped Inline Button Callback Authorization Bypass CWE-288 5.3 Medium 2026-04-10
CVE-2026-35659 OpenClaw < 2026.3.22 - Unresolved Service Metadata Routing via Bonjour and DNS-SD Discovery CWE-345 4.6 Medium 2026-04-10
CVE-2026-35658 OpenClaw < 2026.3.2 - Filesystem Boundary Bypass in Image Tool CWE-668 6.5 Medium 2026-04-10
CVE-2026-35657 OpenClaw < 2026.3.25 - Authorization Bypass in HTTP Session History Route CWE-863 6.5 Medium 2026-04-10
CVE-2026-35656 OpenClaw < 2026.3.22 - XFF Loopback Spoofing Bypass in Canvas Authentication and Rate Limiter CWE-290 6.5 Medium 2026-04-10
CVE-2026-35655 OpenClaw < 2026.3.22 - Identity Spoofing via rawInput Tool in ACP Permission Resolution CWE-807 5.7 Medium 2026-04-10
CVE-2026-35654 OpenClaw < 2026.3.25 - Authorization Bypass in Microsoft Teams Feedback Invoke CWE-288 5.3 Medium 2026-04-10
CVE-2026-35653 OpenClaw < 2026.3.24 - Incorrect Authorization in POST /reset-profile via browser.request CWE-863 8.1 High 2026-04-10
CVE-2026-35652 OpenClaw < 2026.3.22 - Unauthorized Action Execution via Callback Dispatch CWE-696 6.5 Medium 2026-04-10
CVE-2026-35651 OpenClaw 2026.2.13 < 2026.3.25 - ANSI Escape Sequence Injection in Approval Prompt CWE-150 4.3 Medium 2026-04-10
CVE-2026-35650 OpenClaw < 2026.3.22 - Environment Variable Override Bypass via Inconsistent Sanitization CWE-15 7.5 High 2026-04-10
CVE-2026-35648 OpenClaw < 2026.3.22 - Policy Bypass via Unvalidated Queued Node Actions CWE-367 3.7 Low 2026-04-10
CVE-2026-35649 OpenClaw < 2026.3.22 - Settings Reconciliation Bypass via Empty Allowlist CWE-183 6.5 Medium 2026-04-10
CVE-2026-35647 OpenClaw < 2026.3.25 - Direct Message Policy Bypass via Verification Notices CWE-288 5.3 Medium 2026-04-10
CVE-2026-35643 OpenClaw < 2026.3.22 - Arbitrary Code Execution via Unvalidated WebView JavascriptInterface CWE-940 8.8 High 2026-04-10
CVE-2026-35621 OpenClaw < 2026.3.24 - Privilege Escalation via chat.send to Allowlist Persistence CWE-862 6.5 Medium 2026-04-10
CVE-2026-35641 OpenClaw < 2026.3.24 - Arbitrary Code Execution via .npmrc in Local Plugin/Hook Installation CWE-349 7.8 High 2026-04-10
CVE-2026-35620 OpenClaw < 2026.3.24 - Missing Authorization in /send and /allowlist Chat Commands CWE-862 5.4 Medium 2026-04-10
CVE-2026-35619 OpenClaw < 2026.3.24 - Authorization Bypass via HTTP /v1/models Endpoint CWE-863 4.3 Medium 2026-04-10
CVE-2026-6011 OpenClaw assertPublicHostname web-fetch.ts server-side request forgery CWE-918 5.6 Medium 2026-04-10
CVE-2026-35646 OpenClaw < 2026.3.25 - Pre-Authentication Rate-Limit Bypass in Webhook Token Validation CWE-307 4.8 Medium 2026-04-09
CVE-2026-35645 OpenClaw < 2026.3.25 - Privilege Escalation via Synthetic operator.admin in deleteSession CWE-648 8.1 High 2026-04-09
CVE-2026-35644 OpenClaw < 2026.3.22 - Credential Exposure via baseUrl Fields in Gateway Snapshots CWE-312 6.5 Medium 2026-04-09
CVE-2026-35642 OpenClaw < 2026.3.25 - Authorization Bypass in Group Reactions via requireMention Bypass CWE-288 4.3 Medium 2026-04-09
CVE-2026-35640 OpenClaw < 2026.3.25 - Denial of Service via Unauthenticated Webhook Request Parsing CWE-696 5.3 Medium 2026-04-09
CVE-2026-35639 OpenClaw < 2026.3.22 - Privilege Escalation via device.pair.approve Scope Validation CWE-648 8.8 High 2026-04-09
CVE-2026-35637 OpenClaw < 2026.3.22 - Premature Cite Expansion Before Authorization in Channel and DM CWE-696 7.3 High 2026-04-09
CVE-2026-35638 OpenClaw < 2026.3.22 - Privilege Escalation via Self-Declared Scopes in Trusted-Proxy Control UI CWE-286 8.8 High 2026-04-09
CVE-2026-35636 OpenClaw 2026.3.11 < 2026.3.25 - Session Isolation Bypass via sessionId Resolution CWE-696 6.5 Medium 2026-04-09
CVE-2026-35635 OpenClaw < 2026.3.22 - Webhook Path Route Replacement Vulnerability in Synology Chat CWE-706 4.8 Medium 2026-04-09

All 639 known CVE vulnerabilities affecting OpenClaw with full Chinese analysis, references, and POCs where available.