Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

OpenClaw — Vulnerabilities & Security Advisories 573

All 573 CVE vulnerabilities found in OpenClaw, with AI-generated Chinese analysis, references, and POCs.

This page documents security vulnerabilities and weaknesses associated with OpenClaw, a software product developed by OpenClaw, categorized by Common Weakness Enumeration (CWE) classifications. It aggregates a comprehensive collection of identified security flaws, ranging from buffer overflows and injection vulnerabilities to authentication bypasses and permission issues. The data spans from the earliest recorded disclosures up to the most recent updates, ensuring a chronological view of the product’s security landscape over time. Here, you can track a vendor's advisories to understand the context and severity of reported issues, understand a weakness class by seeing how specific CWEs manifest in this particular codebase, and look up a product's vulnerability history to identify patterns or recurring issues that may indicate systemic design flaws. This resource is intended for security professionals, developers, and analysts who need to assess the risk profile of OpenClaw installations. By reviewing these aggregated details, users can better prioritize remediation efforts and compare the stability of this product against industry standards. The information is structured to facilitate efficient research, allowing for quick identification of relevant CVEs and associated metadata without unnecessary noise. This approach supports informed decision-making regarding patch deployment and long-term security maintenance strategies for organizations relying on OpenClaw services.

Vendor: OpenClaw

CVE ID Title CVSS Severity Published
CVE-2026-32896 OpenClaw < 2026.2.21 - Unauthenticated Webhook Access via Passwordless Fallback in BlueBubbles Plugin CWE-306 4.8 Medium 2026-03-21
CVE-2026-32895 OpenClaw < 2026.2.26 - Sender Authorization Bypass in Slack System Event Handlers CWE-863 5.4 Medium 2026-03-21
CVE-2026-32067 OpenClaw < 2026.2.26 - Cross-Account Authorization Bypass in DM Pairing Store CWE-863 3.7 Low 2026-03-21
CVE-2026-32065 OpenClaw < 2026.2.25 - Approval Identity Mismatch in system.run Command Execution CWE-436 4.8 Medium 2026-03-21
CVE-2026-32064 OpenClaw < 2026.2.21 - Missing VNC Authentication in Sandbox Browser noVNC Observer CWE-306 7.7 High 2026-03-21
CVE-2026-32058 OpenClaw < 2026.2.26 - Approval Context-Binding Weakness in system.run via host=node CWE-863 2.6 Low 2026-03-21
CVE-2026-32057 OpenClaw < 2026.2.25 - Authentication Bypass via Control UI client.id Parameter CWE-807 7.1 High 2026-03-21
CVE-2026-32056 OpenClaw < 2026.2.22 - Remote Code Execution via Shell Startup Environment Variable Injection in system.run CWE-78 7.5 High 2026-03-21
CVE-2026-32055 OpenClaw < 2026.2.26 - Workspace Path Boundary Bypass via Non-existent Symlink CWE-22 7.6 High 2026-03-21
CVE-2026-32054 OpenClaw < 2026.2.25 - Symlink Traversal in Browser Trace/Download Path Handling CWE-59 6.5 Medium 2026-03-21
CVE-2026-32053 OpenClaw < 2026.2.23 - Twilio Webhook Replay Bypass via Randomized Event ID Normalization CWE-294 6.5 Medium 2026-03-21
CVE-2026-32052 OpenClaw < 2026.2.24 - Hidden Command Execution via Shell-Wrapper Positional argv Carriers CWE-436 6.4 Medium 2026-03-21
CVE-2026-32051 OpenClaw < 2026.3.1 - Authorization Bypass in Agent Runs via Owner-Only Tool Access CWE-863 8.8 High 2026-03-21
CVE-2026-32050 OpenClaw < 2026.2.25 - Unauthorized Reaction Status Event Enqueue via Access Check Bypass CWE-863 3.7 Low 2026-03-21
CVE-2026-32049 OpenClaw < 2026.2.22 - Denial of Service via Inbound Media Download Byte Limit Bypass CWE-770 7.5 High 2026-03-21
CVE-2026-32048 OpenClaw < 2026.3.1 - Sandbox Escape via Cross-Agent sessions_spawn CWE-732 7.5 High 2026-03-21
CVE-2026-32046 OpenClaw < 2026.2.21 - OS-level Sandbox Bypass via --no-sandbox Flag CWE-1188 5.3 Medium 2026-03-21
CVE-2026-32045 OpenClaw < 2026.2.21 - Authentication Bypass in HTTP Gateway Routes via Tokenless Tailscale Auth CWE-290 5.9 Medium 2026-03-21
CVE-2026-32044 OpenClaw < 2026.3.2 - Tar Archive Safety Bypass in Skills Installation CWE-409 5.5 Medium 2026-03-21
CVE-2026-32043 OpenClaw < 2026.2.25 - Time-of-Check-Time-of-Use via Mutable Symlink in system.run cwd Parameter CWE-367 6.5 Medium 2026-03-21
CVE-2026-32042 OpenClaw < 2026.2.25 - Privilege Escalation via Unpaired Device Identity in Shared Gateway Authentication CWE-863 8.8 High 2026-03-21
CVE-2026-22172 OpenClaw < 2026.3.12 - Scope Elevation in WebSocket Shared-Auth Connections CWE-862 9.9 Critical 2026-03-20
CVE-2026-32041 OpenClaw < 2026.3.1 - Unauthenticated Browser Control Access via Failed Auth Bootstrap CWE-306 6.9 Medium 2026-03-19
CVE-2026-32040 OpenClaw < 2026.2.23 - HTML Injection via Unvalidated Image MIME Type in Data-URL Interpolation CWE-79 4.6 Medium 2026-03-19
CVE-2026-32039 OpenClaw < 2026.2.22 - Sender Authorization Bypass via Identity Collision in toolsBySender CWE-639 5.9 Medium 2026-03-19
CVE-2026-32037 OpenClaw < 2026.2.22 - Redirect Chain Bypass of Media Host Allowlist in MSTeams Attachment Handling CWE-918 6.0 Medium 2026-03-19
CVE-2026-32038 OpenClaw - Sandbox Network Isolation Bypass via docker.network=container Parameter CWE-284 9.8 Critical 2026-03-19
CVE-2026-32036 OpenClaw < 2026.2.26- Authentication Bypass via Encoded Dot-Segment Traversal in /api/channels CWE-289 6.5 Medium 2026-03-19
CVE-2026-32035 OpenClaw < 2026.3.2 - Missing Owner Flag Validation in Discord Voice Transcript Handler CWE-863 5.9 Medium 2026-03-19
CVE-2026-32034 OpenClaw < 2026.2.21 - Insecure Control UI Authentication over Plaintext HTTP CWE-78 8.1 High 2026-03-19

All 573 known CVE vulnerabilities affecting OpenClaw with full Chinese analysis, references, and POCs where available.