Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

OpenClaw — Vulnerabilities & Security Advisories 639

All 639 CVE vulnerabilities found in OpenClaw, with AI-generated Chinese analysis, references, and POCs.

This page aggregates known security vulnerabilities affecting OpenClaw, a software product, categorized by specific weakness types. It collects publicly disclosed security flaws, including buffer overflows, injection issues, and authentication bypasses, spanning the period from the product's initial release through the latest available advisories. Visitors can track the vendor's published security notices, analyze patterns within a specific weakness class, and review the complete historical record of vulnerabilities identified in OpenClaw. The data is organized to facilitate trend analysis and risk assessment, allowing security teams to identify recurring defect classes and evaluate the severity distribution over time. All entries are sourced from public vulnerability databases and official vendor bulletins, ensuring traceability and consistency in reporting standards. Users can filter results by date range, impact score, or component module to focus on relevant subsets of findings. The collection serves as a centralized reference for tracking how OpenClaw's security posture has evolved, supporting maintenance planning and compliance reporting without relying on scattered external sources.

Vendor: OpenClaw

CVE ID Title CVSS Severity Published
CVE-2026-32913 OpenClaw < 2026.3.7 - Custom Authorization Header Leakage via Cross-Origin Redirects CWE-522 9.3 Critical 2026-03-23
CVE-2026-27646 OpenClaw < 2026.3.7 - Sandbox Escape via /acp spawn Command CWE-863 6.1 Medium 2026-03-23
CVE-2026-27183 OpenClaw < 2026.3.7 - Shell Approval Gating Bypass via Dispatch Wrapper Depth Mismatch CWE-863 5.3 Medium 2026-03-23
CVE-2026-32899 OpenClaw < 2026.2.25 - Sender Policy Bypass in Slack Reaction and Pin Event Handlers CWE-863 4.3 Medium 2026-03-21
CVE-2026-32898 OpenClaw < 2026.2.23 - ACP Permission Auto-Approval Bypass via Untrusted Tool Metadata CWE-807 5.4 Medium 2026-03-21
CVE-2026-32897 OpenClaw < 2026.2.22 - Authentication Token Reuse in Owner ID Prompt Hashing Fallback CWE-320 3.7 Low 2026-03-21
CVE-2026-32896 OpenClaw < 2026.2.21 - Unauthenticated Webhook Access via Passwordless Fallback in BlueBubbles Plugin CWE-306 4.8 Medium 2026-03-21
CVE-2026-32895 OpenClaw < 2026.2.26 - Sender Authorization Bypass in Slack System Event Handlers CWE-863 5.4 Medium 2026-03-21
CVE-2026-32067 OpenClaw < 2026.2.26 - Cross-Account Authorization Bypass in DM Pairing Store CWE-863 3.7 Low 2026-03-21
CVE-2026-32065 OpenClaw < 2026.2.25 - Approval Identity Mismatch in system.run Command Execution CWE-436 4.8 Medium 2026-03-21
CVE-2026-32064 OpenClaw < 2026.2.21 - Missing VNC Authentication in Sandbox Browser noVNC Observer CWE-306 7.7 High 2026-03-21
CVE-2026-32058 OpenClaw < 2026.2.26 - Approval Context-Binding Weakness in system.run via host=node CWE-863 2.6 Low 2026-03-21
CVE-2026-32057 OpenClaw < 2026.2.25 - Authentication Bypass via Control UI client.id Parameter CWE-807 7.1 High 2026-03-21
CVE-2026-32056 OpenClaw < 2026.2.22 - Remote Code Execution via Shell Startup Environment Variable Injection in system.run CWE-78 7.5 High 2026-03-21
CVE-2026-32055 OpenClaw < 2026.2.26 - Workspace Path Boundary Bypass via Non-existent Symlink CWE-22 7.6 High 2026-03-21
CVE-2026-32054 OpenClaw < 2026.2.25 - Symlink Traversal in Browser Trace/Download Path Handling CWE-59 6.5 Medium 2026-03-21
CVE-2026-32053 OpenClaw < 2026.2.23 - Twilio Webhook Replay Bypass via Randomized Event ID Normalization CWE-294 6.5 Medium 2026-03-21
CVE-2026-32052 OpenClaw < 2026.2.24 - Hidden Command Execution via Shell-Wrapper Positional argv Carriers CWE-436 6.4 Medium 2026-03-21
CVE-2026-32051 OpenClaw < 2026.3.1 - Authorization Bypass in Agent Runs via Owner-Only Tool Access CWE-863 8.8 High 2026-03-21
CVE-2026-32050 OpenClaw < 2026.2.25 - Unauthorized Reaction Status Event Enqueue via Access Check Bypass CWE-863 3.7 Low 2026-03-21
CVE-2026-32049 OpenClaw < 2026.2.22 - Denial of Service via Inbound Media Download Byte Limit Bypass CWE-770 7.5 High 2026-03-21
CVE-2026-32048 OpenClaw < 2026.3.1 - Sandbox Escape via Cross-Agent sessions_spawn CWE-732 7.5 High 2026-03-21
CVE-2026-32046 OpenClaw < 2026.2.21 - OS-level Sandbox Bypass via --no-sandbox Flag CWE-1188 5.3 Medium 2026-03-21
CVE-2026-32045 OpenClaw < 2026.2.21 - Authentication Bypass in HTTP Gateway Routes via Tokenless Tailscale Auth CWE-290 5.9 Medium 2026-03-21
CVE-2026-32044 OpenClaw < 2026.3.2 - Tar Archive Safety Bypass in Skills Installation CWE-409 5.5 Medium 2026-03-21
CVE-2026-32043 OpenClaw < 2026.2.25 - Time-of-Check-Time-of-Use via Mutable Symlink in system.run cwd Parameter CWE-367 6.5 Medium 2026-03-21
CVE-2026-32042 OpenClaw < 2026.2.25 - Privilege Escalation via Unpaired Device Identity in Shared Gateway Authentication CWE-863 8.8 High 2026-03-21
CVE-2026-22172 OpenClaw < 2026.3.12 - Scope Elevation in WebSocket Shared-Auth Connections CWE-862 9.9 Critical 2026-03-20
CVE-2026-32041 OpenClaw < 2026.3.1 - Unauthenticated Browser Control Access via Failed Auth Bootstrap CWE-306 6.9 Medium 2026-03-19
CVE-2026-32040 OpenClaw < 2026.2.23 - HTML Injection via Unvalidated Image MIME Type in Data-URL Interpolation CWE-79 4.6 Medium 2026-03-19

All 639 known CVE vulnerabilities affecting OpenClaw with full Chinese analysis, references, and POCs where available.