Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

OpenClaw — Vulnerabilities & Security Advisories 639

All 639 CVE vulnerabilities found in OpenClaw, with AI-generated Chinese analysis, references, and POCs.

This page aggregates known security vulnerabilities affecting OpenClaw, a software product, categorized by specific weakness types. It collects publicly disclosed security flaws, including buffer overflows, injection issues, and authentication bypasses, spanning the period from the product's initial release through the latest available advisories. Visitors can track the vendor's published security notices, analyze patterns within a specific weakness class, and review the complete historical record of vulnerabilities identified in OpenClaw. The data is organized to facilitate trend analysis and risk assessment, allowing security teams to identify recurring defect classes and evaluate the severity distribution over time. All entries are sourced from public vulnerability databases and official vendor bulletins, ensuring traceability and consistency in reporting standards. Users can filter results by date range, impact score, or component module to focus on relevant subsets of findings. The collection serves as a centralized reference for tracking how OpenClaw's security posture has evolved, supporting maintenance planning and compliance reporting without relying on scattered external sources.

Vendor: OpenClaw

CVE ID Title CVSS Severity Published
CVE-2026-100568 OpenClaw before 2026.8.1 Unauthorized Command Job Access CWE-200 8.3 High 2026-09-26
CVE-2026-100567 OpenClaw before 2026.8.1 DNS Rebinding via CDP Hostname CWE-918 8.2 High 2026-09-26
CVE-2026-100564 OpenClaw before 2026.8.1 CSV Formula Injection via Attendance Export CWE-1236 5.4 Medium 2026-09-26
CVE-2026-100563 OpenClaw before 2026.8.1 CSV Formula Injection via Session Labels CWE-1236 5.4 Medium 2026-09-26
CVE-2026-100562 OpenClaw before 2026.8.1 Authorization Bypass via sessions.create CWE-863 5.4 Medium 2026-09-26
CVE-2026-100561 OpenClaw before 2026.8.1 Authentication Bypass via Exec Wrapper CWE-88 8.0 High 2026-09-26
CVE-2026-100560 OpenClaw before 2026.8.1 Reusable Exec Approvals Authorization Bypass CWE-863 7.5 High 2026-09-26
CVE-2026-100558 OpenClaw before 2026.8.1 Resource Exhaustion via WebSocket Upgrade CWE-400 7.5 High 2026-09-26
CVE-2026-100559 OpenClaw before 2026.8.1 Command Injection via Escaped Newlines CWE-78 8.0 High 2026-09-26
CVE-2026-100557 OpenClaw before 2026.8.1 Authorization Bypass via Skill Tool Dispatch CWE-863 8.3 High 2026-09-26
CVE-2026-100555 OpenClaw before 2026.8.1 DNS Rebinding via attachment delivery CWE-918 7.1 High 2026-09-26
CVE-2026-100556 OpenClaw before 2026.8.1 Authentication Bypass via Session Reset CWE-863 6.3 Medium 2026-09-26
CVE-2026-100554 OpenClaw before 2026.8.1 Canvas Capability Revocation Bypass CWE-613 4.2 Medium 2026-09-26
CVE-2026-100553 OpenClaw 2026.6.9 before 2026.8.1 Cross-Context Policy Bypass via Feishu unpin CWE-863 4.3 Medium 2026-09-26
CVE-2026-100552 OpenClaw before 2026.8.1 Policy Bypass via Native Tools CWE-863 8.8 High 2026-09-26
CVE-2026-100551 OpenClaw iOS Control UI TLS Pin Enforcement Bypass CWE-295 8.3 High 2026-09-26
CVE-2026-100550 OpenClaw before 2026.8.1 Authentication Bypass via Access Group CWE-863 5.4 Medium 2026-09-26
CVE-2026-100549 OpenClaw before 2026.8.1 Path Traversal via QQBot voice filenames CWE-22 5.4 Medium 2026-09-26
CVE-2026-100548 OpenClaw before 2026.8.1 Credential Exposure via Embedding Fallback CWE-200 5.3 Medium 2026-09-26
CVE-2026-100546 OpenClaw 2026.7.2 before 2026.9.2 Authentication Bypass via Voice Transcript CWE-362 6.4 Medium 2026-09-26
CVE-2026-100547 OpenClaw before 2026.8.1 Authentication Bypass via File URL CWE-180 5.5 Medium 2026-09-26
CVE-2026-100545 OpenClaw before 2026.8.1 Policy Bypass via Session Filename Generation CWE-863 5.3 Medium 2026-09-26
CVE-2026-100543 OpenClaw before 2026.8.1 Information Disclosure via Configuration Hash CWE-200 7.5 High 2026-09-26
CVE-2026-100542 OpenClaw before 2026.8.1 Extraction Limit Bypass via tar.bz2 CWE-400 3.1 Low 2026-09-26
CVE-2026-100539 OpenClaw before 2026.8.1 Memory Access Control Bypass CWE-863 2.6 Low 2026-09-26
CVE-2026-100538 OpenClaw before 2026.8.1 Local File Read via Outbound Attachments CWE-863 6.5 Medium 2026-09-26
CVE-2026-100537 OpenClaw before 2026.8.1 Authentication Bypass via Active Memory CWE-862 3.1 Low 2026-09-26
CVE-2026-100536 OpenClaw before 2026.8.1 Path Traversal via Structured Attachments CWE-22 6.5 Medium 2026-09-26
CVE-2026-100535 OpenClaw before 2026.8.1 Privilege Escalation via Session Memory CWE-863 7.5 High 2026-09-26
CVE-2026-100533 OpenClaw before 2026.8.1 Path Traversal via Unicode Fallback CWE-22 5.3 Medium 2026-09-26

All 639 known CVE vulnerabilities affecting OpenClaw with full Chinese analysis, references, and POCs where available.