Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

OpenClaw — Vulnerabilities & Security Advisories 639

All 639 CVE vulnerabilities found in OpenClaw, with AI-generated Chinese analysis, references, and POCs.

This page aggregates known security vulnerabilities affecting OpenClaw, a software product, categorized by specific weakness types. It collects publicly disclosed security flaws, including buffer overflows, injection issues, and authentication bypasses, spanning the period from the product's initial release through the latest available advisories. Visitors can track the vendor's published security notices, analyze patterns within a specific weakness class, and review the complete historical record of vulnerabilities identified in OpenClaw. The data is organized to facilitate trend analysis and risk assessment, allowing security teams to identify recurring defect classes and evaluate the severity distribution over time. All entries are sourced from public vulnerability databases and official vendor bulletins, ensuring traceability and consistency in reporting standards. Users can filter results by date range, impact score, or component module to focus on relevant subsets of findings. The collection serves as a centralized reference for tracking how OpenClaw's security posture has evolved, supporting maintenance planning and compliance reporting without relying on scattered external sources.

Vendor: OpenClaw

CVE ID Title CVSS Severity Published
CVE-2026-100534 OpenClaw before 2026.8.1 Session Cancellation Authorization Bypass CWE-639 3.1 Low 2026-09-26
CVE-2026-100530 OpenClaw before 2026.8.1 Exec Approval Directory Binding CWE-863 7.3 High 2026-09-26
CVE-2026-100529 OpenClaw before 2026.8.1 Authorization Scope Widening via File-Transfer CWE-863 6.4 Medium 2026-09-26
CVE-2026-100527 OpenClaw before 2026.8.2 Denial of Service via Browser Relay CWE-400 5.3 Medium 2026-09-26
CVE-2026-100528 OpenClaw before 2026.8.1 Credential Disclosure via Provider Endpoint CWE-200 5.4 Medium 2026-09-26
CVE-2026-94094 OpenClaw Canvas Host Route server.ts createCanvasHostHandler denial of service CWE-404 4.3 Medium 2026-09-20
CVE-2026-62229 OpenClaw < 2026.5.18 Authorization Bypass via Glob Matching CWE-22 8.8 High 2026-07-17
CVE-2026-62228 OpenClaw < 2026.6.5 Authorization Bypass via Node Exec Approvals CWE-863 8.8 High 2026-07-17
CVE-2026-62227 OpenClaw 2026.4.14 < 2026.5.26 SSRF via Browser Snapshot CWE-918 7.7 High 2026-07-17
CVE-2026-62225 OpenClaw < 2026.5.18 Authorization Bypass via Skill Command Dispatch CWE-863 5.4 Medium 2026-07-17
CVE-2026-62226 OpenClaw 2026.3.28 < 2026.5.19 Authorization Bypass via Browser Act Route CWE-918 8.5 High 2026-07-17
CVE-2026-62222 OpenClaw < 2026.5.22 Untrusted Plugin Loading via Setup-mode CWE-829 7.8 High 2026-07-17
CVE-2026-62223 OpenClaw < 2026.5.18 Authorization Bypass via Device-pair CWE-863 8.8 High 2026-07-17
CVE-2026-62221 OpenClaw 2026.5.12 < 2026.5.26 Authorization Bypass via allowFrom CWE-863 5.4 Medium 2026-07-17
CVE-2026-62219 OpenClaw 2026.2.12 < 2026.5.26 Authorization Bypass via Blank Agent IDs CWE-863 7.1 High 2026-07-17
CVE-2026-62220 OpenClaw 2026.2.25 < 2026.5.26 WebSocket Rate Limit Bypass CWE-307 5.3 Medium 2026-07-17
CVE-2026-62218 OpenClaw 2026.1.20 < 2026.5.27 Authorization Bypass via device.pair.approve CWE-862 8.8 High 2026-07-17
CVE-2026-62217 OpenClaw 2026.5.14-beta.1 < 2026.5.27 Authentication Bypass via exec approvals CWE-863 8.8 High 2026-07-17
CVE-2026-62216 OpenClaw 2026.4.20 < 2026.5.28 Policy Bypass via Media Upload CWE-918 5.0 Medium 2026-07-17
CVE-2026-62215 OpenClaw < 2026.6.5 Authentication Bypass via HTTP Canvas CWE-345 8.0 High 2026-07-17
CVE-2026-62212 OpenClaw < 2026.5.28 Authentication Bypass via safeFetch CWE-367 7.1 High 2026-07-17
CVE-2026-62211 OpenClaw < 2026.6.1 Credential Redaction Bypass via Trajectory Export CWE-532 5.0 Medium 2026-07-17
CVE-2026-62209 OpenClaw 2026.5.10-beta.1 < 2026.6.5 Authorization Bypass via agent-mode dispatch CWE-863 8.1 High 2026-07-17
CVE-2026-62210 OpenClaw < 2026.6.1 Denial of Service via Remote Media URLs CWE-770 6.5 Medium 2026-07-17
CVE-2026-62208 OpenClaw < 2026.6.5 Authorization Header Forwarding via SSE CWE-522 6.5 Medium 2026-07-17
CVE-2026-62207 OpenClaw < 2026.6.5 Authentication Bypass via Admin Tools CWE-862 8.8 High 2026-07-17
CVE-2026-62206 OpenClaw < 2026.6.9 Authentication Bypass via Moderation Actions CWE-862 7.1 High 2026-07-17
CVE-2026-62205 OpenClaw 2026.4.12-beta.1 < 2026.6.6 Authorization Bypass via message actions CWE-862 7.1 High 2026-07-17
CVE-2026-62203 OpenClaw < 2026.6.6 Environment Variable Injection via rustup CWE-184 8.8 High 2026-07-17
CVE-2026-62202 OpenClaw 2026.6.1 < 2026.6.9 Privilege Escalation via Cron CWE-863 8.8 High 2026-07-17

All 639 known CVE vulnerabilities affecting OpenClaw with full Chinese analysis, references, and POCs where available.