Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

OpenClaw — Vulnerabilities & Security Advisories 639

All 639 CVE vulnerabilities found in OpenClaw, with AI-generated Chinese analysis, references, and POCs.

This page aggregates known security vulnerabilities affecting OpenClaw, a software product, categorized by specific weakness types. It collects publicly disclosed security flaws, including buffer overflows, injection issues, and authentication bypasses, spanning the period from the product's initial release through the latest available advisories. Visitors can track the vendor's published security notices, analyze patterns within a specific weakness class, and review the complete historical record of vulnerabilities identified in OpenClaw. The data is organized to facilitate trend analysis and risk assessment, allowing security teams to identify recurring defect classes and evaluate the severity distribution over time. All entries are sourced from public vulnerability databases and official vendor bulletins, ensuring traceability and consistency in reporting standards. Users can filter results by date range, impact score, or component module to focus on relevant subsets of findings. The collection serves as a centralized reference for tracking how OpenClaw's security posture has evolved, supporting maintenance planning and compliance reporting without relying on scattered external sources.

Vendor: OpenClaw

CVE ID Title CVSS Severity Published
CVE-2026-62201 OpenClaw < 2026.6.6 Network Policy Bypass via exec-server CWE-918 7.7 High 2026-07-17
CVE-2026-62199 OpenClaw < 2026.6.6 Authentication Bypass via Environment Filtering CWE-184 8.8 High 2026-07-13
CVE-2026-62200 OpenClaw < 2026.6.6 Authentication Bypass via Git ext transport CWE-184 8.8 High 2026-07-13
CVE-2026-62198 OpenClaw 2026.5.28 < 2026.6.6 Authorization Bypass via Web Search CWE-863 4.3 Medium 2026-07-13
CVE-2026-62197 OpenClaw < 2026.6.6 Policy Bypass via CDP Discovery CWE-918 8.5 High 2026-07-13
CVE-2026-62196 OpenClaw 2026.3.22 < 2026.6.6 Authorization Bypass via WhatsApp Group IDs CWE-863 8.3 High 2026-07-13
CVE-2026-62195 OpenClaw 2026.5.20 < 2026.6.6 Authorization Bypass via MCP loopback CWE-732 8.3 High 2026-07-13
CVE-2026-62194 OpenClaw 2026.5.20 < 2026.6.9 Privilege Escalation via Plugin Install CWE-732 8.8 High 2026-07-13
CVE-2026-62192 OpenClaw 2026.6.6 < 2026.6.9 Authorization Bypass CWE-863 8.1 High 2026-07-13
CVE-2026-62193 OpenClaw 2026.6.5 < 2026.6.9 Authentication Bypass via Plugin Install CWE-863 4.9 Medium 2026-07-13
CVE-2026-62191 OpenClaw 2026.6.6 < 2026.6.9 Authorization Bypass via Message Mutations CWE-862 7.1 High 2026-07-13
CVE-2026-62190 OpenClaw < 2026.6.9 Authorization Bypass via flock wrapper CWE-706 8.8 High 2026-07-13
CVE-2026-62189 OpenClaw < 2026.6.9 Symlink Following via Mirror Sync CWE-59 7.1 High 2026-07-13
CVE-2026-62186 OpenClaw < 2026.6.8 Authorization Bypass via HTTP Model Override CWE-862 7.6 High 2026-07-13
CVE-2026-59261 OpenClaw < 2026.5.28 - Credential Override via Workspace Dotenv Files CWE-184 7.1 High 2026-07-08
CVE-2026-53866 OpenClaw < 2026.5.12 - Allowlist Bypass in Shell Inline-Command Parsing CWE-862 8.1 High 2026-06-16
CVE-2026-53865 OpenClaw < 2026.5.2 - Arbitrary Command Execution via Workspace-Derived Service PATH CWE-426 7.1 High 2026-06-16
CVE-2026-53864 OpenClaw < 2026.5.26 - Insufficient Environment Variable Sanitization in Node.js Control Variables CWE-184 8.1 High 2026-06-16
CVE-2026-53863 OpenClaw < 2026.4.25 - Unvalidated Group ID Acceptance in Tool Group Policy CWE-639 7.1 High 2026-06-16
CVE-2026-53862 OpenClaw < 2026.5.12 - Bootstrap Token Replay via Pending Pairing Scope Widening CWE-266 4.2 Medium 2026-06-16
CVE-2026-53861 OpenClaw < 2026.5.6 - Allowlist Bypass via Combined POSIX Inline Flags on macOS CWE-184 6.6 Medium 2026-06-16
CVE-2026-53859 OpenClaw < 2026.5.26 - Hostname Validation Bypass via Trailing-Dot Inconsistency CWE-1023 6.5 Medium 2026-06-16
CVE-2026-53860 OpenClaw < 2026.5.7 - Sender Policy Bypass via Mutable Conversation Identifiers in BlueBubbles CWE-807 4.2 Medium 2026-06-16
CVE-2026-53858 OpenClaw < 2026.5.2 - Arbitrary Runtime Dependency Loading via STATE_DIRECTORY Environment Variable CWE-426 7.1 High 2026-06-16
CVE-2026-53857 OpenClaw < 2026.5.3 - Mutable Display Name Binding in Zalo allowFrom Policy CWE-290 8.1 High 2026-06-16
CVE-2026-53855 OpenClaw < 2026.4.2 - Shell Positional Parameters Bypass in Inline-Eval Checks CWE-184 8.1 High 2026-06-16
CVE-2026-53856 OpenClaw 2026.4.23 < 2026.4.24 - Insecure File Permissions in Config Recovery via OpenClaw.json CWE-732 5.5 Medium 2026-06-16
CVE-2026-53854 OpenClaw < 2026.4.25 - Privilege Escalation via ownerAllowFrom Wildcard Inheritance in Internal/Webchat Commands CWE-863 6.5 Medium 2026-06-16
CVE-2026-53852 OpenClaw < 2026.4.25 - Scope Bypass via Empty-Scope Device Re-pairing CWE-636 5.4 Medium 2026-06-16
CVE-2026-53853 OpenClaw < 2026.5.12 - Argument Pattern Bypass in Exec Allowlist via Linux and macOS CWE-693 8.3 High 2026-06-16

All 639 known CVE vulnerabilities affecting OpenClaw with full Chinese analysis, references, and POCs where available.