Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

OpenClaw — Vulnerabilities & Security Advisories 639

All 639 CVE vulnerabilities found in OpenClaw, with AI-generated Chinese analysis, references, and POCs.

This page aggregates known security vulnerabilities affecting OpenClaw, a software product, categorized by specific weakness types. It collects publicly disclosed security flaws, including buffer overflows, injection issues, and authentication bypasses, spanning the period from the product's initial release through the latest available advisories. Visitors can track the vendor's published security notices, analyze patterns within a specific weakness class, and review the complete historical record of vulnerabilities identified in OpenClaw. The data is organized to facilitate trend analysis and risk assessment, allowing security teams to identify recurring defect classes and evaluate the severity distribution over time. All entries are sourced from public vulnerability databases and official vendor bulletins, ensuring traceability and consistency in reporting standards. Users can filter results by date range, impact score, or component module to focus on relevant subsets of findings. The collection serves as a centralized reference for tracking how OpenClaw's security posture has evolved, supporting maintenance planning and compliance reporting without relying on scattered external sources.

Vendor: OpenClaw

CVE ID Title CVSS Severity Published
CVE-2026-44998 OpenClaw < 2026.4.20 - Tool Policy Bypass via Bundled MCP/LSP Tools CWE-863 5.4 Medium 2026-05-11
CVE-2026-44997 OpenClaw < 2026.4.22 - Security Envelope Constraint Bypass in ACP Child Sessions CWE-266 4.3 Medium 2026-05-11
CVE-2026-44996 OpenClaw < 2026.4.15 - Arbitrary Local File Read via Webchat Audio Embedding CWE-22 3.7 Low 2026-05-11
CVE-2026-44995 OpenClaw < 2026.4.20 - Arbitrary Code Execution via MCP stdio Environment Variables CWE-829 7.3 High 2026-05-11
CVE-2026-44994 OpenClaw < 2026.4.22 - Authentication Bypass in Gateway Control UI Bootstrap Config Endpoint CWE-862 5.3 Medium 2026-05-11
CVE-2026-44993 OpenClaw < 2026.4.20 - Direct Message Misclassification in Feishu Card Actions CWE-184 5.4 Medium 2026-05-11
CVE-2026-44992 OpenClaw 2026.4.5 through 2026.4.19 - MiniMax API Host Override via Workspace dotenv CWE-441 5.0 Medium 2026-05-11
CVE-2026-44991 OpenClaw < 2026.4.21 - Authorization Bypass in Owner-Enforced Commands via Wildcard Channel Senders CWE-863 4.2 Medium 2026-05-11
CVE-2026-8305 OpenClaw bluebubbles Webhook monitor.ts handleBlueBubblesWebhookRequest improper authentication CWE-287 7.3 High 2026-05-11
CVE-2026-44118 OpenClaw < 2026.4.22 - Owner Context Spoofing via Bearer Token Header CWE-290 7.8 High 2026-05-06
CVE-2026-44116 OpenClaw < 2026.4.22 - Server-Side Request Forgery in Zalo Photo URL Validation CWE-918 8.6 High 2026-05-06
CVE-2026-44117 OpenClaw < 2026.4.20 - Server-Side Request Forgery in QQBot Direct Media Upload CWE-918 5.8 Medium 2026-05-06
CVE-2026-44115 OpenClaw < 2026.4.22 - Shell Expansion Bypass in Unquoted Heredocs via Exec Allowlist CWE-184 8.8 High 2026-05-06
CVE-2026-44114 OpenClaw < 2026.4.20 - Environment Variable Namespace Collision via Workspace dotenv CWE-184 7.8 High 2026-05-06
CVE-2026-44112 OpenClaw < 2026.4.22 - Symlink Swap Race Condition in OpenShell FS Bridge Writes CWE-367 9.6 Critical 2026-05-06
CVE-2026-44113 OpenClaw < 2026.4.22 - Time-of-Check/Time-of-Use Race Condition in OpenShell FS Bridge CWE-367 7.7 High 2026-05-06
CVE-2026-44111 OpenClaw < 2026.4.15 - Arbitrary Markdown File Read via QMD memory_get CWE-183 4.3 Medium 2026-05-06
CVE-2026-44110 OpenClaw < 2026.4.15 - Authorization Bypass in Matrix Room Control Commands via DM Pairing Store CWE-863 8.8 High 2026-05-06
CVE-2026-44109 OpenClaw < 2026.4.15 - Authentication Bypass in Feishu Webhook and Card-Action Validation CWE-1188 9.8 Critical 2026-05-06
CVE-2026-43585 OpenClaw < 2026.4.15 - Bearer Token Validation Bypass via Stale SecretRef Resolution CWE-672 8.1 High 2026-05-06
CVE-2026-43584 OpenClaw < 2026.4.10 - Insufficient Environment Variable Denylist in Exec Policy CWE-184 8.8 High 2026-05-06
CVE-2026-43583 OpenClaw 2026.4.10 < 2026.4.14 - Loss of Group Tool-Policy Context in Delivery Queue Recovery CWE-862 5.3 Medium 2026-05-06
CVE-2026-43582 OpenClaw < 2026.4.10 - DNS Rebinding SSRF via Hostname Validation Bypass CWE-367 6.3 Medium 2026-05-06
CVE-2026-43581 OpenClaw < 2026.4.10 - Chrome DevTools Protocol Exposure via Overly Broad CDP Relay Binding CWE-1188 9.6 Critical 2026-05-06
CVE-2026-43580 OpenClaw < 2026.4.10 - Incomplete Navigation Guard Coverage in Browser Interactions CWE-862 7.7 High 2026-05-06
CVE-2026-43579 OpenClaw < 2026.4.10 - Insufficient Access Control in Nostr Profile Mutation Routes CWE-862 6.5 Medium 2026-05-06
CVE-2026-43578 OpenClaw 2026.3.31 < 2026.4.10 - Privilege Escalation via Missed Async Exec Completion Events in Heartbeat Owner Downgrade CWE-184 9.1 Critical 2026-05-06
CVE-2026-43577 OpenClaw < 2026.4.9 - Arbitrary File Read via Browser Interaction Routes CWE-862 6.5 Medium 2026-05-06
CVE-2026-43575 OpenClaw 2026.2.21 < 2026.4.10 - Authentication Bypass in Sandbox noVNC Helper Route CWE-862 9.8 Critical 2026-05-06
CVE-2026-43576 OpenClaw < 2026.4.5 - Second-hop SSRF via CDP /json/version WebSocket URL CWE-601 7.7 High 2026-05-06

All 639 known CVE vulnerabilities affecting OpenClaw with full Chinese analysis, references, and POCs where available.