Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

OpenClaw — Vulnerabilities & Security Advisories 573

All 573 CVE vulnerabilities found in OpenClaw, with AI-generated Chinese analysis, references, and POCs.

This page documents security vulnerabilities and weaknesses associated with OpenClaw, a software product developed by OpenClaw, categorized by Common Weakness Enumeration (CWE) classifications. It aggregates a comprehensive collection of identified security flaws, ranging from buffer overflows and injection vulnerabilities to authentication bypasses and permission issues. The data spans from the earliest recorded disclosures up to the most recent updates, ensuring a chronological view of the product’s security landscape over time. Here, you can track a vendor's advisories to understand the context and severity of reported issues, understand a weakness class by seeing how specific CWEs manifest in this particular codebase, and look up a product's vulnerability history to identify patterns or recurring issues that may indicate systemic design flaws. This resource is intended for security professionals, developers, and analysts who need to assess the risk profile of OpenClaw installations. By reviewing these aggregated details, users can better prioritize remediation efforts and compare the stability of this product against industry standards. The information is structured to facilitate efficient research, allowing for quick identification of relevant CVEs and associated metadata without unnecessary noise. This approach supports informed decision-making regarding patch deployment and long-term security maintenance strategies for organizations relying on OpenClaw services.

Vendor: OpenClaw

CVE ID Title CVSS Severity Published
CVE-2026-62229 OpenClaw < 2026.5.18 Authorization Bypass via Glob Matching CWE-22 8.8 High 2026-07-17
CVE-2026-62228 OpenClaw < 2026.6.5 Authorization Bypass via Node Exec Approvals CWE-863 8.8 High 2026-07-17
CVE-2026-62227 OpenClaw 2026.4.14 < 2026.5.26 SSRF via Browser Snapshot CWE-918 7.7 High 2026-07-17
CVE-2026-62225 OpenClaw < 2026.5.18 Authorization Bypass via Skill Command Dispatch CWE-863 5.4 Medium 2026-07-17
CVE-2026-62226 OpenClaw 2026.3.28 < 2026.5.19 Authorization Bypass via Browser Act Route CWE-918 8.5 High 2026-07-17
CVE-2026-62222 OpenClaw < 2026.5.22 Untrusted Plugin Loading via Setup-mode CWE-829 7.8 High 2026-07-17
CVE-2026-62223 OpenClaw < 2026.5.18 Authorization Bypass via Device-pair CWE-863 8.8 High 2026-07-17
CVE-2026-62221 OpenClaw 2026.5.12 < 2026.5.26 Authorization Bypass via allowFrom CWE-863 5.4 Medium 2026-07-17
CVE-2026-62219 OpenClaw 2026.2.12 < 2026.5.26 Authorization Bypass via Blank Agent IDs CWE-863 7.1 High 2026-07-17
CVE-2026-62220 OpenClaw 2026.2.25 < 2026.5.26 WebSocket Rate Limit Bypass CWE-307 5.3 Medium 2026-07-17
CVE-2026-62218 OpenClaw 2026.1.20 < 2026.5.27 Authorization Bypass via device.pair.approve CWE-862 8.8 High 2026-07-17
CVE-2026-62217 OpenClaw 2026.5.14-beta.1 < 2026.5.27 Authentication Bypass via exec approvals CWE-863 8.8 High 2026-07-17
CVE-2026-62216 OpenClaw 2026.4.20 < 2026.5.28 Policy Bypass via Media Upload CWE-918 5.0 Medium 2026-07-17
CVE-2026-62215 OpenClaw < 2026.6.5 Authentication Bypass via HTTP Canvas CWE-345 8.0 High 2026-07-17
CVE-2026-62212 OpenClaw < 2026.5.28 Authentication Bypass via safeFetch CWE-367 7.1 High 2026-07-17
CVE-2026-62211 OpenClaw < 2026.6.1 Credential Redaction Bypass via Trajectory Export CWE-532 5.0 Medium 2026-07-17
CVE-2026-62209 OpenClaw 2026.5.10-beta.1 < 2026.6.5 Authorization Bypass via agent-mode dispatch CWE-863 8.1 High 2026-07-17
CVE-2026-62210 OpenClaw < 2026.6.1 Denial of Service via Remote Media URLs CWE-770 6.5 Medium 2026-07-17
CVE-2026-62208 OpenClaw < 2026.6.5 Authorization Header Forwarding via SSE CWE-522 6.5 Medium 2026-07-17
CVE-2026-62206 OpenClaw < 2026.6.9 Authentication Bypass via Moderation Actions CWE-862 7.1 High 2026-07-17
CVE-2026-62207 OpenClaw < 2026.6.5 Authentication Bypass via Admin Tools CWE-862 8.8 High 2026-07-17
CVE-2026-62205 OpenClaw 2026.4.12-beta.1 < 2026.6.6 Authorization Bypass via message actions CWE-862 7.1 High 2026-07-17
CVE-2026-62203 OpenClaw < 2026.6.6 Environment Variable Injection via rustup CWE-184 8.8 High 2026-07-17
CVE-2026-62202 OpenClaw 2026.6.1 < 2026.6.9 Privilege Escalation via Cron CWE-863 8.8 High 2026-07-17
CVE-2026-62201 OpenClaw < 2026.6.6 Network Policy Bypass via exec-server CWE-918 7.7 High 2026-07-17
CVE-2026-62199 OpenClaw < 2026.6.6 Authentication Bypass via Environment Filtering CWE-184 8.8 High 2026-07-13
CVE-2026-62200 OpenClaw < 2026.6.6 Authentication Bypass via Git ext transport CWE-184 8.8 High 2026-07-13
CVE-2026-62198 OpenClaw 2026.5.28 < 2026.6.6 Authorization Bypass via Web Search CWE-863 4.3 Medium 2026-07-13
CVE-2026-62197 OpenClaw < 2026.6.6 Policy Bypass via CDP Discovery CWE-918 8.5 High 2026-07-13
CVE-2026-62196 OpenClaw 2026.3.22 < 2026.6.6 Authorization Bypass via WhatsApp Group IDs CWE-863 8.3 High 2026-07-13

All 573 known CVE vulnerabilities affecting OpenClaw with full Chinese analysis, references, and POCs where available.