Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

OpenClaw — Vulnerabilities & Security Advisories 573

All 573 CVE vulnerabilities found in OpenClaw, with AI-generated Chinese analysis, references, and POCs.

This page documents security vulnerabilities and weaknesses associated with OpenClaw, a software product developed by OpenClaw, categorized by Common Weakness Enumeration (CWE) classifications. It aggregates a comprehensive collection of identified security flaws, ranging from buffer overflows and injection vulnerabilities to authentication bypasses and permission issues. The data spans from the earliest recorded disclosures up to the most recent updates, ensuring a chronological view of the product’s security landscape over time. Here, you can track a vendor's advisories to understand the context and severity of reported issues, understand a weakness class by seeing how specific CWEs manifest in this particular codebase, and look up a product's vulnerability history to identify patterns or recurring issues that may indicate systemic design flaws. This resource is intended for security professionals, developers, and analysts who need to assess the risk profile of OpenClaw installations. By reviewing these aggregated details, users can better prioritize remediation efforts and compare the stability of this product against industry standards. The information is structured to facilitate efficient research, allowing for quick identification of relevant CVEs and associated metadata without unnecessary noise. This approach supports informed decision-making regarding patch deployment and long-term security maintenance strategies for organizations relying on OpenClaw services.

Vendor: OpenClaw

CVE ID Title CVSS Severity Published
CVE-2026-44993 OpenClaw < 2026.4.20 - Direct Message Misclassification in Feishu Card Actions CWE-184 5.4 Medium 2026-05-11
CVE-2026-44991 OpenClaw < 2026.4.21 - Authorization Bypass in Owner-Enforced Commands via Wildcard Channel Senders CWE-863 4.2 Medium 2026-05-11
CVE-2026-8305 OpenClaw bluebubbles Webhook monitor.ts handleBlueBubblesWebhookRequest improper authentication CWE-287 7.3 High 2026-05-11
CVE-2026-44118 OpenClaw < 2026.4.22 - Owner Context Spoofing via Bearer Token Header CWE-290 7.8 High 2026-05-06
CVE-2026-44116 OpenClaw < 2026.4.22 - Server-Side Request Forgery in Zalo Photo URL Validation CWE-918 8.6 High 2026-05-06
CVE-2026-44117 OpenClaw < 2026.4.20 - Server-Side Request Forgery in QQBot Direct Media Upload CWE-918 5.8 Medium 2026-05-06
CVE-2026-44115 OpenClaw < 2026.4.22 - Shell Expansion Bypass in Unquoted Heredocs via Exec Allowlist CWE-184 8.8 High 2026-05-06
CVE-2026-44114 OpenClaw < 2026.4.20 - Environment Variable Namespace Collision via Workspace dotenv CWE-184 7.8 High 2026-05-06
CVE-2026-44112 OpenClaw < 2026.4.22 - Symlink Swap Race Condition in OpenShell FS Bridge Writes CWE-367 9.6 Critical 2026-05-06
CVE-2026-44113 OpenClaw < 2026.4.22 - Time-of-Check/Time-of-Use Race Condition in OpenShell FS Bridge CWE-367 7.7 High 2026-05-06
CVE-2026-44111 OpenClaw < 2026.4.15 - Arbitrary Markdown File Read via QMD memory_get CWE-183 4.3 Medium 2026-05-06
CVE-2026-44109 OpenClaw < 2026.4.15 - Authentication Bypass in Feishu Webhook and Card-Action Validation CWE-1188 9.8 Critical 2026-05-06
CVE-2026-44110 OpenClaw < 2026.4.15 - Authorization Bypass in Matrix Room Control Commands via DM Pairing Store CWE-863 8.8 High 2026-05-06
CVE-2026-43585 OpenClaw < 2026.4.15 - Bearer Token Validation Bypass via Stale SecretRef Resolution CWE-672 8.1 High 2026-05-06
CVE-2026-43584 OpenClaw < 2026.4.10 - Insufficient Environment Variable Denylist in Exec Policy CWE-184 8.8 High 2026-05-06
CVE-2026-43582 OpenClaw < 2026.4.10 - DNS Rebinding SSRF via Hostname Validation Bypass CWE-367 6.3 Medium 2026-05-06
CVE-2026-43583 OpenClaw 2026.4.10 < 2026.4.14 - Loss of Group Tool-Policy Context in Delivery Queue Recovery CWE-862 5.3 Medium 2026-05-06
CVE-2026-43581 OpenClaw < 2026.4.10 - Chrome DevTools Protocol Exposure via Overly Broad CDP Relay Binding CWE-1188 9.6 Critical 2026-05-06
CVE-2026-43579 OpenClaw < 2026.4.10 - Insufficient Access Control in Nostr Profile Mutation Routes CWE-862 6.5 Medium 2026-05-06
CVE-2026-43580 OpenClaw < 2026.4.10 - Incomplete Navigation Guard Coverage in Browser Interactions CWE-862 7.7 High 2026-05-06
CVE-2026-43578 OpenClaw 2026.3.31 < 2026.4.10 - Privilege Escalation via Missed Async Exec Completion Events in Heartbeat Owner Downgrade CWE-184 9.1 Critical 2026-05-06
CVE-2026-43577 OpenClaw < 2026.4.9 - Arbitrary File Read via Browser Interaction Routes CWE-862 6.5 Medium 2026-05-06
CVE-2026-43575 OpenClaw 2026.2.21 < 2026.4.10 - Authentication Bypass in Sandbox noVNC Helper Route CWE-862 9.8 Critical 2026-05-06
CVE-2026-43576 OpenClaw < 2026.4.5 - Second-hop SSRF via CDP /json/version WebSocket URL CWE-601 7.7 High 2026-05-06
CVE-2026-43574 OpenClaw < 2026.4.12 - Improper Authorization via Empty Approver Lists CWE-183 6.5 Medium 2026-05-05
CVE-2026-43573 OpenClaw < 2026.4.10 - SSRF Policy Bypass in Existing-Session Browser Interaction Routes CWE-862 7.7 High 2026-05-05
CVE-2026-43572 OpenClaw 2026.4.10 < 2026.4.14 - Missing Sender Authorization in Microsoft Teams SSO Invoke Handler CWE-862 5.3 Medium 2026-05-05
CVE-2026-43571 OpenClaw < 2026.4.10 - Untrusted Workspace Plugin Shadow Resolution in Channel Setup CWE-829 8.8 High 2026-05-05
CVE-2026-43570 OpenClaw 2026.3.22 < 2026.4.5 - Symlink Traversal in Remote Marketplace Repository Path Handling CWE-61 6.5 Medium 2026-05-05
CVE-2026-43569 OpenClaw < 2026.4.9 - Untrusted Provider Plugin Auto-enablement via Workspace Provider Auth CWE-829 8.8 High 2026-05-05

All 573 known CVE vulnerabilities affecting OpenClaw with full Chinese analysis, references, and POCs where available.