Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

openclaw — Vulnerabilities & Security Advisories 573

All 573 CVE vulnerabilities found in openclaw, with AI-generated Chinese analysis, references, and POCs.

This page documents security vulnerabilities and weaknesses associated with OpenClaw, a software product developed by OpenClaw, categorized by Common Weakness Enumeration (CWE) classifications. It aggregates a comprehensive collection of identified security flaws, ranging from buffer overflows and injection vulnerabilities to authentication bypasses and permission issues. The data spans from the earliest recorded disclosures up to the most recent updates, ensuring a chronological view of the product’s security landscape over time. Here, you can track a vendor's advisories to understand the context and severity of reported issues, understand a weakness class by seeing how specific CWEs manifest in this particular codebase, and look up a product's vulnerability history to identify patterns or recurring issues that may indicate systemic design flaws. This resource is intended for security professionals, developers, and analysts who need to assess the risk profile of OpenClaw installations. By reviewing these aggregated details, users can better prioritize remediation efforts and compare the stability of this product against industry standards. The information is structured to facilitate efficient research, allowing for quick identification of relevant CVEs and associated metadata without unnecessary noise. This approach supports informed decision-making regarding patch deployment and long-term security maintenance strategies for organizations relying on OpenClaw services.

Vendor: OpenClaw

CVE IDTitleCVSSSeverityPublished
CVE-2026-62229 OpenClaw < 2026.5.18 Authorization Bypass via Glob Matching CWE-22 8.8 High2026-07-17
CVE-2026-62228 OpenClaw < 2026.6.5 Authorization Bypass via Node Exec Approvals CWE-863 8.8 High2026-07-17
CVE-2026-62227 OpenClaw 2026.4.14 < 2026.5.26 SSRF via Browser Snapshot CWE-918 7.7 High2026-07-17
CVE-2026-62225 OpenClaw < 2026.5.18 Authorization Bypass via Skill Command Dispatch CWE-863 5.4 Medium2026-07-17
CVE-2026-62226 OpenClaw 2026.3.28 < 2026.5.19 Authorization Bypass via Browser Act Route CWE-918 8.5 High2026-07-17
CVE-2026-62222 OpenClaw < 2026.5.22 Untrusted Plugin Loading via Setup-mode CWE-829 7.8 High2026-07-17
CVE-2026-62223 OpenClaw < 2026.5.18 Authorization Bypass via Device-pair CWE-863 8.8 High2026-07-17
CVE-2026-62221 OpenClaw 2026.5.12 < 2026.5.26 Authorization Bypass via allowFrom CWE-863 5.4 Medium2026-07-17
CVE-2026-62219 OpenClaw 2026.2.12 < 2026.5.26 Authorization Bypass via Blank Agent IDs CWE-863 7.1 High2026-07-17
CVE-2026-62220 OpenClaw 2026.2.25 < 2026.5.26 WebSocket Rate Limit Bypass CWE-307 5.3 Medium2026-07-17
CVE-2026-62218 OpenClaw 2026.1.20 < 2026.5.27 Authorization Bypass via device.pair.approve CWE-862 8.8 High2026-07-17
CVE-2026-62217 OpenClaw 2026.5.14-beta.1 < 2026.5.27 Authentication Bypass via exec approvals CWE-863 8.8 High2026-07-17
CVE-2026-62216 OpenClaw 2026.4.20 < 2026.5.28 Policy Bypass via Media Upload CWE-918 5.0 Medium2026-07-17
CVE-2026-62215 OpenClaw < 2026.6.5 Authentication Bypass via HTTP Canvas CWE-345 8.0 High2026-07-17
CVE-2026-62212 OpenClaw < 2026.5.28 Authentication Bypass via safeFetch CWE-367 7.1 High2026-07-17
CVE-2026-62211 OpenClaw < 2026.6.1 Credential Redaction Bypass via Trajectory Export CWE-532 5.0 Medium2026-07-17
CVE-2026-62209 OpenClaw 2026.5.10-beta.1 < 2026.6.5 Authorization Bypass via agent-mode dispatch CWE-863 8.1 High2026-07-17
CVE-2026-62210 OpenClaw < 2026.6.1 Denial of Service via Remote Media URLs CWE-770 6.5 Medium2026-07-17
CVE-2026-62208 OpenClaw < 2026.6.5 Authorization Header Forwarding via SSE CWE-522 6.5 Medium2026-07-17
CVE-2026-62206 OpenClaw < 2026.6.9 Authentication Bypass via Moderation Actions CWE-862 7.1 High2026-07-17
CVE-2026-62207 OpenClaw < 2026.6.5 Authentication Bypass via Admin Tools CWE-862 8.8 High2026-07-17
CVE-2026-62205 OpenClaw 2026.4.12-beta.1 < 2026.6.6 Authorization Bypass via message actions CWE-862 7.1 High2026-07-17
CVE-2026-62203 OpenClaw < 2026.6.6 Environment Variable Injection via rustup CWE-184 8.8 High2026-07-17
CVE-2026-62202 OpenClaw 2026.6.1 < 2026.6.9 Privilege Escalation via Cron CWE-863 8.8 High2026-07-17
CVE-2026-62201 OpenClaw < 2026.6.6 Network Policy Bypass via exec-server CWE-918 7.7 High2026-07-17
CVE-2026-62199 OpenClaw < 2026.6.6 Authentication Bypass via Environment Filtering CWE-184 8.8 High2026-07-13
CVE-2026-62200 OpenClaw < 2026.6.6 Authentication Bypass via Git ext transport CWE-184 8.8 High2026-07-13
CVE-2026-62198 OpenClaw 2026.5.28 < 2026.6.6 Authorization Bypass via Web Search CWE-863 4.3 Medium2026-07-13
CVE-2026-62197 OpenClaw < 2026.6.6 Policy Bypass via CDP Discovery CWE-918 8.5 High2026-07-13
CVE-2026-62196 OpenClaw 2026.3.22 < 2026.6.6 Authorization Bypass via WhatsApp Group IDs CWE-863 8.3 High2026-07-13

All 573 known CVE vulnerabilities affecting openclaw with full Chinese analysis, references, and POCs where available.