Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

openclaw — Vulnerabilities & Security Advisories 573

All 573 CVE vulnerabilities found in openclaw, with AI-generated Chinese analysis, references, and POCs.

This page documents security vulnerabilities and weaknesses associated with OpenClaw, a software product developed by OpenClaw, categorized by Common Weakness Enumeration (CWE) classifications. It aggregates a comprehensive collection of identified security flaws, ranging from buffer overflows and injection vulnerabilities to authentication bypasses and permission issues. The data spans from the earliest recorded disclosures up to the most recent updates, ensuring a chronological view of the product’s security landscape over time. Here, you can track a vendor's advisories to understand the context and severity of reported issues, understand a weakness class by seeing how specific CWEs manifest in this particular codebase, and look up a product's vulnerability history to identify patterns or recurring issues that may indicate systemic design flaws. This resource is intended for security professionals, developers, and analysts who need to assess the risk profile of OpenClaw installations. By reviewing these aggregated details, users can better prioritize remediation efforts and compare the stability of this product against industry standards. The information is structured to facilitate efficient research, allowing for quick identification of relevant CVEs and associated metadata without unnecessary noise. This approach supports informed decision-making regarding patch deployment and long-term security maintenance strategies for organizations relying on OpenClaw services.

Vendor: OpenClaw

CVE IDTitleCVSSSeverityPublished
CVE-2026-62195 OpenClaw 2026.5.20 < 2026.6.6 Authorization Bypass via MCP loopback CWE-732 8.3 High2026-07-13
CVE-2026-62194 OpenClaw 2026.5.20 < 2026.6.9 Privilege Escalation via Plugin Install CWE-732 8.8 High2026-07-13
CVE-2026-62192 OpenClaw 2026.6.6 < 2026.6.9 Authorization Bypass CWE-863 8.1 High2026-07-13
CVE-2026-62193 OpenClaw 2026.6.5 < 2026.6.9 Authentication Bypass via Plugin Install CWE-863 4.9 Medium2026-07-13
CVE-2026-62191 OpenClaw 2026.6.6 < 2026.6.9 Authorization Bypass via Message Mutations CWE-862 7.1 High2026-07-13
CVE-2026-62189 OpenClaw < 2026.6.9 Symlink Following via Mirror Sync CWE-59 7.1 High2026-07-13
CVE-2026-62190 OpenClaw < 2026.6.9 Authorization Bypass via flock wrapper CWE-706 8.8 High2026-07-13
CVE-2026-62186 OpenClaw < 2026.6.8 Authorization Bypass via HTTP Model Override CWE-862 7.6 High2026-07-13
CVE-2026-59261 OpenClaw < 2026.5.28 - Credential Override via Workspace Dotenv Files CWE-184 7.1 High2026-07-08
CVE-2026-53865 OpenClaw < 2026.5.2 - Arbitrary Command Execution via Workspace-Derived Service PATH CWE-426 7.1 High2026-06-16
CVE-2026-53866 OpenClaw < 2026.5.12 - Allowlist Bypass in Shell Inline-Command Parsing CWE-862 8.1 High2026-06-16
CVE-2026-53864 OpenClaw < 2026.5.26 - Insufficient Environment Variable Sanitization in Node.js Control Variables CWE-184 8.1 High2026-06-16
CVE-2026-53863 OpenClaw < 2026.4.25 - Unvalidated Group ID Acceptance in Tool Group Policy CWE-639 7.1 High2026-06-16
CVE-2026-53862 OpenClaw < 2026.5.12 - Bootstrap Token Replay via Pending Pairing Scope Widening CWE-266 4.2 Medium2026-06-16
CVE-2026-53861 OpenClaw < 2026.5.6 - Allowlist Bypass via Combined POSIX Inline Flags on macOS CWE-184 6.6 Medium2026-06-16
CVE-2026-53859 OpenClaw < 2026.5.26 - Hostname Validation Bypass via Trailing-Dot Inconsistency CWE-1023 6.5 Medium2026-06-16
CVE-2026-53860 OpenClaw < 2026.5.7 - Sender Policy Bypass via Mutable Conversation Identifiers in BlueBubbles CWE-807 4.2 Medium2026-06-16
CVE-2026-53858 OpenClaw < 2026.5.2 - Arbitrary Runtime Dependency Loading via STATE_DIRECTORY Environment Variable CWE-426 7.1 High2026-06-16
CVE-2026-53857 OpenClaw < 2026.5.3 - Mutable Display Name Binding in Zalo allowFrom Policy CWE-290 8.1 High2026-06-16
CVE-2026-53855 OpenClaw < 2026.4.2 - Shell Positional Parameters Bypass in Inline-Eval Checks CWE-184 8.1 High2026-06-16
CVE-2026-53856 OpenClaw 2026.4.23 < 2026.4.24 - Insecure File Permissions in Config Recovery via OpenClaw.json CWE-732 5.5 Medium2026-06-16
CVE-2026-53854 OpenClaw < 2026.4.25 - Privilege Escalation via ownerAllowFrom Wildcard Inheritance in Internal/Webchat Commands CWE-863 6.5 Medium2026-06-16
CVE-2026-53852 OpenClaw < 2026.4.25 - Scope Bypass via Empty-Scope Device Re-pairing CWE-636 5.4 Medium2026-06-16
CVE-2026-53853 OpenClaw < 2026.5.12 - Argument Pattern Bypass in Exec Allowlist via Linux and macOS CWE-693 8.3 High2026-06-16
CVE-2026-53851 OpenClaw < 2026.5.12 - Slack Reaction Event Notification Bypass CWE-862 5.3 Medium2026-06-16
CVE-2026-53849 OpenClaw < 2026.5.7 - Privilege Escalation via Mutable Discord Display Names in allowFrom CWE-290 8.1 High2026-06-16
CVE-2026-53850 OpenClaw < 2026.4.25 - Control Scope Enforcement Bypass in Focus Command CWE-862 5.5 Medium2026-06-16
CVE-2026-53848 OpenClaw < 2026.5.26 - Exec Allowlist Bypass via Transparent Command Wrappers CWE-184 4.3 Medium2026-06-16
CVE-2026-53847 OpenClaw < 2026.5.6 - Privilege Escalation via Active Memory Write Scope CWE-266 5.4 Medium2026-06-16
CVE-2026-53845 OpenClaw < 2026.5.6 - Skill-Command Dispatch Hook Bypass via Before-Tool-Call Hook Skipping CWE-693 4.3 Medium2026-06-16

All 573 known CVE vulnerabilities affecting openclaw with full Chinese analysis, references, and POCs where available.