Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

openclaw — Vulnerabilities & Security Advisories 573

All 573 CVE vulnerabilities found in openclaw, with AI-generated Chinese analysis, references, and POCs.

This page documents security vulnerabilities and weaknesses associated with OpenClaw, a software product developed by OpenClaw, categorized by Common Weakness Enumeration (CWE) classifications. It aggregates a comprehensive collection of identified security flaws, ranging from buffer overflows and injection vulnerabilities to authentication bypasses and permission issues. The data spans from the earliest recorded disclosures up to the most recent updates, ensuring a chronological view of the product’s security landscape over time. Here, you can track a vendor's advisories to understand the context and severity of reported issues, understand a weakness class by seeing how specific CWEs manifest in this particular codebase, and look up a product's vulnerability history to identify patterns or recurring issues that may indicate systemic design flaws. This resource is intended for security professionals, developers, and analysts who need to assess the risk profile of OpenClaw installations. By reviewing these aggregated details, users can better prioritize remediation efforts and compare the stability of this product against industry standards. The information is structured to facilitate efficient research, allowing for quick identification of relevant CVEs and associated metadata without unnecessary noise. This approach supports informed decision-making regarding patch deployment and long-term security maintenance strategies for organizations relying on OpenClaw services.

Vendor: OpenClaw

CVE IDTitleCVSSSeverityPublished
CVE-2026-53845 OpenClaw < 2026.5.6 - Skill-Command Dispatch Hook Bypass via Before-Tool-Call Hook Skipping CWE-693 4.3 Medium2026-06-16
CVE-2026-53844 OpenClaw < 2026.4.29 - Session Visibility Check Bypass in Shared Memory Search CWE-862 6.5 Medium2026-06-16
CVE-2026-53843 OpenClaw < 2026.5.26 - Node Token Revocation Bypass via Pairing-Scoped Device Session CWE-613 8.8 High2026-06-16
CVE-2026-53842 OpenClaw < 2026.5.2 - Arbitrary Python Runtime Execution via CLOUDSDK_PYTHON Environment Variable CWE-426 7.1 High2026-06-16
CVE-2026-53841 OpenClaw < 2026.5.12 - Cross-Site Scripting via Unsafe Markdown Links in Exported Session HTML CWE-83 6.1 Medium2026-06-16
CVE-2026-53840 OpenClaw < 2026.5.12 - Custom Header Leakage via MCP Streamable HTTP Cross-Origin Redirects CWE-522 7.1 High2026-06-16
CVE-2026-53839 OpenClaw < 2026.5.7 - Hostname Prefix Matching Bypass in Trusted Retry Endpoint Validation CWE-1023 6.5 Medium2026-06-12
CVE-2026-53838 OpenClaw < 2026.5.27 - Node Pairing State Mutation via Reconnection CWE-367 9.8 Critical2026-06-12
CVE-2026-53837 OpenClaw < 2026.5.6 - Missing Channel Type Validation in Mattermost Event Handlers CWE-636 3.7 Low2026-06-12
CVE-2026-53836 OpenClaw < 2026.5.12 - Allowlist Bypass via PowerShell Encoded-Command Aliases CWE-184 8.8 High2026-06-12
CVE-2026-53835 OpenClaw < 2026.5.6 - Config-Write Enforcement Bypass in Feishu Dynamic-Agent Bindings CWE-863 4.3 Medium2026-06-12
CVE-2026-53834 OpenClaw < 2026.4.27 - Authorization Bypass in QQBot Pre-dispatch Slash Commands CWE-863 7.5 High2026-06-12
CVE-2026-53833 QQBot for OpenClaw < 2026.4.29 - Authorization Bypass via QQBot Streaming Command CWE-290 7.7 High2026-06-12
CVE-2026-53832 OpenClaw < 2026.5.18 - Identity Header Forgery via Trusted-Proxy Configuration CWE-290 7.7 High2026-06-12
CVE-2026-53831 OpenClaw < 2026.5.18 - Arbitrary File Read via Shell Expansion in system.run Safe-bin Allowlist CWE-367 8.3 High2026-06-12
CVE-2026-53830 OpenClaw < 2026.4.22 - Webhook Secret Revocation Bypass via secrets.reload CWE-613 6.5 Medium2026-06-12
CVE-2026-53829 OpenClaw < 2026.5.18 - Command Truncation in Exec Approval Display CWE-451 8.0 High2026-06-12
CVE-2026-53827 OpenClaw < 2026.5.2 - Credential Exposure via Model-Supplied Loopback URLs in message.action Forwarding CWE-918 6.5 Medium2026-06-12
CVE-2026-53828 OpenClaw < 2026.5.6 - Native Command Authorization Bypass via Owner-Command Enforcement CWE-863 8.8 High2026-06-12
CVE-2026-53826 OpenClaw < 2026.4.26 - Information Disclosure via Sandboxed Session Spawn CWE-668 4.3 Medium2026-06-12
CVE-2026-53824 Mattermost plugin for OpenClaw < 2026.4.24 - Slash Token Revocation Lag via Monitor Refresh Delay CWE-613 6.5 Medium2026-06-12
CVE-2026-53825 OpenClaw < 2026.4.7 - Arbitrary Local File Read via memory-wiki Ingest with operator.write Scope CWE-22 6.5 Medium2026-06-12
CVE-2026-53823 OpenClaw < 2026.5.3 - Privilege Escalation via Mutable Slack Display Names in allowFrom CWE-290 8.1 High2026-06-12
CVE-2026-53821 OpenClaw < 2026.5.18 - Scope Elevation in trusted-proxy Control UI WebSocket CWE-862 8.8 High2026-06-12
CVE-2026-53822 OpenClaw < 2026.5.18 - Command Argument Modification via Shell Wrapper Between Approval and Execution CWE-367 8.8 High2026-06-12
CVE-2026-53820 OpenClaw < 2026.5.12 - Exec Denylist Bypass in Bundle MCP Loopback Session Spawn CWE-862 6.6 Medium2026-06-12
CVE-2026-53819 OpenClaw < 2026.5.27 - Arbitrary Homebrew Executable Execution via Workspace .env Override CWE-426 8.8 High2026-06-11
CVE-2026-53818 OpenClaw < 2026.4.24 - Owner-Only Tool Policy Bypass via MCP Loopback CWE-862 6.6 Medium2026-06-11
CVE-2026-53817 OpenClaw < 2026.5.22 - Control UI Locality Spoofing in Device Pairing CWE-290 8.8 High2026-06-11
CVE-2026-53816 OpenClaw < 2026.5.18 - Exec Lifecycle Event Forgery via Paired Node CWE-862 7.2 High2026-06-11

All 573 known CVE vulnerabilities affecting openclaw with full Chinese analysis, references, and POCs where available.