Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

OpenClaw — Vulnerabilities & Security Advisories 581

Browse all 581 CVE security advisories affecting OpenClaw. AI-powered Chinese analysis, POCs, and references for each vulnerability.

OpenClaw is a specialized software platform designed for automated threat intelligence aggregation and vulnerability management, primarily serving enterprise security operations centers. Historically, its codebase has exhibited a high frequency of critical flaws, with 428 CVEs documented to date. The most prevalent vulnerability classes include remote code execution (RCE) and cross-site scripting (XSS), often stemming from insufficient input validation in its web interface components. Additionally, privilege escalation issues have been frequently reported, allowing unauthorized users to gain administrative access. A notable incident in 2022 involved a critical RCE flaw that enabled attackers to execute arbitrary commands on unpatched servers, leading to widespread data exposure across multiple client networks. These recurring security deficiencies highlight significant challenges in the platform’s secure development lifecycle, necessitating rigorous patching and continuous monitoring for organizations relying on OpenClaw for their security infrastructure.

CVE ID Title CVSS Severity Published
CVE-2026-62228 OpenClaw < 2026.6.5 Authorization Bypass via Node Exec Approvals — OpenClaw CWE-863 8.8 High 2026-07-17
CVE-2026-62229 OpenClaw < 2026.5.18 Authorization Bypass via Glob Matching — OpenClaw CWE-22 8.8 High 2026-07-17
CVE-2026-62227 OpenClaw 2026.4.14 < 2026.5.26 SSRF via Browser Snapshot — OpenClaw CWE-918 7.7 High 2026-07-17
CVE-2026-62225 OpenClaw < 2026.5.18 Authorization Bypass via Skill Command Dispatch — OpenClaw CWE-863 5.4 Medium 2026-07-17
CVE-2026-62226 OpenClaw 2026.3.28 < 2026.5.19 Authorization Bypass via Browser Act Route — OpenClaw CWE-918 8.5 High 2026-07-17
CVE-2026-62224 OpenClaw MS Teams < 2026.5.12 Authorization Bypass — msteams CWE-290 5.4 Medium 2026-07-17
CVE-2026-62223 OpenClaw < 2026.5.18 Authorization Bypass via Device-pair — OpenClaw CWE-863 8.8 High 2026-07-17
CVE-2026-62222 OpenClaw < 2026.5.22 Untrusted Plugin Loading via Setup-mode — OpenClaw CWE-829 7.8 High 2026-07-17
CVE-2026-62221 OpenClaw 2026.5.12 < 2026.5.26 Authorization Bypass via allowFrom — OpenClaw CWE-863 5.4 Medium 2026-07-17
CVE-2026-62219 OpenClaw 2026.2.12 < 2026.5.26 Authorization Bypass via Blank Agent IDs — OpenClaw CWE-863 7.1 High 2026-07-17
CVE-2026-62220 OpenClaw 2026.2.25 < 2026.5.26 WebSocket Rate Limit Bypass — OpenClaw CWE-307 5.3 Medium 2026-07-17
CVE-2026-62218 OpenClaw 2026.1.20 < 2026.5.27 Authorization Bypass via device.pair.approve — OpenClaw CWE-862 8.8 High 2026-07-17
CVE-2026-62216 OpenClaw 2026.4.20 < 2026.5.28 Policy Bypass via Media Upload — OpenClaw CWE-918 5.0 Medium 2026-07-17
CVE-2026-62217 OpenClaw 2026.5.14-beta.1 < 2026.5.27 Authentication Bypass via exec approvals — OpenClaw CWE-863 8.8 High 2026-07-17
CVE-2026-62215 OpenClaw < 2026.6.5 Authentication Bypass via HTTP Canvas — OpenClaw CWE-345 8.0 High 2026-07-17
CVE-2026-62214 OpenClaw < 2026.5.28 Bot Framework SSRF via serviceUrl Parameter Validation — msteams CWE-522 6.5 Medium 2026-07-17
CVE-2026-62213 OpenClaw < 2026.5.27 Token Leakage via MS Teams Outbound Requests — msteams CWE-522 6.5 Medium 2026-07-17
CVE-2026-62212 OpenClaw < 2026.5.28 Authentication Bypass via safeFetch — OpenClaw CWE-367 7.1 High 2026-07-17
CVE-2026-62211 OpenClaw < 2026.6.1 Credential Redaction Bypass via Trajectory Export — OpenClaw CWE-532 5.0 Medium 2026-07-17
CVE-2026-62210 OpenClaw < 2026.6.1 Denial of Service via Remote Media URLs — OpenClaw CWE-770 6.5 Medium 2026-07-17
CVE-2026-62209 OpenClaw 2026.5.10-beta.1 < 2026.6.5 Authorization Bypass via agent-mode dispatch — OpenClaw CWE-863 8.1 High 2026-07-17
CVE-2026-62208 OpenClaw < 2026.6.5 Authorization Header Forwarding via SSE — OpenClaw CWE-522 6.5 Medium 2026-07-17
CVE-2026-62207 OpenClaw < 2026.6.5 Authentication Bypass via Admin Tools — OpenClaw CWE-862 8.8 High 2026-07-17
CVE-2026-62206 OpenClaw < 2026.6.9 Authentication Bypass via Moderation Actions — OpenClaw CWE-862 7.1 High 2026-07-17
CVE-2026-62205 OpenClaw 2026.4.12-beta.1 < 2026.6.6 Authorization Bypass via message actions — OpenClaw CWE-862 7.1 High 2026-07-17
CVE-2026-62203 OpenClaw < 2026.6.6 Environment Variable Injection via rustup — OpenClaw CWE-184 8.8 High 2026-07-17
CVE-2026-62202 OpenClaw 2026.6.1 < 2026.6.9 Privilege Escalation via Cron — OpenClaw CWE-863 8.8 High 2026-07-17
CVE-2026-62201 OpenClaw < 2026.6.6 Network Policy Bypass via exec-server — OpenClaw CWE-918 7.7 High 2026-07-17
CVE-2026-62200 OpenClaw < 2026.6.6 Authentication Bypass via Git ext transport — OpenClaw CWE-184 8.8 High 2026-07-13
CVE-2026-62199 OpenClaw < 2026.6.6 Authentication Bypass via Environment Filtering — OpenClaw CWE-184 8.8 High 2026-07-13

This page lists every published CVE security advisory associated with OpenClaw. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.