Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

OpenClaw — Vulnerabilities & Security Advisories 581

Browse all 581 CVE security advisories affecting OpenClaw. AI-powered Chinese analysis, POCs, and references for each vulnerability.

OpenClaw is a specialized software platform designed for automated threat intelligence aggregation and vulnerability management, primarily serving enterprise security operations centers. Historically, its codebase has exhibited a high frequency of critical flaws, with 428 CVEs documented to date. The most prevalent vulnerability classes include remote code execution (RCE) and cross-site scripting (XSS), often stemming from insufficient input validation in its web interface components. Additionally, privilege escalation issues have been frequently reported, allowing unauthorized users to gain administrative access. A notable incident in 2022 involved a critical RCE flaw that enabled attackers to execute arbitrary commands on unpatched servers, leading to widespread data exposure across multiple client networks. These recurring security deficiencies highlight significant challenges in the platform’s secure development lifecycle, necessitating rigorous patching and continuous monitoring for organizations relying on OpenClaw for their security infrastructure.

CVE ID Title CVSS Severity Published
CVE-2026-62198 OpenClaw 2026.5.28 < 2026.6.6 Authorization Bypass via Web Search — OpenClaw CWE-863 4.3 Medium 2026-07-13
CVE-2026-62197 OpenClaw < 2026.6.6 Policy Bypass via CDP Discovery — OpenClaw CWE-918 8.5 High 2026-07-13
CVE-2026-62196 OpenClaw 2026.3.22 < 2026.6.6 Authorization Bypass via WhatsApp Group IDs — OpenClaw CWE-863 8.3 High 2026-07-13
CVE-2026-62195 OpenClaw 2026.5.20 < 2026.6.6 Authorization Bypass via MCP loopback — OpenClaw CWE-732 8.3 High 2026-07-13
CVE-2026-62194 OpenClaw 2026.5.20 < 2026.6.9 Privilege Escalation via Plugin Install — OpenClaw CWE-732 8.8 High 2026-07-13
CVE-2026-62192 OpenClaw 2026.6.6 < 2026.6.9 Authorization Bypass — OpenClaw CWE-863 8.1 High 2026-07-13
CVE-2026-62193 OpenClaw 2026.6.5 < 2026.6.9 Authentication Bypass via Plugin Install — OpenClaw CWE-863 4.9 Medium 2026-07-13
CVE-2026-62191 OpenClaw 2026.6.6 < 2026.6.9 Authorization Bypass via Message Mutations — OpenClaw CWE-862 7.1 High 2026-07-13
CVE-2026-62189 OpenClaw < 2026.6.9 Symlink Following via Mirror Sync — OpenClaw CWE-59 7.1 High 2026-07-13
CVE-2026-62190 OpenClaw < 2026.6.9 Authorization Bypass via flock wrapper — OpenClaw CWE-706 8.8 High 2026-07-13
CVE-2026-62188 OpenClaw < 2026.6.9 Feishu Authorization Bypass — feishu CWE-863 8.1 High 2026-07-13
CVE-2026-62187 OpenClaw < 2026.6.9 Feishu tools Authorization Bypass — feishu CWE-863 8.1 High 2026-07-13
CVE-2026-62186 OpenClaw < 2026.6.8 Authorization Bypass via HTTP Model Override — OpenClaw CWE-862 7.6 High 2026-07-13
CVE-2026-59261 OpenClaw < 2026.5.28 - Credential Override via Workspace Dotenv Files — OpenClaw CWE-184 7.1 High 2026-07-08
CVE-2026-53866 OpenClaw < 2026.5.12 - Allowlist Bypass in Shell Inline-Command Parsing — OpenClaw CWE-862 8.1 High 2026-06-16
CVE-2026-53865 OpenClaw < 2026.5.2 - Arbitrary Command Execution via Workspace-Derived Service PATH — OpenClaw CWE-426 7.1 High 2026-06-16
CVE-2026-53864 OpenClaw < 2026.5.26 - Insufficient Environment Variable Sanitization in Node.js Control Variables — OpenClaw CWE-184 8.1 High 2026-06-16
CVE-2026-53863 OpenClaw < 2026.4.25 - Unvalidated Group ID Acceptance in Tool Group Policy — OpenClaw CWE-639 7.1 High 2026-06-16
CVE-2026-53862 OpenClaw < 2026.5.12 - Bootstrap Token Replay via Pending Pairing Scope Widening — OpenClaw CWE-266 4.2 Medium 2026-06-16
CVE-2026-53861 OpenClaw < 2026.5.6 - Allowlist Bypass via Combined POSIX Inline Flags on macOS — OpenClaw CWE-184 6.6 Medium 2026-06-16
CVE-2026-53860 OpenClaw < 2026.5.7 - Sender Policy Bypass via Mutable Conversation Identifiers in BlueBubbles — OpenClaw CWE-807 4.2 Medium 2026-06-16
CVE-2026-53859 OpenClaw < 2026.5.26 - Hostname Validation Bypass via Trailing-Dot Inconsistency — OpenClaw CWE-1023 6.5 Medium 2026-06-16
CVE-2026-53858 OpenClaw < 2026.5.2 - Arbitrary Runtime Dependency Loading via STATE_DIRECTORY Environment Variable — OpenClaw CWE-426 7.1 High 2026-06-16
CVE-2026-53857 OpenClaw < 2026.5.3 - Mutable Display Name Binding in Zalo allowFrom Policy — OpenClaw CWE-290 8.1 High 2026-06-16
CVE-2026-53856 OpenClaw 2026.4.23 < 2026.4.24 - Insecure File Permissions in Config Recovery via OpenClaw.json — OpenClaw CWE-732 5.5 Medium 2026-06-16
CVE-2026-53855 OpenClaw < 2026.4.2 - Shell Positional Parameters Bypass in Inline-Eval Checks — OpenClaw CWE-184 8.1 High 2026-06-16
CVE-2026-53854 OpenClaw < 2026.4.25 - Privilege Escalation via ownerAllowFrom Wildcard Inheritance in Internal/Webchat Commands — OpenClaw CWE-863 6.5 Medium 2026-06-16
CVE-2026-53852 OpenClaw < 2026.4.25 - Scope Bypass via Empty-Scope Device Re-pairing — OpenClaw CWE-636 5.4 Medium 2026-06-16
CVE-2026-53853 OpenClaw < 2026.5.12 - Argument Pattern Bypass in Exec Allowlist via Linux and macOS — OpenClaw CWE-693 8.3 High 2026-06-16
CVE-2026-53851 OpenClaw < 2026.5.12 - Slack Reaction Event Notification Bypass — OpenClaw CWE-862 5.3 Medium 2026-06-16

This page lists every published CVE security advisory associated with OpenClaw. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.