Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

OpenClaw — Vulnerabilities & Security Advisories 581

Browse all 581 CVE security advisories affecting OpenClaw. AI-powered Chinese analysis, POCs, and references for each vulnerability.

OpenClaw is a specialized software platform designed for automated threat intelligence aggregation and vulnerability management, primarily serving enterprise security operations centers. Historically, its codebase has exhibited a high frequency of critical flaws, with 428 CVEs documented to date. The most prevalent vulnerability classes include remote code execution (RCE) and cross-site scripting (XSS), often stemming from insufficient input validation in its web interface components. Additionally, privilege escalation issues have been frequently reported, allowing unauthorized users to gain administrative access. A notable incident in 2022 involved a critical RCE flaw that enabled attackers to execute arbitrary commands on unpatched servers, leading to widespread data exposure across multiple client networks. These recurring security deficiencies highlight significant challenges in the platform’s secure development lifecycle, necessitating rigorous patching and continuous monitoring for organizations relying on OpenClaw for their security infrastructure.

CVE IDTitleCVSSSeverityPublished
CVE-2026-62228 OpenClaw < 2026.6.5 Authorization Bypass via Node Exec Approvals — OpenClawCWE-863 8.8 High2026-07-17
CVE-2026-62229 OpenClaw < 2026.5.18 Authorization Bypass via Glob Matching — OpenClawCWE-22 8.8 High2026-07-17
CVE-2026-62227 OpenClaw 2026.4.14 < 2026.5.26 SSRF via Browser Snapshot — OpenClawCWE-918 7.7 High2026-07-17
CVE-2026-62225 OpenClaw < 2026.5.18 Authorization Bypass via Skill Command Dispatch — OpenClawCWE-863 5.4 Medium2026-07-17
CVE-2026-62226 OpenClaw 2026.3.28 < 2026.5.19 Authorization Bypass via Browser Act Route — OpenClawCWE-918 8.5 High2026-07-17
CVE-2026-62224 OpenClaw MS Teams < 2026.5.12 Authorization Bypass — msteamsCWE-290 5.4 Medium2026-07-17
CVE-2026-62223 OpenClaw < 2026.5.18 Authorization Bypass via Device-pair — OpenClawCWE-863 8.8 High2026-07-17
CVE-2026-62222 OpenClaw < 2026.5.22 Untrusted Plugin Loading via Setup-mode — OpenClawCWE-829 7.8 High2026-07-17
CVE-2026-62221 OpenClaw 2026.5.12 < 2026.5.26 Authorization Bypass via allowFrom — OpenClawCWE-863 5.4 Medium2026-07-17
CVE-2026-62219 OpenClaw 2026.2.12 < 2026.5.26 Authorization Bypass via Blank Agent IDs — OpenClawCWE-863 7.1 High2026-07-17
CVE-2026-62220 OpenClaw 2026.2.25 < 2026.5.26 WebSocket Rate Limit Bypass — OpenClawCWE-307 5.3 Medium2026-07-17
CVE-2026-62218 OpenClaw 2026.1.20 < 2026.5.27 Authorization Bypass via device.pair.approve — OpenClawCWE-862 8.8 High2026-07-17
CVE-2026-62216 OpenClaw 2026.4.20 < 2026.5.28 Policy Bypass via Media Upload — OpenClawCWE-918 5.0 Medium2026-07-17
CVE-2026-62217 OpenClaw 2026.5.14-beta.1 < 2026.5.27 Authentication Bypass via exec approvals — OpenClawCWE-863 8.8 High2026-07-17
CVE-2026-62215 OpenClaw < 2026.6.5 Authentication Bypass via HTTP Canvas — OpenClawCWE-345 8.0 High2026-07-17
CVE-2026-62214 OpenClaw < 2026.5.28 Bot Framework SSRF via serviceUrl Parameter Validation — msteamsCWE-522 6.5 Medium2026-07-17
CVE-2026-62213 OpenClaw < 2026.5.27 Token Leakage via MS Teams Outbound Requests — msteamsCWE-522 6.5 Medium2026-07-17
CVE-2026-62212 OpenClaw < 2026.5.28 Authentication Bypass via safeFetch — OpenClawCWE-367 7.1 High2026-07-17
CVE-2026-62211 OpenClaw < 2026.6.1 Credential Redaction Bypass via Trajectory Export — OpenClawCWE-532 5.0 Medium2026-07-17
CVE-2026-62210 OpenClaw < 2026.6.1 Denial of Service via Remote Media URLs — OpenClawCWE-770 6.5 Medium2026-07-17
CVE-2026-62209 OpenClaw 2026.5.10-beta.1 < 2026.6.5 Authorization Bypass via agent-mode dispatch — OpenClawCWE-863 8.1 High2026-07-17
CVE-2026-62208 OpenClaw < 2026.6.5 Authorization Header Forwarding via SSE — OpenClawCWE-522 6.5 Medium2026-07-17
CVE-2026-62207 OpenClaw < 2026.6.5 Authentication Bypass via Admin Tools — OpenClawCWE-862 8.8 High2026-07-17
CVE-2026-62206 OpenClaw < 2026.6.9 Authentication Bypass via Moderation Actions — OpenClawCWE-862 7.1 High2026-07-17
CVE-2026-62205 OpenClaw 2026.4.12-beta.1 < 2026.6.6 Authorization Bypass via message actions — OpenClawCWE-862 7.1 High2026-07-17
CVE-2026-62203 OpenClaw < 2026.6.6 Environment Variable Injection via rustup — OpenClawCWE-184 8.8 High2026-07-17
CVE-2026-62202 OpenClaw 2026.6.1 < 2026.6.9 Privilege Escalation via Cron — OpenClawCWE-863 8.8 High2026-07-17
CVE-2026-62201 OpenClaw < 2026.6.6 Network Policy Bypass via exec-server — OpenClawCWE-918 7.7 High2026-07-17
CVE-2026-62200 OpenClaw < 2026.6.6 Authentication Bypass via Git ext transport — OpenClawCWE-184 8.8 High2026-07-13
CVE-2026-62199 OpenClaw < 2026.6.6 Authentication Bypass via Environment Filtering — OpenClawCWE-184 8.8 High2026-07-13

This page lists every published CVE security advisory associated with OpenClaw. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.