Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

openclaw — Vulnerabilities & Security Advisories 581

Browse all 581 CVE security advisories affecting openclaw. AI-powered Chinese analysis, POCs, and references for each vulnerability.

OpenClaw is a specialized software platform designed for automated threat intelligence aggregation and vulnerability management, primarily serving enterprise security operations centers. Historically, its codebase has exhibited a high frequency of critical flaws, with 428 CVEs documented to date. The most prevalent vulnerability classes include remote code execution (RCE) and cross-site scripting (XSS), often stemming from insufficient input validation in its web interface components. Additionally, privilege escalation issues have been frequently reported, allowing unauthorized users to gain administrative access. A notable incident in 2022 involved a critical RCE flaw that enabled attackers to execute arbitrary commands on unpatched servers, leading to widespread data exposure across multiple client networks. These recurring security deficiencies highlight significant challenges in the platform’s secure development lifecycle, necessitating rigorous patching and continuous monitoring for organizations relying on OpenClaw for their security infrastructure.

HighGHSA-8v95-qgpm-gp9h2026-07-17
device.pair.approve could bypass role-management checks · Advisory · openclaw/openclaw · GitHub
HighGHSA-34mr-73mr-gfg72026-07-17
Exec allowlist glob matching could allow traversal bypasses · Advisory · openclaw/openclaw · GitHub
Medium2026-07-14
Plugin install wrappers could skip install policy · Advisory · openclaw/openclaw · GitHub
HighGHSA-hy6-g723-hmfm2026-07-14
Host exec environment filtering could miss interpreter startup variables · Advisory · openclaw/openclaw · GitHub
High2026-07-14
Plugin install commands could allow non-owner persistence · Advisory · openclaw/openclaw · GitHub
High2026-07-14
flock wrapper could bypass durable exec approval binding · Advisory · openclaw/openclaw · GitHub
High2026-07-14
OpenAI-compatible HTTP model overrides could miss admin authorization · Advisory · openclaw/openclaw · GitHub
High2026-07-14
Browser CDP discovery could accept blocked WebSocket URLs · Advisory · openclaw/openclaw · GitHub
High2026-07-09
Workspace dotenv files could override provider credentials · Advisory · openclaw/openclaw · GitHub
High2026-06-17
Tool group policy callers could accept unvalidated group IDs · Advisory · openclaw/openclaw · GitHub
Medium2026-06-17
Workspace .env CLOUDSDK_PYTHON could influence Gmail setup gcloud execution · Advisory · openclaw/openclaw · GitHub
High2026-06-17
MCP Streamable HTTP redirects could forward configured custom headers to another origin · Advisory · openclaw/openclaw ·
High2026-06-17
Internal/webchat command auth could inherit ownerAllowFrom wildcard state · Advisory · openclaw/openclaw · GitHub
HighGHSA-3c6j-hq33-3yv42026-06-13
Paired nodes could forge exec lifecycle events without system.run provenance · Advisory · openclaw/openclaw · GitHub
HighGHSA-dfn-66p3-3q42026-06-13
Hook-triggered CLI runs could receive owner MCP tool authority · Advisory · openclaw/openclaw · GitHub
MediumGHSA-7hxm-f538-3xp62026-06-13
Matrix allowFrom could bind to mutable display names · Advisory · openclaw/openclaw · GitHub
Medium2026-06-13
Workspace .env could override Homebrew executable selection for skill install flows · Advisory · openclaw/openclaw · Git
MediumGHSA-gp79-m99v-gjmh2026-06-13
Mattermost handlers could fall open when channel type was missing · Advisory · openclaw/openclaw · GitHub
Medium2026-06-13
QQBot streaming command could mutate config without explicit allowFrom · Advisory · openclaw/openclaw · GitHub
High2026-06-13
POSIX node system.run safe-bin allowlist could be widened by shell expansion · Advisory · openclaw/openclaw · GitHub

Showing up to 20 recent security advisories. View all →

This page lists every published CVE security advisory associated with openclaw. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.