Openclaw
578 known vulnerabilities
Top Products
OpenClaw before 2026.3.24 contains an incorrect authorization vulnerability in the POST /reset-profile endpoint that all
OpenClaw before 2026.3.22 contains an authorization bypass vulnerability in interactive callback dispatch that allows no
OpenClaw versions 2026.2.13 through 2026.3.24 contain an ANSI escape sequence injection vulnerability in approval prompt
OpenClaw before 2026.3.22 contains an environment variable override handling vulnerability that allows attackers to bypa
OpenClaw before 2026.3.22 contains a settings reconciliation vulnerability that allows attackers to bypass intended deny
OpenClaw before 2026.3.22 contains a policy bypass vulnerability where queued node actions are not revalidated against c
OpenClaw before 2026.3.25 contains an access control vulnerability where verification notices bypass DM policy checks an
OpenClaw before 2026.3.22 contains an unvalidated WebView JavascriptInterface vulnerability allowing attackers to inject
OpenClaw before 2026.3.24 contains an arbitrary code execution vulnerability in local plugin and hook installation that
OpenClaw before 2026.3.24 contains a privilege escalation vulnerability where the /allowlist command fails to re-validat
OpenClaw before 2026.3.24 contains missing authorization vulnerabilities in the /send and /allowlist chat command handle
OpenClaw before 2026.3.24 contains an authorization bypass vulnerability in the HTTP /v1/models endpoint that fails to e
A weakness has been identified in OpenClaw up to 2026.1.26. Affected by this issue is some unknown functionality of the
OpenClaw before 2026.3.25 contains a pre-authentication rate-limit bypass vulnerability in webhook token validation that
OpenClaw before 2026.3.25 contains a privilege escalation vulnerability in the gateway plugin subagent fallback deleteSe
OpenClaw before 2026.3.22 contains an information disclosure vulnerability that allows attackers with operator.read scop
OpenClaw before 2026.3.25 contains an authorization bypass vulnerability where group reaction events bypass the requireM
OpenClaw before 2026.3.25 parses JSON request bodies before validating webhook signatures, allowing unauthenticated atta
OpenClaw before 2026.3.22 contains a privilege escalation vulnerability in the device.pair.approve method that allows an
OpenClaw before 2026.3.22 contains a privilege escalation vulnerability in the Control UI that allows unauthenticated se
OpenClaw before 2026.3.22 performs cite expansion before completing channel and DM authorization checks, allowing cite w
OpenClaw versions 2026.3.11 through 2026.3.24 contain a session isolation bypass vulnerability where session_status reso
OpenClaw before 2026.3.22 contains a webhook path route replacement vulnerability in the Synology Chat extension that al
OpenClaw before 2026.3.23 contains an authentication bypass vulnerability in the Canvas gateway where authorizeCanvasReq
OpenClaw before 2026.3.22 contains an unbounded memory allocation vulnerability in remote media HTTP error handling that
OpenClaw through 2026.2.22 contains a symlink traversal vulnerability in agents.create and agents.update handlers that u
OpenClaw before 2026.3.22 fails to enforce operator.admin scope on mutating internal ACP chat commands, allowing unautho
OpenClaw before 2026.3.25 contains a server-side request forgery vulnerability in multiple channel extensions that fail
OpenClaw before 2026.3.25 contains a missing rate limiting vulnerability in Telegram webhook authentication that allows
OpenClaw before 2026.3.22 performs cryptographic and dispatch operations on inbound Nostr direct messages before enforci
OpenClaw before 2026.3.22 contains an unauthenticated resource exhaustion vulnerability in voice call webhook handling t
OpenClaw before 2026.3.25 contains a privilege escalation vulnerability where silent local shared-auth reconnects auto-a
OpenClaw before 2026.3.22 contains a policy confusion vulnerability in room authorization that matches colliding room na
OpenClaw before 2026.3.25 contains a missing rate limiting vulnerability in webhook authentication that allows attackers
OpenClaw before 2026.3.22 contains an improper authentication verification vulnerability in Google Chat app-url webhook
OpenClaw before 2026.3.23 contains a replay identity vulnerability in Plivo V2 signature verification that allows attack
OpenClaw before 2026.3.25 contains an authorization bypass vulnerability in Google Chat group policy enforcement that re
OpenClaw before 2026.3.25 contains an improper access control vulnerability in the HTTP /sessions/:sessionKey/kill route
OpenClaw before 2026.3.31 (patched in 2026.4.8) contains a request body replay vulnerability in fetchWithSsrFGuard that
OpenClaw before 2026.4.2 reuses the PKCE verifier as the OAuth state parameter in the Gemini OAuth flow, exposing it thr
OpenClaw versions prior to commit b57b680 contain an approval bypass vulnerability due to inconsistent environment varia
OpenClaw versions prior to commit 8aceaf5 contain a preflight validation bypass vulnerability in shell-bleed protection
OpenClaw before 2026.3.22 contains a path traversal vulnerability in Windows media loaders that accepts remote-host file
OpenClaw before 2026.3.28 contains a server-side request forgery vulnerability in the fal provider image-generation-prov
OpenClaw before 2026.3.28 fails to disconnect active WebSocket sessions when devices are removed or tokens are revoked.
OpenClaw before 2026.3.24 contains a sandbox bypass vulnerability in the message tool that allows attackers to read arbi
OpenClaw before 2026.3.28 contains a missing rate limiting vulnerability in the Nextcloud Talk webhook authentication th
OpenClaw before 2026.3.28 contains a privilege escalation vulnerability in the /pair approve command path that fails to
OpenClaw before 2026.3.28 contains a sender policy bypass vulnerability in the Google Chat and Zalouser extensions where
OpenClaw before 2026.3.28 contains an insufficient scope validation vulnerability in the node pairing approval path that
Frequently Asked Questions
How many CVEs affect Openclaw?
Openclaw has 578 CVE records in our database, including 29 critical and 251 high severity vulnerabilities.
What are the most severe Openclaw vulnerabilities?
Openclaw has 29 critical severity (CVSS 9.0+) and 251 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.
How can I scan for Openclaw vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Openclaw products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Openclaw Vulnerabilities
CyberStrike scans your infrastructure for Openclaw vulnerabilities and provides real-time remediation guidance.
Get Started