OpenClaw

66 known vulnerabilities in OpenClaw, 1 critical, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2026-102807 CVSS 6.0 medium OpenClaw before 2026.9.4 contains an incorrect authorization vulnerability in the mcp.app.view method that allows read-scoped operators to…
  • CVE-2026-102806 CVSS 6.0 medium OpenClaw before 2026.9.5 contains an incorrect authorization vulnerability in the Gateway's local media root allowlist that breaks…
  • CVE-2026-100599 CVSS 8.7 high OpenClaw versions 2026.5.1 through 2026.7.0 fail to apply the configured exec approval path to Google Meet node commands. The…
  • CVE-2026-100598 CVSS 7.5 high OpenClaw (npm package openclaw) before 2026.7.1 incorrectly binds Signal approval reactions. In affected versions, a reaction intended to…
  • CVE-2026-100597 CVSS 8.8 high OpenClaw (npm package 'openclaw') before 2026.7.1 is vulnerable to a time-of-check time-of-use race condition in OpenShell local mirror…
  • CVE-2026-100596 CVSS 8.7 high OpenClaw versions before 2026.7.1 fail to properly authorize non-owner users executing MCP configuration changes through /mcp set and /mcp…
  • CVE-2026-100595 CVSS 7.1 high OpenClaw versions before 2026.7.1 contain an authorization bypass vulnerability in the diagnostics export command that allows non-owner…
  • CVE-2026-100594 CVSS 7.1 high OpenClaw versions before 2026.7.1 contain an authorization bypass vulnerability in the /export-trajectory endpoint that allows non-owner…
  • CVE-2026-100593 CVSS 5.3 medium OpenClaw (npm package `openclaw`) before 2026.7.1 does not enforce the documented owner-only requirement for persistent `/activation`…
  • CVE-2026-100592 CVSS 5.3 medium OpenClaw is an agent gateway distributed via npm. In versions >= 2026.4.10 and < 2026.7.1, persistent memory dreaming mutations omit owner…
  • CVE-2026-100591 CVSS 5.3 medium OpenClaw is an npm-distributed agent gateway. In versions before 2026.7.1, the global Active Memory toggle mutations could omit owner…
  • CVE-2026-100590 CVSS 5.3 medium OpenClaw before 2026.7.1 contains an authorization bypass vulnerability in the /voice set command that allows non-owner external-channel…
  • CVE-2026-100589 CVSS 8.7 high OpenClaw versions before 2026.7.1 contain a sandbox bypass vulnerability in the browser tool that allows sandboxed sessions to access…
  • CVE-2026-100588 CVSS 8.7 high OpenClaw (npm package 'openclaw') before 2026.7.1 does not enforce the administrator scope requirement on browser control when it is…
  • CVE-2026-100587 CVSS 8.7 high OpenClaw versions before 2026.7.1 fail to properly validate owner authorization in the Codex computer-use installation command. Non-owner…
  • CVE-2026-100586 CVSS 8.7 high OpenClaw Codex before 2026.7.1 fails to properly enforce owner authorization when creating native conversation bindings. Non-owner channel…
  • CVE-2026-100585 CVSS 8.6 high OpenClaw (npm package `openclaw`) before 2026.7.1 fails to enforce the owner-only authorization requirement for Claude Code permission…
  • CVE-2026-100584 CVSS 5.4 medium OpenClaw is an npm-distributed agent runtime. In versions >= 2026.2.26 and < 2026.7.1, PowerShell command analysis on Windows hosts…
  • CVE-2026-100581 CVSS 6.8 medium OpenClaw for iOS before 2026.8.11 stores Gateway credentials as cleartext JSON in App Group UserDefaults instead of the device Keychain…
  • CVE-2026-100580 CVSS 8.7 high OpenClaw (npm package 'openclaw') before 2026.7.1 improperly handles case sensitivity in the model-facing cron tool: a mixed-case payload…
  • CVE-2026-100579 CVSS 7.2 high OpenClaw (npm package 'openclaw') before 2026.7.1 incorrectly trusts requester provenance in message.action. In identity-bearing Gateway…
  • CVE-2026-100578 CVSS 7.2 high OpenClaw (npm package `openclaw`) before 2026.7.1 fails to restrict owner-only infrastructure tools exposed through the chat.send…
  • CVE-2026-100577 CVSS 5.3 medium OpenClaw versions before 2026.8.1 fail to validate video asset URLs returned by providers, allowing server-side requests to private…
  • CVE-2026-100576 CVSS 5.3 medium OpenClaw versions before 2026.8.1 contain a server-side request forgery vulnerability in browser wait predicates that allows attackers to…
  • CVE-2026-100574 CVSS 8.2 high OpenClaw (npm package 'openclaw') before 2026.8.1 contains a server-side request forgery vulnerability in its trusted-host DNS checks. For…
  • CVE-2026-100573 CVSS 4.8 medium OpenClaw versions before 2026.8.1 contain a sandbox policy bypass vulnerability in the MCP loopback component that allows sandboxed…
  • CVE-2026-100572 CVSS 6.9 medium OpenClaw versions >= 2026.3.25 and < 2026.8.1 apply invalid-token rate limiting for Synology Chat webhooks before authentication and key…
  • CVE-2026-100571 CVSS 6.9 medium OpenClaw (npm package 'openclaw') versions >= 2026.6.6 and < 2026.8.1 apply the SMS webhook invalid-request rate limit before Twilio…
  • CVE-2026-100570 CVSS 8.5 high OpenClaw (npm package 'openclaw') versions >= 2026.3.28 and < 2026.8.1 allow an untrusted workspace .env file to set the…
  • CVE-2026-100569 CVSS 6.8 medium OpenClaw is an npm-distributed application. In versions >= 2026.4.25 and < 2026.8.1, the workspace environment-variable filter did not…