openclaw clawhub

5 known vulnerabilities in openclaw clawhub, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2026-100604 CVSS 5.3 medium ClawHub (openclaw/clawhub) contains an incorrect authorization vulnerability in the ClawHub application/backend: an organization-owned…
  • CVE-2026-100603 CVSS 8.7 high ClawHub (openclaw/clawhub) application/backend contains a flaw in the skill report moderation flow: four distinct ordinary authenticated…
  • CVE-2026-100602 CVSS 7.1 high ClawHub (openclaw/clawhub application/backend) contains a missing authorization check in the changelog preview feature. A signed-in caller…
  • CVE-2026-100601 CVSS 6.9 medium ClawHub (openclaw/clawhub) application/backend contains a server-side request forgery vulnerability in the public profile preview's image…
  • CVE-2026-100600 CVSS 6.9 medium ClawHub (the openclaw/clawhub application/backend) does not bind anonymous HTTP API requests to a trusted caller identity, so all direct…