LIVE · cybersecurity feed
Live wire
vendor

Openclaw

182 CVEs published in the last four months and 4 stories. Exploited flaws first.

Critical5
High106
Medium62
Exploited (KEV)0

All recent CVEs

CVECVSSSeverityProductSummaryPublished
CVE-2026-221729.9criticalopenclawOpenClaw versions prior to 2026.3.12 contain an authorization bypass vulnerability in the WebSocket connect path t169d ago
CVE-2026-538389.8criticalopenclawOpenClaw before 2026.5.27 contains a state mutation vulnerability in node pairing reconnection that allows paired 85d ago
CVE-2026-307419.8criticalopenclawA remote code execution (RCE) vulnerability in OpenClaw Agent Platform v2026.2.6 allows attackers to execute arbit178d ago
CVE-2026-320389.8criticalopenclawOpenClaw before 2026.2.24 contains a sandbox network isolation bypass vulnerability that allows trusted operators 170d ago
CVE-2026-329139.3criticalopenclawOpenClaw before 2026.3.7 contains an improper header validation vulnerability in fetchWithSsrFGuard that forwards 166d ago
CVE-2026-622028.8highopenclawOpenClaw versions 2026.6.1 before 2026.6.9 contain a privilege escalation vulnerability in isolated cron jobs that50d ago
CVE-2026-320138.8highopenclawOpenClaw versions prior to 2026.2.25 contain a symlink traversal vulnerability in the agents.files.get and agents.170d ago
CVE-2026-622238.8highopenclawOpenClaw before 2026.5.18 contain an authorization bypass vulnerability in the device-pair approval feature that a50d ago
CVE-2026-622188.8highopenclawOpenClaw 2026.1.20 before 2026.5.27 contain an authorization bypass vulnerability in the device.pair.approve featu50d ago
CVE-2026-622178.8highopenclawOpenClaw 2026.5.14-beta.1 before 2026.5.27 contain an authorization flaw in the QQBot exec approvals feature.50d ago
CVE-2026-622078.8highopenclawOpenClaw versions before 2026.6.5 contain an authentication bypass vulnerability that allows lower-trust callers t50d ago
CVE-2026-622038.8highopenclawOpenClaw versions before 2026.6.6 contain an environment variable filtering vulnerability in host exec that fails 50d ago
CVE-2026-622008.8highopenclawOpenClaw versions before 2026.6.6 contain a flaw in host exec environment filtering that could allow Git ext trans54d ago
CVE-2026-621998.8highopenclawOpenClaw versions before 2026.6.6 contain a flaw in host exec environment filtering that can miss interpreter star54d ago
CVE-2026-621948.8highopenclawOpenClaw versions 2026.5.20 before 2026.6.9 contain a privilege escalation vulnerability in plugin install command54d ago
CVE-2026-621908.8highopenclawOpenClaw versions before 2026.6.9 contain an authorization bypass vulnerability in the flock wrapper that allows l54d ago
CVE-2026-622298.8highopenclawOpenClaw before 2026.5.18 contain an authorization bypass vulnerability in exec allowlist glob matching that allow50d ago
CVE-2026-538438.8highopenclawOpenClaw before 2026.5.26 contains an authorization bypass vulnerability where a surviving pairing-scoped device s81d ago
CVE-2026-538368.8highopenclawOpenClaw before 2026.5.12 contains an allowlist bypass vulnerability in PowerShell encoded-command handling that a85d ago
CVE-2026-538288.8highopenclawOpenClaw before 2026.5.6 contains an authorization bypass vulnerability in native command handling that allows aut85d ago
CVE-2026-538228.8highopenclawOpenClaw before 2026.5.18 contains a command injection vulnerability where shell wrapper argv could change between85d ago
CVE-2026-538218.8highopenclawOpenClaw before 2026.5.18 accepts WebSocket client-declared operator scopes before binding to server-approved pair85d ago
CVE-2026-538198.8highopenclawOpenClaw before 2026.5.27 contains an arbitrary code execution vulnerability in skill install flows where workspac86d ago
CVE-2026-538178.8highopenclawOpenClaw before 2026.5.22 contains a locality validation vulnerability in Control UI pairing that allows attackers86d ago
CVE-2026-622288.8highopenclawOpenClaw before 2026.6.5 contain an authorization bypass vulnerability in node exec approvals that allows lower-tr50d ago
CVE-2026-538118.8highopenclawOpenClaw before 2026.5.7 contains a privilege escalation vulnerability in the Matrix allowFrom feature that allows86d ago
CVE-2026-538108.8highopenclawOpenClaw before 2026.5.18 contains a code execution vulnerability where marketplace runtime extension metadata can86d ago
CVE-2026-538078.8highopenclawOpenClaw before 2026.5.6 contains an authorization bypass vulnerability in Telegram interactive callbacks that all86d ago
CVE-2026-538068.8highopenclawOpenClaw before 2026.5.12 contains a shell option parsing vulnerability that allows combined POSIX shell flags to 86d ago
CVE-2026-356748.8highopenclawOpenClaw before 2026.5.18 contains a scope bypass vulnerability in the Gateway chat.send route that allows scoped 99d ago
CVE-2026-320428.8highopenclawOpenClaw versions 2026.2.22 prior to 2026.2.25 contain a privilege escalation vulnerability allowing unpaired devi169d ago
CVE-2026-320518.8highopenclawOpenClaw versions prior to 2026.3.1 contain an authorization mismatch vulnerability that allows authenticated call169d ago
CVE-2026-450068.8highopenclawOpenClaw before 2026.4.23 contains an improper access control vulnerability in the gateway tool's config.apply and117d ago
CVE-2026-319988.6highopenclawOpenClaw versions 2026.2.22 and 2026.2.23 contain an authorization bypass vulnerability in the synology-chat chann170d ago
CVE-2026-621978.5highopenclawOpenClaw before 2026.6.6 contains a policy bypass vulnerability in browser CDP discovery that accepts blocked WebS54d ago
CVE-2026-622268.5highopenclawOpenClaw 2026.3.28 before 2026.5.19 contain an authorization bypass vulnerability in the browser act route that fa50d ago
CVE-2026-621958.3highopenclawOpenClaw versions 2026.5.20 before 2026.6.6 contain an authorization bypass vulnerability in the MCP loopback feat54d ago
CVE-2026-621968.3highopenclawOpenClaw versions 2026.3.22 before 2026.6.6 contain an authorization bypass vulnerability where WhatsApp group IDs54d ago
CVE-2026-538318.3highopenclawOpenClaw before 2026.5.18 contains a policy enforcement vulnerability in system.run safe-bin allowlist validation 85d ago
CVE-2026-329058.3highopenclawOpenClaw before 2026.5.4 contains an authorization bypass vulnerability in the bundled device-pair plugin that all99d ago
CVE-2026-538538.3highopenclawOpenClaw before 2026.5.12 contains an argument pattern validation bypass in the exec allowlist that allows attacke81d ago
CVE-2026-538148.3highopenclawOpenClaw before 2026.5.20 contains a privilege escalation vulnerability where hook-triggered agent runs incorrectl86d ago
CVE-2026-221718.2highopenclawOpenClaw versions prior to 2026.2.19 contain a path traversal vulnerability in the Feishu media download flow wher171d ago
CVE-2026-538648.1highopenclawOpenClaw before 2026.5.26 contains an insufficient sanitization vulnerability in the host environment sanitizer th81d ago
CVE-2026-538578.1highopenclawOpenClaw before 2026.5.3 contains a policy enforcement vulnerability where Zalo contacts with mutable display meta81d ago
CVE-2026-538558.1highopenclawOpenClaw before 2026.4.2 contains an inline-eval bypass vulnerability allowing authenticated operators to weaken s81d ago
CVE-2026-538498.1highopenclawOpenClaw before 2026.5.7 contains a privilege escalation vulnerability where the allowFrom feature improperly vali81d ago
CVE-2026-538238.1highopenclawOpenClaw before 2026.5.3 contains a privilege escalation vulnerability in the allowFrom feature that binds to muta85d ago
CVE-2026-622098.1highopenclawOpenClaw versions 2026.5.10-beta.1 before 2026.6.5 contain an authorization bypass in the ClickClack agent-mode di50d ago
CVE-2026-320348.1highopenclawOpenClaw versions prior to 2026.2.21 contain an authentication bypass vulnerability in the Control UI when allowIn170d ago
CVE-2026-323028.1highopenclawOpenClaw is a personal AI assistant.176d ago
CVE-2026-621928.1highopenclawOpenClaw versions 2026.6.6 before 2026.6.9 contain an authorization bypass vulnerability in Discord guild actions 54d ago
CVE-2026-621888.1highopenclaw\/feishuOpenClaw @openclaw/feishu versions 2026.6.6 and earlier contain an incorrect authorization vulnerability in which 54d ago
CVE-2026-621878.1highopenclaw\/feishuOpenClaw Feishu tools (npm package @openclaw/feishu) in versions <= 2026.6.6 could ignore per-account disablement.54d ago
CVE-2026-538668.1highopenclawOpenClaw before 2026.5.12 contains an allowlist bypass vulnerability in shell inline-command parsing that allows a81d ago
CVE-2026-356308highopenclawOpenClaw before 2026.5.18 contains an authorization bypass vulnerability in QQBot native approval buttons that fai99d ago
CVE-2026-538298highopenclawOpenClaw before 2026.5.18 contains an approval display truncation vulnerability allowing authenticated users to hi85d ago
CVE-2026-320148highopenclawOpenClaw versions prior to 2026.2.26 contain a metadata spoofing vulnerability where reconnect platform and device170d ago
CVE-2026-622158highopenclawOpenClaw versions before 2026.6.5 contain an authentication bypass vulnerability in HTTP Canvas responses that all50d ago
CVE-2026-320327.8highopenclawOpenClaw versions prior to 2026.2.22 contain an arbitrary shell execution vulnerability in shell environment fallb170d ago
CVE-2026-320157.8highopenclawOpenClaw versions 2026.1.21 prior to 2026.2.19 contain a path hijacking vulnerability in tools.exec.safeBins that 170d ago
CVE-2026-450047.8highopenclawOpenClaw before 2026.4.23 contains an arbitrary code execution vulnerability in the bundled plugin setup resolver 117d ago
CVE-2026-538137.8highopenclawOpenClaw before 2026.4.25 contains a path traversal vulnerability in memory-core artifact loading where workspace 86d ago
CVE-2026-320167.8highopenclawOpenClaw versions prior to 2026.2.22 on macOS contain a path validation bypass vulnerability in the exec-approval 170d ago
CVE-2026-622227.8highopenclawOpenClaw before 2026.5.22 contain a vulnerability in setup-mode discovery that allows loading of untrusted workspa50d ago
CVE-2026-538127.7highopenclawOpenClaw before 2026.5.18 contains a server-side request forgery vulnerability in browser control that allows auth86d ago
CVE-2026-538337.7highopenclawOpenClaw before 2026.4.29 contains an authorization bypass vulnerability in the QQBot streaming command that allow85d ago
CVE-2026-622277.7highopenclawOpenClaw 2026.4.14 before 2026.5.26 contain a server-side request forgery vulnerability in browser snapshot routes50d ago
CVE-2026-622017.7highopenclawOpenClaw versions before 2026.6.6 contain a network policy bypass vulnerability in the sandbox exec-server that al50d ago
CVE-2026-538327.7highopenclawOpenClaw before 2026.5.18 contains an identity header validation vulnerability allowing local same-host callers to85d ago
CVE-2026-320647.7highopenclawOpenClaw versions prior to 2026.2.21 sandbox browser entrypoint launches x11vnc without authentication for noVNC o169d ago
CVE-2026-221817.6highopenclawOpenClaw versions prior to 2026.3.2 contain a DNS pinning bypass vulnerability in strict URL fetch paths that allo171d ago
CVE-2026-621867.6highopenclawOpenClaw versions before 2026.6.8 contain an authorization bypass vulnerability in OpenAI-compatible HTTP model ov54d ago
CVE-2026-320557.6highopenclawOpenClaw versions prior to 2026.2.26 contain a path traversal vulnerability in workspace boundary validation that 169d ago
CVE-2026-320487.5highopenclawOpenClaw versions prior to 2026.3.1 fail to enforce sandbox inheritance during cross-agent sessions_spawn operatio169d ago
CVE-2026-284617.5highopenclawOpenClaw versions prior to 2026.3.1 contain an unbounded memory growth vulnerability in the Zalo webhook endpoint 170d ago
CVE-2026-320257.5highopenclawOpenClaw versions prior to 2026.2.25 contain an authentication hardening gap in browser-origin WebSocket clients t170d ago
CVE-2026-320307.5highopenclawOpenClaw versions prior to 2026.2.19 contain a path traversal vulnerability in the stageSandboxMedia function that170d ago
CVE-2026-320497.5highopenclawOpenClaw versions prior to 2026.2.22 fail to consistently enforce configured inbound media byte limits before buff169d ago
CVE-2026-320567.5highopenclawOpenClaw versions prior to 2026.2.22 fail to sanitize shell startup environment variables HOME and ZDOTDIR in the 169d ago
CVE-2026-320117.5highopenclawOpenClaw versions prior to 2026.3.2 contain a denial of service vulnerability in webhook handlers for BlueBubbles 170d ago
CVE-2026-538347.5highopenclawOpenClaw before 2026.4.27 contains an authorization bypass vulnerability in QQBot pre-dispatch slash commands that85d ago
CVE-2026-319897.4highopenclawOpenClaw versions prior to 2026.3.1 contain a server-side request forgery vulnerability in web_search citation red170d ago
CVE-2026-320197.4highopenclawOpenClaw versions prior to 2026.2.22 contain incomplete IPv4 special-use range validation in the isPrivateIpv4() f170d ago
CVE-2026-449957.3highopenclawOpenClaw before 2026.4.20 contains an improper environment variable validation vulnerability in MCP stdio server c117d ago
CVE-2026-83057.3highopenclawA vulnerability was detected in OpenClaw up to 2026.1.24.117d ago
CVE-2026-538167.2highopenclawOpenClaw before 2026.5.18 contains an insufficient provenance validation vulnerability in node event handling that86d ago
CVE-2026-221797.2highopenclawOpenClaw versions prior to 2026.2.22 in macOS node-host system.run contain an allowlist bypass vulnerability that 171d ago
CVE-2026-320007.1highopenclawOpenClaw versions prior to 2026.2.19 contain a command injection vulnerability in the Lobster extension tool execu170d ago
CVE-2026-622057.1highopenclawOpenClaw versions 2026.4.12-beta.1 before 2026.6.6 contain a missing-authorization vulnerability in the MS Teams m50d ago
CVE-2026-275667.1highopenclawOpenClaw versions prior to 2026.2.22 contain an allowlist bypass vulnerability in system.run exec analysis that fa170d ago
CVE-2026-284607.1highopenclawOpenClaw versions prior to 2026.2.22 contain an allowlist bypass vulnerability in system.run that allows attackers170d ago
CVE-2026-622127.1highopenclawOpenClaw before 2026.5.28 contains a race condition in the MS Teams safeFetch DNS rebinding check.50d ago
CVE-2026-622067.1highopenclawOpenClaw versions before 2026.6.9 contain a missing authorization vulnerability in Discord moderation actions.50d ago
CVE-2026-450017.1highopenclawOpenClaw before 2026.4.20 contains a guard bypass vulnerability in the agent-facing gateway config.patch and confi117d ago
CVE-2026-221757.1highopenclawOpenClaw versions prior to 2026.2.23 contain an exec approval bypass vulnerability in allowlist mode where allow-a171d ago
CVE-2026-319927.1highopenclawOpenClaw versions prior to 2026.2.23 contain an allowlist bypass vulnerability in system.run guardrails that allow170d ago
CVE-2026-622197.1highopenclawOpenClaw 2026.2.12 before 2026.5.26 contain an authorization bypass vulnerability in the hooks allowedAgentIds val50d ago
CVE-2026-621917.1highopenclawOpenClaw versions 2026.6.6 before 2026.6.9 contain an authorization bypass vulnerability in message mutation handl54d ago
CVE-2026-621897.1highopenclawOpenClaw versions before 2026.6.9 contain a symlink following vulnerability in the mirror sync feature that allows54d ago

Filter the full tracker by Openclaw

Our coverage of Openclaw

security

OpenClaw 2.0 pours glitter on slow-burning security dumpster fire

Making installation easier and putting a new wrapper on the interface while leaving most of the security to users is a recipe for more trouble with the popular agent harness

vulnerability

Finding Nemo(Claw): Networking Issue Allows for LLM Poisoning in OpenClaw

Attackers can exploit a security bug in NVIDIA's tool to gain unauthenticated access to the local model server through the Ollama API, paving the way for persistent AI agent corruption.

ai

OpenClaw: risks for the users and how to mitigate them

OpenClaw, an AI agent ecosystem formerly known as Clawdbot and Moltbot, offers flexibility and task automation but introduces security risks to users and organizations. The system's 'skills' feature, which allows for natural language instructions and easy creation of extensions, can be exploited by attackers. The article aims to explore these security aspects, known vulnerabilities, and mitigation strategies.

supply chainhigh

OpenClaw Skill Marketplace Faces AI Supply Chain Threat

Researchers have identified malicious skills within OpenClaw's ClawHub marketplace that evade automated detection. These skills are designed to deploy information-stealing malware and conduct automated financial fraud.