Openclaw operates a narrowly scoped product line—centered on its core platform and voice-call functionality—that nonetheless carries a disproportionately large vulnerability footprint, indicating deep systemic exposure across its codebase. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and recur persistently through authorization and access-control weaknesses, including incorrect authorization, missing authorization checks, path traversal, and OS command injection, alongside server-side request forgery that exposes the platform to indirect attack chains. These weakness classes, particularly the prevalence of authorization failures and command-injection vectors, suggest structural flaws in input validation and privilege enforcement that span multiple product components. Defenders should treat Openclaw disclosures as high-priority within environments where the platform is deployed and should focus remediation on internet-reachable instances and API boundaries; current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Openclaw over time
Signals from CVEs in this vendor scope (582 CVEs).
582 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-25253HIGH OpenClaw (aka clawdbot or Moltbot) before 2026.1.29 obtains a gatewayUrl value from a query string and automatically makes a WebSocket connection without prompting, sending a token | Feb 1, 2026 | 8.8 | 44 | NO | NO |
CVE-2026-53838CRITICAL OpenClaw before 2026.5.27 contains a state mutation vulnerability in node pairing reconnection that allows paired nodes to confuse approval scope decisions. Attackers can exploit r | Jun 12, 2026 | 9.8 | 41 | NO | NO |
CVE-2026-44112CRITICAL OpenClaw before 2026.4.22 contains a time-of-check/time-of-use race condition in OpenShell sandbox filesystem writes that allows attackers to redirect writes outside the intended m | May 6, 2026 | 9.6 | 39 | NO | NO |
CVE-2026-33579CRITICAL OpenClaw before 2026.3.28 contains a privilege escalation vulnerability in the /pair approve command path that fails to forward caller scopes into the core approval check. A caller | Mar 31, 2026 | 9.9 | 39 | NO | NO |
CVE-2026-53822HIGH OpenClaw before 2026.5.18 contains a command injection vulnerability where shell wrapper argv could change between approval and execution. Attackers can rebuild command arguments a | Jun 12, 2026 | 8.8 | 38 | NO | NO |
CVE-2026-44109CRITICAL OpenClaw before 2026.4.15 contains an authentication bypass vulnerability in Feishu webhook and card-action validation that allows unauthenticated requests to reach command dispatc | May 6, 2026 | 9.8 | 38 | NO | NO |
CVE-2026-43575CRITICAL OpenClaw versions 2026.2.21 before 2026.4.10 contain an authentication bypass vulnerability in the sandbox noVNC helper route that exposes interactive browser session credentials. | May 6, 2026 | 9.8 | 38 | NO | NO |
CVE-2026-43534CRITICAL OpenClaw before 2026.4.10 contains an input validation vulnerability that allows external hook metadata to be enqueued as trusted system events. Attackers can supply malicious hook | May 5, 2026 | 9.8 | 38 | NO | NO |
CVE-2026-62229HIGH OpenClaw before 2026.5.18 contain an authorization bypass vulnerability in exec allowlist glob matching that allows lower-trust callers to execute actions beyond intended authoriza | Jul 17, 2026 | 8.8 | 37 | NO | NO |
CVE-2026-62228HIGH OpenClaw before 2026.6.5 contain an authorization bypass vulnerability in node exec approvals that allows lower-trust callers to execute actions beyond their intended authorization | Jul 17, 2026 | 8.8 | 37 | NO | NO |
Signals from CVEs in this vendor scope (582 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Openclaw.
Media articles that mention a CVE ID that affects a product developed by Openclaw — matched by CVE ID, not by vendor name.