OpenClaw
- Total products in the ecosystem
- 16
- Total vulnerabilities (90 days)
- 133
en
Verify to analyze this security profile
As of 10/06/2026, OpenClaw recorded 133 security vulnerabilities in the last 90 days across 15 products, including 69 rated High or above and 0 known exploited vulnerabilities (KEV) that should be prioritized for immediate remediation.
Over the last 90 days, OpenClaw had the most security vulnerabilities in the OpenClaw ecosystem, with 103 vulnerabilities—approximately 77.44% of the provider's total vulnerabilities during this period.
| Vulnerability | Exploitation status | Fix | Affected product | Published | Severity |
|---|---|---|---|---|---|
CVE-2026-101884OpenClaw Windows Node before 2026.7.1 Remote Code Execution via Environment Override | Exploitation statusPublic exploit | FixYes | Affected productOpenClaw Windows Node | Published09/30/2026 | SeverityHigh |
CVE-2026-101883OpenClaw Windows Node through 2026.9.4 SSRF via canvas.present | Exploitation statusPublic exploit | FixYes | Affected productOpenClaw Windows Node | Published09/30/2026 | SeverityMedium |
CVE-2026-101882OpenClaw Windows Node before 2026.7.1 Remote Code Execution via system.execApprovals.set | Exploitation statusPublic exploit | FixYes | Affected productOpenClaw Windows Node | Published09/30/2026 | SeverityHigh |
CVE-2026-101881OpenClaw Windows Node before 2026.7.1 Denial of Service | Exploitation statusPublic exploit | FixYes | Affected productOpenClaw Windows Node | Published09/30/2026 | SeverityHigh |
CVE-2026-101880OpenClaw Windows Node before 2026.7.1 Authorization Bypass | Exploitation statusPublic exploit | FixYes | Affected productOpenClaw Windows Node | Published09/30/2026 | SeverityHigh |
CVE-2026-101879OpenClaw Windows Node before 2026.7.1-3 Missing Authorization | Exploitation statusPublic exploit | FixYes | Affected productOpenClaw Windows Node | Published09/30/2026 | SeverityHigh |
CVE-2026-102807OpenClaw before 2026.9.4 Authorization Bypass via MCP App Standalone Ticket | Exploitation statusNot known exploited | FixYes | Affected productOpenClaw | Published09/29/2026 | SeverityMedium |
CVE-2026-102806OpenClaw before 2026.9.5 Sandbox Isolation Bypass via Media Pipelines | Exploitation statusNot known exploited | FixYes | Affected productOpenClaw | Published09/29/2026 | SeverityMedium |
CVE-2026-100604ClawHub Authentication Bypass via Former Publisher Skill Control | Exploitation statusNot known exploited | FixYes | Affected productclawhub | Published09/26/2026 | SeverityMedium |
CVE-2026-100603ClawHub before 8c2de6c506 Skill Hiding via Coordinated Reports | Exploitation statusNot known exploited | FixYes | Affected productclawhub | Published09/26/2026 | SeverityHigh |
CVE-2026-100602ClawHub Changelog Preview Information Disclosure via Authorization Bypass | Exploitation statusNot known exploited | FixYes | Affected productclawhub | Published09/26/2026 | SeverityHigh |
CVE-2026-100601ClawHub SSRF via Unchecked DNS Resolution in Profile Image | Exploitation statusNot known exploited | FixYes | Affected productclawhub | Published09/26/2026 | SeverityMedium |
CVE-2026-100600ClawHub before 8c2de6c506 Quota Exhaustion via Anonymous API | Exploitation statusNot known exploited | FixYes | Affected productclawhub | Published09/26/2026 | SeverityMedium |
CVE-2026-100599OpenClaw 2026.5.1 before 2026.7.1 Remote Code Execution via googlemeet.chrome | Exploitation statusNot known exploited | FixYes | Affected productOpenClaw | Published09/26/2026 | SeverityHigh |
CVE-2026-100598OpenClaw before 2026.7.1 Approval Binding Logic Error | Exploitation statusNot known exploited | FixYes | Affected productOpenClaw | Published09/26/2026 | SeverityHigh |
CVE-2026-100597OpenClaw before 2026.7.1 Path Traversal via Filesystem Race | Exploitation statusNot known exploited | FixYes | Affected productOpenClaw | Published09/26/2026 | SeverityHigh |
CVE-2026-100596OpenClaw before 2026.7.1 Authorization Bypass via MCP Configuration | Exploitation statusNot known exploited | FixYes | Affected productOpenClaw | Published09/26/2026 | SeverityHigh |
CVE-2026-100595OpenClaw before 2026.7.1 Authorization Bypass via diagnostics | Exploitation statusNot known exploited | FixYes | Affected productOpenClaw | Published09/26/2026 | SeverityHigh |
CVE-2026-100594OpenClaw before 2026.7.1 Authorization Bypass via trajectory export | Exploitation statusNot known exploited | FixYes | Affected productOpenClaw | Published09/26/2026 | SeverityHigh |
CVE-2026-100593OpenClaw before 2026.7.1 Authentication Bypass via activation | Exploitation statusNot known exploited | FixYes | Affected productOpenClaw | Published09/26/2026 | SeverityMedium |
CVE-2026-100592OpenClaw before 2026.7.1 Authentication Bypass via Memory Dreaming | Exploitation statusNot known exploited | FixYes | Affected productOpenClaw | Published09/26/2026 | SeverityMedium |
CVE-2026-100591OpenClaw before 2026.7.1 Authentication Bypass via Active Memory | Exploitation statusNot known exploited | FixYes | Affected productOpenClaw | Published09/26/2026 | SeverityMedium |
CVE-2026-100590OpenClaw before 2026.7.1 Authorization Bypass via voice set | Exploitation statusNot known exploited | FixYes | Affected productOpenClaw | Published09/26/2026 | SeverityMedium |
CVE-2026-100589OpenClaw before 2026.7.1 Sandbox Bypass via Browser Node | Exploitation statusNot known exploited | FixYes | Affected productOpenClaw | Published09/26/2026 | SeverityHigh |
CVE-2026-100588OpenClaw before 2026.7.1 Authentication Bypass via node.invoke | Exploitation statusNot known exploited | FixYes | Affected productOpenClaw | Published09/26/2026 | SeverityHigh |
CVE-2026-100587OpenClaw before 2026.7.1 Authorization Bypass via Codex Install | Exploitation statusNot known exploited | FixYes | Affected productOpenClaw | Published09/26/2026 | SeverityHigh |
CVE-2026-100586OpenClaw Codex before 2026.7.1 Authorization Bypass via Bind | Exploitation statusNot known exploited | FixYes | Affected productOpenClaw | Published09/26/2026 | SeverityHigh |
CVE-2026-100585OpenClaw before 2026.7.1 Authentication Bypass via MCP Channel | Exploitation statusNot known exploited | FixYes | Affected productOpenClaw | Published09/26/2026 | SeverityHigh |
CVE-2026-100584OpenClaw before 2026.7.1 Allowlist Bypass via Workspace Shadows | Exploitation statusNot known exploited | FixYes | Affected productOpenClaw | Published09/26/2026 | SeverityMedium |
CVE-2026-100583OpenClaw Discord before 2026.7.1 Authorization Bypass | Exploitation statusNot known exploited | FixYes | Affected productdiscord | Published09/26/2026 | SeverityMedium |
CVE-2026-100582OpenClaw Channel Plugins before 2026.8.1 Channel Read Allowlist Bypass | Exploitation statusNot known exploited | FixYes | Affected productmsteams | Published09/26/2026 | SeverityHigh |
CVE-2026-100581OpenClaw iOS before 2026.8.11 Credential Storage via Share Extension | Exploitation statusNot known exploited | FixYes | Affected productOpenClaw | Published09/26/2026 | SeverityMedium |
CVE-2026-100580OpenClaw before 2026.7.1 Remote Code Execution via cron tool | Exploitation statusNot known exploited | FixYes | Affected productOpenClaw | Published09/26/2026 | SeverityHigh |
CVE-2026-100579OpenClaw before 2026.7.1 Authentication Bypass via Spoofed Requester | Exploitation statusNot known exploited | FixYes | Affected productOpenClaw | Published09/26/2026 | SeverityHigh |
CVE-2026-100578OpenClaw before 2026.7.1 Authorization Bypass via chat.send | Exploitation statusNot known exploited | FixYes | Affected productOpenClaw | Published09/26/2026 | SeverityHigh |
CVE-2026-100577OpenClaw before 2026.8.1 Server-Side Request Forgery via Video Asset | Exploitation statusNot known exploited | FixYes | Affected productOpenClaw | Published09/26/2026 | SeverityMedium |
CVE-2026-100576OpenClaw before 2026.8.1 SSRF via Browser Wait Predicates | Exploitation statusNot known exploited | FixYes | Affected productOpenClaw | Published09/26/2026 | SeverityMedium |
CVE-2026-100575OpenClaw Slack before 2026.8.1 Authentication Bypass via Group DM | Exploitation statusNot known exploited | FixYes | Affected productslack | Published09/26/2026 | SeverityHigh |
CVE-2026-100574OpenClaw before 2026.8.1 SSRF via Trusted-Host DNS | Exploitation statusNot known exploited | FixYes | Affected productOpenClaw | Published09/26/2026 | SeverityHigh |
CVE-2026-100573OpenClaw before 2026.8.1 Sandbox Policy Bypass via MCP Loopback | Exploitation statusNot known exploited | FixYes | Affected productOpenClaw | Published09/26/2026 | SeverityMedium |
CVE-2026-100572OpenClaw before 2026.8.1 Denial of Service via Rate Limit | Exploitation statusNot known exploited | FixYes | Affected productOpenClaw | Published09/26/2026 | SeverityMedium |
CVE-2026-100571OpenClaw before 2026.8.1 SMS Webhook Rate Limit Bypass | Exploitation statusNot known exploited | FixYes | Affected productOpenClaw | Published09/26/2026 | SeverityMedium |
CVE-2026-100570OpenClaw before 2026.8.1 Remote Code Execution via CLOUDSDK_PYTHON_ARGS | Exploitation statusNot known exploited | FixYes | Affected productOpenClaw | Published09/26/2026 | SeverityHigh |
CVE-2026-100569OpenClaw before 2026.8.1 Credential Exposure via Endpoint Override | Exploitation statusNot known exploited | FixYes | Affected productOpenClaw | Published09/26/2026 | SeverityMedium |
CVE-2026-100568OpenClaw before 2026.8.1 Unauthorized Command Job Access | Exploitation statusNot known exploited | FixYes | Affected productOpenClaw | Published09/26/2026 | SeverityHigh |
CVE-2026-100567OpenClaw before 2026.8.1 DNS Rebinding via CDP Hostname | Exploitation statusNot known exploited | FixYes | Affected productOpenClaw | Published09/26/2026 | SeverityHigh |
CVE-2026-100566OpenClaw LINE before 2026.8.1 Access Control Inheritance | Exploitation statusNot known exploited | FixYes | Affected productline | Published09/26/2026 | SeverityMedium |
CVE-2026-100564OpenClaw before 2026.8.1 CSV Formula Injection via Attendance Export | Exploitation statusNot known exploited | FixYes | Affected productOpenClaw | Published09/26/2026 | SeverityMedium |
CVE-2026-100563OpenClaw before 2026.8.1 CSV Formula Injection via Session Labels | Exploitation statusNot known exploited | FixYes | Affected productOpenClaw | Published09/26/2026 | SeverityMedium |
CVE-2026-100562OpenClaw before 2026.8.1 Authorization Bypass via sessions.create | Exploitation statusNot known exploited | FixYes | Affected productOpenClaw | Published09/26/2026 | SeverityMedium |
CVE-2026-100561OpenClaw before 2026.8.1 Authentication Bypass via Exec Wrapper | Exploitation statusNot known exploited | FixYes | Affected productOpenClaw | Published09/26/2026 | SeverityHigh |
CVE-2026-100560OpenClaw before 2026.8.1 Reusable Exec Approvals Authorization Bypass | Exploitation statusNot known exploited | FixYes | Affected productOpenClaw | Published09/26/2026 | SeverityHigh |
CVE-2026-100559OpenClaw before 2026.8.1 Command Injection via Escaped Newlines | Exploitation statusNot known exploited | FixYes | Affected productOpenClaw | Published09/26/2026 | SeverityHigh |
CVE-2026-100558OpenClaw before 2026.8.1 Resource Exhaustion via WebSocket Upgrade | Exploitation statusNot known exploited | FixYes | Affected productOpenClaw | Published09/26/2026 | SeverityHigh |
CVE-2026-100557OpenClaw before 2026.8.1 Authorization Bypass via Skill Tool Dispatch | Exploitation statusNot known exploited | FixYes | Affected productOpenClaw | Published09/26/2026 | SeverityHigh |
CVE-2026-100556OpenClaw before 2026.8.1 Authentication Bypass via Session Reset | Exploitation statusNot known exploited | FixYes | Affected productOpenClaw | Published09/26/2026 | SeverityMedium |
CVE-2026-100555OpenClaw before 2026.8.1 DNS Rebinding via attachment delivery | Exploitation statusNot known exploited | FixYes | Affected productOpenClaw | Published09/26/2026 | SeverityHigh |
CVE-2026-100554OpenClaw before 2026.8.1 Canvas Capability Revocation Bypass | Exploitation statusNot known exploited | FixYes | Affected productOpenClaw | Published09/26/2026 | SeverityLow |
CVE-2026-100553OpenClaw 2026.6.9 before 2026.8.1 Cross-Context Policy Bypass via Feishu unpin | Exploitation statusNot known exploited | FixYes | Affected productOpenClaw | Published09/26/2026 | SeverityMedium |
CVE-2026-100552OpenClaw before 2026.8.1 Policy Bypass via Native Tools | Exploitation statusNot known exploited | FixYes | Affected productOpenClaw | Published09/26/2026 | SeverityHigh |
CVE-2026-100551OpenClaw iOS Control UI TLS Pin Enforcement Bypass | Exploitation statusNot known exploited | FixYes | Affected productOpenClaw | Published09/26/2026 | SeverityCritical |
CVE-2026-100550OpenClaw before 2026.8.1 Authentication Bypass via Access Group | Exploitation statusNot known exploited | FixYes | Affected productOpenClaw | Published09/26/2026 | SeverityMedium |
CVE-2026-100549OpenClaw before 2026.8.1 Path Traversal via QQBot voice filenames | Exploitation statusNot known exploited | FixYes | Affected productOpenClaw | Published09/26/2026 | SeverityMedium |
CVE-2026-100548OpenClaw before 2026.8.1 Credential Exposure via Embedding Fallback | Exploitation statusNot known exploited | FixYes | Affected productOpenClaw | Published09/26/2026 | SeverityMedium |
CVE-2026-100547OpenClaw before 2026.8.1 Authentication Bypass via File URL | Exploitation statusNot known exploited | FixYes | Affected productOpenClaw | Published09/26/2026 | SeverityMedium |
CVE-2026-100546OpenClaw 2026.7.2 before 2026.9.2 Authentication Bypass via Voice Transcript | Exploitation statusNot known exploited | FixYes | Affected productOpenClaw | Published09/26/2026 | SeverityMedium |
CVE-2026-100545OpenClaw before 2026.8.1 Policy Bypass via Session Filename Generation | Exploitation statusNot known exploited | FixYes | Affected productOpenClaw | Published09/26/2026 | SeverityMedium |
CVE-2026-100544openclaw voice-call before 2026.8.1 Authorization Bypass | Exploitation statusNot known exploited | FixYes | Affected productvoice-call | Published09/26/2026 | SeverityHigh |
CVE-2026-100543OpenClaw before 2026.8.1 Information Disclosure via Configuration Hash | Exploitation statusNot known exploited | FixYes | Affected productOpenClaw | Published09/26/2026 | SeverityHigh |
CVE-2026-100542OpenClaw before 2026.8.1 Extraction Limit Bypass via tar.bz2 | Exploitation statusNot known exploited | FixYes | Affected productOpenClaw | Published09/26/2026 | SeverityLow |
CVE-2026-100541OpenClaw Matrix before 2026.8.1 Authorization Bypass via Case Folding | Exploitation statusNot known exploited | FixYes | Affected productmatrix | Published09/26/2026 | SeverityHigh |
CVE-2026-100540OpenClaw Feishu before 2026.8.1 Authentication Bypass via Disabled Account | Exploitation statusNot known exploited | FixYes | Affected productfeishu | Published09/26/2026 | SeverityHigh |
CVE-2026-100539OpenClaw before 2026.8.1 Memory Access Control Bypass | Exploitation statusNot known exploited | FixYes | Affected productOpenClaw | Published09/26/2026 | SeverityLow |
CVE-2026-100538OpenClaw before 2026.8.1 Local File Read via Outbound Attachments | Exploitation statusNot known exploited | FixYes | Affected productOpenClaw | Published09/26/2026 | SeverityHigh |
CVE-2026-100537OpenClaw before 2026.8.1 Authentication Bypass via Active Memory | Exploitation statusNot known exploited | FixYes | Affected productOpenClaw | Published09/26/2026 | SeverityLow |
CVE-2026-100536OpenClaw before 2026.8.1 Path Traversal via Structured Attachments | Exploitation statusNot known exploited | FixYes | Affected productOpenClaw | Published09/26/2026 | SeverityHigh |
CVE-2026-100535OpenClaw before 2026.8.1 Privilege Escalation via Session Memory | Exploitation statusNot known exploited | FixYes | Affected productOpenClaw | Published09/26/2026 | SeverityHigh |
CVE-2026-100534OpenClaw before 2026.8.1 Session Cancellation Authorization Bypass | Exploitation statusNot known exploited | FixYes | Affected productOpenClaw | Published09/26/2026 | SeverityLow |
CVE-2026-100533OpenClaw before 2026.8.1 Path Traversal via Unicode Fallback | Exploitation statusNot known exploited | FixYes | Affected productOpenClaw | Published09/26/2026 | SeverityMedium |
CVE-2026-100532openclaw WhatsApp before 2026.8.1 Authentication Bypass | Exploitation statusNot known exploited | FixYes | Affected productwhatsapp | Published09/26/2026 | SeverityHigh |
CVE-2026-100531openclaw Slack before 2026.8.1 Authorization Bypass | Exploitation statusNot known exploited | FixYes | Affected productslack | Published09/26/2026 | SeverityHigh |
CVE-2026-100530OpenClaw before 2026.8.1 Exec Approval Directory Binding | Exploitation statusNot known exploited | FixYes | Affected productOpenClaw | Published09/26/2026 | SeverityHigh |
CVE-2026-100529OpenClaw before 2026.8.1 Authorization Scope Widening via File-Transfer | Exploitation statusNot known exploited | FixYes | Affected productOpenClaw | Published09/26/2026 | SeverityHigh |
CVE-2026-100528OpenClaw before 2026.8.1 Credential Disclosure via Provider Endpoint | Exploitation statusNot known exploited | FixYes | Affected productOpenClaw | Published09/26/2026 | SeverityMedium |
CVE-2026-100527OpenClaw before 2026.8.2 Denial of Service via Browser Relay | Exploitation statusNot known exploited | FixYes | Affected productOpenClaw | Published09/26/2026 | SeverityMedium |
CVE-2026-100526Vulnerability in discord | Exploitation statusNot known exploited | FixYes | Affected productdiscord | Published09/26/2026 | SeverityMedium |
CVE-2026-100525OpenClaw diagnostics-prometheus before 2026.9.3 Authentication Bypass | Exploitation statusNot known exploited | FixYes | Affected productdiagnostics-prometheus | Published09/26/2026 | SeverityMedium |
CVE-2026-95815OpenClaw iOS before 2026.8.11 Credential Exposure via Deep-Link URL Logging | Exploitation statusNot known exploited | FixYes | Affected productOpenClaw iOS | Published09/22/2026 | SeverityHigh |
CVE-2026-91836OpenClaw ClawScan Static Scanner static_scanner.go incomplete comparison with missing factors | Exploitation statusPublic exploit | FixYes | Affected productClawScan | Published09/15/2026 | SeverityLow |
CVE-2026-91835OpenClaw ClawScan File Classifier static_scanner.go IsBinaryFile interpretation conflict | Exploitation statusPublic exploit | FixYes | Affected productClawScan | Published09/15/2026 | SeverityLow |
CVE-2026-62229OpenClaw < 2026.5.18 Authorization Bypass via Glob Matching | Exploitation statusNot known exploited | FixYes | Affected productOpenClaw | Published07/17/2026 | SeverityHigh |
CVE-2026-62228OpenClaw < 2026.6.5 Authorization Bypass via Node Exec Approvals | Exploitation statusNot known exploited | FixYes | Affected productOpenClaw | Published07/17/2026 | SeverityHigh |
CVE-2026-62227OpenClaw 2026.4.14 < 2026.5.26 SSRF via Browser Snapshot | Exploitation statusNot known exploited | FixYes | Affected productOpenClaw | Published07/17/2026 | SeverityMedium |
CVE-2026-62226OpenClaw 2026.3.28 < 2026.5.19 Authorization Bypass via Browser Act Route | Exploitation statusNot known exploited | FixYes | Affected productOpenClaw | Published07/17/2026 | SeverityMedium |
CVE-2026-62225OpenClaw < 2026.5.18 Authorization Bypass via Skill Command Dispatch | Exploitation statusNot known exploited | FixYes | Affected productOpenClaw | Published07/17/2026 | SeverityLow |
CVE-2026-62224OpenClaw MS Teams < 2026.5.12 Authorization Bypass | Exploitation statusNot known exploited | FixYes | Affected productmsteams | Published07/17/2026 | SeverityLow |
CVE-2026-62223OpenClaw < 2026.5.18 Authorization Bypass via Device-pair | Exploitation statusNot known exploited | FixYes | Affected productOpenClaw | Published07/17/2026 | SeverityHigh |
CVE-2026-62222OpenClaw < 2026.5.22 Untrusted Plugin Loading via Setup-mode | Exploitation statusNot known exploited | FixYes | Affected productOpenClaw | Published07/17/2026 | SeverityHigh |
CVE-2026-62221OpenClaw 2026.5.12 < 2026.5.26 Authorization Bypass via allowFrom | Exploitation statusNot known exploited | FixYes | Affected productOpenClaw | Published07/17/2026 | SeverityLow |
CVE-2026-62220OpenClaw 2026.2.25 < 2026.5.26 WebSocket Rate Limit Bypass | Exploitation statusNot known exploited | FixYes | Affected productOpenClaw | Published07/17/2026 | SeverityMedium |
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.
Explore CyStack VulnScan