Openclaw
This hub aggregates every CVE we track for Openclaw, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
579
CVEs tracked
29
Critical
252
High
0
In CISA KEV
Severity distribution
MEDIUM275HIGH252CRITICAL29LOW23
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
35
198
174
70
61
41
2024-082026-07
Latest CVEs
The 15 most recently published vulnerabilities affecting Openclaw.
- CVE-2026-62229OpenClaw < 2026.5.18 Authorization Bypass via Glob Matching8.8
- CVE-2026-62228OpenClaw < 2026.6.5 Authorization Bypass via Node Exec Approvals8.8
- CVE-2026-62227OpenClaw 2026.4.14 < 2026.5.26 SSRF via Browser Snapshot7.7
- CVE-2026-62226OpenClaw 2026.3.28 < 2026.5.19 Authorization Bypass via Browser Act Route8.5
- CVE-2026-62225OpenClaw < 2026.5.18 Authorization Bypass via Skill Command Dispatch5.4
- CVE-2026-62223OpenClaw < 2026.5.18 Authorization Bypass via Device-pair8.8
- CVE-2026-62222OpenClaw < 2026.5.22 Untrusted Plugin Loading via Setup-mode7.8
- CVE-2026-62221OpenClaw 2026.5.12 < 2026.5.26 Authorization Bypass via allowFrom5.4
- CVE-2026-62220OpenClaw 2026.2.25 < 2026.5.26 WebSocket Rate Limit Bypass5.3
- CVE-2026-62219OpenClaw 2026.2.12 < 2026.5.26 Authorization Bypass via Blank Agent IDs7.1
- CVE-2026-62218OpenClaw 2026.1.20 < 2026.5.27 Authorization Bypass via device.pair.approve8.8
- CVE-2026-62217OpenClaw 2026.5.14-beta.1 < 2026.5.27 Authentication Bypass via exec approvals8.8
- CVE-2026-62216OpenClaw 2026.4.20 < 2026.5.28 Policy Bypass via Media Upload5.0
- CVE-2026-62215OpenClaw < 2026.6.5 Authentication Bypass via HTTP Canvas8.0
- CVE-2026-62214OpenClaw < 2026.5.28 Bot Framework SSRF via serviceUrl Parameter Validation6.5
Product normalization is registry-driven with AI assist and human review. How it works