Openclaw
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in any Openclaw product.
RSS Feeds for Openclaw security vulnerabilities
Create a CVE RSS feed including security vulnerabilities found in Openclaw products with stack.watch. Just hit watch, then grab your custom RSS feed url.
Products by Openclaw Sorted by Most Security Vulnerabilities since 2018
By the Year
In 2026 there have been 559 vulnerabilities in Openclaw with an average score of 6.8 out of ten.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 559 | 6.77 |
It may take a day or so for new Openclaw vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Openclaw Security Vulnerabilities
| CVE | Date | Vulnerability | Products |
|---|---|---|---|
| CVE-2026-95815 | Sep 22, 2026 |
OpenClaw iOS <2026.8.11: Logging Bearer Keys in Deep-Links Exposes DataOpenClaw iOS before 2026.8.11 logs complete agent deep-link URLs including persistent bearer keys to unified logs as public diagnostic data. Attackers who obtain diagnostic archives can recover unrotated keys and replay them in forged deep links to submit agent requests without local confirmation prompts. |
|
| CVE-2026-94094 | Sep 20, 2026 |
OpenClaw 2026.9.5 Remote DoS via Canvas Host RouteA flaw has been found in OpenClaw up to 2026.9.5. Affected is the function createCanvasHostHandler of the file extensions/canvas/src/host/server.ts of the component Canvas Host Route. Executing a manipulation can lead to denial of service. The attack can be launched remotely. The exploit has been published and may be used. Fix suggestion's "streaming/size-limit" was never shipped - latest 2026.9.5 still buffers the whole file via readFile() (src/canvas/serve.runtime.ts:17,114), unlike the sibling WS path which caps at 64KB. The vendor was contacted early about this disclosure. |
|
| CVE-2026-91836 | Sep 15, 2026 |
OpenClaw ClawScan 0.1.6 Static Scanner Incomplete Comparison FlawA flaw has been found in OpenClaw ClawScan up to 0.1.6. This affects an unknown function of the file internal/runner/static_scanner.go of the component Static Scanner. This manipulation causes incomplete comparison with missing factors. It is possible to launch the attack on the local host. The exploit has been published and may be used. Upgrading to version 0.1.7 mitigates this issue. Patch name: 9f6a6fbb9f1137345566d0ab44c73893dfe112fa. The affected component should be upgraded. |
|
| CVE-2026-91835 | Sep 15, 2026 |
A vulnerability was detected in OpenClaw ClawScan up to 0.1.6A vulnerability was detected in OpenClaw ClawScan up to 0.1.6. The impacted element is the function IsBinaryFile of the file internal/runner/static_scanner.go of the component File Classifier. The manipulation results in interpretation conflict. Attacking locally is a requirement. The exploit is now public and may be used. Upgrading to version 0.1.7 is sufficient to resolve this issue. The patch is identified as 04401337b3adb9343bd338b21e5e258bf49ca9c8. You should upgrade the affected component. |
|
| CVE-2026-62228 | Jul 17, 2026 |
OpenClaw <2026.6.5: Authorization Bypass in Node Exec ApprovalsOpenClaw before 2026.6.5 contain an authorization bypass vulnerability in node exec approvals that allows lower-trust callers to execute actions beyond their intended authorization by using different gateway and node environments. Attackers can exploit mismatched environment configurations to persist or execute actions that exceed the caller's approved permissions. |
|
| CVE-2026-62229 | Jul 17, 2026 |
OpenClaw <2026.5.18 Auth Bypass via Exec Allowlist GlobOpenClaw before 2026.5.18 contain an authorization bypass vulnerability in exec allowlist glob matching that allows lower-trust callers to execute actions beyond intended authorization. Attackers can craft input paths that traverse the allowlist glob patterns to execute or persist unauthorized actions when the affected feature is enabled. |
|
| CVE-2026-62227 | Jul 17, 2026 |
OpenClaw <2026.5.26 SSRF via Browser Snapshot RoutesOpenClaw 2026.4.14 before 2026.5.26 contain a server-side request forgery vulnerability in browser snapshot routes that fail to validate post-navigation destinations. Attackers with lower-trust access can bypass OpenClaw policy checks to reach network destinations that should have been blocked. |
|
| CVE-2026-62225 | Jul 17, 2026 |
OpenClaw Auth Bypass in Skill Cmd Dispatch (V<2026.5.18)OpenClaw versions before 2026.5.18 contain an authorization bypass vulnerability in skill command dispatch that allows lower-trust callers to execute or persist actions beyond their intended authorization. Attackers can bypass tool policy restrictions through configured input paths to perform unauthorized actions when the affected feature is enabled and reachable. |
|
| CVE-2026-62226 | Jul 17, 2026 |
OpenClaw Browser 2026.3.28 Auth Bypass via act Route (v<2026.5.19)OpenClaw 2026.3.28 before 2026.5.19 contain an authorization bypass vulnerability in the browser act route that fails to properly validate current-tab URL checks. Attackers with lower-trust access or configured input paths can perform actions requiring stronger authorization or policy checks. |
|
| CVE-2026-62224 | Jul 17, 2026 |
MS Teams <2026.5.12 Auth Bypass via AllowFrom Mutable NamesOpenClaw MS Teams before 2026.5.12 contain an authorization bypass vulnerability where the allowFrom feature binds to mutable display names. Attackers with lower-trust access can perform actions requiring stronger authorization by exploiting the mutable display name binding in the affected feature. |