Openclaw Openclaw

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Openclaw.

By the Year

In 2026 there have been 543 vulnerabilities in Openclaw with an average score of 6.8 out of ten.

Year Vulnerabilities Average Score
2026 543 6.76

It may take a day or so for new Openclaw vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Openclaw Security Vulnerabilities

OpenClaw <2026.5.18 Auth Bypass via Exec Allowlist Glob
CVE-2026-62229 8.8 - High - July 17, 2026

OpenClaw before 2026.5.18 contain an authorization bypass vulnerability in exec allowlist glob matching that allows lower-trust callers to execute actions beyond intended authorization. Attackers can craft input paths that traverse the allowlist glob patterns to execute or persist unauthorized actions when the affected feature is enabled.

Directory traversal

OpenClaw <2026.6.5: Authorization Bypass in Node Exec Approvals
CVE-2026-62228 8.8 - High - July 17, 2026

OpenClaw before 2026.6.5 contain an authorization bypass vulnerability in node exec approvals that allows lower-trust callers to execute actions beyond their intended authorization by using different gateway and node environments. Attackers can exploit mismatched environment configurations to persist or execute actions that exceed the caller's approved permissions.

AuthZ

OpenClaw <2026.5.26 SSRF via Browser Snapshot Routes
CVE-2026-62227 7.7 - High - July 17, 2026

OpenClaw 2026.4.14 before 2026.5.26 contain a server-side request forgery vulnerability in browser snapshot routes that fail to validate post-navigation destinations. Attackers with lower-trust access can bypass OpenClaw policy checks to reach network destinations that should have been blocked.

SSRF

OpenClaw Browser 2026.3.28 Auth Bypass via act Route (v<2026.5.19)
CVE-2026-62226 8.5 - High - July 17, 2026

OpenClaw 2026.3.28 before 2026.5.19 contain an authorization bypass vulnerability in the browser act route that fails to properly validate current-tab URL checks. Attackers with lower-trust access or configured input paths can perform actions requiring stronger authorization or policy checks.

SSRF

OpenClaw Auth Bypass in Skill Cmd Dispatch (V<2026.5.18)
CVE-2026-62225 5.4 - Medium - July 17, 2026

OpenClaw versions before 2026.5.18 contain an authorization bypass vulnerability in skill command dispatch that allows lower-trust callers to execute or persist actions beyond their intended authorization. Attackers can bypass tool policy restrictions through configured input paths to perform unauthorized actions when the affected feature is enabled and reachable.

AuthZ

OpenClaw <2026.5.18 Authorization Bypass in Device-Pair Approval (CVE-2026-62223)
CVE-2026-62223 8.8 - High - July 17, 2026

OpenClaw before 2026.5.18 contain an authorization bypass vulnerability in the device-pair approval feature that allows lower-trust callers to execute actions beyond their intended authorization. Attackers can exploit misconfigured input paths to execute or persist unauthorized actions when the affected feature is enabled and reachable.

AuthZ

OpenClaw <2026.5.22: SetupMode Allows Untrusted Plugin Load
CVE-2026-62222 7.8 - High - July 17, 2026

OpenClaw before 2026.5.22 contain a vulnerability in setup-mode discovery that allows loading of untrusted workspace plugins. Attackers with lower-trust caller access or control over configured input paths can execute or persist actions beyond their intended authorization level.

Inclusion of Functionality from Untrusted Control Sphere

OpenClaw <=2026.5.25 ClickClack allowFrom incorrect auth
CVE-2026-62221 5.4 - Medium - July 17, 2026

OpenClaw 2026.5.12 before 2026.5.26 contain an incorrect authorization vulnerability in the ClickClack allowFrom feature. When the affected feature is enabled and reachable, a lower-trust caller or configured input path could execute or persist actions beyond the caller's intended authorization, including running non-allowlisted commands.

AuthZ

OpenClaw <=2026.5.25 WebSocket Rate-Limit Bypass (CVE-2026-62220)
CVE-2026-62220 5.3 - Medium - July 17, 2026

OpenClaw 2026.2.25 before 2026.5.26 allow a lower-trust caller or configured input path to bypass non-browser rate limits on WebSocket authentication attempts. When the affected feature is enabled and reachable by lower-trust input, this can consume gateway resources and reduce service availability.

Improper Restriction of Excessive Authentication Attempts

OpenClaw 2026.2.12 Authorization Bypass in allowedAgentIds (before 2026.5.26)
CVE-2026-62219 7.1 - High - July 17, 2026

OpenClaw 2026.2.12 before 2026.5.26 contain an authorization bypass vulnerability in the hooks allowedAgentIds validation. A lower-trust caller or configured input path can bypass agent ID restrictions by submitting blank agent IDs, allowing actions that should require stronger authorization or policy checks.

AuthZ

OpenClaw 2026.1.20-<2026.5.27 Auth Bypass via device.pair.approve
CVE-2026-62218 8.8 - High - July 17, 2026

OpenClaw 2026.1.20 before 2026.5.27 contain an authorization bypass vulnerability in the device.pair.approve feature that allows lower-trust callers to bypass role-management checks. Attackers can perform actions requiring stronger authorization by reaching the affected feature through configured input paths.

AuthZ

OpenClaw 2026.5.14-beta.1 2026.5.27: QQBot Exec Approvals Auth Bypass
CVE-2026-62217 8.8 - High - July 17, 2026

OpenClaw 2026.5.14-beta.1 before 2026.5.27 contain an authorization flaw in the QQBot exec approvals feature. When the feature is enabled and reachable, a lower-trust caller or configured input path could execute or persist actions beyond the caller's intended authorization, allowing non-allowlisted senders to perform unauthorized operations.

AuthZ

OpenClaw 2026.4.20/2026.5.28 SSRF QQBot media upload
CVE-2026-62216 5 - Medium - July 17, 2026

OpenClaw 2026.4.20 before 2026.5.28 contain a policy bypass in the QQBot media upload feature. A lower-trust caller or configured input path could cause the media upload to reach network destinations that should have been blocked by OpenClaw policy (server-side request forgery). The practical impact depends on the operator's configuration and whether lower-trust input can reach that path.

SSRF

OpenClaw <2026.6.5 Auth Bypass via HTTP Canvas (A2UI)
CVE-2026-62215 8 - High - July 17, 2026

OpenClaw versions before 2026.6.5 contain an authentication bypass vulnerability in HTTP Canvas responses that allows lower-trust callers to forge trusted A2UI actions. Attackers can perform actions requiring stronger authorization by submitting crafted requests through configured input paths, bypassing intended policy checks.

Insufficient Verification of Data Authenticity

OpenClaw <2026.5.28: Race Cond in MS Teams safeFetch DNS Rebnd Check
CVE-2026-62212 7.1 - High - July 17, 2026

OpenClaw before 2026.5.28 contains a race condition in the MS Teams safeFetch DNS rebinding check. When the affected feature is enabled and reachable, a lower-trust caller or configured input path could win a timing window between the DNS validation check and use, allowing actions that should have required a stronger authorization or policy check. Practical impact depends on the operator's configuration and whether lower-trust input can reach that path.

TOCTTOU

OpenClaw <2026.6.1: Trajectory Export Bypass Credential Redaction
CVE-2026-62211 5 - Medium - July 17, 2026

OpenClaw versions before 2026.6.1 contain a credential redaction bypass vulnerability in the trajectory export feature that allows lower-trust callers to access data that should remain within trusted boundaries. Attackers can exploit misconfigured input paths or feature accessibility to expose sensitive credentials and data through the export mechanism.

Insertion of Sensitive Information into Log File

OpenClaw <2026.6.1: DoS via Slow-Read Attack on Gateway Worker
CVE-2026-62210 6.5 - Medium - July 17, 2026

OpenClaw versions before 2026.6.1 contain a denial of service vulnerability where remote media URLs can trigger slow-read attacks that exhaust gateway worker resources. Attackers with access to configured input paths can supply remote media URLs that consume gateway resources and reduce availability.

Allocation of Resources Without Limits or Throttling

OpenClaw 2026.5.10-beta.1 Auth Bypass in ClickClack Agent-Mode (before 2026.6.5)
CVE-2026-62209 8.1 - High - July 17, 2026

OpenClaw versions 2026.5.10-beta.1 before 2026.6.5 contain an authorization bypass in the ClickClack agent-mode dispatch feature, which could ignore the toolsAllow policy check. When the affected feature is enabled and reachable, a lower-trust caller or configured input path could perform actions that should have required a stronger authorization or policy check.

AuthZ

OpenClaw <2026.6.5: Auth Header Leakage via MCP SSE Redirects
CVE-2026-62208 6.5 - Medium - July 17, 2026

OpenClaw before 2026.6.5 could forward Authorization headers during MCP SSE redirects. When the affected feature is enabled and reachable, a lower-trust caller or configured input path could execute or persist actions beyond the caller's intended authorization. Impact depends on the operator's configuration and whether lower-trust input can reach the affected path.

Insufficiently Protected Credentials

OpenClaw <2026.6.5: Auth Bypass via Insufficient Policy Checks
CVE-2026-62207 8.8 - High - July 17, 2026

OpenClaw versions before 2026.6.5 contain an authentication bypass vulnerability that allows lower-trust callers to reach admin-scoped tools. Attackers can perform actions requiring stronger authorization by exploiting insufficient policy checks on configured input paths.

AuthZ

OpenClaw <2026.6.9 Missing Auth for Discord Moderation Actions
CVE-2026-62206 7.1 - High - July 17, 2026

OpenClaw versions before 2026.6.9 contain a missing authorization vulnerability in Discord moderation actions. In affected versions, a lower-trust caller or configured input path could perform moderation actions that should have required a stronger authorization or policy check. Practical impact depends on the operator's configuration and whether lower-trust input can reach the affected path.

AuthZ

OpenClaw <2026.6.6 Missing Auth in MS Teams Message Actions
CVE-2026-62205 7.1 - High - July 17, 2026

OpenClaw versions 2026.4.12-beta.1 before 2026.6.6 contain a missing-authorization vulnerability in the MS Teams message actions feature. When the affected feature is enabled and reachable, a lower-trust caller or a configured input path can perform actions that should have required a stronger authorization or policy check. Practical impact depends on the operator's configuration and whether lower-trust input can reach that path. The issue is fixed in 2026.6.6.

AuthZ

OpenClaw <2026.6.6: Host Exec Env Variable Filtering Vulnerability (rustup)
CVE-2026-62203 8.8 - High - July 17, 2026

OpenClaw versions before 2026.6.6 contain an environment variable filtering vulnerability in host exec that fails to properly sanitize rustup startup variables. Attackers with lower-trust caller access or configured input paths can execute or persist actions beyond their intended authorization level.

Denylist / Deny List

OpenClaw 2026.6.1<2026.6.9 PrivEsc via Cron Jobs
CVE-2026-62202 8.8 - High - July 17, 2026

OpenClaw versions 2026.6.1 before 2026.6.9 contain a privilege escalation vulnerability in isolated cron jobs that allows lower-trust callers to regain denied execution tools. Attackers can execute or persist actions beyond their intended authorization by leveraging misconfigured input paths in the affected cron feature.

AuthZ

OpenClaw 2026.6.6 Exec-Server Network Policy Bypass
CVE-2026-62201 7.7 - High - July 17, 2026

OpenClaw versions before 2026.6.6 contain a network policy bypass vulnerability in the sandbox exec-server that allows lower-trust callers to reach internal network destinations blocked by OpenClaw policy. Attackers can send HTTP requests through the exec-server to access network resources that should have been restricted by configured policies.

SSRF

OpenClaw <2026.6.1 Host Exec Env Filtering Flaw
CVE-2026-62200 8.8 - High - July 13, 2026

OpenClaw versions before 2026.6.6 contain a flaw in host exec environment filtering that could allow Git ext transport to be abused. When the affected feature is enabled and reachable, a lower-trust caller or configured input path could execute or persist actions beyond the caller's intended authorization.

Denylist / Deny List

OpenClaw <2026.6.6 Exec Env Filter Bypass via Startup Vars
CVE-2026-62199 8.8 - High - July 13, 2026

OpenClaw versions before 2026.6.6 contain a flaw in host exec environment filtering that can miss interpreter startup variables. When the affected feature is enabled and reachable, a lower-trust caller or configured input path can supply crafted environment variables to execute or persist actions beyond the caller's intended authorization.

Denylist / Deny List

OpenClaw 2026.5.28 Auth Bypass in Web Search Pre-2026.6.6
CVE-2026-62198 4.3 - Medium - July 13, 2026

OpenClaw versions 2026.5.28 before 2026.6.6 contain an authorization bypass vulnerability in native web search that allows lower-trust callers to perform actions requiring stronger policy checks. Attackers can exploit misconfigured input paths to bypass intended authorization controls and execute restricted operations.

AuthZ

OpenClaw <2026.6.6: Policy Bypass via CDP Discovery on Blocked WS URLs
CVE-2026-62197 8.5 - High - July 13, 2026

OpenClaw before 2026.6.6 contains a policy bypass vulnerability in browser CDP discovery that accepts blocked WebSocket URLs. Attackers with lower-trust access can reach network destinations that should have been blocked by OpenClaw policy when the affected feature is enabled.

SSRF

OpenClaw (<2026.6.6): Auth Bypass via WhatsApp Group ID
CVE-2026-62196 8.3 - High - July 13, 2026

OpenClaw versions 2026.3.22 before 2026.6.6 contain an authorization bypass vulnerability where WhatsApp group IDs can satisfy elevated sender allowlists. Attackers with lower-trust access can perform actions requiring stronger authorization by leveraging group ID validation in the affected feature.

AuthZ

OpenClaw < 2026.6.6 Auth Bypass in MCP Loopback
CVE-2026-62195 8.3 - High - July 13, 2026

OpenClaw versions 2026.5.20 before 2026.6.6 contain an authorization bypass vulnerability in the MCP loopback feature that allows lower-trust callers to execute owner-only tools. Attackers can bypass authorization checks through configured input paths to execute or persist actions beyond their intended permissions.

Incorrect Permission Assignment for Critical Resource

OpenClaw <2026.6.9 PrivEsc via Plugin Install Path Hijack
CVE-2026-62194 8.8 - High - July 13, 2026

OpenClaw versions 2026.5.20 before 2026.6.9 contain a privilege escalation vulnerability in plugin install commands that allows lower-trust callers to execute or persist actions beyond their intended authorization. Attackers can exploit misconfigured input paths or enabled features to escalate privileges and perform unauthorized actions when the feature is reachable.

Incorrect Permission Assignment for Critical Resource

OpenClaw <2026.6.9 Plugin Install Wrapper Bypass (Auth)
CVE-2026-62193 4.9 - Medium - July 13, 2026

OpenClaw versions 2026.6.5 before 2026.6.9 contain a vulnerability in the plugin install wrappers that could skip the install policy (authorization) check. When the affected feature is enabled and reachable, a lower-trust caller or a configured input path could execute or persist actions beyond the caller's intended authorization. Impact depends on the operator's configuration and whether lower-trust input can reach the affected path. The issue is fixed in 2026.6.9.

AuthZ

Auth Bypass in Discord Guild Actions OpenClaw <2026.6.9
CVE-2026-62192 8.1 - High - July 13, 2026

OpenClaw versions 2026.6.6 before 2026.6.9 contain an authorization bypass vulnerability in Discord guild actions that allows lower-trust callers to perform actions requiring stronger authorization checks. Attackers can exploit misconfigured input paths to skip cross-provider requester authorization and execute restricted operations.

AuthZ

OpenClaw <2026.6.9 Auth Bypass via Message Mutation
CVE-2026-62191 7.1 - High - July 13, 2026

OpenClaw versions 2026.6.6 before 2026.6.9 contain an authorization bypass vulnerability in message mutation handling that allows lower-trust callers to perform actions requiring stronger authorization checks. Attackers can exploit misconfigured input paths to skip requester authorization and execute privileged operations when the affected feature is enabled and reachable.

AuthZ

OpenClaw <2026.6.9 Auth Bypass via flock wrapper
CVE-2026-62190 8.8 - High - July 13, 2026

OpenClaw versions before 2026.6.9 contain an authorization bypass vulnerability in the flock wrapper that allows lower-trust callers to execute or persist actions beyond their intended authorization. Attackers can leverage configured input paths to bypass durable exec approval binding and perform unauthorized operations when the affected feature is enabled.

Use of Incorrectly-Resolved Name or Reference

OpenClaw <2026.6.9: Symlink Follow in Mirror Sync Bypass Auth
CVE-2026-62189 7.1 - High - July 13, 2026

OpenClaw versions before 2026.6.9 contain a symlink following vulnerability in the mirror sync feature that allows lower-trust callers to perform actions requiring stronger authorization. Attackers can exploit remote symlink parents to bypass policy checks and authorization boundaries when the feature is enabled and reachable.

insecure temporary file

OpenClaw < 2026.6.8: Auth Bypass via OpenAI-Compat HTTP Overrides
CVE-2026-62186 7.6 - High - July 13, 2026

OpenClaw versions before 2026.6.8 contain an authorization bypass vulnerability in OpenAI-compatible HTTP model overrides that allows lower-trust callers to perform actions requiring stronger authorization checks. Attackers can exploit misconfigured input paths to bypass admin authorization policies and execute restricted operations.

AuthZ

OpenClaw <2026.5.28: Credential Exposure via .env Override
CVE-2026-59261 7.1 - High - July 08, 2026

OpenClaw before 2026.5.28 contains a credential exposure vulnerability where workspace dotenv files can override provider credentials. Attackers with lower-trust access to configured input paths can expose sensitive data and credentials that should remain within trusted boundaries.

Denylist / Deny List

OpenClaw <=2026.5.12 Allowlist Bypass in Shell Inline-Command Parser
CVE-2026-53866 8.1 - High - June 16, 2026

OpenClaw before 2026.5.12 contains an allowlist bypass vulnerability in shell inline-command parsing that allows authenticated operators to execute unapproved commands. A command request using shell inline-command forms could route through a parser case missing the expected allowlist decision, enabling shell content execution without intended approval prompts.

AuthZ

OpenClaw 2026.5.2 Path Traversal via Maintenance Tasks
CVE-2026-53865 7.1 - High - June 16, 2026

OpenClaw before 2026.5.2 contains a path traversal vulnerability in maintenance task execution that allows workspace-derived service paths to influence trash command selection. Attackers can execute unintended local executables from operator-unintended paths during maintenance operations by manipulating workspace-derived environment paths.

Untrusted Path

OpenClaw <2026.5.26: Env Sanitizer Bypass via Node.js Vars
CVE-2026-53864 8.1 - High - June 16, 2026

OpenClaw before 2026.5.26 contains an insufficient sanitization vulnerability in the host environment sanitizer that allows Node.js control variables to bypass validation. Attackers with access to workspace .env files, tool environment overrides, or skill environment blocks can pass malicious Node.js control variables to influence child processes or coverage output paths.

Denylist / Deny List

OpenClaw < 2026.4.25 Group ID Policy Bypass (CVE-2026-53863)
CVE-2026-53863 7.1 - High - June 16, 2026

OpenClaw before 2026.4.25 contains an input validation vulnerability in tool group policy callers that accept unvalidated group IDs. Attackers who can supply a group ID to the policy resolver could trigger incorrect group-policy decisions for tool invocations, potentially bypassing intended access controls.

Insecure Direct Object Reference / IDOR

OpenClaw < 2026.5.12 Token Replay Escalates Pairing Authority
CVE-2026-53862 4.2 - Medium - June 16, 2026

OpenClaw before 2026.5.12 contains a bootstrap token replay vulnerability allowing callers with pending token access to reuse tokens with broader requested scopes. Attackers can replay bootstrap tokens before approval to escalate pairing authority beyond intended scope limits.

Incorrect Privilege Assignment

OpenClaw <2026.5.6: Allowlist Bypass in Swift Exec (macOS)
CVE-2026-53861 6.6 - Medium - June 16, 2026

OpenClaw before 2026.5.6 contains an allowlist bypass vulnerability in the macOS Swift exec feature that misses combined POSIX inline-command flags. Attackers can execute shell content outside the intended allowlist check by using combined flag forms, potentially allowing unauthorized command execution depending on operator configuration.

Denylist / Deny List

OpenClaw 2026.5.6 Sender Policy Bypass via BlueBubbles Metadata
CVE-2026-53860 4.2 - Medium - June 16, 2026

OpenClaw before 2026.5.7 contains a sender policy bypass vulnerability in BlueBubbles that allows participants to match allowlist entries through conversation metadata rather than stable sender identity. Attackers can influence conversation-level identifiers to receive agent responses intended for configured senders, potentially bypassing access controls.

Reliance on Untrusted Inputs in a Security Decision

OpenClaw <2026.5.26 Hostname Validation Bypass via Trailing-Dot URLs
CVE-2026-53859 6.5 - Medium - June 16, 2026

OpenClaw before 2026.5.26 contains a hostname validation vulnerability allowing attackers to bypass blocklist comparisons using trailing-dot notation in model or workspace-derived URLs. Attackers can exploit inconsistent hostname checks to reach destinations that operators intended to block through hostname policies.

Incomplete Comparison with Missing Factors

OpenClaw 2026.5.2 Env Variable Injection
CVE-2026-53858 7.1 - High - June 16, 2026

OpenClaw before 2026.5.2 contains an environment variable injection vulnerability where workspace .env STATE_DIRECTORY could influence bundled runtime dependency roots. Attackers can manipulate the STATE_DIRECTORY variable to load runtime dependencies from unintended local paths, potentially executing malicious code during dependency resolution.

Untrusted Path

OpenClaw < 2026.5.3: Policy Enf. Flaw via Mutable Display Meta
CVE-2026-53857 8.1 - High - June 16, 2026

OpenClaw before 2026.5.3 contains a policy enforcement vulnerability where Zalo contacts with mutable display metadata could match allowFrom policy entries through display name changes. Attackers with mutable display names could receive agent responses intended for different Zalo identities when the feature is enabled.

Authentication Bypass by Spoofing

OpenClaw <2026.4.24 insecure file perms in config recovery
CVE-2026-53856 5.5 - Medium - June 16, 2026

OpenClaw 2026.4.23 before 2026.4.24 contains an insecure file permissions vulnerability in config recovery that restores OpenClaw.json with overly broad permissions. Local attackers on shared hosts can read sensitive configuration data by exploiting the recovery path to access the restored config file.

Incorrect Permission Assignment for Critical Resource

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Openclaw or by Openclaw? Click the Watch button to subscribe.

Openclaw
Vendor

Openclaw
Product

subscribe