OpenClaw
OpenClaw · 603 CVEs
OpenClaw before 2026.9.4 Authorization Bypass via MCP App Standalone Ticket
Sep 29, 2026
OpenClaw before 2026.9.5 Sandbox Isolation Bypass via Media Pipelines
Sep 29, 2026
OpenClaw 2026.5.1 before 2026.7.1 Remote Code Execution via googlemeet.chrome
Sep 26, 2026
OpenClaw before 2026.7.1 Approval Binding Logic Error
Sep 26, 2026
OpenClaw before 2026.7.1 Path Traversal via Filesystem Race
Sep 26, 2026
OpenClaw before 2026.7.1 Authorization Bypass via MCP Configuration
Sep 26, 2026
OpenClaw before 2026.7.1 Authorization Bypass via diagnostics
Sep 26, 2026
OpenClaw before 2026.7.1 Authorization Bypass via trajectory export
Sep 26, 2026
OpenClaw before 2026.7.1 Authentication Bypass via activation
Sep 26, 2026
OpenClaw before 2026.7.1 Authentication Bypass via Memory Dreaming
Sep 26, 2026
OpenClaw before 2026.7.1 Authentication Bypass via Active Memory
Sep 26, 2026
OpenClaw before 2026.7.1 Authorization Bypass via voice set
Sep 26, 2026
OpenClaw before 2026.7.1 Sandbox Bypass via Browser Node
Sep 26, 2026
OpenClaw before 2026.7.1 Authentication Bypass via node.invoke
Sep 26, 2026
OpenClaw before 2026.7.1 Authorization Bypass via Codex Install
Sep 26, 2026
OpenClaw Codex before 2026.7.1 Authorization Bypass via Bind
Sep 26, 2026
OpenClaw before 2026.7.1 Authentication Bypass via MCP Channel
Sep 26, 2026
OpenClaw before 2026.7.1 Allowlist Bypass via Workspace Shadows
Sep 26, 2026
OpenClaw iOS before 2026.8.11 Credential Storage via Share Extension
Sep 26, 2026
OpenClaw before 2026.7.1 Remote Code Execution via cron tool
Sep 26, 2026
OpenClaw before 2026.7.1 Authentication Bypass via Spoofed Requester
Sep 26, 2026
OpenClaw before 2026.7.1 Authorization Bypass via chat.send
Sep 26, 2026
OpenClaw before 2026.8.1 Server-Side Request Forgery via Video Asset
Sep 26, 2026
OpenClaw before 2026.8.1 SSRF via Browser Wait Predicates
Sep 26, 2026
OpenClaw before 2026.8.1 SSRF via Trusted-Host DNS
Sep 26, 2026
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-102807 | OpenClaw before 2026.9.4 Authorization Bypass via MCP App Standalone Ticket | MEDIUM | 0.23% | Sep 29, 2026 |
| CVE-2026-102806 | OpenClaw before 2026.9.5 Sandbox Isolation Bypass via Media Pipelines | MEDIUM | 0.25% | Sep 29, 2026 |
| CVE-2026-100599 | OpenClaw 2026.5.1 before 2026.7.1 Remote Code Execution via googlemeet.chrome | HIGH | 0.30% | Sep 26, 2026 |
| CVE-2026-100598 | OpenClaw before 2026.7.1 Approval Binding Logic Error | HIGH | 0.11% | Sep 26, 2026 |
| CVE-2026-100597 | OpenClaw before 2026.7.1 Path Traversal via Filesystem Race | HIGH | 0.08% | Sep 26, 2026 |
| CVE-2026-100596 | OpenClaw before 2026.7.1 Authorization Bypass via MCP Configuration | HIGH | 0.25% | Sep 26, 2026 |
| CVE-2026-100595 | OpenClaw before 2026.7.1 Authorization Bypass via diagnostics | HIGH | 0.24% | Sep 26, 2026 |
| CVE-2026-100594 | OpenClaw before 2026.7.1 Authorization Bypass via trajectory export | HIGH | 0.24% | Sep 26, 2026 |
| CVE-2026-100593 | OpenClaw before 2026.7.1 Authentication Bypass via activation | MEDIUM | 0.14% | Sep 26, 2026 |
| CVE-2026-100592 | OpenClaw before 2026.7.1 Authentication Bypass via Memory Dreaming | MEDIUM | 0.16% | Sep 26, 2026 |
| CVE-2026-100591 | OpenClaw before 2026.7.1 Authentication Bypass via Active Memory | MEDIUM | 0.16% | Sep 26, 2026 |
| CVE-2026-100590 | OpenClaw before 2026.7.1 Authorization Bypass via voice set | MEDIUM | 0.18% | Sep 26, 2026 |
| CVE-2026-100589 | OpenClaw before 2026.7.1 Sandbox Bypass via Browser Node | HIGH | 0.32% | Sep 26, 2026 |
| CVE-2026-100588 | OpenClaw before 2026.7.1 Authentication Bypass via node.invoke | HIGH | 0.30% | Sep 26, 2026 |
| CVE-2026-100587 | OpenClaw before 2026.7.1 Authorization Bypass via Codex Install | HIGH | 0.25% | Sep 26, 2026 |
| CVE-2026-100586 | OpenClaw Codex before 2026.7.1 Authorization Bypass via Bind | HIGH | 0.25% | Sep 26, 2026 |
| CVE-2026-100585 | OpenClaw before 2026.7.1 Authentication Bypass via MCP Channel | HIGH | 0.19% | Sep 26, 2026 |
| CVE-2026-100584 | OpenClaw before 2026.7.1 Allowlist Bypass via Workspace Shadows | MEDIUM | 0.10% | Sep 26, 2026 |
| CVE-2026-100581 | OpenClaw iOS before 2026.8.11 Credential Storage via Share Extension | MEDIUM | 0.08% | Sep 26, 2026 |
| CVE-2026-100580 | OpenClaw before 2026.7.1 Remote Code Execution via cron tool | HIGH | 0.34% | Sep 26, 2026 |
| CVE-2026-100579 | OpenClaw before 2026.7.1 Authentication Bypass via Spoofed Requester | HIGH | 0.23% | Sep 26, 2026 |
| CVE-2026-100578 | OpenClaw before 2026.7.1 Authorization Bypass via chat.send | HIGH | 0.23% | Sep 26, 2026 |
| CVE-2026-100577 | OpenClaw before 2026.8.1 Server-Side Request Forgery via Video Asset | MEDIUM | 0.14% | Sep 26, 2026 |
| CVE-2026-100576 | OpenClaw before 2026.8.1 SSRF via Browser Wait Predicates | MEDIUM | 0.21% | Sep 26, 2026 |
| CVE-2026-100574 | OpenClaw before 2026.8.1 SSRF via Trusted-Host DNS | HIGH | 0.23% | Sep 26, 2026 |
Showing 1 to 25 of 603 CVEs