OpenClaw Vulnerabilities

pip AI Agents

AI Threat Alert tracks 479 known vulnerabilities in OpenClaw, 18 rated critical — an AI/ML ai agents in the pip ecosystem. Each CVE includes CVSS severity, EPSS exploit probability, patch status, and CISO-grade analysis.

Data sources
479
Total CVEs
18
Critical
pip
Ecosystem
Jul 30, 2026
Last CVE
37%
Patch Rate
3d
Avg Time to Patch

Known Vulnerabilities (479 total, page 1 of 20)

Severity CVE ID Summary CVSS Published
CRITICAL CVE-2026-66421 OpenClaw Dashboard: stored XSS enables admin takeover 9.3 Jul 30, 2026 HIGH CVE-2026-66420 MeshCentral: origin-check bypass lets attackers hijack admin sessions 8.8 Jul 30, 2026 CRITICAL CVE-2026-66418 OpenClaw: stored XSS via login field hijacks admin 9.3 Jul 30, 2026 HIGH CVE-2026-62229 OpenClaw: glob bypass in exec allowlist enables auth bypass 8.8 Jul 17, 2026 HIGH CVE-2026-62228 OpenClaw: authz bypass in node exec approvals 8.8 Jul 17, 2026 HIGH CVE-2026-62227 OpenClaw: SSRF bypass in browser snapshot navigation 7.7 Jul 17, 2026 HIGH CVE-2026-62226 OpenClaw: auth bypass in browser act route 8.5 Jul 17, 2026 MEDIUM CVE-2026-62225 OpenClaw: authz bypass in skill dispatch 5.4 Jul 17, 2026 MEDIUM CVE-2026-62224 OpenClaw: MS Teams auth bypass via display name spoof 5.4 Jul 17, 2026 HIGH CVE-2026-62223 OpenClaw: authorization bypass in device pairing 8.8 Jul 17, 2026 HIGH CVE-2026-62222 OpenClaw: untrusted plugin loading in setup-mode 7.8 Jul 17, 2026 MEDIUM CVE-2026-62221 OpenClaw: allowFrom auth bypass runs blocked commands 5.4 Jul 17, 2026 MEDIUM CVE-2026-62220 OpenClaw: WS auth rate-limit bypass enables DoS 5.3 Jul 17, 2026 HIGH CVE-2026-62219 OpenClaw: agent hook auth bypass via blank IDs 7.1 Jul 17, 2026 HIGH CVE-2026-62218 OpenClaw: authorization bypass in device pairing 8.8 Jul 17, 2026 HIGH CVE-2026-62217 OpenClaw: QQBot exec approval bypass enables RCE 8.8 Jul 17, 2026 MEDIUM CVE-2026-62216 OpenClaw: policy bypass enables SSRF via media upload 5.0 Jul 17, 2026 HIGH CVE-2026-62215 OpenClaw: auth bypass forges trusted A2UI actions 8.0 Jul 17, 2026 MEDIUM CVE-2026-62214 OpenClaw: serviceUrl validation flaw leaks bot tokens 6.5 Jul 17, 2026 MEDIUM CVE-2026-62213 OpenClaw: Teams outbound leaks Bot Framework tokens 6.5 Jul 17, 2026 HIGH CVE-2026-62212 OpenClaw: TOCTOU race bypasses Teams SSRF guard 7.1 Jul 17, 2026 MEDIUM CVE-2026-62211 OpenClaw: credential redaction bypass via export 5.0 Jul 17, 2026 MEDIUM CVE-2026-62210 OpenClaw: slow-read DoS via remote media URLs 6.5 Jul 17, 2026 HIGH CVE-2026-62209 OpenClaw: agent dispatch bypasses toolsAllow authz 8.1 Jul 17, 2026 MEDIUM CVE-2026-62208 OpenClaw: Auth header leak via MCP SSE redirects 6.5 Jul 17, 2026

Showing 1–25 of 479

Frequently asked questions

What is OpenClaw?

OpenClaw is an AI/ML ai agents tracked by AI Threat Alert for security vulnerabilities in the pip ecosystem.

How many known vulnerabilities does OpenClaw have?

OpenClaw has 479 known CVEs, 18 of them critical, tracked from NVD and GitHub Advisory.

Which ecosystem is OpenClaw distributed in?

OpenClaw is distributed via the pip ecosystem and categorized as ai agents.

Where does the OpenClaw vulnerability data come from?

Vulnerability data is sourced from NVD and GitHub Advisory, enriched with CVSS, EPSS, exploit signals, and patch status for each CVE.

How do I assess the risk of OpenClaw?

Review each CVE below — every entry shows CVSS severity, EPSS exploit probability, exploitation signals, and whether a patched version is available.

Monitor OpenClaw in your stack

Get instant alerts when new vulnerabilities affect OpenClaw. CISO analysis, ATLAS technique mappings, and compliance reports included.

Start Monitoring