OpenClaw Vulnerabilities

pip AI Agents

AI Threat Alert tracks 479 known vulnerabilities in OpenClaw, 18 rated critical — an AI/ML ai agents in the pip ecosystem. Each CVE includes CVSS severity, EPSS exploit probability, patch status, and CISO-grade analysis.

Data sources
479
Total CVEs
18
Critical
pip
Ecosystem
Jul 30, 2026
Last CVE
37%
Patch Rate
3d
Avg Time to Patch

Known Vulnerabilities (479 total, page 16 of 20)

Severity CVE ID Summary CVSS Published
MEDIUM GHSA-g2hm-779g-vm32 openclaw: auth bypass preserves owner-level agent execution -- Apr 17, 2026 HIGH GHSA-vw3h-q6xq-jjm5 openclaw: WebSocket DoS via oversized frame ingestion -- Apr 17, 2026 MEDIUM GHSA-g375-h3v6-4873 openclaw: privilege retention via async exec completion miss -- Apr 17, 2026 LOW GHSA-r77c-2cmr-7p47 openclaw: group policy bypass in delivery queue recovery -- Apr 17, 2026 LOW GHSA-gc9r-867r-j85f openclaw: auth bypass in Teams SSO invoke handler -- Apr 17, 2026 MEDIUM GHSA-5gjc-grvm-m88j openclaw: auth bypass enables persistent memory config change -- Apr 17, 2026 MEDIUM GHSA-j6c7-3h5x-99g9 openclaw: OS command injection via shell env-argv bypass -- Apr 17, 2026 HIGH GHSA-vfp4-8x56-j7c5 openclaw: env denylist bypass enables code exec in agents -- Apr 17, 2026 MEDIUM GHSA-7g8c-cfr3-vqqr openclaw: trust escalation via unsanitized agent hook events -- Apr 17, 2026 MEDIUM GHSA-49cg-279w-m73x openclaw: auth bypass via empty approver list -- Apr 17, 2026 MEDIUM GHSA-c9h3-5p7r-mrjh openclaw: path traversal bypasses media sandbox -- Apr 17, 2026 MEDIUM GHSA-7wv4-cc7p-jhxc openclaw: .env injection hijacks agent runtime config -- Apr 17, 2026 MEDIUM GHSA-2767-2q9v-9326 openclaw: QQBot SSRF leaks internal service responses -- Apr 17, 2026 MEDIUM GHSA-xq94-r468-qwgj openclaw: DNS rebinding bypasses browser SSRF protection -- Apr 17, 2026 MEDIUM GHSA-53vx-pmqw-863c openclaw: Browser SSRF exposes internal services by default -- Apr 17, 2026 MEDIUM GHSA-jf25-7968-h2h5 openclaw: path traversal bypasses workspace filesystem guard -- Apr 17, 2026 HIGH GHSA-82qx-6vj7-p8m2 openclaw: trust bypass loads untrusted workspace plugins -- Apr 17, 2026 HIGH GHSA-525j-hqq2-66r4 openclaw: CDP relay exposes browser DevTools on 0.0.0.0 -- Apr 17, 2026 MEDIUM GHSA-f3h5-h452-vp3j openclaw: insufficient authz allows agent config persistence -- Apr 17, 2026 MEDIUM GHSA-rj2p-j66c-mgqh openclaw: SSRF policy bypass in browser tab actions -- Apr 17, 2026 MEDIUM GHSA-527m-976r-jf79 openclaw: SSRF bypass in existing browser session routes -- Apr 17, 2026 HIGH GHSA-939r-rj45-g2rj openclaw: untrusted plugin auto-enabled during onboarding -- Apr 17, 2026 MEDIUM GHSA-qmwg-qprg-3j38 openclaw: CDP pivot bypasses file:// navigation guards -- Apr 17, 2026 MEDIUM GHSA-536q-mj95-h29h openclaw: SSRF bypass via browser navigation guard gap -- Apr 17, 2026 HIGH GHSA-736r-jwj6-4w23 openclaw: sandbox escape via host=node exec routing bypass -- Apr 17, 2026

Showing 376–400 of 479

Frequently asked questions

What is OpenClaw?

OpenClaw is an AI/ML ai agents tracked by AI Threat Alert for security vulnerabilities in the pip ecosystem.

How many known vulnerabilities does OpenClaw have?

OpenClaw has 479 known CVEs, 18 of them critical, tracked from NVD and GitHub Advisory.

Which ecosystem is OpenClaw distributed in?

OpenClaw is distributed via the pip ecosystem and categorized as ai agents.

Where does the OpenClaw vulnerability data come from?

Vulnerability data is sourced from NVD and GitHub Advisory, enriched with CVSS, EPSS, exploit signals, and patch status for each CVE.

How do I assess the risk of OpenClaw?

Review each CVE below — every entry shows CVSS severity, EPSS exploit probability, exploitation signals, and whether a patched version is available.

Monitor OpenClaw in your stack

Get instant alerts when new vulnerabilities affect OpenClaw. CISO analysis, ATLAS technique mappings, and compliance reports included.

Start Monitoring