OpenClaw Vulnerabilities

pip AI Agents

AI Threat Alert tracks 479 known vulnerabilities in OpenClaw, 18 rated critical — an AI/ML ai agents in the pip ecosystem. Each CVE includes CVSS severity, EPSS exploit probability, patch status, and CISO-grade analysis.

Data sources
479
Total CVEs
18
Critical
pip
Ecosystem
Jul 30, 2026
Last CVE
37%
Patch Rate
3d
Avg Time to Patch

Known Vulnerabilities (479 total, page 2 of 20)

Severity CVE ID Summary CVSS Published
HIGH CVE-2026-62207 OpenClaw: auth bypass exposes admin agent tools 8.8 Jul 17, 2026 HIGH CVE-2026-62206 OpenClaw: missing authorization in Discord moderation 7.1 Jul 17, 2026 HIGH CVE-2026-62205 OpenClaw: auth bypass in MS Teams message actions 7.1 Jul 17, 2026 HIGH CVE-2026-62203 OpenClaw: env var filter gap enables priv escalation 8.8 Jul 17, 2026 HIGH CVE-2026-62202 OpenClaw: cron isolation flaw regains denied tools 8.8 Jul 17, 2026 HIGH CVE-2026-62201 OpenClaw: exec-server bypass allows internal SSRF 7.7 Jul 17, 2026 HIGH CVE-2026-8629 Crabbox: IDOR lets viewers hijack Code/VNC/Egress 8.1 May 14, 2026 HIGH CVE-2026-8621 Crabbox: header spoofing bypasses lease auth 8.8 May 14, 2026 CRITICAL CVE-2026-8634 Crabbox: env-var allowlist leaks secrets to remote exec 9.1 May 14, 2026 HIGH CVE-2026-45223 Crabbox: coordinator auth bypass via forged admin claim 8.8 May 11, 2026 HIGH CVE-2026-45224 Crabbox: path traversal enables arbitrary file wipe 7.1 May 11, 2026 HIGH CVE-2026-32846 OpenClaw: path traversal in media parsing leaks secrets -- Mar 26, 2026 HIGH CVE-2026-62200 OpenClaw: Git ext transport flaw allows auth-bypass RCE 8.8 Jul 13, 2026 HIGH CVE-2026-62199 OpenClaw: env-var filtering bypass enables RCE 8.8 Jul 13, 2026 MEDIUM CVE-2026-62198 OpenClaw: web search auth bypass enables restricted ops 5.4 Jul 13, 2026 HIGH CVE-2026-62197 OpenClaw: CDP policy bypass reaches blocked network 8.5 Jul 13, 2026 HIGH CVE-2026-62196 OpenClaw: WhatsApp group ID spoof enables auth bypass 8.3 Jul 13, 2026 HIGH CVE-2026-62195 OpenClaw: MCP loopback auth bypass on owner tools 8.3 Jul 13, 2026 HIGH CVE-2026-62194 OpenClaw: privilege escalation in plugin install 8.8 Jul 13, 2026 MEDIUM CVE-2026-62193 OpenClaw: auth bypass in plugin install wrapper 6.5 Jul 13, 2026 HIGH CVE-2026-62192 OpenClaw: authz bypass in Discord guild actions 8.1 Jul 13, 2026 HIGH CVE-2026-62191 OpenClaw: authorization bypass in message mutations 7.1 Jul 13, 2026 HIGH CVE-2026-62190 OpenClaw: auth bypass skips agent exec approval 8.8 Jul 13, 2026 HIGH CVE-2026-62189 OpenClaw: symlink following bypasses authorization 7.1 Jul 13, 2026 HIGH CVE-2026-62188 OpenClaw Feishu: authz bypass ignores disablement 8.1 Jul 13, 2026

Showing 26–50 of 479

Frequently asked questions

What is OpenClaw?

OpenClaw is an AI/ML ai agents tracked by AI Threat Alert for security vulnerabilities in the pip ecosystem.

How many known vulnerabilities does OpenClaw have?

OpenClaw has 479 known CVEs, 18 of them critical, tracked from NVD and GitHub Advisory.

Which ecosystem is OpenClaw distributed in?

OpenClaw is distributed via the pip ecosystem and categorized as ai agents.

Where does the OpenClaw vulnerability data come from?

Vulnerability data is sourced from NVD and GitHub Advisory, enriched with CVSS, EPSS, exploit signals, and patch status for each CVE.

How do I assess the risk of OpenClaw?

Review each CVE below — every entry shows CVSS severity, EPSS exploit probability, exploitation signals, and whether a patched version is available.

Monitor OpenClaw in your stack

Get instant alerts when new vulnerabilities affect OpenClaw. CISO analysis, ATLAS technique mappings, and compliance reports included.

Start Monitoring