{"schema_version":1,"title":"Openclaw vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 973 vulnerabilities in Openclaw: 56 in the last 7 days and 127 in the last 90 days, 14 of them critical and 0 exploited in the wild. The most recent, CVE-2026-100599, was published on 26 September 2026.","url":"https://junglewise.ai/threats/technologies/openclaw","json_url":"https://junglewise.ai/threats/technologies/openclaw.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/openclaw","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":198,"all_time":973,"critical":14,"exploited":0,"last_7_days":56,"last_30_days":58,"last_90_days":127,"last_365_days":973},"latest":[{"cve":"CVE-2026-100599","cvss":8.8,"slug":"cve-2026-100599-openclaw-versions-2026-5-1-through-2026-7-0-fail-to-apply-the","title":"OpenClaw exec approval bypass in Google Meet node commands","severity":"high","exploited":false,"published_at":"2026-09-26T03:17:08.667+00:00","url":"https://junglewise.ai/threats/cve-2026-100599-openclaw-versions-2026-5-1-through-2026-7-0-fail-to-apply-the"},{"cve":"CVE-2026-100598","cvss":7.1,"slug":"cve-2026-100598-openclaw-npm-package-openclaw-before-2026-7-1-incorrectly-binds","title":"OpenClaw Signal approval reaction binding logic error","severity":"high","exploited":false,"published_at":"2026-09-26T03:17:08.487+00:00","url":"https://junglewise.ai/threats/cve-2026-100598-openclaw-npm-package-openclaw-before-2026-7-1-incorrectly-binds"},{"cve":"CVE-2026-100597","cvss":7.8,"slug":"cve-2026-100597-openclaw-npm-package-openclaw-before-2026-7-1-is-vulnerable-to-a","title":"OpenClaw time-of-check time-of-use race condition in filesystem operations","severity":"high","exploited":false,"published_at":"2026-09-26T03:17:08.337+00:00","url":"https://junglewise.ai/threats/cve-2026-100597-openclaw-npm-package-openclaw-before-2026-7-1-is-vulnerable-to-a"},{"cve":"CVE-2026-100596","cvss":8.8,"slug":"cve-2026-100596-openclaw-versions-before-2026-7-1-fail-to-properly-authorize-non","title":"OpenClaw authorization bypass in MCP configuration","severity":"high","exploited":false,"published_at":"2026-09-26T03:17:08.187+00:00","url":"https://junglewise.ai/threats/cve-2026-100596-openclaw-versions-before-2026-7-1-fail-to-properly-authorize-non"},{"cve":"CVE-2026-100595","cvss":6.5,"slug":"cve-2026-100595-openclaw-versions-before-2026-7-1-contain-an-authorization","title":"OpenClaw authorization bypass in diagnostics export","severity":"medium","exploited":false,"published_at":"2026-09-26T03:17:08.037+00:00","url":"https://junglewise.ai/threats/cve-2026-100595-openclaw-versions-before-2026-7-1-contain-an-authorization"},{"cve":"CVE-2026-100594","cvss":6.5,"slug":"cve-2026-100594-openclaw-versions-before-2026-7-1-contain-an-authorization","title":"OpenClaw authorization bypass in /export-trajectory endpoint","severity":"medium","exploited":false,"published_at":"2026-09-26T03:17:07.857+00:00","url":"https://junglewise.ai/threats/cve-2026-100594-openclaw-versions-before-2026-7-1-contain-an-authorization"},{"cve":"CVE-2026-100593","cvss":5.4,"slug":"cve-2026-100593-openclaw-npm-package-openclaw-before-2026-7-1-does-not-enforce","title":"OpenClaw authorization bypass in activation policy","severity":"medium","exploited":false,"published_at":"2026-09-26T03:17:07.703+00:00","url":"https://junglewise.ai/threats/cve-2026-100593-openclaw-npm-package-openclaw-before-2026-7-1-does-not-enforce"},{"cve":"CVE-2026-100592","cvss":6.3,"slug":"cve-2026-100592-openclaw-is-an-agent-gateway-distributed-via-npm-in-versions","title":"OpenClaw authorization bypass in memory dreaming commands","severity":"medium","exploited":false,"published_at":"2026-09-26T03:17:07.553+00:00","url":"https://junglewise.ai/threats/cve-2026-100592-openclaw-is-an-agent-gateway-distributed-via-npm-in-versions"},{"cve":"CVE-2026-100591","cvss":6.3,"slug":"cve-2026-100591-openclaw-is-an-npm-distributed-agent-gateway-in-versions-before","title":"OpenClaw missing owner authorization check on Active Memory global toggles","severity":"medium","exploited":false,"published_at":"2026-09-26T03:17:07.403+00:00","url":"https://junglewise.ai/threats/cve-2026-100591-openclaw-is-an-npm-distributed-agent-gateway-in-versions-before"},{"cve":"CVE-2026-100590","cvss":4.3,"slug":"cve-2026-100590-openclaw-before-2026-7-1-contains-an-authorization-bypass","title":"OpenClaw authorization bypass in /voice set command","severity":"medium","exploited":false,"published_at":"2026-09-26T03:17:07.257+00:00","url":"https://junglewise.ai/threats/cve-2026-100590-openclaw-before-2026-7-1-contains-an-authorization-bypass"},{"cve":"CVE-2026-100589","cvss":8.3,"slug":"cve-2026-100589-openclaw-versions-before-2026-7-1-contain-a-sandbox-bypass","title":"OpenClaw sandbox bypass in browser tool","severity":"high","exploited":false,"published_at":"2026-09-26T03:17:07.11+00:00","url":"https://junglewise.ai/threats/cve-2026-100589-openclaw-versions-before-2026-7-1-contain-a-sandbox-bypass"},{"cve":"CVE-2026-100588","cvss":8.3,"slug":"cve-2026-100588-openclaw-npm-package-openclaw-before-2026-7-1-does-not-enforce","title":"OpenClaw authorization bypass in node.invoke browser control","severity":"high","exploited":false,"published_at":"2026-09-26T03:17:06.963+00:00","url":"https://junglewise.ai/threats/cve-2026-100588-openclaw-npm-package-openclaw-before-2026-7-1-does-not-enforce"},{"cve":"CVE-2026-100587","cvss":8.8,"slug":"cve-2026-100587-openclaw-versions-before-2026-7-1-fail-to-properly-validate","title":"OpenClaw missing authorization in Codex computer-use install","severity":"high","exploited":false,"published_at":"2026-09-26T03:17:06.81+00:00","url":"https://junglewise.ai/threats/cve-2026-100587-openclaw-versions-before-2026-7-1-fail-to-properly-validate"},{"cve":"CVE-2026-100585","cvss":8,"slug":"cve-2026-100585-openclaw-npm-package-openclaw-before-2026-7-1-fails-to-enforce","title":"OpenClaw authorization bypass in Claude Code permission prompts","severity":"high","exploited":false,"published_at":"2026-09-26T03:17:06.517+00:00","url":"https://junglewise.ai/threats/cve-2026-100585-openclaw-npm-package-openclaw-before-2026-7-1-fails-to-enforce"},{"cve":"CVE-2026-100584","cvss":6.7,"slug":"cve-2026-100584-openclaw-is-an-npm-distributed-agent-runtime-in-versions-2026-2","title":"OpenClaw arbitrary code execution via PATH search allowlist bypass","severity":"medium","exploited":false,"published_at":"2026-09-26T03:17:06.373+00:00","url":"https://junglewise.ai/threats/cve-2026-100584-openclaw-is-an-npm-distributed-agent-runtime-in-versions-2026-2"},{"cve":"CVE-2026-100580","cvss":8.8,"slug":"cve-2026-100580-openclaw-npm-package-openclaw-before-2026-7-1-improperly-handles","title":"OpenClaw case sensitivity bypass in cron tool","severity":"high","exploited":false,"published_at":"2026-09-26T03:17:05.783+00:00","url":"https://junglewise.ai/threats/cve-2026-100580-openclaw-npm-package-openclaw-before-2026-7-1-improperly-handles"},{"cve":"CVE-2026-100579","cvss":7.6,"slug":"cve-2026-100579-openclaw-npm-package-openclaw-before-2026-7-1-incorrectly-trusts","title":"OpenClaw authorization bypass via spoofed requester identity","severity":"high","exploited":false,"published_at":"2026-09-26T03:17:05.633+00:00","url":"https://junglewise.ai/threats/cve-2026-100579-openclaw-npm-package-openclaw-before-2026-7-1-incorrectly-trusts"},{"cve":"CVE-2026-100578","cvss":7.6,"slug":"cve-2026-100578-openclaw-npm-package-openclaw-before-2026-7-1-fails-to-restrict","title":"OpenClaw authorization bypass in chat.send endpoint","severity":"high","exploited":false,"published_at":"2026-09-26T03:17:05.483+00:00","url":"https://junglewise.ai/threats/cve-2026-100578-openclaw-npm-package-openclaw-before-2026-7-1-fails-to-restrict"},{"cve":"CVE-2026-100577","cvss":6.3,"slug":"cve-2026-100577-openclaw-versions-before-2026-8-1-fail-to-validate-video-asset","title":"OpenClaw server-side request forgery in video asset handling","severity":"medium","exploited":false,"published_at":"2026-09-26T03:17:05.333+00:00","url":"https://junglewise.ai/threats/cve-2026-100577-openclaw-versions-before-2026-8-1-fail-to-validate-video-asset"},{"cve":"CVE-2026-100576","cvss":5.4,"slug":"cve-2026-100576-openclaw-versions-before-2026-8-1-contain-a-server-side-request","title":"OpenClaw server-side request forgery in browser wait predicates","severity":"medium","exploited":false,"published_at":"2026-09-26T03:17:05.187+00:00","url":"https://junglewise.ai/threats/cve-2026-100576-openclaw-versions-before-2026-8-1-contain-a-server-side-request"},{"cve":"CVE-2026-100574","cvss":5.9,"slug":"cve-2026-100574-openclaw-npm-package-openclaw-before-2026-8-1-contains-a-server","title":"OpenClaw server-side request forgery in DNS validation","severity":"medium","exploited":false,"published_at":"2026-09-26T03:17:04.887+00:00","url":"https://junglewise.ai/threats/cve-2026-100574-openclaw-npm-package-openclaw-before-2026-8-1-contains-a-server"},{"cve":"CVE-2026-100572","cvss":5.3,"slug":"cve-2026-100572-openclaw-versions-2026-3-25-and-2026-8-1-apply-invalid-token","title":"OpenClaw rate-limit bypass in Synology Chat webhooks","severity":"medium","exploited":false,"published_at":"2026-09-26T03:17:04.57+00:00","url":"https://junglewise.ai/threats/cve-2026-100572-openclaw-versions-2026-3-25-and-2026-8-1-apply-invalid-token"},{"cve":"CVE-2026-100571","cvss":5.3,"slug":"cve-2026-100571-openclaw-npm-package-openclaw-versions-2026-6-6-and-2026-8-1","title":"OpenClaw SMS webhook rate limit bypass","severity":"medium","exploited":false,"published_at":"2026-09-26T03:17:04.33+00:00","url":"https://junglewise.ai/threats/cve-2026-100571-openclaw-npm-package-openclaw-versions-2026-6-6-and-2026-8-1"},{"cve":"CVE-2026-100570","cvss":7.8,"slug":"cve-2026-100570-openclaw-npm-package-openclaw-versions-2026-3-28-and-2026-8-1","title":"OpenClaw argument injection in Gmail setup","severity":"high","exploited":false,"published_at":"2026-09-26T03:17:04.177+00:00","url":"https://junglewise.ai/threats/cve-2026-100570-openclaw-npm-package-openclaw-versions-2026-3-28-and-2026-8-1"},{"cve":"CVE-2026-100569","cvss":5.5,"slug":"cve-2026-100569-openclaw-is-an-npm-distributed-application-in-versions-2026-4-25","title":"OpenClaw workspace environment-variable filter credential exposure","severity":"medium","exploited":false,"published_at":"2026-09-26T03:17:04.03+00:00","url":"https://junglewise.ai/threats/cve-2026-100569-openclaw-is-an-npm-distributed-application-in-versions-2026-4-25"}],"weekly":[{"week":"2026-06-29","critical":1,"exploited":0,"vulnerabilities":29},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":39},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":2},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":55}],"related":[{"name":"Openclaw Crabbox","slug":"crabbox","vulnerabilities":5,"url":"https://junglewise.ai/threats/technologies/crabbox"},{"name":"Openclaw Msteams","slug":"msteams","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/msteams"}],"technology":{"hub":true,"name":"Openclaw","slug":"openclaw","vendor":{"name":"Openclaw","slug":"openclaw","url":"https://junglewise.ai/threats/vendors/openclaw"},"aliases":[],"category":"library","url":"https://junglewise.ai/threats/technologies/openclaw"},"most_severe":[{"cve":"CVE-2026-33579","cvss":9.9,"epss":0.0051,"slug":"cve-2026-33579-openclaw-privilege-escalation-in-device-pairing-approval","title":"OpenClaw privilege escalation in device pairing approval","severity":"critical","exploited":false,"published_at":"2026-03-31T15:16:14.96+00:00","url":"https://junglewise.ai/threats/cve-2026-33579-openclaw-privilege-escalation-in-device-pairing-approval"},{"cve":"CVE-2026-32917","cvss":9.8,"epss":0.032,"slug":"cve-2026-32917-openclaw-remote-command-injection-in-imessage-attachment-staging","title":"OpenClaw remote command injection in iMessage attachment staging","severity":"critical","exploited":false,"published_at":"2026-03-31T12:16:28.487+00:00","url":"https://junglewise.ai/threats/cve-2026-32917-openclaw-remote-command-injection-in-imessage-attachment-staging"},{"cve":"CVE-2026-28474","cvss":9.8,"epss":0.0085,"slug":"cve-2026-28474-openclaw-nextcloud-talk-allowlist-bypass-via-display-name","title":"OpenClaw's Nextcloud Talk plugin versions prior to 2026.2.6 accept equality matching on the mutable actor.name display name field for allowl","severity":"critical","exploited":false,"published_at":"2026-03-05T22:16:21.423+00:00","url":"https://junglewise.ai/threats/cve-2026-28474-openclaw-nextcloud-talk-allowlist-bypass-via-display-name"},{"cve":"CVE-2026-53838","cvss":9.8,"epss":0.0037,"slug":"cve-2026-53838-openclaw-state-mutation-in-node-pairing-reconnection","title":"OpenClaw state mutation in node pairing reconnection","severity":"critical","exploited":false,"published_at":"2026-06-12T22:16:55.723+00:00","url":"https://junglewise.ai/threats/cve-2026-53838-openclaw-state-mutation-in-node-pairing-reconnection"},{"cvss":9.8,"slug":"openclaw-node-pairing-state-mutation-on-reconnection-40b03ce4","title":"OpenClaw node pairing state mutation on reconnection","severity":"critical","exploited":false,"published_at":"2026-06-13T00:34:33+00:00","url":"https://junglewise.ai/threats/openclaw-node-pairing-state-mutation-on-reconnection-40b03ce4"},{"cvss":9.8,"slug":"openclaw-authentication-bypass-in-feishu-webhook-validation-5fe7b465","title":"OpenClaw authentication bypass in Feishu webhook validation","severity":"critical","exploited":false,"published_at":"2026-05-06T21:31:42+00:00","url":"https://junglewise.ai/threats/openclaw-authentication-bypass-in-feishu-webhook-validation-5fe7b465"},{"cve":"CVE-2026-44112","cvss":9.6,"epss":0.0039,"slug":"cve-2026-44112-openclaw-openclaw-toctou-race-condition-in-openshell-fs-bridge","title":"OpenClaw TOCTOU race condition in OpenShell sandbox filesystem writes","severity":"critical","exploited":false,"published_at":"2026-05-06T20:16:35.057+00:00","url":"https://junglewise.ai/threats/cve-2026-44112-openclaw-openclaw-toctou-race-condition-in-openshell-fs-bridge"},{"cve":"CVE-2026-41294","cvss":9.6,"epss":0.0019,"slug":"cve-2026-41294-openclaw-has-a-cwd-env-environment-variable-injection-which","title":"OpenClaw has a CWD `.env` environment variable injection which bypasses host-env policy and allows config takeover","severity":"critical","exploited":false,"published_at":"2026-04-01T00:02:42+00:00","url":"https://junglewise.ai/threats/cve-2026-41294-openclaw-has-a-cwd-env-environment-variable-injection-which"},{"cve":"CVE-2026-32916","cvss":9.4,"epss":0.0063,"slug":"cve-2026-32916-openclaw-authorization-bypass-in-plugin-subagent-routes","title":"OpenClaw authorization bypass in plugin subagent routes","severity":"critical","exploited":false,"published_at":"2026-03-31T12:16:28.197+00:00","url":"https://junglewise.ai/threats/cve-2026-32916-openclaw-authorization-bypass-in-plugin-subagent-routes"},{"cvss":9.3,"slug":"openclaw-qqbot-authorization-bypass-in-admin-commands-70474b74","title":"OpenClaw QQBot authorization bypass in admin commands","severity":"critical","exploited":false,"published_at":"2026-07-02T16:48:45+00:00","url":"https://junglewise.ai/threats/openclaw-qqbot-authorization-bypass-in-admin-commands-70474b74"}],"generated_at":"2026-09-26T12:07:00.15149+00:00"}