{"schema_version":1,"title":"Openclaw vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 1,005 vulnerabilities in Openclaw: 74 in the last 7 days and 151 in the last 90 days, 15 of them critical and 0 exploited in the wild. The most recent, CVE-2026-100604, was published on 26 September 2026. 3 technologies have a page of their own.","url":"https://junglewise.ai/threats/vendors/openclaw","json_url":"https://junglewise.ai/threats/vendors/openclaw.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/vendors/openclaw","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"vendor","counts":{"high":210,"all_time":1005,"critical":15,"exploited":0,"last_7_days":74,"last_30_days":78,"last_90_days":151,"last_365_days":1005},"latest":[{"cve":"CVE-2026-100604","cvss":5.4,"slug":"cve-2026-100604-clawhub-openclaw-clawhub-contains-an-incorrect-authorization","title":"ClawHub incorrect authorization in organization skill transfer","severity":"medium","exploited":false,"published_at":"2026-09-26T14:16:40.473+00:00","url":"https://junglewise.ai/threats/cve-2026-100604-clawhub-openclaw-clawhub-contains-an-incorrect-authorization"},{"cve":"CVE-2026-100603","cvss":5.4,"slug":"cve-2026-100603-clawhub-openclaw-clawhub-application-backend-contains-a-flaw-in","title":"ClawHub application backend authorization bypass in skill report moderation","severity":"medium","exploited":false,"published_at":"2026-09-26T14:16:40.33+00:00","url":"https://junglewise.ai/threats/cve-2026-100603-clawhub-openclaw-clawhub-application-backend-contains-a-flaw-in"},{"cve":"CVE-2026-100602","cvss":6.5,"slug":"cve-2026-100602-clawhub-openclaw-clawhub-application-backend-contains-a-missing","title":"ClawHub missing authorization check in changelog preview","severity":"medium","exploited":false,"published_at":"2026-09-26T14:16:40.187+00:00","url":"https://junglewise.ai/threats/cve-2026-100602-clawhub-openclaw-clawhub-application-backend-contains-a-missing"},{"cve":"CVE-2026-100601","cvss":5.3,"slug":"cve-2026-100601-clawhub-openclaw-clawhub-application-backend-contains-a-server","title":"ClawHub server-side request forgery in profile image preview","severity":"medium","exploited":false,"published_at":"2026-09-26T14:16:40.04+00:00","url":"https://junglewise.ai/threats/cve-2026-100601-clawhub-openclaw-clawhub-application-backend-contains-a-server"},{"cve":"CVE-2026-100600","cvss":5.3,"slug":"cve-2026-100600-clawhub-the-openclaw-clawhub-application-backend-does-not-bind","title":"ClawHub anonymous API quota exhaustion and identity spoofing","severity":"medium","exploited":false,"published_at":"2026-09-26T14:16:39.42+00:00","url":"https://junglewise.ai/threats/cve-2026-100600-clawhub-the-openclaw-clawhub-application-backend-does-not-bind"},{"cve":"CVE-2026-100599","cvss":8.8,"slug":"cve-2026-100599-openclaw-versions-2026-5-1-through-2026-7-0-fail-to-apply-the","title":"OpenClaw exec approval bypass in Google Meet node commands","severity":"high","exploited":false,"published_at":"2026-09-26T03:17:08.667+00:00","url":"https://junglewise.ai/threats/cve-2026-100599-openclaw-versions-2026-5-1-through-2026-7-0-fail-to-apply-the"},{"cve":"CVE-2026-100598","cvss":7.1,"slug":"cve-2026-100598-openclaw-npm-package-openclaw-before-2026-7-1-incorrectly-binds","title":"OpenClaw Signal approval reaction binding logic error","severity":"high","exploited":false,"published_at":"2026-09-26T03:17:08.487+00:00","url":"https://junglewise.ai/threats/cve-2026-100598-openclaw-npm-package-openclaw-before-2026-7-1-incorrectly-binds"},{"cve":"CVE-2026-100597","cvss":7.8,"slug":"cve-2026-100597-openclaw-npm-package-openclaw-before-2026-7-1-is-vulnerable-to-a","title":"OpenClaw time-of-check time-of-use race condition in filesystem operations","severity":"high","exploited":false,"published_at":"2026-09-26T03:17:08.337+00:00","url":"https://junglewise.ai/threats/cve-2026-100597-openclaw-npm-package-openclaw-before-2026-7-1-is-vulnerable-to-a"},{"cve":"CVE-2026-100596","cvss":8.8,"slug":"cve-2026-100596-openclaw-versions-before-2026-7-1-fail-to-properly-authorize-non","title":"OpenClaw authorization bypass in MCP configuration","severity":"high","exploited":false,"published_at":"2026-09-26T03:17:08.187+00:00","url":"https://junglewise.ai/threats/cve-2026-100596-openclaw-versions-before-2026-7-1-fail-to-properly-authorize-non"},{"cve":"CVE-2026-100595","cvss":6.5,"slug":"cve-2026-100595-openclaw-versions-before-2026-7-1-contain-an-authorization","title":"OpenClaw authorization bypass in diagnostics export","severity":"medium","exploited":false,"published_at":"2026-09-26T03:17:08.037+00:00","url":"https://junglewise.ai/threats/cve-2026-100595-openclaw-versions-before-2026-7-1-contain-an-authorization"},{"cve":"CVE-2026-100594","cvss":6.5,"slug":"cve-2026-100594-openclaw-versions-before-2026-7-1-contain-an-authorization","title":"OpenClaw authorization bypass in /export-trajectory endpoint","severity":"medium","exploited":false,"published_at":"2026-09-26T03:17:07.857+00:00","url":"https://junglewise.ai/threats/cve-2026-100594-openclaw-versions-before-2026-7-1-contain-an-authorization"},{"cve":"CVE-2026-100593","cvss":5.4,"slug":"cve-2026-100593-openclaw-npm-package-openclaw-before-2026-7-1-does-not-enforce","title":"OpenClaw authorization bypass in activation policy","severity":"medium","exploited":false,"published_at":"2026-09-26T03:17:07.703+00:00","url":"https://junglewise.ai/threats/cve-2026-100593-openclaw-npm-package-openclaw-before-2026-7-1-does-not-enforce"},{"cve":"CVE-2026-100592","cvss":6.3,"slug":"cve-2026-100592-openclaw-is-an-agent-gateway-distributed-via-npm-in-versions","title":"OpenClaw authorization bypass in memory dreaming commands","severity":"medium","exploited":false,"published_at":"2026-09-26T03:17:07.553+00:00","url":"https://junglewise.ai/threats/cve-2026-100592-openclaw-is-an-agent-gateway-distributed-via-npm-in-versions"},{"cve":"CVE-2026-100591","cvss":6.3,"slug":"cve-2026-100591-openclaw-is-an-npm-distributed-agent-gateway-in-versions-before","title":"OpenClaw missing owner authorization check on Active Memory global toggles","severity":"medium","exploited":false,"published_at":"2026-09-26T03:17:07.403+00:00","url":"https://junglewise.ai/threats/cve-2026-100591-openclaw-is-an-npm-distributed-agent-gateway-in-versions-before"},{"cve":"CVE-2026-100590","cvss":4.3,"slug":"cve-2026-100590-openclaw-before-2026-7-1-contains-an-authorization-bypass","title":"OpenClaw authorization bypass in /voice set command","severity":"medium","exploited":false,"published_at":"2026-09-26T03:17:07.257+00:00","url":"https://junglewise.ai/threats/cve-2026-100590-openclaw-before-2026-7-1-contains-an-authorization-bypass"},{"cve":"CVE-2026-100589","cvss":8.3,"slug":"cve-2026-100589-openclaw-versions-before-2026-7-1-contain-a-sandbox-bypass","title":"OpenClaw sandbox bypass in browser tool","severity":"high","exploited":false,"published_at":"2026-09-26T03:17:07.11+00:00","url":"https://junglewise.ai/threats/cve-2026-100589-openclaw-versions-before-2026-7-1-contain-a-sandbox-bypass"},{"cve":"CVE-2026-100588","cvss":8.3,"slug":"cve-2026-100588-openclaw-npm-package-openclaw-before-2026-7-1-does-not-enforce","title":"OpenClaw authorization bypass in node.invoke browser control","severity":"high","exploited":false,"published_at":"2026-09-26T03:17:06.963+00:00","url":"https://junglewise.ai/threats/cve-2026-100588-openclaw-npm-package-openclaw-before-2026-7-1-does-not-enforce"},{"cve":"CVE-2026-100587","cvss":8.8,"slug":"cve-2026-100587-openclaw-versions-before-2026-7-1-fail-to-properly-validate","title":"OpenClaw missing authorization in Codex computer-use install","severity":"high","exploited":false,"published_at":"2026-09-26T03:17:06.81+00:00","url":"https://junglewise.ai/threats/cve-2026-100587-openclaw-versions-before-2026-7-1-fail-to-properly-validate"},{"cve":"CVE-2026-100586","cvss":8.8,"slug":"cve-2026-100586-openclaw-codex-before-2026-7-1-fails-to-properly-enforce-owner","title":"OpenClaw Codex authorization bypass in native conversation bindings","severity":"high","exploited":false,"published_at":"2026-09-26T03:17:06.66+00:00","url":"https://junglewise.ai/threats/cve-2026-100586-openclaw-codex-before-2026-7-1-fails-to-properly-enforce-owner"},{"cve":"CVE-2026-100585","cvss":8,"slug":"cve-2026-100585-openclaw-npm-package-openclaw-before-2026-7-1-fails-to-enforce","title":"OpenClaw authorization bypass in Claude Code permission prompts","severity":"high","exploited":false,"published_at":"2026-09-26T03:17:06.517+00:00","url":"https://junglewise.ai/threats/cve-2026-100585-openclaw-npm-package-openclaw-before-2026-7-1-fails-to-enforce"},{"cve":"CVE-2026-100584","cvss":6.7,"slug":"cve-2026-100584-openclaw-is-an-npm-distributed-agent-runtime-in-versions-2026-2","title":"OpenClaw arbitrary code execution via PATH search allowlist bypass","severity":"medium","exploited":false,"published_at":"2026-09-26T03:17:06.373+00:00","url":"https://junglewise.ai/threats/cve-2026-100584-openclaw-is-an-npm-distributed-agent-runtime-in-versions-2026-2"},{"cve":"CVE-2026-100583","cvss":4.3,"slug":"cve-2026-100583-openclaw-discord-versions-before-2026-7-1-contain-an","title":"OpenClaw Discord authorization bypass in guild metadata reads","severity":"medium","exploited":false,"published_at":"2026-09-26T03:17:06.223+00:00","url":"https://junglewise.ai/threats/cve-2026-100583-openclaw-discord-versions-before-2026-7-1-contain-an"},{"cve":"CVE-2026-100582","cvss":6.5,"slug":"cve-2026-100582-openclaw-channel-plugins-openclaw-msteams-openclaw-feishu","title":"OpenClaw channel plugins missing authorization in read actions","severity":"medium","exploited":false,"published_at":"2026-09-26T03:17:06.08+00:00","url":"https://junglewise.ai/threats/cve-2026-100582-openclaw-channel-plugins-openclaw-msteams-openclaw-feishu"},{"cve":"CVE-2026-100581","cvss":5.5,"slug":"cve-2026-100581-openclaw-for-ios-before-2026-8-11-stores-gateway-credentials-as","title":"OpenClaw for iOS cleartext credential storage in Share Extension","severity":"medium","exploited":false,"published_at":"2026-09-26T03:17:05.93+00:00","url":"https://junglewise.ai/threats/cve-2026-100581-openclaw-for-ios-before-2026-8-11-stores-gateway-credentials-as"},{"cve":"CVE-2026-100580","cvss":8.8,"slug":"cve-2026-100580-openclaw-npm-package-openclaw-before-2026-7-1-improperly-handles","title":"OpenClaw case sensitivity bypass in cron tool","severity":"high","exploited":false,"published_at":"2026-09-26T03:17:05.783+00:00","url":"https://junglewise.ai/threats/cve-2026-100580-openclaw-npm-package-openclaw-before-2026-7-1-improperly-handles"}],"vendor":{"hub":true,"name":"Openclaw","slug":"openclaw","description":"OpenClaw is a security testing and vulnerability assessment tool.","url":"https://junglewise.ai/threats/vendors/openclaw"},"weekly":[{"week":"2026-06-29","critical":1,"exploited":0,"vulnerabilities":29},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":43},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":2},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":3},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":73}],"most_severe":[{"cve":"CVE-2026-33579","cvss":9.9,"epss":0.0051,"slug":"cve-2026-33579-openclaw-privilege-escalation-in-device-pairing-approval","title":"OpenClaw privilege escalation in device pairing approval","severity":"critical","exploited":false,"published_at":"2026-03-31T15:16:14.96+00:00","url":"https://junglewise.ai/threats/cve-2026-33579-openclaw-privilege-escalation-in-device-pairing-approval"},{"cve":"CVE-2026-32917","cvss":9.8,"epss":0.032,"slug":"cve-2026-32917-openclaw-remote-command-injection-in-imessage-attachment-staging","title":"OpenClaw remote command injection in iMessage attachment staging","severity":"critical","exploited":false,"published_at":"2026-03-31T12:16:28.487+00:00","url":"https://junglewise.ai/threats/cve-2026-32917-openclaw-remote-command-injection-in-imessage-attachment-staging"},{"cve":"CVE-2026-28474","cvss":9.8,"epss":0.0085,"slug":"cve-2026-28474-openclaw-nextcloud-talk-allowlist-bypass-via-display-name","title":"OpenClaw's Nextcloud Talk plugin versions prior to 2026.2.6 accept equality matching on the mutable actor.name display name field for allowl","severity":"critical","exploited":false,"published_at":"2026-03-05T22:16:21.423+00:00","url":"https://junglewise.ai/threats/cve-2026-28474-openclaw-nextcloud-talk-allowlist-bypass-via-display-name"},{"cve":"CVE-2026-53838","cvss":9.8,"epss":0.0037,"slug":"cve-2026-53838-openclaw-state-mutation-in-node-pairing-reconnection","title":"OpenClaw state mutation in node pairing reconnection","severity":"critical","exploited":false,"published_at":"2026-06-12T22:16:55.723+00:00","url":"https://junglewise.ai/threats/cve-2026-53838-openclaw-state-mutation-in-node-pairing-reconnection"},{"cvss":9.8,"slug":"openclaw-node-pairing-state-mutation-on-reconnection-40b03ce4","title":"OpenClaw node pairing state mutation on reconnection","severity":"critical","exploited":false,"published_at":"2026-06-13T00:34:33+00:00","url":"https://junglewise.ai/threats/openclaw-node-pairing-state-mutation-on-reconnection-40b03ce4"},{"cvss":9.8,"slug":"openclaw-authentication-bypass-in-feishu-webhook-validation-5fe7b465","title":"OpenClaw authentication bypass in Feishu webhook validation","severity":"critical","exploited":false,"published_at":"2026-05-06T21:31:42+00:00","url":"https://junglewise.ai/threats/openclaw-authentication-bypass-in-feishu-webhook-validation-5fe7b465"},{"cve":"CVE-2026-44112","cvss":9.6,"epss":0.0039,"slug":"cve-2026-44112-openclaw-openclaw-toctou-race-condition-in-openshell-fs-bridge","title":"OpenClaw TOCTOU race condition in OpenShell sandbox filesystem writes","severity":"critical","exploited":false,"published_at":"2026-05-06T20:16:35.057+00:00","url":"https://junglewise.ai/threats/cve-2026-44112-openclaw-openclaw-toctou-race-condition-in-openshell-fs-bridge"},{"cve":"CVE-2026-41294","cvss":9.6,"epss":0.0019,"slug":"cve-2026-41294-openclaw-has-a-cwd-env-environment-variable-injection-which","title":"OpenClaw has a CWD `.env` environment variable injection which bypasses host-env policy and allows config takeover","severity":"critical","exploited":false,"published_at":"2026-04-01T00:02:42+00:00","url":"https://junglewise.ai/threats/cve-2026-41294-openclaw-has-a-cwd-env-environment-variable-injection-which"},{"cve":"CVE-2026-32916","cvss":9.4,"epss":0.0063,"slug":"cve-2026-32916-openclaw-authorization-bypass-in-plugin-subagent-routes","title":"OpenClaw authorization bypass in plugin subagent routes","severity":"critical","exploited":false,"published_at":"2026-03-31T12:16:28.197+00:00","url":"https://junglewise.ai/threats/cve-2026-32916-openclaw-authorization-bypass-in-plugin-subagent-routes"},{"cvss":9.3,"slug":"openclaw-qqbot-authorization-bypass-in-admin-commands-70474b74","title":"OpenClaw QQBot authorization bypass in admin commands","severity":"critical","exploited":false,"published_at":"2026-07-02T16:48:45+00:00","url":"https://junglewise.ai/threats/openclaw-qqbot-authorization-bypass-in-admin-commands-70474b74"}],"generated_at":"2026-09-26T15:07:00.181821+00:00","technologies":[{"name":"Openclaw","slug":"openclaw","vulnerabilities":917,"url":"https://junglewise.ai/threats/technologies/openclaw"},{"name":"Openclaw Crabbox","slug":"crabbox","vulnerabilities":5,"url":"https://junglewise.ai/threats/technologies/crabbox"},{"name":"Openclaw Msteams","slug":"msteams","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/msteams"}]}