Openclaw
1,108 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Openclaw, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
Openclaw CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 45 |
| 2026-03 | 459 |
| 2026-04 | 329 |
| 2026-05 | 81 |
| 2026-06 | 61 |
| 2026-07 | 70 |
| 2026-08 | 0 |
| 2026-09 | 63 |
Severity
How the 1,108 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical29
- High278
- Medium308
- Low28
Latest CVEs
The 15 most recently published vulnerabilities affecting Openclaw.
- CVE-2026-100598OpenClaw before 2026.7.1 Approval Binding Logic Error7.1
- CVE-2026-100599OpenClaw 2026.5.1 before 2026.7.1 Remote Code Execution via googlemeet.chrome8.8
- CVE-2026-100597OpenClaw before 2026.7.1 Path Traversal via Filesystem Race7.8
- CVE-2026-100596OpenClaw before 2026.7.1 Authorization Bypass via MCP Configuration8.8
- CVE-2026-100595OpenClaw before 2026.7.1 Authorization Bypass via diagnostics6.5
- CVE-2026-100594OpenClaw before 2026.7.1 Authorization Bypass via trajectory export6.5
- CVE-2026-100593OpenClaw before 2026.7.1 Authentication Bypass via activation5.4
- CVE-2026-100592OpenClaw before 2026.7.1 Authentication Bypass via Memory Dreaming6.3
- CVE-2026-100591OpenClaw before 2026.7.1 Authentication Bypass via Active Memory6.3
- CVE-2026-100589OpenClaw before 2026.7.1 Sandbox Bypass via Browser Node8.3
- CVE-2026-100590OpenClaw before 2026.7.1 Authorization Bypass via voice set4.3
- CVE-2026-100588OpenClaw before 2026.7.1 Authentication Bypass via node.invoke8.3
- CVE-2026-100586OpenClaw Codex before 2026.7.1 Authorization Bypass via Bind8.8
- CVE-2026-100587OpenClaw before 2026.7.1 Authorization Bypass via Codex Install8.8
- CVE-2026-100585OpenClaw before 2026.7.1 Authentication Bypass via MCP Channel8.0
Product grouping is registry-driven, with AI assist and human review. How it works