CVE Tools

Clawdbot

12 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Clawdbot, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.

Clawdbot CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Clawdbot CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-010
2025-020
2025-030
2025-040
2025-050
2025-060
2025-070
2025-080
2025-090
2025-100
2025-110
2025-120
2026-010
2026-027
2026-035
2026-040
2026-050
2026-060
2026-070
2026-080
2026-090

Severity

How the 12 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • High655%
  • Medium436%
  • Low19%

Latest CVEs

The 12 most recently published vulnerabilities affecting Clawdbot.

  1. CVE-2026-29612OpenClaw < 2026.2.14 - Denial of Service via Large Base64 Media File Decoding5.5
  2. CVE-2026-28480OpenClaw < 2026.2.14 - Identity Spoofing via Mutable Username in Telegram Allowlist Authorization6.5
  3. CVE-2026-28478OpenClaw < 2026.2.13 - Denial of Service via Unbounded Webhook Request Body Buffering7.5
  4. CVE-2026-28469OpenClaw < 2026.2.14 - Cross-Account Policy Context Misrouting via Shared Webhook Path Ambiguity7.5
  5. CVE-2026-28452OpenClaw < 2026.2.14 - Denial of Service via Unguarded Archive Extraction in extractArchive5.5
  6. CVE-2026-26328OpenClaw iMessage group allowlist authorization inherited DM pairing-store identities6.5
  7. CVE-2026-26317OpenClaw affected by cross-site request forgery (CSRF) through loopback browser mutation endpoints7.1
  8. CVE-2026-24764OpenClaw has Remote Code Execution via System Prompt Injection in Slack Channel Descriptions3.7
  9. GHSA-chm2-m3w2-wcxmOpenClaw Google Chat spoofing access with allowlist authorized mutable email principal despite sender-ID mismatch—
  10. CVE-2026-25157OpenClaw/Clawdbot has OS Command Injection via Project Root Path in sshNodeCommand7.7
  11. CVE-2026-24763Authenticated Command Injection in OpenClaw Docker Execution via PATH Environment Variable8.8
  12. CVE-2026-25253OpenClaw (aka clawdbot or Moltbot) before 2026.1.29 obtains a gatewayUrl value from a query string and automatically makes a WebSocket connection without prompting, sending a token value.8.8

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store