Openclaw Security Analysis
Openclaw has 67 known security vulnerabilities in npm (Node.js). Upgrade to version 2026.5.27 or later to resolve all known issues. Data sourced from OSV, enriched with EPSS exploit probability and CISA KEV.
Low Immediate Risk
No actively exploited vulnerabilities detected. Monitor and update in your next maintenance window.
Recommended safe version: 2026.5.27
Upgrading to 2026.5.27 or later resolves all 67 known vulnerabilities in Openclaw. Run: npm install Openclaw@2026.5.27
Is Openclaw in your project?
Check if you're affected and upgrade to 2026.5.27 to stay secure.
Vulnerabilities
67 unique vulnerabilities — sorted by exploitation risk (KEV → EPSS → CVSS). Click a CVE/GHSA ID for full details.
| CVE / GHSA | Severity | Affected | Fixed In |
|---|---|---|---|
| CVE-2026-34507 OpenClaw: QQBot admin commands could skip DM-only and allowFrom policy | CRITICAL | All versions | 2026.4.29 |
| CVE-2026-33579 OpenClaw: /pair approve command path omitted caller scope subsetting and reopened device pairing escalation | CRITICAL | All versions | 2026.3.28 |
| CVE-2026-35639 OpenClaw Gateway: RCE and Privilege Escalation from operator.pairing to operator.admin via device.pair.approve | CRITICAL | All versions | 2026.3.22 |
| CVE-2026-22172 OpenClaw: WebSocket shared-auth connections could self-declare elevated scopes | CRITICAL | All versions | 2026.3.12 |
| CVE-2026-32922 OpenClaw: Pairing-scoped device tokens could mint `operator.admin` and reach node RCE | CRITICAL | All versions | 2026.3.11 |
| CVE-2026-28466 OpenClaw Vulnerable to Remote Code Execution via Node Invoke Approval Bypass in Gateway | CRITICAL | All versions | 2026.2.14 |
| CVE-2026-28363 OpenClaw is vulnerable to validation bypass through GNU long-option abbreviations in allowlist mode | CRITICAL | All versions | 2026.2.23 |
| CVE-2026-44109 OpenClaw: Feishu webhook and card-action validation now fail closed | CRITICAL | All versions | 2026.4.15 |
| CVE-2026-31999 CpenClaw's ACPX Windows wrapper shell fallback allowed cwd injection in specific paths | CRITICAL | All versions | 2026.3.1 |
| CVE-2026-28454 OpenClaw has a potential access-group authorization bypass if channel type lookup fails | CRITICAL | All versions | 2026.2.1 |
| CVE-2026-28472 OpenClaw's gateway connect could skip device identity checks when auth.token was present but not yet validated | CRITICAL | All versions | 2026.2.2 |
| CVE-2026-41294 OpenClaw has a CWD `.env` environment variable injection which bypasses host-env policy and allows config takeover | CRITICAL | All versions | 2026.3.28 |
| CVE-2026-35663 OpenClaw: Gateway Backend Reconnect lets Non-Admin Operator Scopes Self-Claim operator.admin | CRITICAL | All versions | No fix available |
| CVE-2026-41329 OpenClaw: Heartbeat context inheritance bypasses sandbox via senderIsOwner escalation | CRITICAL | All versions | 2026.3.31 |
| CVE-2026-32916 OpenClaw: Plugin subagent routes could bypass gateway authorization with synthetic admin scopes | CRITICAL | All versions | 2026.3.11 |
| CVE-2026-28446 OpenClaw has an inbound allowlist policy bypass in voice-call extension (empty caller ID + suffix matching) | CRITICAL | All versions | 2026.2.2 |
| CVE-2026-35625 OpenClaw: Silent privilege escalation via gateway shared-auth reconnect | CRITICAL | All versions | No fix available |
| CVE-2026-32013 OpenClaw gateway agents.files symlink escape allowed out-of-workspace file read/write | CRITICAL | All versions | 2026.2.25 |
| CVE-2026-28469 OpenClaw Google Chat shared-path webhook target ambiguity allowed cross-account policy-context misrouting | HIGH | All versions | 2026.2.14 |
| CVE-2026-41386 OpenClaw: Unbound bootstrap setup codes allow privilege escalation during pairing | HIGH | All versions | 2026.3.22 |
| CVE-2026-28470 OpenClaw has an exec allowlist bypass via command substitution/backticks inside double quotes | HIGH | All versions | 2026.2.2 |
| CVE-2026-28391 OpenClaw's Windows cmd.exe parsing may bypass exec allowlist/approval gating | HIGH | All versions | 2026.2.2 |
| CVE-2026-41397 OpenClaw: OpenShell Mirror Sync — Sandbox Escape via Unrestricted File Sync + Symlink Traversal | HIGH | All versions | 2026.3.31 |
| CVE-2026-41387 OpenClaw's incomplete host env sanitization blocklist allows supply-chain redirection via package-manager env overrides | HIGH | All versions | 2026.3.22 |
| CVE-2026-35669 OpenClaw: Gateway Plugin HTTP Auth Grants Unrestricted operator.admin Runtime Scope to All Callers | HIGH | All versions | No fix available |
| CVE-2026-32917 OpneClaw accepts unsanitized iMessage attachment paths which allowed SCP remote-path command injection | HIGH | All versions | 2026.3.13 |
| CVE-2026-32913 OpenClaw: fetch-guard forwards custom authorization headers across cross-origin redirects | HIGH | All versions | 2026.3.7 |
| CVE-2026-53836 OpenClaw: PowerShell encoded-command aliases could miss exec allowlist checks | HIGH | All versions | 2026.5.12 |
| CVE-2026-53811 OpenClaw: Matrix allowFrom could bind to mutable display names | HIGH | All versions | 2026.5.7 |
| CVE-2026-53806 OpenClaw: Combined POSIX shell options could confuse exec revalidation | HIGH | All versions | 2026.5.12 |
| CVE-2026-53819 OpenClaw: Workspace .env could override Homebrew executable selection for skill install flows | HIGH | All versions | 2026.5.27 |
| CVE-2026-53821 OpenClaw: Trusted-proxy Control UI WebSocket accepted client-declared scopes before pairing | HIGH | All versions | 2026.5.18 |
| CVE-2026-35674 OpenClaw: Scoped chat.send route inheritance could bypass admin command scope gates | HIGH | All versions | 2026.5.18 |
| CVE-2026-53810 OpenClaw's marketplace runtime extension metadata could point at unscanned payloads | HIGH | All versions | 2026.5.18 |
| CVE-2026-53822 OpenClaw: Shell wrapper argv could change between approval and execution | HIGH | All versions | 2026.5.18 |
| CVE-2026-53843 OpenClaw: Pairing-scoped device session could restore revoked node token authority | HIGH | All versions | 2026.5.26 |
| CVE-2026-45006 OpenClaw's gateway config mutation guard allowed unsafe model-driven config writes | HIGH | All versions | 2026.4.23 |
| CVE-2026-43530 OpenClaw: busybox and toybox applet execution weakened exec approval binding | HIGH | All versions | 2026.4.12 |
| CVE-2026-42434 OpenClaw: Sandboxed agents could escape exec routing via host=node override | HIGH | All versions | 2026.4.10 |
| CVE-2026-43569 OpenClaw: Workspace provider auth choices could auto-enable untrusted provider plugins | HIGH | All versions | 2026.4.9 |
| CVE-2026-43571 OpenClaw: Channel setup catalog lookups could include untrusted workspace plugin shadows | HIGH | All versions | 2026.4.10 |
| CVE-2026-43584 OpenClaw: Exec environment denylist missed high-risk interpreter startup variables | HIGH | All versions | 2026.4.10 |
| CVE-2026-41378 OpenClaw: Paired node escalates to gateway RCE via unrestricted node.event agent dispatch | HIGH | All versions | 2026.3.31 |
| CVE-2026-41352 OpenClaw: Device-Paired Node Skips Node Scope Gate → Host RCE.md | HIGH | All versions | 2026.3.31 |
| CVE-2026-41303 OpenClaw: Discord text `/approve` bypasses `channels.discord.execApprovals.approvers` and allows non-approvers to resolve pending exec approvals | HIGH | All versions | 2026.3.28 |
| CVE-2026-35643 OpenClaw: Arbitrary code execution via unvalidated WebView JavascriptInterface | HIGH | All versions | 2026.3.22 |
| CVE-2026-35666 OpenClaw's system.run allowlist can be bypassed through an unregistered time dispatch wrapper | HIGH | All versions | 2026.3.22 |
| CVE-2026-33573 OpenClaw: Gateway `agent` calls could override the workspace boundary | HIGH | All versions | 2026.3.11 |
| CVE-2026-32914 OpenClaw: Command-authorized non-owners could reach owner-only `/config` and `/debug` surfaces | HIGH | All versions | 2026.3.12 |
| CVE-2026-32915 OpenClaw: Leaf subagents could steer sibling sessions across sandbox boundaries | HIGH | All versions | 2026.3.11 |
| CVE-2026-28363 OpenClaw's tools.exec.safeBins sort long-option abbreviation bypass can skip exec approval in allowlist mode | HIGH | All versions | 2026.2.23 |
| CVE-2026-32060 OpenClaw has a path traversal in apply_patch could write/delete files outside the workspace | HIGH | All versions | 2026.2.14 |
| CVE-2026-29610 OpenClaw: Command hijacking via unsafe PATH handling (bootstrapping + node-host PATH overrides) | HIGH | All versions | 2026.2.14 |
| CVE-2026-53807 OpenClaw: Telegram interactive callbacks could skip commands.allowFrom | HIGH | All versions | 2026.5.6 |
| CVE-2026-44116 OpenClaw validates Zalo outbound photo URLs through the SSRF guard | MEDIUM | All versions | 2026.4.22 |
| CVE-2026-33578 OpenClaw: Google Chat and Zalouser group sender allowlist bypass via policy downgrade | MEDIUM | All versions | 2026.3.28 |
| CVE-2026-33577 OpenClaw: node.pair.approve missing callerScopes validation allows low-privilege operator to approve malicious nodes | MEDIUM | All versions | 2026.3.28 |
| CVE-2026-33576 OpenClaw: Zalo channel downloads media before sender authorization | MEDIUM | All versions | 2026.3.28 |
| CVE-2026-43534 OpenClaw: Agent hook events could enqueue trusted system events from unsanitized external input | MEDIUM | All versions | 2026.4.10 |
| CVE-2026-43566 OpenClaw: Heartbeat owner downgrade missed untrusted webhook wake events | MEDIUM | All versions | 2026.4.14 |
| CVE-2026-32038 OpenClaw has a sandbox network isolation bypass via docker.network=container:<id> | MEDIUM | All versions | 2026.2.24 |
| CVE-2026-43531 OpenClaw: Workspace .env could inject OpenClaw runtime-control variables | MEDIUM | All versions | 2026.4.9 |
| CVE-2026-42426 OpenClaw `node.pair.approve` placed in `operator.write` scope instead of `operator.pairing` allows unprivileged pairing approval | MEDIUM | All versions | 2026.4.8 |
| CVE-2026-42422 OpenClaw `device.token.rotate` mints tokens for unapproved roles, bypassing device role-upgrade pairing | MEDIUM | All versions | 2026.4.8 |
| CVE-2026-32010 In OpenClaw, manually adding sort to tools.exec.safeBins could bypass allowlist approval via --compress-program | MEDIUM | All versions | 2026.2.22 |
| CVE-2026-22177 OpenClaw's config env vars allowed startup env injection into service runtime | MEDIUM | All versions | 2026.2.21 |
| CVE-2026-32023 OpenClaw's dispatch-wrapper depth-cap mismatch can bypass shell-wrapper approval gating in system.run allowlist mode | MEDIUM | All versions | 2026.2.24 |
About This Data
Vulnerability data for Openclaw is sourced from the Open Source Vulnerability (OSV) database, aggregating reports from GitHub Advisory Database, NIST NVD, and ecosystem-specific sources.
CVSS (Common Vulnerability Scoring System) scores reflect exploitability and impact. EPSS (Exploit Prediction Scoring System) scores indicate the probability of exploitation within the next 30 days. Vulnerabilities marked with are listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.
Related npm (Node.js) Packages
Other packages in this ecosystem, ranked by shared vulnerabilities where available.
Check Your Dependencies
Scan your project to check if you're using a vulnerable version of Openclaw.