Loading...
Skip to main content
npm (Node.js)

openclaw Security Analysis

openclaw has 67 known security vulnerabilities in npm (Node.js). Upgrade to version 2026.5.27 or later to resolve all known issues. Data sourced from OSV, enriched with EPSS exploit probability and CISA KEV.

67 Vulnerabilities

Low Immediate Risk

No actively exploited vulnerabilities detected. Monitor and update in your next maintenance window.

Recommended safe version: 2026.5.27

Upgrading to 2026.5.27 or later resolves all 67 known vulnerabilities in openclaw. Run: npm install openclaw@2026.5.27

Is openclaw in your project?

Check if you're affected and upgrade to 2026.5.27 to stay secure.

67
Total
0
Critical
0
High
0
Medium
0
Low

Vulnerabilities

67 unique vulnerabilities — sorted by exploitation risk (KEV → EPSS → CVSS). Click a CVE/GHSA ID for full details.

CVE / GHSASeverityAffectedFixed In
CVE-2026-34507
OpenClaw: QQBot admin commands could skip DM-only and allowFrom policy
CRITICAL
All versions2026.4.29
CVE-2026-33579
OpenClaw: /pair approve command path omitted caller scope subsetting and reopened device pairing escalation
CRITICAL
All versions2026.3.28
CVE-2026-35639
OpenClaw Gateway: RCE and Privilege Escalation from operator.pairing to operator.admin via device.pair.approve
CRITICAL
All versions2026.3.22
CVE-2026-22172
OpenClaw: WebSocket shared-auth connections could self-declare elevated scopes
CRITICAL
All versions2026.3.12
CVE-2026-32922
OpenClaw: Pairing-scoped device tokens could mint `operator.admin` and reach node RCE
CRITICAL
All versions2026.3.11
CVE-2026-28466
OpenClaw Vulnerable to Remote Code Execution via Node Invoke Approval Bypass in Gateway
CRITICAL
All versions2026.2.14
CVE-2026-28363
OpenClaw is vulnerable to validation bypass through GNU long-option abbreviations in allowlist mode
CRITICAL
All versions2026.2.23
CVE-2026-44109
OpenClaw: Feishu webhook and card-action validation now fail closed
CRITICAL
All versions2026.4.15
CVE-2026-31999
CpenClaw's ACPX Windows wrapper shell fallback allowed cwd injection in specific paths
CRITICAL
All versions2026.3.1
CVE-2026-28454
OpenClaw has a potential access-group authorization bypass if channel type lookup fails
CRITICAL
All versions2026.2.1
CVE-2026-28472
OpenClaw's gateway connect could skip device identity checks when auth.token was present but not yet validated
CRITICAL
All versions2026.2.2
CVE-2026-41294
OpenClaw has a CWD `.env` environment variable injection which bypasses host-env policy and allows config takeover
CRITICAL
All versions2026.3.28
CVE-2026-35663
OpenClaw: Gateway Backend Reconnect lets Non-Admin Operator Scopes Self-Claim operator.admin
CRITICAL
All versionsNo fix available
CVE-2026-41329
OpenClaw: Heartbeat context inheritance bypasses sandbox via senderIsOwner escalation
CRITICAL
All versions2026.3.31
CVE-2026-32916
OpenClaw: Plugin subagent routes could bypass gateway authorization with synthetic admin scopes
CRITICAL
All versions2026.3.11
CVE-2026-28446
OpenClaw has an inbound allowlist policy bypass in voice-call extension (empty caller ID + suffix matching)
CRITICAL
All versions2026.2.2
CVE-2026-35625
OpenClaw: Silent privilege escalation via gateway shared-auth reconnect
CRITICAL
All versionsNo fix available
CVE-2026-32013
OpenClaw gateway agents.files symlink escape allowed out-of-workspace file read/write
CRITICAL
All versions2026.2.25
CVE-2026-28469
OpenClaw Google Chat shared-path webhook target ambiguity allowed cross-account policy-context misrouting
HIGH
All versions2026.2.14
CVE-2026-41386
OpenClaw: Unbound bootstrap setup codes allow privilege escalation during pairing
HIGH
All versions2026.3.22
CVE-2026-28470
OpenClaw has an exec allowlist bypass via command substitution/backticks inside double quotes
HIGH
All versions2026.2.2
CVE-2026-28391
OpenClaw's Windows cmd.exe parsing may bypass exec allowlist/approval gating
HIGH
All versions2026.2.2
CVE-2026-41397
OpenClaw: OpenShell Mirror Sync — Sandbox Escape via Unrestricted File Sync + Symlink Traversal
HIGH
All versions2026.3.31
CVE-2026-41387
OpenClaw's incomplete host env sanitization blocklist allows supply-chain redirection via package-manager env overrides
HIGH
All versions2026.3.22
CVE-2026-35669
OpenClaw: Gateway Plugin HTTP Auth Grants Unrestricted operator.admin Runtime Scope to All Callers
HIGH
All versionsNo fix available
CVE-2026-32917
OpneClaw accepts unsanitized iMessage attachment paths which allowed SCP remote-path command injection
HIGH
All versions2026.3.13
CVE-2026-32913
OpenClaw: fetch-guard forwards custom authorization headers across cross-origin redirects
HIGH
All versions2026.3.7
CVE-2026-53836
OpenClaw: PowerShell encoded-command aliases could miss exec allowlist checks
HIGH
All versions2026.5.12
CVE-2026-53811
OpenClaw: Matrix allowFrom could bind to mutable display names
HIGH
All versions2026.5.7
CVE-2026-53806
OpenClaw: Combined POSIX shell options could confuse exec revalidation
HIGH
All versions2026.5.12
CVE-2026-53819
OpenClaw: Workspace .env could override Homebrew executable selection for skill install flows
HIGH
All versions2026.5.27
CVE-2026-53821
OpenClaw: Trusted-proxy Control UI WebSocket accepted client-declared scopes before pairing
HIGH
All versions2026.5.18
CVE-2026-35674
OpenClaw: Scoped chat.send route inheritance could bypass admin command scope gates
HIGH
All versions2026.5.18
CVE-2026-53810
OpenClaw's marketplace runtime extension metadata could point at unscanned payloads
HIGH
All versions2026.5.18
CVE-2026-53822
OpenClaw: Shell wrapper argv could change between approval and execution
HIGH
All versions2026.5.18
CVE-2026-53843
OpenClaw: Pairing-scoped device session could restore revoked node token authority
HIGH
All versions2026.5.26
CVE-2026-45006
OpenClaw's gateway config mutation guard allowed unsafe model-driven config writes
HIGH
All versions2026.4.23
CVE-2026-43530
OpenClaw: busybox and toybox applet execution weakened exec approval binding
HIGH
All versions2026.4.12
CVE-2026-42434
OpenClaw: Sandboxed agents could escape exec routing via host=node override
HIGH
All versions2026.4.10
CVE-2026-43569
OpenClaw: Workspace provider auth choices could auto-enable untrusted provider plugins
HIGH
All versions2026.4.9
CVE-2026-43571
OpenClaw: Channel setup catalog lookups could include untrusted workspace plugin shadows
HIGH
All versions2026.4.10
CVE-2026-43584
OpenClaw: Exec environment denylist missed high-risk interpreter startup variables
HIGH
All versions2026.4.10
CVE-2026-41378
OpenClaw: Paired node escalates to gateway RCE via unrestricted node.event agent dispatch
HIGH
All versions2026.3.31
CVE-2026-41352
OpenClaw: Device-Paired Node Skips Node Scope Gate → Host RCE.md
HIGH
All versions2026.3.31
CVE-2026-41303
OpenClaw: Discord text `/approve` bypasses `channels.discord.execApprovals.approvers` and allows non-approvers to resolve pending exec approvals
HIGH
All versions2026.3.28
CVE-2026-35643
OpenClaw: Arbitrary code execution via unvalidated WebView JavascriptInterface
HIGH
All versions2026.3.22
CVE-2026-35666
OpenClaw's system.run allowlist can be bypassed through an unregistered time dispatch wrapper
HIGH
All versions2026.3.22
CVE-2026-33573
OpenClaw: Gateway `agent` calls could override the workspace boundary
HIGH
All versions2026.3.11
CVE-2026-32914
OpenClaw: Command-authorized non-owners could reach owner-only `/config` and `/debug` surfaces
HIGH
All versions2026.3.12
CVE-2026-32915
OpenClaw: Leaf subagents could steer sibling sessions across sandbox boundaries
HIGH
All versions2026.3.11
CVE-2026-28363
OpenClaw's tools.exec.safeBins sort long-option abbreviation bypass can skip exec approval in allowlist mode
HIGH
All versions2026.2.23
CVE-2026-32060
OpenClaw has a path traversal in apply_patch could write/delete files outside the workspace
HIGH
All versions2026.2.14
CVE-2026-29610
OpenClaw: Command hijacking via unsafe PATH handling (bootstrapping + node-host PATH overrides)
HIGH
All versions2026.2.14
CVE-2026-53807
OpenClaw: Telegram interactive callbacks could skip commands.allowFrom
HIGH
All versions2026.5.6
CVE-2026-44116
OpenClaw validates Zalo outbound photo URLs through the SSRF guard
MEDIUM
All versions2026.4.22
CVE-2026-33578
OpenClaw: Google Chat and Zalouser group sender allowlist bypass via policy downgrade
MEDIUM
All versions2026.3.28
CVE-2026-33577
OpenClaw: node.pair.approve missing callerScopes validation allows low-privilege operator to approve malicious nodes
MEDIUM
All versions2026.3.28
CVE-2026-33576
OpenClaw: Zalo channel downloads media before sender authorization
MEDIUM
All versions2026.3.28
CVE-2026-43534
OpenClaw: Agent hook events could enqueue trusted system events from unsanitized external input
MEDIUM
All versions2026.4.10
CVE-2026-43566
OpenClaw: Heartbeat owner downgrade missed untrusted webhook wake events
MEDIUM
All versions2026.4.14
CVE-2026-32038
OpenClaw has a sandbox network isolation bypass via docker.network=container:<id>
MEDIUM
All versions2026.2.24
CVE-2026-43531
OpenClaw: Workspace .env could inject OpenClaw runtime-control variables
MEDIUM
All versions2026.4.9
CVE-2026-42426
OpenClaw `node.pair.approve` placed in `operator.write` scope instead of `operator.pairing` allows unprivileged pairing approval
MEDIUM
All versions2026.4.8
CVE-2026-42422
OpenClaw `device.token.rotate` mints tokens for unapproved roles, bypassing device role-upgrade pairing
MEDIUM
All versions2026.4.8
CVE-2026-32010
In OpenClaw, manually adding sort to tools.exec.safeBins could bypass allowlist approval via --compress-program
MEDIUM
All versions2026.2.22
CVE-2026-22177
OpenClaw's config env vars allowed startup env injection into service runtime
MEDIUM
All versions2026.2.21
CVE-2026-32023
OpenClaw's dispatch-wrapper depth-cap mismatch can bypass shell-wrapper approval gating in system.run allowlist mode
MEDIUM
All versions2026.2.24

About This Data

Vulnerability data for openclaw is sourced from the Open Source Vulnerability (OSV) database, aggregating reports from GitHub Advisory Database, NIST NVD, and ecosystem-specific sources.

CVSS (Common Vulnerability Scoring System) scores reflect exploitability and impact. EPSS (Exploit Prediction Scoring System) scores indicate the probability of exploitation within the next 30 days. Vulnerabilities marked with are listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.

Related npm (Node.js) Packages

Other packages in this ecosystem, ranked by shared vulnerabilities where available.

Check Your Dependencies

Scan your project to check if you're using a vulnerable version of openclaw.

Data from OSV DatabaseUpdated daily200K+ vulnerabilities indexed