OpenClaw CVE Tracker

Public state of known OpenClaw vulnerabilities: one major CVE (ClawBleed, CVE-2026-25253, CVSS 8.8, patched in v2026.1.29 on January 30, 2026) and two structural risks, the ClawHavoc malicious-skills campaign (1,184+ skills, Antiy CERT, February 2026) and public exposure of unhardened instances (~93% vulnerable, Maor Dayan, early 2026). Every entry is sourced. Reviewed quarterly.

Last reviewed: · No other public OpenClaw CVEs tracked as of this date.

Published CVEs

Published OpenClaw CVEs
IDSeverityTypeFix / mitigationOpenClawPro statusSource
CVE-2026-25253
ClawBleed
8.8 (HIGH)One-click RCE via cross-site WebSocket hijack (gatewayUrl query param, auto-connect without prompt, token sent)v2026.1.29 (2026-01-30), disclosed 2026-02-03Patched: every OpenClawPro instance runs ≥ 2026.1.29NVD: CVE-2026-25253

Advisories & campaigns (non-CVE)

OpenClaw security advisories
IDSeverityTypeFix / mitigationOpenClawPro statusSource
CLAWHAVOC-2026
ClawHavoc
Supply chainCoordinated campaign: 1,184+ malicious skills planted on the ClawHub registry (~247,693 cumulative installs), several distributing Atomic macOS Stealer (AMOS)Mitigation: vetted skills onlyOngoing risk: OpenClawPro installs pre-vetted, sandbox-tested skills onlyAntiy CERT research, February 2026
EXPOSURE-2026
Public exposure scans
Config riskIndependent scans found tens of thousands of publicly reachable OpenClaw instances, ~93% with authentication-bypass conditionsMitigation: 12-point hardening (firewall, auth, TLS, no public gateway)Ongoing risk: covered by our 12-point auditCSO Online / Maor Dayan, early 2026

Patching is literally our job

OpenClawPro maintenance plans (from $45/mo) include security patching, 24/7 monitoring and update testing: the patch discipline that would have closed CVE-2026-25253 before public disclosure.

Need it built for you?

WarMachine33: AI automation agency. We design and ship custom AI workflows for your business.

Discover WarMachine33 →