OpenClaw CVE Tracker
Public state of known OpenClaw vulnerabilities: one major CVE (ClawBleed, CVE-2026-25253, CVSS 8.8, patched in v2026.1.29 on January 30, 2026) and two structural risks, the ClawHavoc malicious-skills campaign (1,184+ skills, Antiy CERT, February 2026) and public exposure of unhardened instances (~93% vulnerable, Maor Dayan, early 2026). Every entry is sourced. Reviewed quarterly.
Last reviewed: · No other public OpenClaw CVEs tracked as of this date.
Published CVEs
| ID | Severity | Type | Fix / mitigation | OpenClawPro status | Source |
|---|---|---|---|---|---|
| CVE-2026-25253 ClawBleed | 8.8 (HIGH) | One-click RCE via cross-site WebSocket hijack (gatewayUrl query param, auto-connect without prompt, token sent) | v2026.1.29 (2026-01-30), disclosed 2026-02-03 | Patched: every OpenClawPro instance runs ≥ 2026.1.29 | NVD: CVE-2026-25253 |
Advisories & campaigns (non-CVE)
| ID | Severity | Type | Fix / mitigation | OpenClawPro status | Source |
|---|---|---|---|---|---|
| CLAWHAVOC-2026 ClawHavoc | Supply chain | Coordinated campaign: 1,184+ malicious skills planted on the ClawHub registry (~247,693 cumulative installs), several distributing Atomic macOS Stealer (AMOS) | Mitigation: vetted skills only | Ongoing risk: OpenClawPro installs pre-vetted, sandbox-tested skills only | Antiy CERT research, February 2026 |
| EXPOSURE-2026 Public exposure scans | Config risk | Independent scans found tens of thousands of publicly reachable OpenClaw instances, ~93% with authentication-bypass conditions | Mitigation: 12-point hardening (firewall, auth, TLS, no public gateway) | Ongoing risk: covered by our 12-point audit | CSO Online / Maor Dayan, early 2026 |
Patching is literally our job
OpenClawPro maintenance plans (from $45/mo) include security patching, 24/7 monitoring and update testing: the patch discipline that would have closed CVE-2026-25253 before public disclosure.