Disclosure
and other people's unfavorite are kool-aid stains on a white T-Shirt.
Known OpenClaw Security Issues (as of 18 Mar 2026; core engine hardened via patches in 2026.1.29–2026.3.x, but risks persist)
Remote Code Execution & Command Injection: CVE-2026-25253 (CVSS 8.8, 1-click via UI token exfil/WebSocket), CVE-2026-24763 (Docker PATH/cmd injection), CVE-2026-25157 (OS command injection), plus workspace/plugin auto-discovery.
Authentication & Authorization Failures: Multiple auth bypasses, scope escalation, CSRF, missing webhook validation, CVE-2026-28458 (browser relay), CVE-2026-32302 (trusted-proxy admin access).
Denial of Service & Forgery: CVE-2026-28478 (webhook exhaustion), SSRF, unbounded buffering.
Data Disclosure & Leaks: Plaintext API keys/credentials, local file disclosure (MEDIA tokens), cross-session exfil via prompt injection.
Supply-Chain (ClawHub / ClawHavoc): 341–1,184+ malicious skills delivering stealers (Atomic Stealer, crypto/key loggers); 13.4–36.8% of scanned skills contain critical flaws; unvetted marketplace runs with full agent privileges.
Exposure & Defaults: 30k–42k+ publicly exposed instances (default 0.0.0.0 bind, weak/no auth early versions).
Other: Sandbox bypasses, memory poisoning, fake GitHub installers with infostealers, prompt-injection-driven unauthorized actions.
Known Shortcomings (security-adjacent + functional)
Insecure-by-default early design + over-privileged agent model.
Impractical manual skill vetting (Lucas-highlighted scalability gap).
Unpredictable autonomy (reasoning loops, task drift, stalls, silent/false completions).
Steep setup & secure-configuration curve (CLI-heavy, not beginner-friendly).
High resource/maintenance burden (frequent patches, memory tuning, 24/7 isolation required).
Dependency on external LLMs + evolving unvetted ecosystem.
Recommended immediate mitigations (actionable): Run in VM/Docker with no internet except vetted LLM endpoints; never expose publicly; install only from official/pinned verified ClawHub tier; enable any built-in VirusTotal scanning; update to latest 2026.3.x; monitor GitHub advisories.
Post summary
The article catalogs several OpenClaw CVEs, detailing their technical aspects, CVSS scores, and available patches, while providing mitigations but making no claims of active exploitation or PoCs.