OpenClaw security report: 1,788 vulnerability reports, only 14 confirmed critical
vincent_koc · x · 2026-09-11
- OpenClaw's Vincent Koc published the project's security state: 1,788 reports filed since January 2026, 57% closed as invalid/duplicate/by-design, 647 fixed and published (39 with CVEs). Of 144 reports claimed critical, only 14 were confirmed — all fixed and disclosed. No known compromise of infrastructure or install/update channels.
- Fix distribution: 33% (215) in add-ons; core runtime includes gateway/auth/scopes (164), exec/sandbox/approvals (149), chat connectors (109), filesystem/path handling (25), network egress/SSRF (17).
- Ongoing work: every ClawHub skill version scanned via static analysis, VirusTotal, and NVIDIA SkillSpector; a dataset of 67,453 skill scans on Hugging Face; malicious-skill install blocking; root-bounded file access; full command-chain exec approvals; centralized egress proxy with policy.
More from coding & agent
- Models got less conversational as they got agentic — here's how to get a thinking partner back — evielync · 2026-09-11
- BBCraft: Someone Skinned the bb Editor as Classic Warcraft III Menus — msg · 2026-09-11
- Giving a Grok bot a phone number: live demo of a calling agent with transcript and cost review — mattyp · 2026-09-11
- Dev finally ships his Tamagotchi-style IFS therapy app on the 5th try with GPT Astra — brandon_galang · 2026-09-11
- Cognition Launches Devin Voice: Speak Your Idea, Devin Ships It, Powered by GPT-Live and SWE-2 — marvinvonhagen · 2026-09-11
- SkillAdam ports Adam's moment estimates to agent skill docs to fix self-evolution loops — dair_ai · 2026-09-11