clawdbot
v2026.1.24-3npm· JavaScriptWhatsApp gateway CLI (Baileys web) with Pi RPC agent
The verdict
Has 11 high-severity advisories. Verify a patched version exists before using. Check the OSV link for the fixed-in version.
Check the OSV link for the fixed-in version.
Live from the npm registry · derived rules, not AI
How it scores
MaintenanceHealthy
PopularityNiche
Security11 advisories
LicensePermissive
DepsHeavy
Maintenance
Last published 4 months ago.
Popularity
15K downloads / week
Security
11 known advisories (worst: high severity).
License
MIT
Dependencies
53 direct dependencies
Security advisories
Live from OSV.dev · cached 24h- HIGHOpenClaw affected by cross-site request forgery (CSRF) through loopback browser mutation endpointsGHSA-3fqr-4cg8-h96q Published 2026-02-18
- HIGHOpenClaw/Clawdbot has 1-Click RCE via Authentication Token Exfiltration From gatewayUrl
- HIGHOpenClaw/Clawdbot Docker Execution has Authenticated Command Injection via PATH Environment Variable
- HIGHOpenClaw/Clawdbot has OS Command Injection via Project Root Path in sshNodeCommand
- HIGHOpenClaw affected by denial of service via unbounded webhook request body bufferingGHSA-q447-rj3r-2cgh Published 2026-02-18
- HIGHOpenClaw Google Chat shared-path webhook target ambiguity allowed cross-account policy-context misroutingGHSA-rq6g-px6m-c248 Published 2026-02-18
- MEDIUMOpenClaw iMessage group allowlist authorization inherited DM pairing-store identities
- MEDIUMOpenClaw affected by denial of service through unguarded archive extraction allowing high expansion/resource abuse (ZIP/TAR)GHSA-h89v-j3x9-8wqj Published 2026-02-18
- MEDIUMOpenClaw Telegram allowlist authorization accepted mutable usernamesGHSA-mj5r-hh7j-4gxf Published 2026-02-18
- MEDIUMOpenClaw: denial of service through large base64 media files allocating large buffers before limit checksGHSA-w2cg-vxx6-5xjg Published 2026-02-18
- LOWOpenClaw Google Chat spoofing access with allowlist authorized mutable email principal despite sender-ID mismatchGHSA-chm2-m3w2-wcxm Published 2026-02-17
Recent releases
- 2026.1.24-34 months ago
- 2026.1.24-24 months ago
- 2026.1.24-14 months ago
- 2026.1.244 months ago
- 2026.1.23-14 months ago
- 2026.1.234 months ago
- 2026.1.224 months ago
- 2026.1.21-24 months ago