clawsmith.com/signal/openclaw-nine-cves-four-days-march-2026
โ IssueWide OpenLive
OpenClaw Nine CVEs in Four Days: 9.9 CVSS Admin Bypass via WebSocket Handshake
Between March 18-21, 2026, nine CVEs were disclosed for OpenClaw. The most critical (CVSS 9.9) let any authenticated user self-declare admin via WebSocket scope handshake โ no special privileges required. Six more were high severity, including command approval bypasses and session sandbox escapes. The jgamblin/OpenClawCVEs tracker now lists 156+ total advisories, 128 still awaiting CVE assignment. Belgium CCB issued a Patch Immediately advisory.
Product Idea from this Signal
A network firewall that blocks WebSocket hijack attacks on local OpenClaw agents before malicious sites connect
900 โฒSECURITYCLIDEVTOOLOPEN-SOURCE
CompetitiveView Opportunity โ
Score Breakdown
HN
500
GitHub
400
Social Proof 3 sources
Frequently Asked Questions
Virality Score
900
across 0 platforms
Details
Signalissue
Ecosystemโ
Sources3
Platforms0
Updated12d ago
Trendโ stable
Top ideas
All ideas โRelated signals
All signals โ