CVE-2026-62225
OpenClaw (formerly Moltbot or Clawdbot) vulnerability analysis and mitigation

Overview

CVE-2026-62225 is an authorization bypass vulnerability in OpenClaw's skill command dispatch mechanism that allows lower-trust authenticated callers to execute or persist actions beyond their intended authorization. It affects OpenClaw (npm package) versions before 2026.5.18 and was published on July 17, 2026, with the underlying advisory (GHSA-mhm4-93fw-4qr2) published by maintainer joshavant on June 30, 2026. The vulnerability carries a CVSS v3.1 base score of 5.4 (Medium) and a CVSS v4.0 base score of 2.3 (Low) (Github Advisory, OpenClaw Advisory).

Technical details

The root cause is classified as CWE-863 (Incorrect Authorization): the skill command dispatch subsystem fails to correctly enforce tool policy checks, allowing configured input paths to route commands from lower-trust callers into execution or persistence flows that should be restricted (OpenClaw Advisory). An attacker with low-privilege network access can exploit this by sending crafted requests through a reachable input path to the affected feature, bypassing the intended tool policy restrictions. Exploitation requires the affected skill command dispatch feature to be enabled and reachable, and specific deployment conditions (Attack Requirements: Present in CVSS v4.0) must be met (Github Advisory). The advisory explicitly notes this does not affect OpenClaw's trusted-operator model for authenticated Gateway operators, installed plugins, or intentional local execution surfaces unless a separate policy boundary is crossed (OpenClaw Advisory).

Impact

Successful exploitation allows any authenticated low-privilege user reachable over the network to bypass authorization controls and execute or persist actions beyond their intended permissions, including running unauthorized commands and modifying data that should be restricted (OpenClaw Advisory). The confidentiality and integrity impacts are rated Low, with no availability impact; the practical severity depends heavily on the operator's configuration and whether lower-trust input can reach the vulnerable dispatch path (Github Advisory). There is no impact to subsequent/downstream systems per the CVSS v4.0 assessment.

Mitigation and workarounds

The first stable patched version is OpenClaw 2026.5.18; operators should upgrade immediately (OpenClaw Advisory). Prior to upgrading, the recommended mitigations are: (1) restrict the affected skill command dispatch feature to trusted operators only, or disable it entirely if not required; (2) keep channel and tool allowlists narrow; (3) avoid sharing a single Gateway between mutually untrusted users; and (4) implement network access controls to limit exposure to trusted users only (OpenClaw Advisory, Github Advisory).

Additional resources


SourceThis report was generated using AI

Related OpenClaw (formerly Moltbot or Clawdbot) vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-62228HIGH7.7
  • OpenClaw (formerly Moltbot or Clawdbot) logoOpenClaw (formerly Moltbot or Clawdbot)
  • openclaw
NoYesJul 17, 2026
CVE-2026-45623HIGH7.5
  • JavaScript logoJavaScript
  • kubeflow-pipelines-frontend
NoYesJul 23, 2026
CVE-2026-62226MEDIUM5.1
  • OpenClaw (formerly Moltbot or Clawdbot) logoOpenClaw (formerly Moltbot or Clawdbot)
  • openclaw
NoYesJul 17, 2026
CVE-2026-62227MEDIUM4.9
  • OpenClaw (formerly Moltbot or Clawdbot) logoOpenClaw (formerly Moltbot or Clawdbot)
  • openclaw
NoYesJul 17, 2026
CVE-2026-62225LOW2.3
  • OpenClaw (formerly Moltbot or Clawdbot) logoOpenClaw (formerly Moltbot or Clawdbot)
  • openclaw
NoYesJul 17, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management