clawdbot
MITWhatsApp gateway CLI (Baileys web) with Pi RPC agent
20
Security score
11 known advisories in v2026.1.24-3
Weekly downloads
—
Unpacked size
42.1 MB
Dependencies
53
Last publish
7 months ago
Security advisories
- OpenClaw iMessage group allowlist authorization inherited DM pairing-store identitiesmoderate
GHSA-g34w-4xqq-h79m · fixed in 2026.2.14
- OpenClaw/Clawdbot has 1-Click RCE via Authentication Token Exfiltration From gatewayUrlhigh
GHSA-g8p2-7wf7-98mq · fixed in 2026.1.29
- OpenClaw/Clawdbot Docker Execution has Authenticated Command Injection via PATH Environment Variablehigh
GHSA-mc68-q9jw-2h3v · fixed in 2026.1.29
- OpenClaw Telegram allowlist authorization accepted mutable usernamesmoderate
GHSA-mj5r-hh7j-4gxf
- OpenClaw/Clawdbot has OS Command Injection via Project Root Path in sshNodeCommandhigh
GHSA-q284-4pvr-m585 · fixed in 2026.1.29
- OpenClaw affected by denial of service via unbounded webhook request body bufferinghigh
GHSA-q447-rj3r-2cgh
- OpenClaw: denial of service through large base64 media files allocating large buffers before limit checksmoderate
GHSA-w2cg-vxx6-5xjg