OpenClaw is averaging 1.8 CVEs *PER DAY* https://days-since-openclaw-cve.com/

That's... wow. New high score!

OpenClaw CVE Tracker โ€” Intruder

Tracking days since the last OpenClaw CVE, because apparently that's a full-time job.

OpenClaw also got a terrifying privilege escalation vulnerability https://nvd.nist.gov/vuln/detail/CVE-2026-33579

Meanwhile the OpenClaw founder is claiming shush, it's no big deal, probably most of these aren't really exploitable! (There's good business interest reasons to argue that, since OpenClaw's founders got acquired by OpenAI) https://news.ycombinator.com/item?id=47629849

Okay. I know I have more than a few security researchers following me. There's a public list of literally hundreds of thousands of publicly accessible OpenClaw instances right here: https://openclaw.allegro.earth/

Anyone try taking a sampling of them and testing how vulnerable against recent escalation CVEs they are? Could be a rather juicy writeup!

NVD - CVE-2026-33579

By the way, I encourage browsing through the CVEs reported https://nvd.nist.gov/vuln/search#/nvd/home?keyword=openclaw&resultType=records

These are by and large not minor CVEs.

NVD - Search and Statistics

@cwebber the more CVEs a project has, the more Web Scale it is
Mongodb Mongodb Is Web Scale GIF - Mongodb Mongodb is web scale Fourth wall break - Discover & Share GIFs

Click to view the GIF

Tenor
@phl @cwebber yep, this is what i was thinking of, haha
@vv @cwebber It lives rent free in our heads all these years later :D
@phl @cwebber i can't bring myself to watch it because the voice is so annoying
@vv @cwebber I thought webscale was the unsightly crusty build-up on the inside of the intertubes.

@cwebber

Is it a crime to hack instances in a country you're at war with?

Some of those openclaw agents were in Russia.

@cwebber I mean you could make an argument that the CVE s dont matter given the target audience of openclaw 
@lunathemoongirl Indeed, OpenClaw is a CVE
@cwebber why bother exploiting the program when i can ask the Aiagent to please hand over all the keys and password 
@cwebber I doubt they update frequently, so you can even try some quite old CVEs against them!
@cwebber honestly, at this point i expect openclaw servers to get automatically hacked within minutes, the same way you couldn't let a windows xp sp1 machine online without having it subjected to either the malware that knocked down a system service and forced your machine to shut down after a minute or the malware that knocked down a system service and caused weird bugs to happen

@cwebber
OpenClaw is averaging 1.8 CVEs *PER DAY*... since day 1, i.e. November 2025, wow!

They must be popular to have so many security researchers check them out ๐Ÿค“

@cwebber
CVE = Common Vulnerabilities and Exposures, in case that helps anyone else besides me

I try to do for initialisms and acronyms what alt text does for images.

Wikipedia: "The Common Vulnerabilities and Exposures (CVE) system, originally Common Vulnerability Enumeration, provides a reference method for publicly known information-security vulnerabilities and exposures."

@cwebber CVE as a service
@cwebber Everybody: AI canโ€™t find CVEs
OpenClaw: Bet
@cwebber The non-deterministic RCE engine for plagerized stackoverflow answers? Gasp. Who could have ever seen this coming.

@cwebber
@DaveMWilburn

The mind boggles to consider that anyone, anywhere, at anytime expected *any* different outcome from this snake-oil hyped up malarkey laughingly characterized as "AI"...

๐Ÿคฆโ€โ™‚๏ธ๐Ÿคทโ€โ™‚๏ธ๐Ÿคก๐Ÿซ๐Ÿ–•๐Ÿ–•๐Ÿ’ฉ๐Ÿ’ฉ

@cwebber the stat is missing the npm package ๐Ÿฅฒ
@cwebber It can't be that bad, can i- 238 CVEs already!?
@cwebber average CVSS value is a boring metric, I think this is more fun