From the source
Security at OpenClaw is an ongoing initiative, and part of that work is being transparent about what we find and fix along the way.
OpenClaw recently completed a broad security audit with Trail of Bits through OpenAI’s Patch the Planet initiative, giving us a clearer view of where OpenClaw’s security boundaries needed enhancements.
Today we’re sharing the results.
Summary: Trail of Bits submitted 27 private repository advisories and 3 standalone hardening pull requests.
Of the advisory reports, 24 described severity-rated vulnerabilities. 23 were classified as confirmed vulnerabilities, although some were closed without publication because they were fixed before reaching a stable release.
The remaining 1 concerned a vulnerability fixed before submission.
Those 24 reports were rated 0 Critical, 2 High, 16 Medium, and 6 Low.
The other 3 were classified as defense-in-depth findings and did not receive severity ratings because they did not cross a documented trust boundary.
Every actionable issue has been repaired, and all 3 standalone hardening PRs were merged.
How the Engagement Worked Patch the Planet combines AI-assisted security research with human review.
…






