cd /news/ai-safety/where-to-find-openclaw-security-upda… · home topics ai-safety article
[ARTICLE · art-131760] src=openclaw.ai ↗ pub= topic=ai-safety verified=true sentiment=· neutral

Where to find OpenClaw security updates

OpenClaw launched a public security page at openclaw.ai/security detailing its vulnerability work, reporting that 722 fixes have been published since January and that 14 reports resulted in confirmed critical vulnerabilities, all of which have been fixed and disclosed. The open-source project, whose maintainers include security engineers from NVIDIA and Tencent, also published an open dataset of more than 67,000 ClawHub skill scans on Hugging Face. The page consolidates advisories, ongoing work such as ClawHub skill scanning and network egress controls, and the private vulnerability reporting process.

read2 min views1 publishedSep 16, 2026
Where to find OpenClaw security updates
Image: Openclaw (auto-discovered)

As an open-source project, securing OpenClaw is ongoing work.

A trusted group of maintainers, including security engineers from NVIDIA and Tencent, volunteer their time to review reports, investigate issues, ship fixes, and strengthen the project as it evolves. A lot of this work happens behind the scenes, and we want to make more of it visible and easier to understand.

This week, we rolled out a security page for all to see where OpenClaw security stands, what we’re working on, what we’ve fixed, and how to reach us when something needs our attention.

The page brings together information that previously lived across GitHub, documentation, blog posts, and individual advisories. It includes:

  • Current security status and advisories, including whether there are any active security bulletins.
  • The numbers behind vulnerability reports. Since January, 722 fixes have been published. Fourteen reports resulted in confirmed critical vulnerabilities; all of them had been fixed and disclosed.
  • Where fixes are happening, from gateway authentication and scopes to sandboxing, approvals, connectors, filesystem handling, plugins, skills, and network access.
  • Ongoing security work, including ClawHub skill scanning, install blocking for malicious or quarantined skills, safer filesystem access, command-chain checks, network egress controls, and regression testing based on previously patched advisories.
  • A clear vulnerability reporting process, including what makes a useful report, what happens after one is submitted, and what falls outside OpenClaw’s security model.
  • Security research and write-ups, from both OpenClaw contributors and outside researchers.

We’re also making more of our underlying security work available. One recent example: OpenClaw has published an open dataset containing more than 67,000 ClawHub skill scans, alongside research into how different security scanners evaluate the same skills.

Our work is never done. OpenClaw connects models to tools, files, browsers, services, and other systems, and those capabilities create security boundaries that keep evolving with the project.

As a reminder, if you find a potential vulnerability, please report it privately to give our maintainers time to investigate and ship a fix before technical details are public.

Explore more at openclaw.ai/security. 🦞

── more in #ai-safety 4 stories · sorted by recency
── more on @openclaw 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/where-to-find-opencl…] indexed:0 read:2min 2026-09-16 ·