OpenClaw, a self-hosted AI agent that rapidly became GitHub’s most-starred repository, triggered an unusual surge of vulnerability disclosures that exposed friction between GitHub Security Advisories (GHSAs) and the traditional CVE assignment pipeline. In late February, OpenClaw published 200+ GHSAs within roughly three weeks (with reports citing ~255 total advisories), covering issues such as command execution controls, authorization checks, allowlist enforcement, and plugin boundary weaknesses; many advisories lacked corresponding CVE identifiers due to the volume outpacing normal CVE processing.
The situation escalated when vulnerability intelligence firm VulnCheck asked the CVE Project researcher working group to call “DIBS” on 170 OpenClaw advisories without CVE IDs—an informal CNA coordination signal indicating intent to evaluate and potentially assign CVEs—citing customer demand and a desire to ensure coverage “before they are weaponized.” The request prompted pushback within the CVE community (including from MITRE’s TL-Root) that DIBS is intended for individual vulnerabilities meeting defined criteria, not as a mechanism to broadly categorize or preemptively claim large sets of supplier advisories; separately, a podcast episode referenced an “OpenClaw bot” allegedly moving from research into malicious activity, but provided insufficient detail to corroborate or connect it to the GHSA/CVE tracking dispute.

See the reporting duties and controls this puts on the clock.
5 events from the most recent confirmed update back to the earliest known activity.
In response to the disclosure surge, Jerry Gamblin created a cross-referencing tracker to map OpenClaw advisories between GitHub advisory data and CVE sources, including handling naming transitions such as Clawdbot, Moltbot, and OpenClaw. The effort aimed to help defenders follow advisories that might otherwise be missed in CVE-centric workflows.
MITRE’s TL-Root responded that DIBS is meant for individual vulnerabilities meeting CVE criteria, not bulk reservation of advisories for a popular supplier. The request was subsequently closed, and VulnCheck acknowledged that the mass-DIBS format was likely inappropriate, though other CVE assignment paths remained possible.
VulnCheck attempted to "call DIBS" on 170 OpenClaw advisories that lacked CVE IDs, citing customer interest and concern that the vulnerabilities could be weaponized. The move was intended to coordinate possible CVE assignment for the advisories.
As OpenClaw’s advisory count grew to roughly 255, only a subset had corresponding CVE IDs, creating visibility gaps for enterprises that rely on CVE-based scanners, SBOM tools, patch management, and compliance workflows. The episode highlighted how GHSA publication can outpace traditional CVE assignment processes.
Shortly after the OpenClaw project went viral and became one of GitHub’s most-starred repositories, it started issuing GitHub Security Advisories at an unusually high rate. Over the following few weeks, the project published hundreds of GHSAs, many without CVE IDs.
See what this changes for your reporting obligations and which controls it puts on the clock.
3 references tracked. Mallory keeps watching after this page renders.
gbhackers.com
Open sourcecybersecuritynews.com
Open sourcesocket.dev
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.