CVE-2026-102807
- EPSS 0.23%
- Veröffentlicht 29.09.2026 17:22:40
- Zuletzt bearbeitet 29.09.2026 21:33:56
OpenClaw before 2026.9.4 contains an incorrect authorization vulnerability in the mcp.app.view method that allows read-scoped operators to execute MCP App tools requiring operator.write scope. Attackers with operator.read tokens can obtain a standalo...
CVE-2026-102806
- EPSS 0.25%
- Veröffentlicht 29.09.2026 17:22:39
- Zuletzt bearbeitet 29.09.2026 21:33:56
OpenClaw before 2026.9.5 contains an incorrect authorization vulnerability in the Gateway's local media root allowlist that breaks filesystem isolation between sandboxed sessions. Sandboxed sessions or untrusted content can cause the Gateway to read ...
CVE-2026-100598
- EPSS 0.11%
- Veröffentlicht 26.09.2026 02:19:18
- Zuletzt bearbeitet 28.09.2026 20:17:07
OpenClaw (npm package openclaw) before 2026.7.1 incorrectly binds Signal approval reactions. In affected versions, a reaction intended to resolve a structured approval request could instead attach to ordinary outbound text when unrelated outbound mes...
CVE-2026-100599
- EPSS 0.31%
- Veröffentlicht 26.09.2026 02:19:18
- Zuletzt bearbeitet 28.09.2026 17:17:42
OpenClaw versions 2026.5.1 through 2026.7.0 fail to apply the configured exec approval path to Google Meet node commands. The googlemeet.chrome command accepts caller-supplied audio command arrays and executes them on a paired node without going thro...
CVE-2026-100597
- EPSS 0.08%
- Veröffentlicht 26.09.2026 02:19:17
- Zuletzt bearbeitet 30.09.2026 01:16:35
OpenClaw (npm package 'openclaw') before 2026.7.1 is vulnerable to a time-of-check time-of-use race condition in OpenShell local mirror filesystem mutation operations. The remove, mkdir, and rename operations could act on a different filesystem targe...
CVE-2026-100595
- EPSS 0.24%
- Veröffentlicht 26.09.2026 02:19:16
- Zuletzt bearbeitet 28.09.2026 18:17:14
OpenClaw versions before 2026.7.1 contain an authorization bypass vulnerability in the diagnostics export command that allows non-owner channel senders to access owner-only host diagnostic bundles. Attackers can request and receive diagnostic details...
CVE-2026-100596
- EPSS 0.25%
- Veröffentlicht 26.09.2026 02:19:16
- Zuletzt bearbeitet 05.10.2026 15:17:14
OpenClaw versions before 2026.7.1 fail to properly authorize non-owner users executing MCP configuration changes through /mcp set and /mcp unset commands. Attackers can persist arbitrary stdio MCP commands that execute with OpenClaw process privilege...
CVE-2026-100594
- EPSS 0.24%
- Veröffentlicht 26.09.2026 02:19:15
- Zuletzt bearbeitet 28.09.2026 20:17:07
OpenClaw versions before 2026.7.1 contain an authorization bypass vulnerability in the /export-trajectory endpoint that allows non-owner senders to request and receive owner-only trajectory bundles. Attackers can access prompts, model messages, tool ...
CVE-2026-100592
- EPSS 0.16%
- Veröffentlicht 26.09.2026 02:19:14
- Zuletzt bearbeitet 05.10.2026 15:17:13
OpenClaw is an agent gateway distributed via npm. In versions >= 2026.4.10 and < 2026.7.1, persistent memory dreaming mutations omit owner permission checks. An authorized but non-owner external-channel sender can issue the persistent '/dreaming on' ...
CVE-2026-100593
- EPSS 0.14%
- Veröffentlicht 26.09.2026 02:19:14
- Zuletzt bearbeitet 30.09.2026 01:16:35
OpenClaw (npm package `openclaw`) before 2026.7.1 does not enforce the documented owner-only requirement for persistent `/activation` policy changes in group channels. An authorized non-owner channel sender can change whether the agent requires menti...