OpenClaw

OpenClaw

600 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.45%
  • Veröffentlicht 17.07.2026 00:07:06
  • Zuletzt bearbeitet 30.07.2026 14:49:36

OpenClaw before 2026.5.18 contain an authorization bypass vulnerability in exec allowlist glob matching that allows lower-trust callers to execute actions beyond intended authorization. Attackers can craft input paths that traverse the allowlist glob...

  • EPSS 0.23%
  • Veröffentlicht 17.07.2026 00:07:05
  • Zuletzt bearbeitet 21.07.2026 20:00:20

OpenClaw 2026.4.14 before 2026.5.26 contain a server-side request forgery vulnerability in browser snapshot routes that fail to validate post-navigation destinations. Attackers with lower-trust access can bypass OpenClaw policy checks to reach networ...

  • EPSS 0.25%
  • Veröffentlicht 17.07.2026 00:07:05
  • Zuletzt bearbeitet 29.07.2026 19:16:50

OpenClaw before 2026.6.5 contain an authorization bypass vulnerability in node exec approvals that allows lower-trust callers to execute actions beyond their intended authorization by using different gateway and node environments. Attackers can explo...

  • EPSS 0.24%
  • Veröffentlicht 17.07.2026 00:07:04
  • Zuletzt bearbeitet 21.07.2026 19:57:34

OpenClaw 2026.3.28 before 2026.5.19 contain an authorization bypass vulnerability in the browser act route that fails to properly validate current-tab URL checks. Attackers with lower-trust access or configured input paths can perform actions requiri...

  • EPSS 0.15%
  • Veröffentlicht 17.07.2026 00:07:03
  • Zuletzt bearbeitet 21.07.2026 02:16:23

OpenClaw versions before 2026.5.18 contain an authorization bypass vulnerability in skill command dispatch that allows lower-trust callers to execute or persist actions beyond their intended authorization. Attackers can bypass tool policy restriction...

  • EPSS 0.25%
  • Veröffentlicht 17.07.2026 00:07:02
  • Zuletzt bearbeitet 20.07.2026 16:57:40

OpenClaw before 2026.5.18 contain an authorization bypass vulnerability in the device-pair approval feature that allows lower-trust callers to execute actions beyond their intended authorization. Attackers can exploit misconfigured input paths to exe...

  • EPSS 0.12%
  • Veröffentlicht 17.07.2026 00:07:01
  • Zuletzt bearbeitet 29.07.2026 19:16:50

OpenClaw before 2026.5.22 contain a vulnerability in setup-mode discovery that allows loading of untrusted workspace plugins. Attackers with lower-trust caller access or control over configured input paths can execute or persist actions beyond their ...

  • EPSS 0.29%
  • Veröffentlicht 17.07.2026 00:07:00
  • Zuletzt bearbeitet 21.07.2026 20:01:26

OpenClaw 2026.2.25 before 2026.5.26 allow a lower-trust caller or configured input path to bypass non-browser rate limits on WebSocket authentication attempts. When the affected feature is enabled and reachable by lower-trust input, this can consume ...

  • EPSS 0.14%
  • Veröffentlicht 17.07.2026 00:07:00
  • Zuletzt bearbeitet 21.07.2026 20:00:31

OpenClaw 2026.5.12 before 2026.5.26 contain an incorrect authorization vulnerability in the ClickClack allowFrom feature. When the affected feature is enabled and reachable, a lower-trust caller or configured input path could execute or persist actio...

  • EPSS 0.17%
  • Veröffentlicht 17.07.2026 00:06:59
  • Zuletzt bearbeitet 21.07.2026 19:58:07

OpenClaw 2026.2.12 before 2026.5.26 contain an authorization bypass vulnerability in the hooks allowedAgentIds validation. A lower-trust caller or configured input path can bypass agent ID restrictions by submitting blank agent IDs, allowing actions ...