OpenClaw

OpenClaw

600 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.31%
  • Veröffentlicht 11.06.2026 20:09:38
  • Zuletzt bearbeitet 12.06.2026 20:08:17

OpenClaw before 2026.5.22 contains a locality validation vulnerability in Control UI pairing that allows attackers with network access to spoof locality information and obtain durable admin-capable device tokens. Attackers can exploit insufficient lo...

  • EPSS 0.34%
  • Veröffentlicht 11.06.2026 20:09:15
  • Zuletzt bearbeitet 12.06.2026 20:08:26

OpenClaw before 2026.5.18 contains an insufficient provenance validation vulnerability in node event handling that allows paired nodes to forge exec lifecycle events without system.run authorization. A malicious or compromised paired node can send cr...

  • EPSS 0.22%
  • Veröffentlicht 11.06.2026 20:08:52
  • Zuletzt bearbeitet 12.06.2026 19:24:55

OpenClaw before 2026.5.19 contains an authorization bypass vulnerability in message read actions that skips channel allowlist checks. Lower-trust callers can request messages from channels not intended for them by exploiting insufficient validation i...

  • EPSS 0.28%
  • Veröffentlicht 11.06.2026 20:08:31
  • Zuletzt bearbeitet 12.06.2026 19:25:09

OpenClaw before 2026.5.20 contains a privilege escalation vulnerability where hook-triggered agent runs incorrectly receive owner-scoped MCP loopback authority instead of hook-appropriate scope. Attackers with a valid hook token can exploit the /hook...

  • EPSS 0.12%
  • Veröffentlicht 11.06.2026 20:08:11
  • Zuletzt bearbeitet 12.06.2026 19:25:15

OpenClaw before 2026.4.25 contains a path traversal vulnerability in memory-core artifact loading where workspace state influences local package root resolution. Attackers with access to affected workspaces can load memory-core artifacts from uninten...

  • EPSS 0.25%
  • Veröffentlicht 11.06.2026 20:07:51
  • Zuletzt bearbeitet 12.06.2026 19:25:23

OpenClaw before 2026.5.18 contains a server-side request forgery vulnerability in browser control that allows authenticated users to bypass private-network navigation checks through Playwright act interactions. Attackers can trigger navigation to pri...

  • EPSS 0.31%
  • Veröffentlicht 11.06.2026 20:07:29
  • Zuletzt bearbeitet 12.06.2026 19:32:22

OpenClaw before 2026.5.7 contains a privilege escalation vulnerability in the Matrix allowFrom feature that allows authenticated accounts to match policy entries through mutable display name metadata. Attackers with the ability to change display name...

  • EPSS 0.42%
  • Veröffentlicht 11.06.2026 20:07:04
  • Zuletzt bearbeitet 12.06.2026 19:32:38

OpenClaw before 2026.5.18 contains a code execution vulnerability where marketplace runtime extension metadata can redirect loading toward unscanned package payloads. Attackers with trusted operator access can manipulate extension metadata to load pl...

  • EPSS 0.09%
  • Veröffentlicht 11.06.2026 20:06:43
  • Zuletzt bearbeitet 12.06.2026 19:32:51

OpenClaw before 2026.4.25 contains a policy bypass vulnerability in embedded runner policy that allows requests using provider aliases to compare against aliases instead of canonical provider identities. Attackers can exploit this confusion to select...

  • EPSS 0.19%
  • Veröffentlicht 11.06.2026 20:06:14
  • Zuletzt bearbeitet 12.06.2026 19:32:56

OpenClaw before 2026.5.6 contains an approval policy bypass vulnerability in the Skill Workshop apply flow that allows agent tool calls to set apply: true despite approvalPolicy: pending configuration. Attackers can exploit this by reaching the affec...