CVE-2026-62203
- EPSS 0.29%
- Veröffentlicht 17.07.2026 00:06:49
- Zuletzt bearbeitet 29.07.2026 19:16:50
OpenClaw versions before 2026.6.6 contain an environment variable filtering vulnerability in host exec that fails to properly sanitize rustup startup variables. Attackers with lower-trust caller access or configured input paths can execute or persist...
CVE-2026-62201
- EPSS 0.26%
- Veröffentlicht 17.07.2026 00:06:48
- Zuletzt bearbeitet 20.07.2026 17:01:14
OpenClaw versions before 2026.6.6 contain a network policy bypass vulnerability in the sandbox exec-server that allows lower-trust callers to reach internal network destinations blocked by OpenClaw policy. Attackers can send HTTP requests through the...
CVE-2026-62202
- EPSS 0.3%
- Veröffentlicht 17.07.2026 00:06:48
- Zuletzt bearbeitet 21.07.2026 19:59:58
OpenClaw versions 2026.6.1 before 2026.6.9 contain a privilege escalation vulnerability in isolated cron jobs that allows lower-trust callers to regain denied execution tools. Attackers can execute or persist actions beyond their intended authorizati...
CVE-2026-62200
- EPSS 0.29%
- Veröffentlicht 13.07.2026 21:30:20
- Zuletzt bearbeitet 15.07.2026 05:17:24
OpenClaw versions before 2026.6.6 contain a flaw in host exec environment filtering that could allow Git ext transport to be abused. When the affected feature is enabled and reachable, a lower-trust caller or configured input path could execute or pe...
CVE-2026-62199
- EPSS 0.29%
- Veröffentlicht 13.07.2026 21:30:19
- Zuletzt bearbeitet 15.07.2026 11:16:34
OpenClaw versions before 2026.6.6 contain a flaw in host exec environment filtering that can miss interpreter startup variables. When the affected feature is enabled and reachable, a lower-trust caller or configured input path can supply crafted envi...
CVE-2026-62197
- EPSS 0.21%
- Veröffentlicht 13.07.2026 21:30:18
- Zuletzt bearbeitet 14.07.2026 17:46:43
OpenClaw before 2026.6.6 contains a policy bypass vulnerability in browser CDP discovery that accepts blocked WebSocket URLs. Attackers with lower-trust access can reach network destinations that should have been blocked by OpenClaw policy when the a...
CVE-2026-62198
- EPSS 0.2%
- Veröffentlicht 13.07.2026 21:30:18
- Zuletzt bearbeitet 14.07.2026 17:46:31
OpenClaw versions 2026.5.28 before 2026.6.6 contain an authorization bypass vulnerability in native web search that allows lower-trust callers to perform actions requiring stronger policy checks. Attackers can exploit misconfigured input paths to byp...
CVE-2026-62196
- EPSS 0.24%
- Veröffentlicht 13.07.2026 21:30:17
- Zuletzt bearbeitet 05.09.2026 04:17:56
OpenClaw versions 2026.3.22 before 2026.6.6 contain an authorization bypass vulnerability where WhatsApp group IDs can satisfy elevated sender allowlists. Attackers with lower-trust access can perform actions requiring stronger authorization by lever...
CVE-2026-62194
- EPSS 0.25%
- Veröffentlicht 13.07.2026 21:30:16
- Zuletzt bearbeitet 15.07.2026 05:17:24
OpenClaw versions 2026.5.20 before 2026.6.9 contain a privilege escalation vulnerability in plugin install commands that allows lower-trust callers to execute or persist actions beyond their intended authorization. Attackers can exploit misconfigured...
CVE-2026-62195
- EPSS 0.24%
- Veröffentlicht 13.07.2026 21:30:16
- Zuletzt bearbeitet 15.07.2026 05:17:24
OpenClaw versions 2026.5.20 before 2026.6.6 contain an authorization bypass vulnerability in the MCP loopback feature that allows lower-trust callers to execute owner-only tools. Attackers can bypass authorization checks through configured input path...