OpenClaw

OpenClaw

666 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.2%
  • Veröffentlicht 13.07.2026 21:30:15
  • Zuletzt bearbeitet 15.07.2026 15:16:48

OpenClaw versions 2026.6.5 before 2026.6.9 contain a vulnerability in the plugin install wrappers that could skip the install policy (authorization) check. When the affected feature is enabled and reachable, a lower-trust caller or a configured input...

  • EPSS 0.22%
  • Veröffentlicht 13.07.2026 21:30:14
  • Zuletzt bearbeitet 14.07.2026 18:17:36

OpenClaw versions 2026.6.6 before 2026.6.9 contain an authorization bypass vulnerability in message mutation handling that allows lower-trust callers to perform actions requiring stronger authorization checks. Attackers can exploit misconfigured inpu...

  • EPSS 0.25%
  • Veröffentlicht 13.07.2026 21:30:14
  • Zuletzt bearbeitet 14.07.2026 18:17:30

OpenClaw versions 2026.6.6 before 2026.6.9 contain an authorization bypass vulnerability in Discord guild actions that allows lower-trust callers to perform actions requiring stronger authorization checks. Attackers can exploit misconfigured input pa...

  • EPSS 0.27%
  • Veröffentlicht 13.07.2026 21:30:13
  • Zuletzt bearbeitet 15.07.2026 11:16:33

OpenClaw versions before 2026.6.9 contain an authorization bypass vulnerability in the flock wrapper that allows lower-trust callers to execute or persist actions beyond their intended authorization. Attackers can leverage configured input paths to b...

  • EPSS 0.25%
  • Veröffentlicht 13.07.2026 21:30:12
  • Zuletzt bearbeitet 15.07.2026 05:17:24

OpenClaw versions before 2026.6.9 contain a symlink following vulnerability in the mirror sync feature that allows lower-trust callers to perform actions requiring stronger authorization. Attackers can exploit remote symlink parents to bypass policy ...

  • EPSS 0.2%
  • Veröffentlicht 13.07.2026 21:30:10
  • Zuletzt bearbeitet 14.07.2026 18:19:17

OpenClaw versions before 2026.6.8 contain an authorization bypass vulnerability in OpenAI-compatible HTTP model overrides that allows lower-trust callers to perform actions requiring stronger authorization checks. Attackers can exploit misconfigured ...

  • EPSS 0.13%
  • Veröffentlicht 08.07.2026 16:01:14
  • Zuletzt bearbeitet 09.07.2026 19:34:08

OpenClaw before 2026.5.28 contains a credential exposure vulnerability where workspace dotenv files can override provider credentials. Attackers with lower-trust access to configured input paths can expose sensitive data and credentials that should r...

  • EPSS 0.27%
  • Veröffentlicht 16.06.2026 18:05:11
  • Zuletzt bearbeitet 16.06.2026 20:42:46

OpenClaw before 2026.5.12 contains an allowlist bypass vulnerability in shell inline-command parsing that allows authenticated operators to execute unapproved commands. A command request using shell inline-command forms could route through a parser c...

  • EPSS 0.12%
  • Veröffentlicht 16.06.2026 18:05:10
  • Zuletzt bearbeitet 16.06.2026 20:42:46

OpenClaw before 2026.5.2 contains a path traversal vulnerability in maintenance task execution that allows workspace-derived service paths to influence trash command selection. Attackers can execute unintended local executables from operator-unintend...

  • EPSS 0.17%
  • Veröffentlicht 16.06.2026 18:05:09
  • Zuletzt bearbeitet 16.06.2026 20:42:46

OpenClaw before 2026.4.25 contains an input validation vulnerability in tool group policy callers that accept unvalidated group IDs. Attackers who can supply a group ID to the policy resolver could trigger incorrect group-policy decisions for tool in...