CVE-2026-33575
- EPSS 0.04%
- Veröffentlicht 29.03.2026 12:44:32
- Zuletzt bearbeitet 30.03.2026 15:51:26
OpenClaw before 2026.3.12 embeds long-lived shared gateway credentials directly in pairing setup codes generated by /pair endpoint and OpenClaw qr command. Attackers with access to leaked setup codes from chat history, logs, or screenshots can recove...
CVE-2026-33573
- EPSS 0.05%
- Veröffentlicht 29.03.2026 12:44:31
- Zuletzt bearbeitet 30.03.2026 15:51:37
OpenClaw before 2026.3.11 contains an authorization bypass vulnerability in the gateway agent RPC that allows authenticated operators with operator.write permission to override workspace boundaries by supplying attacker-controlled spawnedBy and works...
CVE-2026-33574
- EPSS 0.01%
- Veröffentlicht 29.03.2026 12:44:31
- Zuletzt bearbeitet 31.03.2026 17:12:54
OpenClaw before 2026.3.8 contains a path traversal vulnerability in the skills download installer that validates the tools root lexically but reuses the mutable path during archive download and copy operations. A local attacker can rebind the tools-r...
CVE-2026-33572
- EPSS 0.01%
- Veröffentlicht 29.03.2026 12:44:30
- Zuletzt bearbeitet 31.03.2026 17:37:29
OpenClaw before 2026.2.17 creates session transcript JSONL files with overly broad default permissions, allowing local users to read transcript contents. Attackers with local access can read transcript files to extract sensitive information including...
CVE-2026-32987
- EPSS 0.05%
- Veröffentlicht 29.03.2026 12:44:29
- Zuletzt bearbeitet 31.03.2026 17:53:28
OpenClaw before 2026.3.13 allows bootstrap setup codes to be replayed during device pairing verification in src/infra/device-bootstrap.ts. Attackers can verify a valid bootstrap code multiple times before approval to escalate pending pairing scopes, ...
CVE-2026-32979
- EPSS 0.04%
- Veröffentlicht 29.03.2026 12:44:28
- Zuletzt bearbeitet 30.03.2026 15:56:55
OpenClaw before 2026.3.11 contains an approval integrity vulnerability allowing attackers to execute rewritten local code by modifying scripts between approval and execution when exact file binding cannot occur. Remote attackers can change approved l...
CVE-2026-32980
- EPSS 0.09%
- Veröffentlicht 29.03.2026 12:44:28
- Zuletzt bearbeitet 31.03.2026 17:54:44
OpenClaw before 2026.3.13 reads and buffers Telegram webhook request bodies before validating the x-telegram-bot-api-secret-token header, allowing unauthenticated attackers to exhaust server resources. Attackers can send POST requests to the webhook ...
CVE-2026-32978
- EPSS 0.04%
- Veröffentlicht 29.03.2026 12:44:27
- Zuletzt bearbeitet 30.03.2026 17:15:43
OpenClaw before 2026.3.11 contains an approval integrity vulnerability where system.run approvals fail to bind mutable file operands for certain script runners like tsx and jiti. Attackers can obtain approval for benign script commands, rewrite refer...
CVE-2026-32974
- EPSS 0.06%
- Veröffentlicht 29.03.2026 12:44:26
- Zuletzt bearbeitet 30.03.2026 17:13:29
OpenClaw before 2026.3.12 contains an authentication bypass vulnerability in Feishu webhook mode when only verificationToken is configured without encryptKey, allowing acceptance of forged events. Unauthenticated network attackers can inject forged F...
CVE-2026-32975
- EPSS 0.08%
- Veröffentlicht 29.03.2026 12:44:26
- Zuletzt bearbeitet 30.03.2026 17:13:46
OpenClaw before 2026.3.12 contains a weak authorization vulnerability in Zalouser allowlist mode that matches mutable group display names instead of stable group identifiers. Attackers can create groups with identical names to allowlisted groups to b...