OpenClaw

OpenClaw

331 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.08%
  • Veröffentlicht 29.03.2026 12:44:25
  • Zuletzt bearbeitet 30.03.2026 17:03:28

OpenClaw before 2026.3.11 contains an exec allowlist bypass vulnerability where matchesExecAllowlistPattern improperly normalizes patterns with lowercasing and glob matching that overmatches on POSIX paths. Attackers can exploit the ? wildcard matchi...

  • EPSS 0.06%
  • Veröffentlicht 29.03.2026 12:44:24
  • Zuletzt bearbeitet 31.03.2026 17:57:06

OpenClaw before 2026.3.12 contains an authorization bypass vulnerability where Feishu reaction events with omitted chat_type are misclassified as p2p conversations instead of group chats. Attackers can exploit this misclassification to bypass groupAl...

  • EPSS 0.04%
  • Veröffentlicht 29.03.2026 12:44:24
  • Zuletzt bearbeitet 31.03.2026 17:55:59

OpenClaw before 2026.3.11 contains an authorization bypass vulnerability allowing authenticated operators with only operator.write permission to access admin-only browser profile management routes through browser.request. Attackers can create or modi...

  • EPSS 0.03%
  • Veröffentlicht 29.03.2026 12:44:23
  • Zuletzt bearbeitet 31.03.2026 18:01:13

OpenClaw before 2026.3.11 contains an authorization bypass vulnerability in Discord guild reaction ingestion that fails to enforce member users and roles allowlist checks. Non-allowlisted guild members can trigger reaction events accepted as trusted ...

  • EPSS 0.01%
  • Veröffentlicht 29.03.2026 12:44:22
  • Zuletzt bearbeitet 31.03.2026 18:08:30

OpenClaw before 2026.3.11 contains an authorization bypass vulnerability allowing write-scoped callers to reach admin-only session reset logic. Attackers with operator.write scope can issue agent requests containing /new or /reset slash commands to r...

Medienbericht
  • EPSS 0.24%
  • Veröffentlicht 29.03.2026 12:44:22
  • Zuletzt bearbeitet 31.03.2026 18:02:26

OpenClaw before 2026.3.11 contains a privilege escalation vulnerability in device.token.rotate that allows callers with operator.pairing scope to mint tokens with broader scopes by failing to constrain newly minted scopes to the caller's current scop...

  • EPSS 0.01%
  • Veröffentlicht 29.03.2026 12:44:21
  • Zuletzt bearbeitet 31.03.2026 18:09:19

OpenClaw before 2026.3.11 contains a session sandbox escape vulnerability in the session_status tool that allows sandboxed subagents to access parent or sibling session state. Attackers can supply arbitrary sessionKey values to read or modify session...

  • EPSS 0.01%
  • Veröffentlicht 29.03.2026 12:44:20
  • Zuletzt bearbeitet 31.03.2026 18:10:23

OpenClaw before 2026.3.11 contains a sandbox boundary bypass vulnerability allowing leaf subagents to access the subagents control surface and resolve against parent requester scope instead of their own session tree. A low-privilege sandboxed leaf wo...

  • EPSS 0.05%
  • Veröffentlicht 29.03.2026 12:44:19
  • Zuletzt bearbeitet 31.03.2026 18:11:06

OpenClaw before 2026.3.12 contains an insufficient access control vulnerability in the /config and /debug command handlers that allows command-authorized non-owners to access owner-only surfaces. Attackers with command authorization can read or modif...

Exploit
  • EPSS 0.06%
  • Veröffentlicht 26.03.2026 16:36:00
  • Zuletzt bearbeitet 31.03.2026 21:40:05

OpenClaw through 2026.3.23 (fixed in commit 4797bbc) contains a path traversal vulnerability in media parsing that allows attackers to read arbitrary files by bypassing path validation in the isLikelyLocalPath() and isValidMedia() functions. Attacker...