CVE-2026-53843
- EPSS 0.28%
- Veröffentlicht 16.06.2026 18:04:55
- Zuletzt bearbeitet 16.06.2026 20:42:46
OpenClaw before 2026.5.26 contains an authorization bypass vulnerability where a surviving pairing-scoped device session can re-establish node token authority after revocation. Attackers with a paired device can regain WebSocket node-level access wit...
CVE-2026-53841
- EPSS 0.19%
- Veröffentlicht 16.06.2026 18:04:54
- Zuletzt bearbeitet 16.06.2026 20:42:46
OpenClaw before 2026.5.12 contains a cross-site scripting vulnerability in exported session HTML that preserves unsafe javascript: and data: links in generated content. Attackers can execute browser-side scripts if a trusted operator opens the export...
CVE-2026-53842
- EPSS 0.13%
- Veröffentlicht 16.06.2026 18:04:54
- Zuletzt bearbeitet 16.06.2026 20:42:46
OpenClaw before 2026.5.2 contains an environment variable injection vulnerability allowing workspace .env files to influence Python runtime selection through CLOUDSDK_PYTHON during Gmail setup gcloud execution. Attackers with repository access can ma...
CVE-2026-53840
- EPSS 0.22%
- Veröffentlicht 16.06.2026 18:04:53
- Zuletzt bearbeitet 16.06.2026 20:42:46
OpenClaw before 2026.5.12 contains an information disclosure vulnerability in streamable-http MCP servers that forwards operator-configured custom headers during cross-origin redirects. Attackers controlling or compromising an MCP endpoint can redire...
CVE-2026-53834
- EPSS 0.2%
- Veröffentlicht 12.06.2026 22:16:55
- Zuletzt bearbeitet 20.07.2026 20:10:00
OpenClaw before 2026.4.27 contains an authorization bypass vulnerability in QQBot pre-dispatch slash commands that allows authenticated senders to skip allowFrom policy checks. Attackers can invoke slash commands before configured access control poli...
CVE-2026-53835
- EPSS 0.17%
- Veröffentlicht 12.06.2026 22:16:55
- Zuletzt bearbeitet 23.07.2026 09:10:00
OpenClaw before 2026.5.6 contains a configuration enforcement bypass vulnerability in Feishu dynamic-agent bindings that allows authenticated senders to create or update bindings without honoring configured config-write controls. Attackers can exploi...
CVE-2026-53836
- EPSS 0.45%
- Veröffentlicht 12.06.2026 22:16:55
- Zuletzt bearbeitet 23.07.2026 09:10:00
OpenClaw before 2026.5.12 contains an allowlist bypass vulnerability in PowerShell encoded-command handling that allows attackers to execute encoded commands using abbreviated flag aliases not recognized by the allowlist parser. Remote authenticated ...
CVE-2026-53837
- EPSS 0.19%
- Veröffentlicht 12.06.2026 22:16:55
- Zuletzt bearbeitet 23.07.2026 09:10:00
OpenClaw before 2026.5.6 contains an improper access control vulnerability in Mattermost event handlers that fails to validate channel type metadata. Attackers can bypass intended DM policy decisions by sending crafted Mattermost events missing chann...
CVE-2026-53838
- EPSS 0.23%
- Veröffentlicht 12.06.2026 22:16:55
- Zuletzt bearbeitet 23.07.2026 09:10:00
OpenClaw before 2026.5.27 contains a state mutation vulnerability in node pairing reconnection that allows paired nodes to confuse approval scope decisions. Attackers can exploit reconnection logic to restore or present broader node authority than in...
CVE-2026-53839
- EPSS 0.27%
- Veröffentlicht 12.06.2026 22:16:55
- Zuletzt bearbeitet 08.10.2026 16:17:20
OpenClaw before 2026.5.7 contains a hostname validation vulnerability in retry endpoint checks that allows matching hostname prefixes instead of exact hostnames. Attackers can exploit this by crafting a hostname prefix resembling a trusted host to se...