OpenClaw

OpenClaw

559 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.28%
  • Veröffentlicht 28.04.2026 18:10:13
  • Zuletzt bearbeitet 30.04.2026 14:04:50

OpenClaw before 2026.4.8 contains a role bypass vulnerability in the device.token.rotate function that allows minting tokens for unapproved roles. Attackers can bypass device role-upgrade pairing to preserve or mint roles and scopes that had not unde...

  • EPSS 0.19%
  • Veröffentlicht 28.04.2026 18:10:12
  • Zuletzt bearbeitet 30.04.2026 14:04:08

OpenClaw before 2026.4.8 contains a session management vulnerability where existing WebSocket sessions survive shared gateway token rotation. Attackers can maintain unauthorized access to WebSocket connections after token rotation by exploiting the f...

  • EPSS 0.3%
  • Veröffentlicht 28.04.2026 18:10:11
  • Zuletzt bearbeitet 30.04.2026 14:04:43

OpenClaw before 2026.4.8 contains improper input validation in base64 decode paths that allocate memory before enforcing decoded-size limits. Attackers can exploit multiple code paths to cause memory exhaustion or denial of service through crafted ba...

  • EPSS 0.12%
  • Veröffentlicht 28.04.2026 18:10:10
  • Zuletzt bearbeitet 30.04.2026 14:04:15

OpenClaw before 2026.4.8 fails to remove git plumbing environment variables from the execution environment before host exec operations. Attackers can exploit this by setting GIT_DIR and related variables to redirect git operations and compromise repo...

  • EPSS 0.22%
  • Veröffentlicht 28.04.2026 18:10:10
  • Zuletzt bearbeitet 30.04.2026 14:04:22

OpenClaw before 2026.4.8 contains an authentication state management vulnerability where the resolvedAuth closure becomes stale after configuration reload. Newly accepted gateway connections continue using outdated resolved auth state, allowing attac...

  • EPSS 0.22%
  • Veröffentlicht 28.04.2026 18:10:09
  • Zuletzt bearbeitet 30.04.2026 14:02:57

OpenClaw before 2026.4.8 contains a server-side request forgery vulnerability in QQ Bot media download paths that bypass SSRF protection. Attackers can exploit unprotected media fetch endpoints to access internal resources and bypass allowlist polici...

  • EPSS 0.21%
  • Veröffentlicht 28.04.2026 18:10:08
  • Zuletzt bearbeitet 30.04.2026 14:15:24

OpenClaw before 2026.4.4 contains a race condition vulnerability in shared-secret authentication that allows concurrent asynchronous requests to bypass the per-key rate-limit budget. Attackers can exploit this by sending multiple simultaneous authent...

  • EPSS 0.33%
  • Veröffentlicht 28.04.2026 18:10:07
  • Zuletzt bearbeitet 30.04.2026 19:38:38

OpenClaw before 2026.4.8 contains a filesystem policy bypass vulnerability in docx upload processing that allows local file reads outside workspace boundaries. Attackers can exploit upload_file and upload_image endpoints to access files beyond the in...

  • EPSS 0.21%
  • Veröffentlicht 28.04.2026 18:10:07
  • Zuletzt bearbeitet 30.04.2026 19:38:47

OpenClaw before 2026.4.8 contains a server-side request forgery policy bypass vulnerability allowing attackers to trigger navigations bypassing normal SSRF checks. Attackers can exploit browser interactions to bypass SSRF protections and access restr...

  • EPSS 0.24%
  • Veröffentlicht 28.04.2026 18:10:06
  • Zuletzt bearbeitet 30.04.2026 19:38:28

OpenClaw before 2026.4.8 omits owner-only enforcement for cross-channel allowlist writes in the /allowlist endpoint. An authorized non-owner sender can bypass access controls to perform allowlist modifications against different channels, violating th...