CVE-2026-53827
- EPSS 0.25%
- Veröffentlicht 12.06.2026 22:16:54
- Zuletzt bearbeitet 23.07.2026 09:10:00
OpenClaw before 2026.5.2 contains a credential exposure vulnerability in message.action forwarding that allows model-controlled metadata to forward action payloads with Gateway credentials to attacker-supplied loopback URLs. Remote attackers can inte...
CVE-2026-53828
- EPSS 0.27%
- Veröffentlicht 12.06.2026 22:16:54
- Zuletzt bearbeitet 23.07.2026 09:10:00
OpenClaw before 2026.5.6 contains an authorization bypass vulnerability in native command handling that allows authenticated senders to execute owner-only commands without proper policy enforcement. Attackers can trigger native command handling to by...
CVE-2026-53829
- EPSS 0.23%
- Veröffentlicht 12.06.2026 22:16:54
- Zuletzt bearbeitet 23.07.2026 09:10:00
OpenClaw before 2026.5.18 contains an approval display truncation vulnerability allowing authenticated users to hide command suffixes from approvers. Attackers can submit oversized exec commands with benign prefixes and malicious suffixes to execute ...
CVE-2026-53830
- EPSS 0.21%
- Veröffentlicht 12.06.2026 22:16:54
- Zuletzt bearbeitet 23.07.2026 09:10:00
OpenClaw before 2026.4.22 contains a webhook secret revocation bypass vulnerability allowing callers with old Slack and Zalo webhook secrets to remain active after secrets.reload. Attackers can exploit the stale-secret window to deliver webhook event...
CVE-2026-53831
- EPSS 0.2%
- Veröffentlicht 12.06.2026 22:16:54
- Zuletzt bearbeitet 23.07.2026 09:10:00
OpenClaw before 2026.5.18 contains a policy enforcement vulnerability in system.run safe-bin allowlist validation that allows shell expansion to modify command interpretation on POSIX nodes. Authenticated operators can exploit shell metacharacters in...
CVE-2026-53832
- EPSS 0.1%
- Veröffentlicht 12.06.2026 22:16:54
- Zuletzt bearbeitet 23.07.2026 09:10:00
OpenClaw before 2026.5.18 contains an identity header validation vulnerability allowing local same-host callers to forge trusted-proxy identity headers. Attackers with access to the proxy-facing Gateway port can supply forged identity headers to assu...
CVE-2026-53833
- EPSS 0.18%
- Veröffentlicht 12.06.2026 22:16:54
- Zuletzt bearbeitet 08.10.2026 16:17:20
OpenClaw before 2026.4.29 contains an authorization bypass vulnerability in the QQBot streaming command that allows authenticated senders to mutate configuration without explicit allowFrom restrictions. Attackers can modify QQBot streaming configurat...
CVE-2026-53820
- EPSS 0.09%
- Veröffentlicht 12.06.2026 22:16:53
- Zuletzt bearbeitet 23.07.2026 09:10:00
OpenClaw before 2026.5.12 contains an exec denylist bypass vulnerability in the bundle MCP loopback session-spawn path that allows authenticated callers to bypass intended command restrictions. Attackers can reach the affected bundled MCP session-spa...
CVE-2026-53821
- EPSS 0.29%
- Veröffentlicht 12.06.2026 22:16:53
- Zuletzt bearbeitet 23.07.2026 09:10:00
OpenClaw before 2026.5.18 accepts WebSocket client-declared operator scopes before binding to server-approved pairing or trusted-proxy authorization baseline. Unpaired or restricted trusted-proxy Control UI clients can obtain cached operator.admin au...
CVE-2026-53822
- EPSS 0.98%
- Veröffentlicht 12.06.2026 22:16:53
- Zuletzt bearbeitet 23.07.2026 09:10:00
OpenClaw before 2026.5.18 contains a command injection vulnerability where shell wrapper argv could change between approval and execution. Attackers can rebuild command arguments after allowlist approval to execute unapproved command shapes, potentia...