OpenClaw

OpenClaw

666 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.21%
  • Veröffentlicht 12.06.2026 22:16:53
  • Zuletzt bearbeitet 23.07.2026 09:10:00

OpenClaw before 2026.5.3 contains a privilege escalation vulnerability in the allowFrom feature that binds to mutable Slack display names. Attackers with Slack account access can change display name metadata to match policy entries, potentially gaini...

  • EPSS 0.18%
  • Veröffentlicht 12.06.2026 22:16:53
  • Zuletzt bearbeitet 23.07.2026 09:10:00

OpenClaw before 2026.4.24 contains a token revocation vulnerability allowing callers with revoked slash tokens to continue executing commands during monitor refresh windows. Attackers can exploit stale token acceptance to invoke slash command behavio...

  • EPSS 0.38%
  • Veröffentlicht 12.06.2026 22:16:53
  • Zuletzt bearbeitet 23.07.2026 09:10:00

OpenClaw before 2026.4.7 contains an arbitrary file read vulnerability in the memory-wiki ingest feature that allows authenticated Gateway operators with operator.write scope to read local files outside intended ingest sources. Attackers with operato...

  • EPSS 0.19%
  • Veröffentlicht 12.06.2026 22:16:53
  • Zuletzt bearbeitet 23.07.2026 09:10:00

OpenClaw before 2026.4.26 contains an information disclosure vulnerability in sandboxed session spawning that exposes the real workspace path to child prompts. Attackers can exploit this by spawning child sessions from sandboxed parents to reveal hos...

  • EPSS 0.3%
  • Veröffentlicht 11.06.2026 20:10:24
  • Zuletzt bearbeitet 12.06.2026 20:08:46

OpenClaw before 2026.5.27 contains an arbitrary code execution vulnerability in skill install flows where workspace .env files can override the Homebrew executable selection. Attackers with access to trusted operator workspaces can execute unintended...

  • EPSS 0.1%
  • Veröffentlicht 11.06.2026 20:09:57
  • Zuletzt bearbeitet 12.06.2026 20:08:06

OpenClaw before 2026.4.24 contains an authorization bypass vulnerability in the MCP loopback feature that allows non-owner callers to skip owner-only tool policies and before-tool-call hooks. Attackers can invoke owner-only behavior through the affec...

  • EPSS 0.31%
  • Veröffentlicht 11.06.2026 20:09:38
  • Zuletzt bearbeitet 12.06.2026 20:08:17

OpenClaw before 2026.5.22 contains a locality validation vulnerability in Control UI pairing that allows attackers with network access to spoof locality information and obtain durable admin-capable device tokens. Attackers can exploit insufficient lo...

  • EPSS 0.34%
  • Veröffentlicht 11.06.2026 20:09:15
  • Zuletzt bearbeitet 12.06.2026 20:08:26

OpenClaw before 2026.5.18 contains an insufficient provenance validation vulnerability in node event handling that allows paired nodes to forge exec lifecycle events without system.run authorization. A malicious or compromised paired node can send cr...

  • EPSS 0.22%
  • Veröffentlicht 11.06.2026 20:08:52
  • Zuletzt bearbeitet 12.06.2026 19:24:55

OpenClaw before 2026.5.19 contains an authorization bypass vulnerability in message read actions that skips channel allowlist checks. Lower-trust callers can request messages from channels not intended for them by exploiting insufficient validation i...

  • EPSS 0.28%
  • Veröffentlicht 11.06.2026 20:08:31
  • Zuletzt bearbeitet 12.06.2026 19:25:09

OpenClaw before 2026.5.20 contains a privilege escalation vulnerability where hook-triggered agent runs incorrectly receive owner-scoped MCP loopback authority instead of hook-appropriate scope. Attackers with a valid hook token can exploit the /hook...