OpenClaw

OpenClaw

600 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.22%
  • Veröffentlicht 05.05.2026 12:16:20
  • Zuletzt bearbeitet 07.05.2026 01:52:51

OpenClaw before 2026.4.10 contains a path traversal vulnerability in the screen_record tool's outPath parameter that bypasses workspace-only filesystem guards. Attackers can exploit this by specifying an outPath outside the workspace boundary to writ...

  • EPSS 0.21%
  • Veröffentlicht 05.05.2026 12:16:20
  • Zuletzt bearbeitet 07.05.2026 01:52:39

OpenClaw versions 2026.4.5 before 2026.4.10 contain a privilege escalation vulnerability allowing write-scoped operators to modify persistent memory dreaming settings. Attackers with write-scoped gateway access can toggle admin-class configuration mu...

  • EPSS 0.38%
  • Veröffentlicht 05.05.2026 12:16:20
  • Zuletzt bearbeitet 07.05.2026 01:52:25

OpenClaw before 2026.4.9 contains an authentication bypass vulnerability allowing untrusted workspace plugins to be auto-enabled during non-interactive onboarding when provider auth choices are shadowed. Attackers can exploit this by crafting malicio...

  • EPSS 0.32%
  • Veröffentlicht 05.05.2026 12:16:20
  • Zuletzt bearbeitet 07.05.2026 16:03:14

OpenClaw versions 2026.3.22 before 2026.4.5 contain a symlink traversal vulnerability in remote marketplace repository path handling that allows attackers to escape the expected repository root. Attackers can exploit this by providing crafted symlink...

  • EPSS 0.39%
  • Veröffentlicht 05.05.2026 12:16:20
  • Zuletzt bearbeitet 07.05.2026 16:03:35

OpenClaw before 2026.4.10 contains a plugin trust bypass vulnerability that allows channel setup catalog lookups to resolve workspace plugin shadows before bundled channel plugins. Attackers can exploit this by crafting malicious workspace plugins th...

  • EPSS 0.08%
  • Veröffentlicht 05.05.2026 12:16:19
  • Zuletzt bearbeitet 07.05.2026 01:54:29

OpenClaw before 2026.4.10 contains a time-of-check-time-of-use vulnerability in the validateScriptFileForShellBleed function that allows local attackers to bypass workspace boundary checks. An attacker with workspace write access can race-condition s...

  • EPSS 0.36%
  • Veröffentlicht 05.05.2026 12:16:19
  • Zuletzt bearbeitet 07.05.2026 15:57:29

OpenClaw versions 2026.2.23 before 2026.4.12 contain a weakened exec approval binding vulnerability in busybox and toybox applet execution that allows attackers to obscure which applet would actually run. Attackers can exploit opaque multi-call binar...

  • EPSS 0.2%
  • Veröffentlicht 05.05.2026 12:16:19
  • Zuletzt bearbeitet 07.05.2026 15:59:05

OpenClaw before 2026.4.9 contains an environment variable injection vulnerability allowing malicious workspace .env files to set runtime-control variables. Attackers can inject variables affecting update sources, gateway URLs, ClawHub resolution, and...

  • EPSS 0.26%
  • Veröffentlicht 05.05.2026 12:16:19
  • Zuletzt bearbeitet 07.05.2026 01:54:05

OpenClaw versions 2026.4.7 before 2026.4.10 fail to normalize Discord event cover image parameters in sandbox media processing. Attackers can bypass media normalization to inject host-local media references into channel action paths expecting normali...

  • EPSS 0.37%
  • Veröffentlicht 05.05.2026 12:16:19
  • Zuletzt bearbeitet 07.05.2026 01:53:48

OpenClaw before 2026.4.10 contains an arbitrary file read vulnerability in QQBot media tags that allows attackers to reference host-local paths outside the intended media storage boundary. Attackers can craft malicious reply text containing media tag...