CVE-2026-53813
- EPSS 0.12%
- Veröffentlicht 11.06.2026 20:08:11
- Zuletzt bearbeitet 12.06.2026 19:25:15
OpenClaw before 2026.4.25 contains a path traversal vulnerability in memory-core artifact loading where workspace state influences local package root resolution. Attackers with access to affected workspaces can load memory-core artifacts from uninten...
CVE-2026-53812
- EPSS 0.25%
- Veröffentlicht 11.06.2026 20:07:51
- Zuletzt bearbeitet 12.06.2026 19:25:23
OpenClaw before 2026.5.18 contains a server-side request forgery vulnerability in browser control that allows authenticated users to bypass private-network navigation checks through Playwright act interactions. Attackers can trigger navigation to pri...
CVE-2026-53811
- EPSS 0.31%
- Veröffentlicht 11.06.2026 20:07:29
- Zuletzt bearbeitet 12.06.2026 19:32:22
OpenClaw before 2026.5.7 contains a privilege escalation vulnerability in the Matrix allowFrom feature that allows authenticated accounts to match policy entries through mutable display name metadata. Attackers with the ability to change display name...
CVE-2026-53810
- EPSS 0.42%
- Veröffentlicht 11.06.2026 20:07:04
- Zuletzt bearbeitet 12.06.2026 19:32:38
OpenClaw before 2026.5.18 contains a code execution vulnerability where marketplace runtime extension metadata can redirect loading toward unscanned package payloads. Attackers with trusted operator access can manipulate extension metadata to load pl...
CVE-2026-53809
- EPSS 0.09%
- Veröffentlicht 11.06.2026 20:06:43
- Zuletzt bearbeitet 12.06.2026 19:32:51
OpenClaw before 2026.4.25 contains a policy bypass vulnerability in embedded runner policy that allows requests using provider aliases to compare against aliases instead of canonical provider identities. Attackers can exploit this confusion to select...
CVE-2026-53808
- EPSS 0.19%
- Veröffentlicht 11.06.2026 20:06:14
- Zuletzt bearbeitet 12.06.2026 19:32:56
OpenClaw before 2026.5.6 contains an approval policy bypass vulnerability in the Skill Workshop apply flow that allows agent tool calls to set apply: true despite approvalPolicy: pending configuration. Attackers can exploit this by reaching the affec...
CVE-2026-53807
- EPSS 0.31%
- Veröffentlicht 11.06.2026 20:05:48
- Zuletzt bearbeitet 12.06.2026 19:33:01
OpenClaw before 2026.5.6 contains an authorization bypass vulnerability in Telegram interactive callbacks that allows authenticated users to skip commands.allowFrom validation. Attackers can invoke affected callbacks to mark themselves as authorized ...
CVE-2026-53806
- EPSS 0.42%
- Veröffentlicht 11.06.2026 20:05:21
- Zuletzt bearbeitet 12.06.2026 19:33:05
OpenClaw before 2026.5.12 contains a shell option parsing vulnerability that allows combined POSIX shell flags to bypass exec revalidation checks. Attackers can exploit this by using combined shell options to execute inline shell content without inte...
- EPSS 0.21%
- Veröffentlicht 29.05.2026 16:16:26
- Zuletzt bearbeitet 21.07.2026 15:10:00
OpenClaw before 2026.5.18 contains an authorization bypass vulnerability in QQBot native approval buttons that fails to enforce configured approver identity. Non-approver users can click approval buttons to resolve pending exec or plugin approval req...
CVE-2026-35673
- EPSS 0.16%
- Veröffentlicht 29.05.2026 16:16:26
- Zuletzt bearbeitet 21.07.2026 15:10:00
OpenClaw before 2026.4.29 contains an SSRF policy bypass vulnerability in browser debug and export routes that allows reuse of already-open blocked tabs. Attackers with access to these routes can bypass private-network SSRF policies by reusing blocke...