OpenClaw

OpenClaw

666 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.25%
  • Veröffentlicht 29.05.2026 16:16:26
  • Zuletzt bearbeitet 21.07.2026 15:10:00

OpenClaw before 2026.5.18 contains a scope bypass vulnerability in the Gateway chat.send route that allows scoped clients to execute privileged commands. Attackers with operator.write scope can deliver commands through inherited external routes to by...

  • EPSS 0.24%
  • Veröffentlicht 29.05.2026 16:16:25
  • Zuletzt bearbeitet 21.07.2026 15:10:00

OpenClaw before 2026.5.4 contains an authorization bypass vulnerability in the bundled device-pair plugin that allows non-owner authorized chat senders to issue device-pairing bootstrap codes without proper scope validation. Attackers with chat comma...

  • EPSS 0.17%
  • Veröffentlicht 29.05.2026 16:16:25
  • Zuletzt bearbeitet 21.07.2026 15:10:00

OpenClaw before 2026.5.12 contains a privilege escalation vulnerability in Slack plugin approvals that allows exec-authorized users to resolve plugin approvals through the exec approver gate. Attackers with limited exec approval permissions can bypas...

  • EPSS 0.15%
  • Veröffentlicht 29.05.2026 16:16:25
  • Zuletzt bearbeitet 21.07.2026 15:10:00

OpenClaw before 2026.4.29 contains a policy bypass vulnerability in QQBot admin commands that allows authenticated senders to skip DM-only and allowFrom policy checks. Attackers can route admin commands from unauthorized senders or contexts to execut...

Exploit
  • EPSS 0.66%
  • Veröffentlicht 11.05.2026 18:16:44
  • Zuletzt bearbeitet 16.05.2026 03:06:20

A vulnerability was detected in OpenClaw up to 2026.1.24. The impacted element is the function handleBlueBubblesWebhookRequest of the file extensions/bluebubbles/src/monitor.ts of the component bluebubbles Webhook. Performing a manipulation results i...

  • EPSS 0.25%
  • Veröffentlicht 11.05.2026 18:16:40
  • Zuletzt bearbeitet 13.05.2026 14:12:59

OpenClaw before 2026.4.20 contains a server-side request forgery vulnerability in browser CDP profile creation that skips strict-mode SSRF policy checks. Attackers can create stored profiles pointing to private-network or metadata endpoints that bypa...

  • EPSS 0.22%
  • Veröffentlicht 11.05.2026 18:16:40
  • Zuletzt bearbeitet 13.05.2026 14:13:10

OpenClaw before 2026.4.20 contains a guard bypass vulnerability in the agent-facing gateway config.patch and config.apply endpoints that fails to protect operator-trusted settings including sandbox policy, plugin enablement, gateway auth/TLS, hook ro...

  • EPSS 0.28%
  • Veröffentlicht 11.05.2026 18:16:40
  • Zuletzt bearbeitet 13.05.2026 14:13:21

OpenClaw before 2026.4.20 contains a hook session-key bypass vulnerability that allows attackers to circumvent the hooks.allowRequestSessionKey opt-in restriction. Attackers can render externally influenced session keys through templated hook mapping...

  • EPSS 0.11%
  • Veröffentlicht 11.05.2026 18:16:40
  • Zuletzt bearbeitet 13.05.2026 14:13:30

OpenClaw before 2026.4.22 allows workspace dotenv files to override connector endpoint hosts for Matrix, Mattermost, IRC, and Synology connectors. Attackers with workspace access can redirect runtime traffic to malicious endpoints by setting endpoint...

  • EPSS 0.14%
  • Veröffentlicht 11.05.2026 18:16:40
  • Zuletzt bearbeitet 13.05.2026 14:13:43

OpenClaw before 2026.4.23 contains an arbitrary code execution vulnerability in the bundled plugin setup resolver that loads setup-api.js from process.cwd() during provider setup metadata resolution. Attackers can execute arbitrary JavaScript under t...