CVE-2026-41375
- EPSS 0.33%
- Veröffentlicht 28.04.2026 18:09:39
- Zuletzt bearbeitet 01.05.2026 15:47:49
OpenClaw before 2026.3.28 contains an authorization bypass vulnerability in the /phone arm and /phone disarm endpoints that fails to properly enforce operator.admin scope checks for external channels. Attackers can bypass authentication restrictions ...
CVE-2026-41376
- EPSS 0.16%
- Veröffentlicht 28.04.2026 18:09:39
- Zuletzt bearbeitet 01.05.2026 15:50:24
OpenClaw before 2026.3.31 contains an allowlist bypass vulnerability in Matrix thread root and reply context handling that fails to properly validate message senders. Attackers can fetch thread-root and reply context messages that should be filtered ...
CVE-2026-41374
- EPSS 0.47%
- Veröffentlicht 28.04.2026 18:09:38
- Zuletzt bearbeitet 30.04.2026 13:19:13
OpenClaw before 2026.3.31 performs Discord audio preflight transcription before validating member authorization, allowing unauthenticated attackers to consume resources. Remote attackers can trigger audio preflight processing without member allowlist...
CVE-2026-41373
- EPSS 0.13%
- Veröffentlicht 28.04.2026 18:09:36
- Zuletzt bearbeitet 01.05.2026 15:46:57
OpenClaw before 2026.3.31 contains an incomplete host-env-security-policy.json that fails to restrict compiler binary environment variables, allowing untrusted models to substitute CC, CXX, CARGO_BUILD_RUSTC, and CMAKE_C_COMPILER via environment over...
CVE-2026-41372
- EPSS 0.25%
- Veröffentlicht 27.04.2026 23:24:33
- Zuletzt bearbeitet 28.04.2026 18:43:52
OpenClaw before 2026.4.2 fails to normalize trailing-dot localhost hosts in remote CDP discovery responses, allowing bypass of loopback protections. Attackers can craft hostile discovery responses returning localhost. to retarget authenticated browse...
CVE-2026-41370
- EPSS 0.42%
- Veröffentlicht 27.04.2026 23:24:32
- Zuletzt bearbeitet 28.04.2026 18:41:09
OpenClaw before 2026.3.31 contains a path traversal vulnerability in ACP dispatch that allows attackers to read arbitrary files by manipulating inbound channel attachment paths. Remote attackers can bypass attachment-cache and root directory checks t...
CVE-2026-41371
- EPSS 0.26%
- Veröffentlicht 27.04.2026 23:24:32
- Zuletzt bearbeitet 28.04.2026 18:44:10
OpenClaw before 2026.3.28 contains a privilege escalation vulnerability in chat.send that allows write-scoped gateway callers to trigger admin-only session reset operations. Attackers can rotate target sessions, archive prior transcript state, and fo...
CVE-2026-41369
- EPSS 0.31%
- Veröffentlicht 27.04.2026 23:24:31
- Zuletzt bearbeitet 28.04.2026 18:44:40
OpenClaw before 2026.3.31 contains insufficient environment variable sanitization in host exec operations, failing to filter package, registry, Docker, compiler, and TLS override variables. Attackers can exploit this by injecting malicious environmen...
CVE-2026-41368
- EPSS 0.24%
- Veröffentlicht 27.04.2026 23:24:30
- Zuletzt bearbeitet 28.04.2026 18:44:57
OpenClaw before 2026.3.28 contains an environment variable disclosure vulnerability in the jq safe-bin policy that fails to block the $ENV filter. Attackers can bypass safe-bin restrictions by using $ENV in jq programs to access sensitive environment...
CVE-2026-41366
- EPSS 0.18%
- Veröffentlicht 27.04.2026 23:24:29
- Zuletzt bearbeitet 28.04.2026 18:45:27
OpenClaw before 2026.3.31 contains a local roots self-whitelisting vulnerability in appendLocalMediaParentRoots that allows model-initiated arbitrary host file read. Attackers can exploit improper media parent directory validation to exfiltrate crede...