OpenClaw

OpenClaw

666 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.29%
  • Veröffentlicht 11.05.2026 18:16:40
  • Zuletzt bearbeitet 13.05.2026 14:14:00

OpenClaw before 2026.4.23 caches resolved webhook route secrets backed by SecretRef values, allowing stale secrets to remain valid after rotation and reload. Attackers with previously valid webhook route secrets can continue authenticating requests a...

  • EPSS 0.49%
  • Veröffentlicht 11.05.2026 18:16:40
  • Zuletzt bearbeitet 13.05.2026 14:14:28

OpenClaw before 2026.4.23 contains an improper access control vulnerability in the gateway tool's config.apply and config.patch operations that allows compromised models to write unsafe configuration changes by bypassing an incomplete denylist protec...

  • EPSS 0.27%
  • Veröffentlicht 11.05.2026 18:16:39
  • Zuletzt bearbeitet 13.05.2026 14:11:07

OpenClaw before 2026.4.20 contains a message classification vulnerability in Feishu card-action callbacks that misclassifies direct messages as group conversations. Attackers can bypass dmPolicy enforcement by triggering card-action flows in direct m...

  • EPSS 0.32%
  • Veröffentlicht 11.05.2026 18:16:39
  • Zuletzt bearbeitet 13.05.2026 14:11:21

OpenClaw before 2026.4.22 contains an authentication bypass vulnerability in the Control UI bootstrap config endpoint that allows unauthenticated attackers to read sensitive configuration fields. Attackers can access the bootstrap config route withou...

  • EPSS 0.14%
  • Veröffentlicht 11.05.2026 18:16:39
  • Zuletzt bearbeitet 13.05.2026 14:11:44

OpenClaw before 2026.4.20 contains an improper environment variable validation vulnerability in MCP stdio server configuration that allows attackers to execute arbitrary code. Malicious workspace configurations can pass dangerous startup variables li...

  • EPSS 0.31%
  • Veröffentlicht 11.05.2026 18:16:39
  • Zuletzt bearbeitet 13.05.2026 14:12:01

OpenClaw before 2026.4.15 contains an arbitrary local file read vulnerability in the webchat audio embedding helper that fails to apply local media root containment checks. Attackers can influence agent or tool-produced ReplyPayload.mediaUrl paramete...

  • EPSS 0.22%
  • Veröffentlicht 11.05.2026 18:16:39
  • Zuletzt bearbeitet 13.05.2026 14:12:19

OpenClaw before 2026.4.22 contains a security envelope constraint bypass vulnerability allowing restricted subagents to spawn ACP child sessions that fail to inherit depth, child-count limits, control scope, or target-agent restrictions. Attackers ca...

  • EPSS 0.71%
  • Veröffentlicht 11.05.2026 18:16:39
  • Zuletzt bearbeitet 13.05.2026 14:12:32

OpenClaw before 2026.4.20 contains a tool policy bypass vulnerability allowing bundled MCP and LSP tools to circumvent configured tool restrictions. Attackers with local agent access can append restricted tools to the effective tool set after policy ...

  • EPSS 0.15%
  • Veröffentlicht 11.05.2026 18:16:39
  • Zuletzt bearbeitet 13.05.2026 14:12:44

OpenClaw before 2026.4.20 fails to properly preserve untrusted labels for isolated cron awareness events, allowing webhook-triggered cron agent output to be recorded as trusted system events. Attackers can exploit this trust-labeling issue to strengt...

  • EPSS 0.24%
  • Veröffentlicht 11.05.2026 18:16:38
  • Zuletzt bearbeitet 13.05.2026 14:10:51

OpenClaw before 2026.4.21 contains an authorization bypass vulnerability in command-auth.ts that allows non-owner senders to execute owner-enforced slash commands when wildcard inbound senders are configured without explicit owner allowFrom settings....