CVE-2026-41361
- EPSS 0.2%
- Veröffentlicht 23.04.2026 22:16:43
- Zuletzt bearbeitet 29.04.2026 14:08:18
OpenClaw before 2026.3.28 contains an SSRF guard bypass vulnerability that fails to block four IPv6 special-use ranges. Attackers can exploit this by crafting URLs targeting internal or non-routable IPv6 addresses to bypass SSRF protections.
CVE-2026-41350
- EPSS 0.2%
- Veröffentlicht 23.04.2026 22:16:42
- Zuletzt bearbeitet 28.04.2026 18:56:39
OpenClaw before 2026.3.31 contains a session visibility bypass vulnerability where the session_status function fails to enforce configured tools.sessions.visibility restrictions for unsandboxed invocations. Attackers can invoke session_status without...
CVE-2026-41351
- EPSS 0.33%
- Veröffentlicht 23.04.2026 22:16:42
- Zuletzt bearbeitet 28.04.2026 18:56:43
OpenClaw before 2026.3.31 contains a replay detection bypass vulnerability in webhook signature handling that treats Base64 and Base64URL encoded signatures as distinct requests. Attackers can re-encode Telnyx webhook signatures to bypass replay dete...
CVE-2026-41352
- EPSS 0.54%
- Veröffentlicht 23.04.2026 22:16:42
- Zuletzt bearbeitet 28.04.2026 18:54:57
OpenClaw before 2026.3.31 contains a remote code execution vulnerability where a device-paired node can bypass the node scope gate authentication mechanism. Attackers with device pairing credentials can execute arbitrary node commands on the host sys...
CVE-2026-41353
- EPSS 0.34%
- Veröffentlicht 23.04.2026 22:16:42
- Zuletzt bearbeitet 01.05.2026 20:14:12
OpenClaw before 2026.3.22 contains an access control bypass vulnerability in the allowProfiles feature that allows attackers to circumvent profile restrictions through persistent profile mutation and runtime profile selection. Remote attackers can ex...
CVE-2026-41354
- EPSS 0.28%
- Veröffentlicht 23.04.2026 22:16:42
- Zuletzt bearbeitet 01.05.2026 20:17:23
OpenClaw before 2026.4.2 contains an insufficient scope vulnerability in Zalo webhook replay dedupe keys that allows legitimate events from different conversations or senders to collide. Attackers can exploit weak deduplication scoping to cause silen...
CVE-2026-41355
- EPSS 0.12%
- Veröffentlicht 23.04.2026 22:16:42
- Zuletzt bearbeitet 12.05.2026 02:16:12
OpenClaw before 2026.3.28 contains an arbitrary code execution vulnerability in mirror mode that converts untrusted sandbox files into workspace hooks. Attackers with mirror mode access can execute arbitrary code on the host during gateway startup by...
- EPSS 0.3%
- Veröffentlicht 23.04.2026 22:16:41
- Zuletzt bearbeitet 28.04.2026 18:56:28
OpenClaw before 2026.3.31 contains a credential exposure vulnerability in media download functionality that forwards Authorization headers across cross-origin redirects. Attackers can exploit this by crafting malicious cross-origin redirect chains to...
CVE-2026-41346
- EPSS 0.42%
- Veröffentlicht 23.04.2026 22:16:41
- Zuletzt bearbeitet 29.04.2026 14:44:10
OpenClaw 2026.2.26 before 2026.3.31 enforces pending pairing-request caps per channel file instead of per account, allowing attackers to exhaust the shared pending window. Remote attackers can submit pairing requests from other accounts to block new ...
CVE-2026-41347
- EPSS 0.11%
- Veröffentlicht 23.04.2026 22:16:41
- Zuletzt bearbeitet 28.04.2026 18:56:34
OpenClaw before 2026.3.31 lacks browser-origin validation in HTTP operator endpoints when operating in trusted-proxy mode, allowing cross-site request forgery attacks. Attackers can exploit this by sending malicious requests from a browser in trusted...