OpenClaw

OpenClaw

666 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.24%
  • Veröffentlicht 05.05.2026 12:16:18
  • Zuletzt bearbeitet 07.05.2026 01:59:57

OpenClaw versions 2026.4.9 before 2026.4.10 contain a sender policy bypass vulnerability in the outbound host-media attachment read helper that allows unauthorized local file disclosure. Attackers with denied read access via toolsBySender or group po...

  • EPSS 0.24%
  • Veröffentlicht 05.05.2026 12:16:18
  • Zuletzt bearbeitet 07.05.2026 01:59:18

OpenClaw before 2026.4.10 contains a server-side request forgery policy bypass vulnerability in the browser tabs action select and close routes. Attackers can bypass configured browser SSRF policy protections by exploiting the /tabs/action endpoint t...

  • EPSS 0.25%
  • Veröffentlicht 05.05.2026 12:16:18
  • Zuletzt bearbeitet 07.05.2026 01:57:11

OpenClaw before 2026.4.12 contains a server-side request forgery vulnerability in QQBot reply media URL handling that allows attackers to fetch arbitrary content. Attackers can exploit this by providing malicious media URLs that trigger SSRF requests...

  • EPSS 0.28%
  • Veröffentlicht 05.05.2026 12:16:18
  • Zuletzt bearbeitet 07.05.2026 13:29:50

OpenClaw before 2026.4.14 contains a server-side request forgery vulnerability in browser SSRF policy that allows private-network navigation by default. Attackers can exploit this misconfiguration to access internal services or metadata endpoints thr...

  • EPSS 0.33%
  • Veröffentlicht 05.05.2026 12:16:18
  • Zuletzt bearbeitet 07.05.2026 01:54:40

OpenClaw before 2026.4.14 contains a redaction bypass vulnerability that allows authenticated gateway clients to receive unredacted secrets through sourceConfig and runtimeConfig alias fields. Attackers with config read access can exploit this to obt...

  • EPSS 0.3%
  • Veröffentlicht 05.05.2026 12:16:17
  • Zuletzt bearbeitet 05.05.2026 19:47:31

OpenClaw before 2026.4.10 contains an authorization bypass vulnerability allowing operator.write message-tool paths to access Matrix profile persistence requiring admin-level authority. Attackers can exploit insufficient access controls to mutate per...

  • EPSS 0.35%
  • Veröffentlicht 05.05.2026 12:16:17
  • Zuletzt bearbeitet 05.05.2026 19:47:31

OpenClaw versions 2026.4.5 before 2026.4.10 contain a sandbox escape vulnerability allowing sandboxed agents to override exec routing by specifying host=node. Attackers can bypass sandbox boundaries and route execution to remote nodes instead of inte...

  • EPSS 0.41%
  • Veröffentlicht 05.05.2026 12:16:17
  • Zuletzt bearbeitet 05.05.2026 19:47:31

OpenClaw versions from 2026.2.22 before 2026.4.12 contain an insufficient shell-wrapper detection vulnerability allowing attackers to inject environment variable assignments at the argv level. Attackers can bypass exec preflight handling to manipulat...

  • EPSS 0.13%
  • Veröffentlicht 28.04.2026 18:10:20
  • Zuletzt bearbeitet 26.05.2026 14:16:36

OpenClaw before 2026.4.8 contains a privilege escalation vulnerability allowing previously paired nodes to reconnect with exec-capable commands without the operator.admin scope requirement. Attackers can bypass re-pairing authentication to execute pr...

  • EPSS 0.19%
  • Veröffentlicht 28.04.2026 18:10:19
  • Zuletzt bearbeitet 30.04.2026 14:05:56

OpenClaw before 2026.4.8 contains a server-side request forgery vulnerability in Playwright redirect handling that allows attackers to bypass strict SSRF checks. Attackers can exploit request-time navigation to reach private targets that should be re...