OpenClaw

OpenClaw

559 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.41%
  • Veröffentlicht 20.04.2026 23:08:15
  • Zuletzt bearbeitet 27.04.2026 15:20:33

OpenClaw before 2026.3.28 contains an authorization bypass vulnerability in Discord text approval commands that allows non-approvers to resolve pending exec approvals. Attackers can send Discord text commands to bypass the channels.discord.execApprov...

  • EPSS 0.25%
  • Veröffentlicht 20.04.2026 23:08:14
  • Zuletzt bearbeitet 27.04.2026 16:56:50

OpenClaw versions 2026.3.22 before 2026.3.31 contain a signature verification bypass vulnerability in the Nostr DM ingress path that allows pairing challenges to be issued before event signature validation. An unauthenticated remote attacker can send...

  • EPSS 0.22%
  • Veröffentlicht 20.04.2026 23:08:14
  • Zuletzt bearbeitet 27.04.2026 15:26:49

OpenClaw before 2026.3.31 contains a server-side request forgery vulnerability in the marketplace plugin download functionality that allows remote attackers to make arbitrary network requests. Attackers can exploit unguarded fetch() calls to access i...

  • EPSS 0.25%
  • Veröffentlicht 20.04.2026 23:08:13
  • Zuletzt bearbeitet 27.04.2026 16:56:39

OpenClaw before 2026.3.31 contains a trust-decline vulnerability that preserves attacker-discovered endpoints in remote onboarding flows. Attackers can route gateway credentials to malicious endpoints by having their discovered URL survive the trust ...

  • EPSS 0.2%
  • Veröffentlicht 20.04.2026 23:08:12
  • Zuletzt bearbeitet 27.04.2026 16:56:28

OpenClaw before 2026.3.28 contains an authorization bypass vulnerability in the chat.send gateway method where ACP-only provenance fields are gated by self-declared client metadata from WebSocket handshake rather than verified authorization state. Au...

  • EPSS 0.19%
  • Veröffentlicht 20.04.2026 23:08:11
  • Zuletzt bearbeitet 27.04.2026 16:56:17

OpenClaw before 2026.4.2 fails to enforce write scopes on the POST /sessions/:sessionKey/kill endpoint in identity-bearing HTTP modes. Read-scoped callers can terminate running subagent sessions by sending requests to this endpoint, bypassing authori...

  • EPSS 0.2%
  • Veröffentlicht 20.04.2026 23:08:10
  • Zuletzt bearbeitet 27.04.2026 15:06:33

OpenClaw before 2026.3.31 contains a time-of-check-time-of-use race condition in the remote filesystem bridge readFile function that allows sandbox escape. Attackers can exploit the separate path validation and file read operations to bypass sandbox ...

  • EPSS 0.24%
  • Veröffentlicht 20.04.2026 23:08:10
  • Zuletzt bearbeitet 27.04.2026 15:05:17

OpenClaw before 2026.3.31 contains a server-side request forgery vulnerability in the marketplace plugin download functionality that allows attackers to access internal resources by following unvalidated redirects. The marketplace.ts module fails to ...

  • EPSS 0.13%
  • Veröffentlicht 20.04.2026 23:08:09
  • Zuletzt bearbeitet 27.04.2026 15:06:44

OpenClaw before 2026.4.2 contains an improper trust boundary vulnerability allowing untrusted workspace channel shadows to execute during built-in channel setup and login. Attackers can clone a workspace with a malicious plugin claiming a bundled cha...

  • EPSS 0.13%
  • Veröffentlicht 20.04.2026 23:08:08
  • Zuletzt bearbeitet 27.04.2026 15:07:46

OpenClaw before 2026.3.28 loads the current working directory .env file before trusted state-dir configuration, allowing environment variable injection. Attackers can place a malicious .env file in a repository or workspace to override runtime config...