CVE-2026-40045
- EPSS 0.12%
- Veröffentlicht 20.04.2026 23:08:07
- Zuletzt bearbeitet 24.04.2026 19:03:59
OpenClaw before 2026.4.2 accepts non-loopback cleartext ws:// gateway endpoints and transmits stored gateway credentials over unencrypted connections. Attackers can forge discovery results or craft setup codes to redirect clients to malicious endpoin...
CVE-2026-41389
- EPSS 0.26%
- Veröffentlicht 20.04.2026 17:48:43
- Zuletzt bearbeitet 28.04.2026 18:57:30
OpenClaw versions 2026.4.7 before 2026.4.15 fail to enforce local-root containment on tool-result media paths, allowing arbitrary local and UNC file access. Attackers can craft malicious tool-result media references to trigger host-side file reads or...
CVE-2026-3691
- EPSS 0.46%
- Veröffentlicht 11.04.2026 00:17:40
- Zuletzt bearbeitet 27.04.2026 17:10:36
OpenClaw Client PKCE Verifier Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose stored credentials on affected installations of OpenClaw. User interaction is required to exploit this vulnerability in that th...
CVE-2026-3690
- EPSS 0.67%
- Veröffentlicht 11.04.2026 00:17:32
- Zuletzt bearbeitet 27.04.2026 17:09:55
OpenClaw Canvas Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of OpenClaw. Authentication is not required to exploit this vulnerability. The specific flaw exists wi...
CVE-2026-3689
- EPSS 0.94%
- Veröffentlicht 11.04.2026 00:17:24
- Zuletzt bearbeitet 27.04.2026 17:08:57
OpenClaw Canvas Path Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of OpenClaw. Authentication is required to exploit this vulnerability. The sp...
CVE-2026-35670
- EPSS 0.24%
- Veröffentlicht 10.04.2026 16:03:28
- Zuletzt bearbeitet 13.04.2026 21:06:17
OpenClaw before 2026.3.22 contains a webhook reply delivery vulnerability that allows attackers to rebind chat replies to unintended users by exploiting mutable username matching instead of stable numeric user identifiers. Attackers can manipulate us...
CVE-2026-35668
- EPSS 0.38%
- Veröffentlicht 10.04.2026 16:03:27
- Zuletzt bearbeitet 13.04.2026 20:43:10
OpenClaw before 2026.3.24 contains a path traversal vulnerability in sandbox enforcement allowing sandboxed agents to read arbitrary files from other agents' workspaces via unnormalized mediaUrl or fileUrl parameter keys. Attackers can exploit incomp...
CVE-2026-35669
- EPSS 0.3%
- Veröffentlicht 10.04.2026 16:03:27
- Zuletzt bearbeitet 13.04.2026 21:06:24
OpenClaw before 2026.3.25 contains a privilege escalation vulnerability in gateway-authenticated plugin HTTP routes that incorrectly mint operator.admin runtime scope regardless of caller-granted scopes. Attackers can exploit this scope boundary bypa...
CVE-2026-35667
- EPSS 0.15%
- Veröffentlicht 10.04.2026 16:03:26
- Zuletzt bearbeitet 28.04.2026 18:57:14
OpenClaw before 2026.3.24 contains an incomplete fix for CVE-2026-27486 where the !stop chat command uses an unpatched killProcessTree function from shell-utils.ts that sends SIGKILL immediately without graceful SIGTERM shutdown. Attackers can trigge...
CVE-2026-35665
- EPSS 0.33%
- Veröffentlicht 10.04.2026 16:03:25
- Zuletzt bearbeitet 13.04.2026 20:42:44
OpenClaw before 2026.3.24 contains an incomplete fix for CVE-2026-32011 where the Feishu webhook handler accepts request bodies with permissive limits of 1MB and 30-second timeout before signature verification. An unauthenticated attacker can exhaust...