OpenClaw

OpenClaw

666 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.12%
  • Veröffentlicht 28.04.2026 18:10:10
  • Zuletzt bearbeitet 30.04.2026 14:04:15

OpenClaw before 2026.4.8 fails to remove git plumbing environment variables from the execution environment before host exec operations. Attackers can exploit this by setting GIT_DIR and related variables to redirect git operations and compromise repo...

  • EPSS 0.22%
  • Veröffentlicht 28.04.2026 18:10:10
  • Zuletzt bearbeitet 30.04.2026 14:04:22

OpenClaw before 2026.4.8 contains an authentication state management vulnerability where the resolvedAuth closure becomes stale after configuration reload. Newly accepted gateway connections continue using outdated resolved auth state, allowing attac...

  • EPSS 0.22%
  • Veröffentlicht 28.04.2026 18:10:09
  • Zuletzt bearbeitet 30.04.2026 14:02:57

OpenClaw before 2026.4.8 contains a server-side request forgery vulnerability in QQ Bot media download paths that bypass SSRF protection. Attackers can exploit unprotected media fetch endpoints to access internal resources and bypass allowlist polici...

  • EPSS 0.21%
  • Veröffentlicht 28.04.2026 18:10:08
  • Zuletzt bearbeitet 30.04.2026 14:15:24

OpenClaw before 2026.4.4 contains a race condition vulnerability in shared-secret authentication that allows concurrent asynchronous requests to bypass the per-key rate-limit budget. Attackers can exploit this by sending multiple simultaneous authent...

  • EPSS 0.33%
  • Veröffentlicht 28.04.2026 18:10:07
  • Zuletzt bearbeitet 30.04.2026 19:38:38

OpenClaw before 2026.4.8 contains a filesystem policy bypass vulnerability in docx upload processing that allows local file reads outside workspace boundaries. Attackers can exploit upload_file and upload_image endpoints to access files beyond the in...

  • EPSS 0.21%
  • Veröffentlicht 28.04.2026 18:10:07
  • Zuletzt bearbeitet 30.04.2026 19:38:47

OpenClaw before 2026.4.8 contains a server-side request forgery policy bypass vulnerability allowing attackers to trigger navigations bypassing normal SSRF checks. Attackers can exploit browser interactions to bypass SSRF protections and access restr...

  • EPSS 0.24%
  • Veröffentlicht 28.04.2026 18:10:06
  • Zuletzt bearbeitet 30.04.2026 19:38:28

OpenClaw before 2026.4.8 omits owner-only enforcement for cross-channel allowlist writes in the /allowlist endpoint. An authorized non-owner sender can bypass access controls to perform allowlist modifications against different channels, violating th...

  • EPSS 0.34%
  • Veröffentlicht 28.04.2026 18:10:05
  • Zuletzt bearbeitet 30.04.2026 19:38:19

OpenClaw before 2026.3.31 contains a resource exhaustion vulnerability in media downloads that bypasses core safety limits for file size, count, and cleanup operations. Attackers can exhaust disk space by downloading media files without triggering in...

  • EPSS 0.23%
  • Veröffentlicht 28.04.2026 18:10:04
  • Zuletzt bearbeitet 30.04.2026 19:37:48

OpenClaw before 2026.3.31 contains a sender allowlist bypass vulnerability that allows remote attackers to access restricted messages. Attackers can exploit fetched quoted, root, and thread context messages to bypass sender allowlist restrictions and...

  • EPSS 0.23%
  • Veröffentlicht 28.04.2026 18:10:04
  • Zuletzt bearbeitet 30.04.2026 19:38:01

OpenClaw before 2026.4.2 contains a timing side channel vulnerability in shared-secret comparison call sites that use early length-mismatch checks instead of fixed-length comparison helpers. Attackers can measure timing differences to leak secret-len...