OpenClaw

OpenClaw

559 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.14%
  • Veröffentlicht 10.04.2026 16:03:10
  • Zuletzt bearbeitet 14.04.2026 15:16:30

OpenClaw before 2026.3.24 contains an arbitrary code execution vulnerability in local plugin and hook installation that allows attackers to execute malicious code by crafting a .npmrc file with a git executable override. During npm install execution ...

Exploit
  • EPSS 0.44%
  • Veröffentlicht 10.04.2026 16:03:09
  • Zuletzt bearbeitet 13.04.2026 20:27:09

OpenClaw before 2026.3.24 contains missing authorization vulnerabilities in the /send and /allowlist chat command handlers. The /send command allows non-owner command-authorized senders to change owner-only session delivery policy settings, and the /...

Exploit
  • EPSS 0.26%
  • Veröffentlicht 10.04.2026 16:03:09
  • Zuletzt bearbeitet 13.04.2026 20:14:25

OpenClaw before 2026.3.24 contains a privilege escalation vulnerability where the /allowlist command fails to re-validate gateway client scopes for internal callers, allowing operator.write-scoped clients to mutate channel authorization policy. Attac...

  • EPSS 0.27%
  • Veröffentlicht 10.04.2026 16:03:08
  • Zuletzt bearbeitet 13.04.2026 20:27:19

OpenClaw before 2026.3.24 contains an authorization bypass vulnerability in the HTTP /v1/models endpoint that fails to enforce operator read scope requirements. Attackers with only operator.approvals scope can enumerate gateway model metadata through...

Exploit
  • EPSS 0.42%
  • Veröffentlicht 10.04.2026 05:16:06
  • Zuletzt bearbeitet 30.04.2026 14:22:11

A weakness has been identified in OpenClaw up to 2026.1.26. Affected by this issue is some unknown functionality of the file src/agents/tools/web-fetch.ts of the component assertPublicHostname Handler. Executing a manipulation can lead to server-side...

  • EPSS 0.28%
  • Veröffentlicht 09.04.2026 22:16:34
  • Zuletzt bearbeitet 15.04.2026 19:25:19

OpenClaw before 2026.3.25 contains a privilege escalation vulnerability in the gateway plugin subagent fallback deleteSession function that uses a synthetic operator.admin runtime scope. Attackers can exploit this by triggering session deletion witho...

  • EPSS 0.24%
  • Veröffentlicht 09.04.2026 22:16:34
  • Zuletzt bearbeitet 15.04.2026 18:52:49

OpenClaw before 2026.3.25 contains a pre-authentication rate-limit bypass vulnerability in webhook token validation that allows attackers to brute-force weak webhook secrets. The vulnerability exists because invalid webhook tokens are rejected withou...

  • EPSS 0.29%
  • Veröffentlicht 09.04.2026 22:16:33
  • Zuletzt bearbeitet 15.04.2026 16:52:11

OpenClaw before 2026.3.22 contains a privilege escalation vulnerability in the Control UI that allows unauthenticated sessions to retain self-declared privileged scopes without device identity verification. Attackers can exploit the device-less allow...

  • EPSS 0.46%
  • Veröffentlicht 09.04.2026 22:16:33
  • Zuletzt bearbeitet 15.04.2026 16:51:14

OpenClaw before 2026.3.22 contains a privilege escalation vulnerability in the device.pair.approve method that allows an operator.pairing approver to approve pending device requests with broader operator scopes than the approver actually holds. Attac...

  • EPSS 0.44%
  • Veröffentlicht 09.04.2026 22:16:33
  • Zuletzt bearbeitet 15.04.2026 19:52:39

OpenClaw before 2026.3.25 parses JSON request bodies before validating webhook signatures, allowing unauthenticated attackers to force resource-intensive parsing operations. Remote attackers can send malicious webhook requests to trigger denial of se...