OpenClaw

OpenClaw

666 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.15%
  • Veröffentlicht 28.04.2026 18:09:54
  • Zuletzt bearbeitet 30.04.2026 20:45:25

OpenClaw before 2026.3.28 contains a webhook replay vulnerability in Plivo V3 signature verification that canonicalizes query ordering for signatures but hashes raw URLs for replay detection. Attackers can reorder query parameters to bypass replay ca...

  • EPSS 0.12%
  • Veröffentlicht 28.04.2026 18:09:53
  • Zuletzt bearbeitet 30.04.2026 20:45:01

OpenClaw before 2026.3.31 contains a wide-area discovery vulnerability allowing arbitrary tailnet peers to be accepted as DNS authorities. Attackers with same-tailnet position and CA-trusted endpoint access can exfiltrate operator credentials through...

  • EPSS 0.12%
  • Veröffentlicht 28.04.2026 18:09:52
  • Zuletzt bearbeitet 30.04.2026 20:42:43

OpenClaw before 2026.3.31 contains an exec allowlist bypass vulnerability allowing attackers to inherit allowlist trust via shell init-file wrapper invocations. Attackers can exploit shell options like --rcfile, --init-file, and --startup-file to loa...

  • EPSS 0.13%
  • Veröffentlicht 28.04.2026 18:09:51
  • Zuletzt bearbeitet 30.04.2026 20:42:12

OpenClaw before 2026.3.31 fails to properly sanitize PIP_INDEX_URL and UV_INDEX_URL environment variables in host execution contexts, allowing attackers to redirect Python package-index traffic. Attackers can exploit this bypass to intercept or manip...

  • EPSS 0.31%
  • Veröffentlicht 28.04.2026 18:09:50
  • Zuletzt bearbeitet 30.04.2026 20:37:42

OpenClaw before 2026.3.31 contains a configuration management vulnerability where startup migration treats empty-array settings as missing values. Attackers can restart the application to rehydrate revoked Tlon configuration from file state, bypassin...

  • EPSS 0.12%
  • Veröffentlicht 28.04.2026 18:09:50
  • Zuletzt bearbeitet 30.04.2026 20:38:27

OpenClaw before 2026.3.28 contains an exec allowlist bypass vulnerability where allow-always persistence fails to unwrap /usr/bin/script and similar wrappers before storing trust decisions. Attackers can obtain user approval for one wrapped command t...

  • EPSS 0.24%
  • Veröffentlicht 28.04.2026 18:09:49
  • Zuletzt bearbeitet 30.04.2026 20:36:10

OpenClaw before 2026.3.22 contains an incomplete host environment variable sanitization vulnerability in host-env-security-policy.json and host-env-security.ts that allows package-manager environment overrides. Attackers can exploit approved exec req...

  • EPSS 0.21%
  • Veröffentlicht 28.04.2026 18:09:48
  • Zuletzt bearbeitet 01.05.2026 15:52:19

OpenClaw before 2026.3.31 stores Nostr privateKey as plaintext in configuration, allowing exposure through config.get method calls that bypass redaction mechanisms. Attackers can retrieve unredacted configuration data to obtain plaintext signing keys...

  • EPSS 0.33%
  • Veröffentlicht 28.04.2026 18:09:48
  • Zuletzt bearbeitet 01.05.2026 15:52:35

OpenClaw before 2026.3.22 contains a privilege escalation vulnerability where bootstrap setup codes are not bound to intended device roles and scopes during pairing. Attackers can exploit this during first-use device pairing to escalate privileges be...

  • EPSS 0.37%
  • Veröffentlicht 28.04.2026 18:09:46
  • Zuletzt bearbeitet 01.05.2026 15:52:02

OpenClaw before 2026.4.2 contains an arbitrary directory deletion vulnerability in mirror mode that allows attackers to delete remote directories by influencing remoteWorkspaceDir and remoteAgentWorkspaceDir configuration values. Attackers can manipu...