OpenClaw

OpenClaw

666 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.23%
  • Veröffentlicht 26.09.2026 02:19:05
  • Zuletzt bearbeitet 28.09.2026 18:17:13

OpenClaw (npm package 'openclaw') before 2026.7.1 incorrectly trusts requester provenance in message.action. In identity-bearing Gateway deployments (authentication modes that honor caller identity and narrower operator scopes), a write-scoped caller...

  • EPSS 0.14%
  • Veröffentlicht 26.09.2026 02:19:04
  • Zuletzt bearbeitet 30.09.2026 01:16:35

OpenClaw versions before 2026.8.1 fail to validate video asset URLs returned by providers, allowing server-side requests to private destinations. A malicious or compromised provider can return private or loopback URLs to cause the CLI to make request...

  • EPSS 0.23%
  • Veröffentlicht 26.09.2026 02:19:04
  • Zuletzt bearbeitet 28.09.2026 20:17:07

OpenClaw (npm package `openclaw`) before 2026.7.1 fails to restrict owner-only infrastructure tools exposed through the chat.send endpoint. In Gateway deployments using authentication modes that honor caller identity and narrower operator scopes, a w...

  • EPSS 0.21%
  • Veröffentlicht 26.09.2026 02:19:03
  • Zuletzt bearbeitet 05.10.2026 15:17:13

OpenClaw versions before 2026.8.1 contain a server-side request forgery vulnerability in browser wait predicates that allows attackers to bypass SSRF protections by reaching blocked destinations. Attackers can use the wait --fn function against an ex...

  • EPSS 0.23%
  • Veröffentlicht 26.09.2026 02:19:02
  • Zuletzt bearbeitet 29.09.2026 17:17:03

OpenClaw (npm package 'openclaw') before 2026.8.1 contains a server-side request forgery vulnerability in its trusted-host DNS checks. For fetches that use the trusted-host DNS recheck, a trusted hostname that resolves to an unspecified address (0.0....

  • EPSS 0.11%
  • Veröffentlicht 26.09.2026 02:19:01
  • Zuletzt bearbeitet 30.09.2026 01:16:34

OpenClaw versions before 2026.8.1 contain a sandbox policy bypass vulnerability in the MCP loopback component that allows sandboxed coding-agent sessions to invoke tools explicitly denied by sandbox.tools.deny policy. Attackers can list and invoke de...

  • EPSS 0.35%
  • Veröffentlicht 26.09.2026 02:19:00
  • Zuletzt bearbeitet 28.09.2026 18:17:13

OpenClaw (npm package 'openclaw') versions >= 2026.6.6 and < 2026.8.1 apply the SMS webhook invalid-request rate limit before Twilio signature verification and identify clients only by the raw proxy socket address. In deployments where the SMS/Twilio...

  • EPSS 0.35%
  • Veröffentlicht 26.09.2026 02:19:00
  • Zuletzt bearbeitet 05.10.2026 15:17:13

OpenClaw versions >= 2026.3.25 and < 2026.8.1 apply invalid-token rate limiting for Synology Chat webhooks before authentication and key the limit on the raw proxy socket address. In deployments where OpenClaw sits behind a trusted reverse proxy or t...

  • EPSS 0.13%
  • Veröffentlicht 26.09.2026 02:18:59
  • Zuletzt bearbeitet 29.09.2026 17:17:02

OpenClaw (npm package 'openclaw') versions >= 2026.3.28 and < 2026.8.1 allow an untrusted workspace .env file to set the CLOUDSDK_PYTHON_ARGS environment variable. When an operator starts OpenClaw in attacker-controlled workspace content and then run...

  • EPSS 0.25%
  • Veröffentlicht 26.09.2026 02:18:58
  • Zuletzt bearbeitet 05.10.2026 15:17:11

OpenClaw versions before 2026.8.1 fail to properly restrict access to operator command cron jobs, allowing model-visible agent callers to read and execute ownerless command jobs. Attackers can inspect stored environment variables and force-run disabl...