CVE-2026-53846
- EPSS 0.12%
- Veröffentlicht 16.06.2026 18:04:57
- Zuletzt bearbeitet 16.06.2026 20:42:46
OpenClaw before 2026.4.29 contains a path traversal vulnerability in the install helper that allows workspace .env files to override the npm_execpath configuration used for bundled runtime dependency installation. Attackers with workspace access can ...
CVE-2026-53844
- EPSS 0.21%
- Veröffentlicht 16.06.2026 18:04:56
- Zuletzt bearbeitet 16.06.2026 20:42:46
OpenClaw before 2026.4.29 contains a session visibility check bypass vulnerability in shared memory search that allows authenticated callers to access memory entries without proper authorization. Attackers can skip session visibility guards on the se...
CVE-2026-53845
- EPSS 0.19%
- Veröffentlicht 16.06.2026 18:04:56
- Zuletzt bearbeitet 16.06.2026 20:42:46
OpenClaw before 2026.5.6 contains a hook bypass vulnerability where skill commands routed through the affected dispatch path skip before-tool-call hook coverage. Attackers can exploit this by sending skill commands through the vulnerable dispatch pat...
CVE-2026-53843
- EPSS 0.28%
- Veröffentlicht 16.06.2026 18:04:55
- Zuletzt bearbeitet 16.06.2026 20:42:46
OpenClaw before 2026.5.26 contains an authorization bypass vulnerability where a surviving pairing-scoped device session can re-establish node token authority after revocation. Attackers with a paired device can regain WebSocket node-level access wit...
CVE-2026-53841
- EPSS 0.19%
- Veröffentlicht 16.06.2026 18:04:54
- Zuletzt bearbeitet 16.06.2026 20:42:46
OpenClaw before 2026.5.12 contains a cross-site scripting vulnerability in exported session HTML that preserves unsafe javascript: and data: links in generated content. Attackers can execute browser-side scripts if a trusted operator opens the export...
CVE-2026-53842
- EPSS 0.13%
- Veröffentlicht 16.06.2026 18:04:54
- Zuletzt bearbeitet 16.06.2026 20:42:46
OpenClaw before 2026.5.2 contains an environment variable injection vulnerability allowing workspace .env files to influence Python runtime selection through CLOUDSDK_PYTHON during Gmail setup gcloud execution. Attackers with repository access can ma...
CVE-2026-53840
- EPSS 0.22%
- Veröffentlicht 16.06.2026 18:04:53
- Zuletzt bearbeitet 16.06.2026 20:42:46
OpenClaw before 2026.5.12 contains an information disclosure vulnerability in streamable-http MCP servers that forwards operator-configured custom headers during cross-origin redirects. Attackers controlling or compromising an MCP endpoint can redire...
CVE-2026-53834
- EPSS 0.19%
- Veröffentlicht 12.06.2026 22:16:55
- Zuletzt bearbeitet 16.06.2026 00:28:27
OpenClaw before 2026.4.27 contains an authorization bypass vulnerability in QQBot pre-dispatch slash commands that allows authenticated senders to skip allowFrom policy checks. Attackers can invoke slash commands before configured access control poli...
CVE-2026-53835
- EPSS 0.17%
- Veröffentlicht 12.06.2026 22:16:55
- Zuletzt bearbeitet 16.06.2026 00:25:16
OpenClaw before 2026.5.6 contains a configuration enforcement bypass vulnerability in Feishu dynamic-agent bindings that allows authenticated senders to create or update bindings without honoring configured config-write controls. Attackers can exploi...
CVE-2026-53836
- EPSS 0.45%
- Veröffentlicht 12.06.2026 22:16:55
- Zuletzt bearbeitet 16.06.2026 00:22:56
OpenClaw before 2026.5.12 contains an allowlist bypass vulnerability in PowerShell encoded-command handling that allows attackers to execute encoded commands using abbreviated flag aliases not recognized by the allowlist parser. Remote authenticated ...