OpenClaw

OpenClaw

559 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.12%
  • Veröffentlicht 16.06.2026 18:04:57
  • Zuletzt bearbeitet 16.06.2026 20:42:46

OpenClaw before 2026.4.29 contains a path traversal vulnerability in the install helper that allows workspace .env files to override the npm_execpath configuration used for bundled runtime dependency installation. Attackers with workspace access can ...

  • EPSS 0.21%
  • Veröffentlicht 16.06.2026 18:04:56
  • Zuletzt bearbeitet 16.06.2026 20:42:46

OpenClaw before 2026.4.29 contains a session visibility check bypass vulnerability in shared memory search that allows authenticated callers to access memory entries without proper authorization. Attackers can skip session visibility guards on the se...

  • EPSS 0.19%
  • Veröffentlicht 16.06.2026 18:04:56
  • Zuletzt bearbeitet 16.06.2026 20:42:46

OpenClaw before 2026.5.6 contains a hook bypass vulnerability where skill commands routed through the affected dispatch path skip before-tool-call hook coverage. Attackers can exploit this by sending skill commands through the vulnerable dispatch pat...

  • EPSS 0.28%
  • Veröffentlicht 16.06.2026 18:04:55
  • Zuletzt bearbeitet 16.06.2026 20:42:46

OpenClaw before 2026.5.26 contains an authorization bypass vulnerability where a surviving pairing-scoped device session can re-establish node token authority after revocation. Attackers with a paired device can regain WebSocket node-level access wit...

  • EPSS 0.19%
  • Veröffentlicht 16.06.2026 18:04:54
  • Zuletzt bearbeitet 16.06.2026 20:42:46

OpenClaw before 2026.5.12 contains a cross-site scripting vulnerability in exported session HTML that preserves unsafe javascript: and data: links in generated content. Attackers can execute browser-side scripts if a trusted operator opens the export...

  • EPSS 0.13%
  • Veröffentlicht 16.06.2026 18:04:54
  • Zuletzt bearbeitet 16.06.2026 20:42:46

OpenClaw before 2026.5.2 contains an environment variable injection vulnerability allowing workspace .env files to influence Python runtime selection through CLOUDSDK_PYTHON during Gmail setup gcloud execution. Attackers with repository access can ma...

  • EPSS 0.22%
  • Veröffentlicht 16.06.2026 18:04:53
  • Zuletzt bearbeitet 16.06.2026 20:42:46

OpenClaw before 2026.5.12 contains an information disclosure vulnerability in streamable-http MCP servers that forwards operator-configured custom headers during cross-origin redirects. Attackers controlling or compromising an MCP endpoint can redire...

  • EPSS 0.19%
  • Veröffentlicht 12.06.2026 22:16:55
  • Zuletzt bearbeitet 16.06.2026 00:28:27

OpenClaw before 2026.4.27 contains an authorization bypass vulnerability in QQBot pre-dispatch slash commands that allows authenticated senders to skip allowFrom policy checks. Attackers can invoke slash commands before configured access control poli...

  • EPSS 0.17%
  • Veröffentlicht 12.06.2026 22:16:55
  • Zuletzt bearbeitet 16.06.2026 00:25:16

OpenClaw before 2026.5.6 contains a configuration enforcement bypass vulnerability in Feishu dynamic-agent bindings that allows authenticated senders to create or update bindings without honoring configured config-write controls. Attackers can exploi...

  • EPSS 0.45%
  • Veröffentlicht 12.06.2026 22:16:55
  • Zuletzt bearbeitet 16.06.2026 00:22:56

OpenClaw before 2026.5.12 contains an allowlist bypass vulnerability in PowerShell encoded-command handling that allows attackers to execute encoded commands using abbreviated flag aliases not recognized by the allowlist parser. Remote authenticated ...