CVE-2026-100579
- EPSS 0.23%
- Veröffentlicht 26.09.2026 02:19:05
- Zuletzt bearbeitet 28.09.2026 18:17:13
OpenClaw (npm package 'openclaw') before 2026.7.1 incorrectly trusts requester provenance in message.action. In identity-bearing Gateway deployments (authentication modes that honor caller identity and narrower operator scopes), a write-scoped caller...
CVE-2026-100577
- EPSS 0.14%
- Veröffentlicht 26.09.2026 02:19:04
- Zuletzt bearbeitet 30.09.2026 01:16:35
OpenClaw versions before 2026.8.1 fail to validate video asset URLs returned by providers, allowing server-side requests to private destinations. A malicious or compromised provider can return private or loopback URLs to cause the CLI to make request...
CVE-2026-100578
- EPSS 0.23%
- Veröffentlicht 26.09.2026 02:19:04
- Zuletzt bearbeitet 28.09.2026 20:17:07
OpenClaw (npm package `openclaw`) before 2026.7.1 fails to restrict owner-only infrastructure tools exposed through the chat.send endpoint. In Gateway deployments using authentication modes that honor caller identity and narrower operator scopes, a w...
CVE-2026-100576
- EPSS 0.21%
- Veröffentlicht 26.09.2026 02:19:03
- Zuletzt bearbeitet 05.10.2026 15:17:13
OpenClaw versions before 2026.8.1 contain a server-side request forgery vulnerability in browser wait predicates that allows attackers to bypass SSRF protections by reaching blocked destinations. Attackers can use the wait --fn function against an ex...
CVE-2026-100574
- EPSS 0.23%
- Veröffentlicht 26.09.2026 02:19:02
- Zuletzt bearbeitet 29.09.2026 17:17:03
OpenClaw (npm package 'openclaw') before 2026.8.1 contains a server-side request forgery vulnerability in its trusted-host DNS checks. For fetches that use the trusted-host DNS recheck, a trusted hostname that resolves to an unspecified address (0.0....
CVE-2026-100573
- EPSS 0.11%
- Veröffentlicht 26.09.2026 02:19:01
- Zuletzt bearbeitet 30.09.2026 01:16:34
OpenClaw versions before 2026.8.1 contain a sandbox policy bypass vulnerability in the MCP loopback component that allows sandboxed coding-agent sessions to invoke tools explicitly denied by sandbox.tools.deny policy. Attackers can list and invoke de...
CVE-2026-100571
- EPSS 0.35%
- Veröffentlicht 26.09.2026 02:19:00
- Zuletzt bearbeitet 28.09.2026 18:17:13
OpenClaw (npm package 'openclaw') versions >= 2026.6.6 and < 2026.8.1 apply the SMS webhook invalid-request rate limit before Twilio signature verification and identify clients only by the raw proxy socket address. In deployments where the SMS/Twilio...
CVE-2026-100572
- EPSS 0.35%
- Veröffentlicht 26.09.2026 02:19:00
- Zuletzt bearbeitet 05.10.2026 15:17:13
OpenClaw versions >= 2026.3.25 and < 2026.8.1 apply invalid-token rate limiting for Synology Chat webhooks before authentication and key the limit on the raw proxy socket address. In deployments where OpenClaw sits behind a trusted reverse proxy or t...
CVE-2026-100570
- EPSS 0.13%
- Veröffentlicht 26.09.2026 02:18:59
- Zuletzt bearbeitet 29.09.2026 17:17:02
OpenClaw (npm package 'openclaw') versions >= 2026.3.28 and < 2026.8.1 allow an untrusted workspace .env file to set the CLOUDSDK_PYTHON_ARGS environment variable. When an operator starts OpenClaw in attacker-controlled workspace content and then run...
CVE-2026-100568
- EPSS 0.25%
- Veröffentlicht 26.09.2026 02:18:58
- Zuletzt bearbeitet 05.10.2026 15:17:11
OpenClaw versions before 2026.8.1 fail to properly restrict access to operator command cron jobs, allowing model-visible agent callers to read and execute ownerless command jobs. Attackers can inspect stored environment variables and force-run disabl...