OpenClaw

OpenClaw

600 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.21%
  • Veröffentlicht 17.07.2026 00:06:52
  • Zuletzt bearbeitet 21.07.2026 19:59:43

OpenClaw versions 2026.5.10-beta.1 before 2026.6.5 contain an authorization bypass in the ClickClack agent-mode dispatch feature, which could ignore the toolsAllow policy check. When the affected feature is enabled and reachable, a lower-trust caller...

  • EPSS 0.3%
  • Veröffentlicht 17.07.2026 00:06:51
  • Zuletzt bearbeitet 29.07.2026 19:16:50

OpenClaw versions before 2026.6.5 contain an authentication bypass vulnerability that allows lower-trust callers to reach admin-scoped tools. Attackers can perform actions requiring stronger authorization by exploiting insufficient policy checks on c...

  • EPSS 0.25%
  • Veröffentlicht 17.07.2026 00:06:50
  • Zuletzt bearbeitet 21.07.2026 20:00:45

OpenClaw versions 2026.4.12-beta.1 before 2026.6.6 contain a missing-authorization vulnerability in the MS Teams message actions feature. When the affected feature is enabled and reachable, a lower-trust caller or a configured input path can perform ...

  • EPSS 0.25%
  • Veröffentlicht 17.07.2026 00:06:50
  • Zuletzt bearbeitet 20.07.2026 17:00:58

OpenClaw versions before 2026.6.9 contain a missing authorization vulnerability in Discord moderation actions. In affected versions, a lower-trust caller or configured input path could perform moderation actions that should have required a stronger a...

  • EPSS 0.29%
  • Veröffentlicht 17.07.2026 00:06:49
  • Zuletzt bearbeitet 29.07.2026 19:16:50

OpenClaw versions before 2026.6.6 contain an environment variable filtering vulnerability in host exec that fails to properly sanitize rustup startup variables. Attackers with lower-trust caller access or configured input paths can execute or persist...

  • EPSS 0.26%
  • Veröffentlicht 17.07.2026 00:06:48
  • Zuletzt bearbeitet 20.07.2026 17:01:14

OpenClaw versions before 2026.6.6 contain a network policy bypass vulnerability in the sandbox exec-server that allows lower-trust callers to reach internal network destinations blocked by OpenClaw policy. Attackers can send HTTP requests through the...

  • EPSS 0.3%
  • Veröffentlicht 17.07.2026 00:06:48
  • Zuletzt bearbeitet 21.07.2026 19:59:58

OpenClaw versions 2026.6.1 before 2026.6.9 contain a privilege escalation vulnerability in isolated cron jobs that allows lower-trust callers to regain denied execution tools. Attackers can execute or persist actions beyond their intended authorizati...

  • EPSS 0.29%
  • Veröffentlicht 13.07.2026 21:30:20
  • Zuletzt bearbeitet 15.07.2026 05:17:24

OpenClaw versions before 2026.6.6 contain a flaw in host exec environment filtering that could allow Git ext transport to be abused. When the affected feature is enabled and reachable, a lower-trust caller or configured input path could execute or pe...

  • EPSS 0.29%
  • Veröffentlicht 13.07.2026 21:30:19
  • Zuletzt bearbeitet 15.07.2026 11:16:34

OpenClaw versions before 2026.6.6 contain a flaw in host exec environment filtering that can miss interpreter startup variables. When the affected feature is enabled and reachable, a lower-trust caller or configured input path can supply crafted envi...

  • EPSS 0.21%
  • Veröffentlicht 13.07.2026 21:30:18
  • Zuletzt bearbeitet 14.07.2026 17:46:43

OpenClaw before 2026.6.6 contains a policy bypass vulnerability in browser CDP discovery that accepts blocked WebSocket URLs. Attackers with lower-trust access can reach network destinations that should have been blocked by OpenClaw policy when the a...