OpenClaw

OpenClaw

600 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.45%
  • Veröffentlicht 09.04.2026 22:16:31
  • Zuletzt bearbeitet 16.04.2026 20:52:44

OpenClaw before 2026.3.22 performs cryptographic and dispatch operations on inbound Nostr direct messages before enforcing sender and pairing policy validation. Attackers can trigger unauthorized pre-authentication computation by sending crafted DM m...

  • EPSS 0.29%
  • Veröffentlicht 09.04.2026 22:16:31
  • Zuletzt bearbeitet 15.04.2026 20:38:33

OpenClaw before 2026.3.25 contains a missing rate limiting vulnerability in Telegram webhook authentication that allows attackers to brute-force weak webhook secrets. The vulnerability enables repeated authentication guesses without throttling, permi...

  • EPSS 0.24%
  • Veröffentlicht 09.04.2026 22:16:31
  • Zuletzt bearbeitet 15.04.2026 20:09:39

OpenClaw before 2026.3.25 contains a server-side request forgery vulnerability in multiple channel extensions that fail to properly guard configured base URLs against SSRF attacks. Attackers can exploit unprotected fetch() calls against configured en...

  • EPSS 0.23%
  • Veröffentlicht 09.04.2026 22:16:31
  • Zuletzt bearbeitet 15.04.2026 17:21:40

OpenClaw before 2026.3.22 fails to enforce operator.admin scope on mutating internal ACP chat commands, allowing unauthorized modifications. Attackers without admin privileges can execute mutating control-plane actions by directly invoking affected A...

  • EPSS 0.28%
  • Veröffentlicht 09.04.2026 22:16:30
  • Zuletzt bearbeitet 17.04.2026 12:20:03

OpenClaw before 2026.3.23 contains a replay identity vulnerability in Plivo V2 signature verification that allows attackers to bypass replay protection by modifying query parameters. The verification path derives replay keys from the full URL includi...

  • EPSS 0.29%
  • Veröffentlicht 09.04.2026 22:16:30
  • Zuletzt bearbeitet 17.04.2026 12:19:18

OpenClaw before 2026.3.22 contains an improper authentication verification vulnerability in Google Chat app-url webhook handling that accepts add-on principals outside intended deployment bindings. Attackers can bypass webhook authentication by provi...

  • EPSS 0.36%
  • Veröffentlicht 09.04.2026 22:16:30
  • Zuletzt bearbeitet 16.04.2026 14:17:26

OpenClaw before 2026.3.25 contains a missing rate limiting vulnerability in webhook authentication that allows attackers to brute-force weak webhook passwords without throttling. Remote attackers can repeatedly submit incorrect password guesses to th...

  • EPSS 0.24%
  • Veröffentlicht 09.04.2026 22:16:30
  • Zuletzt bearbeitet 17.04.2026 12:18:26

OpenClaw before 2026.3.22 contains a policy confusion vulnerability in room authorization that matches colliding room names instead of stable room tokens. Attackers can exploit similarly named rooms to bypass allowlist policies and gain unauthorized ...

  • EPSS 0.19%
  • Veröffentlicht 09.04.2026 22:16:30
  • Zuletzt bearbeitet 16.04.2026 13:43:35

OpenClaw before 2026.3.25 contains a privilege escalation vulnerability where silent local shared-auth reconnects auto-approve scope-upgrade requests, widening paired device permissions from operator.read to operator.admin. Attackers can exploit this...

  • EPSS 0.35%
  • Veröffentlicht 09.04.2026 22:16:29
  • Zuletzt bearbeitet 15.04.2026 17:23:36

OpenClaw before 2026.3.25 contains an improper access control vulnerability in the HTTP /sessions/:sessionKey/kill route that allows any bearer-authenticated user to invoke admin-level session termination functions without proper scope validation. At...