OpenClaw

OpenClaw

666 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.09%
  • Veröffentlicht 23.04.2026 22:16:39
  • Zuletzt bearbeitet 28.04.2026 18:56:08

OpenClaw before 2026.3.31 contains a time-of-check-time-of-use vulnerability in sandbox file operations that allows attackers to bypass fd-based defenses. Attackers can exploit check-then-act patterns in apply_patch, remove, and mkdir operations to m...

  • EPSS 0.11%
  • Veröffentlicht 23.04.2026 22:16:38
  • Zuletzt bearbeitet 29.04.2026 17:10:15

OpenClaw before 2026.3.28 contains an environment variable sanitization vulnerability where GIT_TEMPLATE_DIR and AWS_CONFIG_FILE are not blocked in the host-env blocklist. Attackers can exploit approved exec requests to redirect git or AWS CLI behavi...

  • EPSS 0.22%
  • Veröffentlicht 23.04.2026 18:16:29
  • Zuletzt bearbeitet 28.04.2026 19:41:00

OpenClaw before 2026.4.20 contains a scope enforcement bypass vulnerability in the assistant-media route that allows trusted-proxy callers without operator.read scope to access protected assistant-media files and metadata. Attackers can bypass identi...

  • EPSS 0.17%
  • Veröffentlicht 23.04.2026 18:16:29
  • Zuletzt bearbeitet 28.04.2026 19:40:13

OpenClaw before 2026.4.20 contains an improper authorization vulnerability in paired-device pairing management that allows limited-scope sessions to enumerate and act on pairing requests. Attackers with paired-device access can approve or operate on ...

  • EPSS 0.3%
  • Veröffentlicht 20.04.2026 23:08:17
  • Zuletzt bearbeitet 27.04.2026 15:08:05

OpenClaw before 2026.3.31 contains a resource consumption vulnerability in Telegram audio preflight transcription that allows unauthorized group senders to trigger transcription processing. Attackers can exploit insufficient allowlist enforcement to ...

  • EPSS 0.3%
  • Veröffentlicht 20.04.2026 23:08:16
  • Zuletzt bearbeitet 27.04.2026 15:09:01

OpenClaw before 2026.3.31 contains a sandbox bypass vulnerability allowing attackers to escalate privileges via heartbeat context inheritance and senderIsOwner parameter manipulation. Attackers can exploit improper context validation to bypass sandbo...

  • EPSS 0.12%
  • Veröffentlicht 20.04.2026 23:08:16
  • Zuletzt bearbeitet 27.04.2026 15:08:32

OpenClaw before 2026.3.31 contains an environment variable override vulnerability in host exec policy that fails to properly enforce proxy, TLS, Docker, and Git TLS controls. Attackers can bypass security controls by overriding environment variables ...

  • EPSS 0.41%
  • Veröffentlicht 20.04.2026 23:08:15
  • Zuletzt bearbeitet 27.04.2026 15:20:33

OpenClaw before 2026.3.28 contains an authorization bypass vulnerability in Discord text approval commands that allows non-approvers to resolve pending exec approvals. Attackers can send Discord text commands to bypass the channels.discord.execApprov...

  • EPSS 0.25%
  • Veröffentlicht 20.04.2026 23:08:14
  • Zuletzt bearbeitet 27.04.2026 16:56:50

OpenClaw versions 2026.3.22 before 2026.3.31 contain a signature verification bypass vulnerability in the Nostr DM ingress path that allows pairing challenges to be issued before event signature validation. An unauthenticated remote attacker can send...

  • EPSS 0.22%
  • Veröffentlicht 20.04.2026 23:08:14
  • Zuletzt bearbeitet 27.04.2026 15:26:49

OpenClaw before 2026.3.31 contains a server-side request forgery vulnerability in the marketplace plugin download functionality that allows remote attackers to make arbitrary network requests. Attackers can exploit unguarded fetch() calls to access i...