CVE-2026-41300
- EPSS 0.25%
- Veröffentlicht 20.04.2026 23:08:13
- Zuletzt bearbeitet 27.04.2026 16:56:39
OpenClaw before 2026.3.31 contains a trust-decline vulnerability that preserves attacker-discovered endpoints in remote onboarding flows. Attackers can route gateway credentials to malicious endpoints by having their discovered URL survive the trust ...
CVE-2026-41299
- EPSS 0.2%
- Veröffentlicht 20.04.2026 23:08:12
- Zuletzt bearbeitet 27.04.2026 16:56:28
OpenClaw before 2026.3.28 contains an authorization bypass vulnerability in the chat.send gateway method where ACP-only provenance fields are gated by self-declared client metadata from WebSocket handshake rather than verified authorization state. Au...
CVE-2026-41298
- EPSS 0.19%
- Veröffentlicht 20.04.2026 23:08:11
- Zuletzt bearbeitet 27.04.2026 16:56:17
OpenClaw before 2026.4.2 fails to enforce write scopes on the POST /sessions/:sessionKey/kill endpoint in identity-bearing HTTP modes. Read-scoped callers can terminate running subagent sessions by sending requests to this endpoint, bypassing authori...
CVE-2026-41296
- EPSS 0.2%
- Veröffentlicht 20.04.2026 23:08:10
- Zuletzt bearbeitet 27.04.2026 15:06:33
OpenClaw before 2026.3.31 contains a time-of-check-time-of-use race condition in the remote filesystem bridge readFile function that allows sandbox escape. Attackers can exploit the separate path validation and file read operations to bypass sandbox ...
CVE-2026-41297
- EPSS 0.24%
- Veröffentlicht 20.04.2026 23:08:10
- Zuletzt bearbeitet 27.04.2026 15:05:17
OpenClaw before 2026.3.31 contains a server-side request forgery vulnerability in the marketplace plugin download functionality that allows attackers to access internal resources by following unvalidated redirects. The marketplace.ts module fails to ...
CVE-2026-41295
- EPSS 0.13%
- Veröffentlicht 20.04.2026 23:08:09
- Zuletzt bearbeitet 27.04.2026 15:06:44
OpenClaw before 2026.4.2 contains an improper trust boundary vulnerability allowing untrusted workspace channel shadows to execute during built-in channel setup and login. Attackers can clone a workspace with a malicious plugin claiming a bundled cha...
CVE-2026-41294
- EPSS 0.13%
- Veröffentlicht 20.04.2026 23:08:08
- Zuletzt bearbeitet 27.04.2026 15:07:46
OpenClaw before 2026.3.28 loads the current working directory .env file before trusted state-dir configuration, allowing environment variable injection. Attackers can place a malicious .env file in a repository or workspace to override runtime config...
CVE-2026-40045
- EPSS 0.12%
- Veröffentlicht 20.04.2026 23:08:07
- Zuletzt bearbeitet 24.04.2026 19:03:59
OpenClaw before 2026.4.2 accepts non-loopback cleartext ws:// gateway endpoints and transmits stored gateway credentials over unencrypted connections. Attackers can forge discovery results or craft setup codes to redirect clients to malicious endpoin...
CVE-2026-41389
- EPSS 0.26%
- Veröffentlicht 20.04.2026 17:48:43
- Zuletzt bearbeitet 28.04.2026 18:57:30
OpenClaw versions 2026.4.7 before 2026.4.15 fail to enforce local-root containment on tool-result media paths, allowing arbitrary local and UNC file access. Attackers can craft malicious tool-result media references to trigger host-side file reads or...
CVE-2026-3691
- EPSS 0.46%
- Veröffentlicht 11.04.2026 00:17:40
- Zuletzt bearbeitet 27.04.2026 17:10:36
OpenClaw Client PKCE Verifier Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose stored credentials on affected installations of OpenClaw. User interaction is required to exploit this vulnerability in that th...