OpenClaw

OpenClaw

666 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.27%
  • Veröffentlicht 10.04.2026 16:03:08
  • Zuletzt bearbeitet 13.04.2026 20:27:19

OpenClaw before 2026.3.24 contains an authorization bypass vulnerability in the HTTP /v1/models endpoint that fails to enforce operator read scope requirements. Attackers with only operator.approvals scope can enumerate gateway model metadata through...

Exploit
  • EPSS 0.42%
  • Veröffentlicht 10.04.2026 05:16:06
  • Zuletzt bearbeitet 30.04.2026 14:22:11

A weakness has been identified in OpenClaw up to 2026.1.26. Affected by this issue is some unknown functionality of the file src/agents/tools/web-fetch.ts of the component assertPublicHostname Handler. Executing a manipulation can lead to server-side...

  • EPSS 0.28%
  • Veröffentlicht 09.04.2026 22:16:34
  • Zuletzt bearbeitet 15.04.2026 19:25:19

OpenClaw before 2026.3.25 contains a privilege escalation vulnerability in the gateway plugin subagent fallback deleteSession function that uses a synthetic operator.admin runtime scope. Attackers can exploit this by triggering session deletion witho...

  • EPSS 0.24%
  • Veröffentlicht 09.04.2026 22:16:34
  • Zuletzt bearbeitet 15.04.2026 18:52:49

OpenClaw before 2026.3.25 contains a pre-authentication rate-limit bypass vulnerability in webhook token validation that allows attackers to brute-force weak webhook secrets. The vulnerability exists because invalid webhook tokens are rejected withou...

  • EPSS 0.29%
  • Veröffentlicht 09.04.2026 22:16:33
  • Zuletzt bearbeitet 15.04.2026 16:52:11

OpenClaw before 2026.3.22 contains a privilege escalation vulnerability in the Control UI that allows unauthenticated sessions to retain self-declared privileged scopes without device identity verification. Attackers can exploit the device-less allow...

  • EPSS 0.46%
  • Veröffentlicht 09.04.2026 22:16:33
  • Zuletzt bearbeitet 15.04.2026 16:51:14

OpenClaw before 2026.3.22 contains a privilege escalation vulnerability in the device.pair.approve method that allows an operator.pairing approver to approve pending device requests with broader operator scopes than the approver actually holds. Attac...

  • EPSS 0.44%
  • Veröffentlicht 09.04.2026 22:16:33
  • Zuletzt bearbeitet 15.04.2026 19:52:39

OpenClaw before 2026.3.25 parses JSON request bodies before validating webhook signatures, allowing unauthenticated attackers to force resource-intensive parsing operations. Remote attackers can send malicious webhook requests to trigger denial of se...

  • EPSS 0.2%
  • Veröffentlicht 09.04.2026 22:16:33
  • Zuletzt bearbeitet 15.04.2026 19:39:31

OpenClaw before 2026.3.25 contains an authorization bypass vulnerability where group reaction events bypass the requireMention access control mechanism. Attackers can trigger reactions in mention-gated groups to enqueue agent-visible system events th...

  • EPSS 0.19%
  • Veröffentlicht 09.04.2026 22:16:33
  • Zuletzt bearbeitet 15.04.2026 16:03:03

OpenClaw before 2026.3.22 contains an information disclosure vulnerability that allows attackers with operator.read scope to expose credentials embedded in channel baseUrl and httpUrl fields. Attackers can access gateway snapshots via config.get and ...

Exploit
  • EPSS 0.32%
  • Veröffentlicht 09.04.2026 22:16:32
  • Zuletzt bearbeitet 15.04.2026 17:09:56

OpenClaw through 2026.2.22 contains a symlink traversal vulnerability in agents.create and agents.update handlers that use fs.appendFile on IDENTITY.md without symlink containment checks. Attackers with workspace access can plant symlinks to append a...