CVE-2026-100569
- EPSS 0.12%
- Veröffentlicht 26.09.2026 02:18:58
- Zuletzt bearbeitet 30.09.2026 01:16:34
OpenClaw is an npm-distributed application. In versions >= 2026.4.25 and < 2026.8.1, the workspace environment-variable filter did not block variables ending in `_ENDPOINT`, so an untrusted workspace `.env` file could set AZURE_SPEECH_ENDPOINT. Azure...
CVE-2026-100567
- EPSS 0.25%
- Veröffentlicht 26.09.2026 02:18:57
- Zuletzt bearbeitet 28.09.2026 18:17:13
OpenClaw is an agent gateway distributed as the npm package 'openclaw'. In versions >= 2026.4.5 and < 2026.8.1, the Gateway validated a single DNS resolution result for a configured remote Chrome DevTools Protocol (CDP) hostname, but the raw WebSocke...
CVE-2026-100564
- EPSS 0.19%
- Veröffentlicht 26.09.2026 02:18:56
- Zuletzt bearbeitet 30.09.2026 01:16:34
OpenClaw versions before 2026.8.1 fail to neutralize spreadsheet formula characters in participant display names within attendance CSV exports. Attackers can inject formula-like cells that execute with spreadsheet user permissions when the export is ...
CVE-2026-100563
- EPSS 0.19%
- Veröffentlicht 26.09.2026 02:18:55
- Zuletzt bearbeitet 05.10.2026 15:17:11
OpenClaw (npm package `openclaw`) before 2026.8.1 does not neutralize leading characters that spreadsheet applications interpret as formulas when the Control UI exports session data to CSV. Although session labels were quoted as CSV text, a lower-tru...
CVE-2026-100562
- EPSS 0.19%
- Veröffentlicht 26.09.2026 02:18:54
- Zuletzt bearbeitet 28.09.2026 18:17:12
OpenClaw versions before 2026.8.1 contain an authorization bypass vulnerability in the sessions.create endpoint that allows operator.write callers to modify session configurations reserved for operator.admin scope. Attackers with write-scoped credent...
CVE-2026-100560
- EPSS 0.58%
- Veröffentlicht 26.09.2026 02:18:53
- Zuletzt bearbeitet 30.09.2026 01:16:34
OpenClaw versions before 2026.8.1 contain an authorization bypass vulnerability where Allow Always approvals for exact commands persist as path-only grants on macOS and Linux. Attackers can reuse the same executable with different arguments to execut...
CVE-2026-100561
- EPSS 0.25%
- Veröffentlicht 26.09.2026 02:18:53
- Zuletzt bearbeitet 29.09.2026 17:17:02
OpenClaw (npm package 'openclaw') versions >= 2026.3.22 and < 2026.8.1 contain an approval-bypass flaw in the exec approval policy: the policy could trust a command-running wrapper without inspecting the command carried in its arguments. After an ope...
CVE-2026-100559
- EPSS 0.25%
- Veröffentlicht 26.09.2026 02:18:52
- Zuletzt bearbeitet 05.10.2026 15:17:11
OpenClaw versions before 2026.8.1 contain a command parser vulnerability where escaped newlines confuse exec allowlist parsing, allowing hidden commands to execute. Attackers can craft input with escaped newlines to bypass allowlist validation and ex...
CVE-2026-100557
- EPSS 0.24%
- Veröffentlicht 26.09.2026 02:18:51
- Zuletzt bearbeitet 29.09.2026 17:17:02
OpenClaw versions before 2026.8.1 contain an authorization bypass vulnerability in skill tool dispatch that fails to carry the sender's owner status. Non-owner senders authorized to invoke skill commands can access owner-only tools and server credent...
CVE-2026-100558
- EPSS 0.28%
- Veröffentlicht 26.09.2026 02:18:51
- Zuletzt bearbeitet 28.09.2026 18:17:12
OpenClaw versions before 2026.8.1 contain a resource exhaustion vulnerability in the Gateway listener that allows unauthenticated clients to retain response sockets by sending WebSocket upgrade requests without matching connection semantics. Attacker...