OpenClaw

OpenClaw

666 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.12%
  • Veröffentlicht 26.09.2026 02:18:58
  • Zuletzt bearbeitet 30.09.2026 01:16:34

OpenClaw is an npm-distributed application. In versions >= 2026.4.25 and < 2026.8.1, the workspace environment-variable filter did not block variables ending in `_ENDPOINT`, so an untrusted workspace `.env` file could set AZURE_SPEECH_ENDPOINT. Azure...

  • EPSS 0.25%
  • Veröffentlicht 26.09.2026 02:18:57
  • Zuletzt bearbeitet 28.09.2026 18:17:13

OpenClaw is an agent gateway distributed as the npm package 'openclaw'. In versions >= 2026.4.5 and < 2026.8.1, the Gateway validated a single DNS resolution result for a configured remote Chrome DevTools Protocol (CDP) hostname, but the raw WebSocke...

  • EPSS 0.19%
  • Veröffentlicht 26.09.2026 02:18:56
  • Zuletzt bearbeitet 30.09.2026 01:16:34

OpenClaw versions before 2026.8.1 fail to neutralize spreadsheet formula characters in participant display names within attendance CSV exports. Attackers can inject formula-like cells that execute with spreadsheet user permissions when the export is ...

  • EPSS 0.19%
  • Veröffentlicht 26.09.2026 02:18:55
  • Zuletzt bearbeitet 05.10.2026 15:17:11

OpenClaw (npm package `openclaw`) before 2026.8.1 does not neutralize leading characters that spreadsheet applications interpret as formulas when the Control UI exports session data to CSV. Although session labels were quoted as CSV text, a lower-tru...

  • EPSS 0.19%
  • Veröffentlicht 26.09.2026 02:18:54
  • Zuletzt bearbeitet 28.09.2026 18:17:12

OpenClaw versions before 2026.8.1 contain an authorization bypass vulnerability in the sessions.create endpoint that allows operator.write callers to modify session configurations reserved for operator.admin scope. Attackers with write-scoped credent...

  • EPSS 0.58%
  • Veröffentlicht 26.09.2026 02:18:53
  • Zuletzt bearbeitet 30.09.2026 01:16:34

OpenClaw versions before 2026.8.1 contain an authorization bypass vulnerability where Allow Always approvals for exact commands persist as path-only grants on macOS and Linux. Attackers can reuse the same executable with different arguments to execut...

  • EPSS 0.25%
  • Veröffentlicht 26.09.2026 02:18:53
  • Zuletzt bearbeitet 29.09.2026 17:17:02

OpenClaw (npm package 'openclaw') versions >= 2026.3.22 and < 2026.8.1 contain an approval-bypass flaw in the exec approval policy: the policy could trust a command-running wrapper without inspecting the command carried in its arguments. After an ope...

  • EPSS 0.25%
  • Veröffentlicht 26.09.2026 02:18:52
  • Zuletzt bearbeitet 05.10.2026 15:17:11

OpenClaw versions before 2026.8.1 contain a command parser vulnerability where escaped newlines confuse exec allowlist parsing, allowing hidden commands to execute. Attackers can craft input with escaped newlines to bypass allowlist validation and ex...

  • EPSS 0.24%
  • Veröffentlicht 26.09.2026 02:18:51
  • Zuletzt bearbeitet 29.09.2026 17:17:02

OpenClaw versions before 2026.8.1 contain an authorization bypass vulnerability in skill tool dispatch that fails to carry the sender's owner status. Non-owner senders authorized to invoke skill commands can access owner-only tools and server credent...

  • EPSS 0.28%
  • Veröffentlicht 26.09.2026 02:18:51
  • Zuletzt bearbeitet 28.09.2026 18:17:12

OpenClaw versions before 2026.8.1 contain a resource exhaustion vulnerability in the Gateway listener that allows unauthenticated clients to retain response sockets by sending WebSocket upgrade requests without matching connection semantics. Attacker...