CVE-2026-32022
- EPSS 0.26%
- Veröffentlicht 19.03.2026 22:16:36
- Zuletzt bearbeitet 26.05.2026 14:16:32
OpenClaw versions prior to 2026.2.21 contain a stdin-only policy bypass vulnerability in the grep tool within tools.exec.safeBins that allows attackers to read arbitrary files by supplying a pattern via the -e flag parameter. Attackers can include a ...
CVE-2026-32023
- EPSS 0.28%
- Veröffentlicht 19.03.2026 22:16:36
- Zuletzt bearbeitet 25.03.2026 15:16:45
OpenClaw versions prior to 2026.2.24 contain an approval gating bypass vulnerability in system.run allowlist mode where nested transparent dispatch wrappers can suppress shell-wrapper detection. Attackers can exploit this by chaining multiple dispatc...
CVE-2026-32024
- EPSS 0.33%
- Veröffentlicht 19.03.2026 22:16:36
- Zuletzt bearbeitet 23.03.2026 17:46:50
OpenClaw versions prior to 2026.2.22 contain a symlink traversal vulnerability in avatar handling that allows attackers to read arbitrary files outside the configured workspace boundary. Remote attackers can exploit this by requesting avatar resource...
CVE-2026-32016
- EPSS 0.12%
- Veröffentlicht 19.03.2026 22:16:35
- Zuletzt bearbeitet 25.03.2026 15:16:43
OpenClaw versions prior to 2026.2.22 on macOS contain a path validation bypass vulnerability in the exec-approval allowlist mode that allows local attackers to execute unauthorized binaries by exploiting basename-only allowlist entries. Attackers can...
CVE-2026-32017
- EPSS 0.26%
- Veröffentlicht 19.03.2026 22:16:35
- Zuletzt bearbeitet 25.03.2026 15:16:44
OpenClaw versions prior to 2026.2.19 contain an allowlist bypass vulnerability in the exec safeBins policy that allows attackers to write arbitrary files using short-option payloads. Attackers can bypass argument validation by attaching short options...
CVE-2026-32018
- EPSS 0.13%
- Veröffentlicht 19.03.2026 22:16:35
- Zuletzt bearbeitet 20.04.2026 14:03:44
OpenClaw versions prior to 2026.2.19 contain a race condition vulnerability in concurrent updateRegistry and removeRegistryEntry operations for sandbox containers and browsers. Attackers can exploit unsynchronized read-modify-write operations without...
CVE-2026-32019
- EPSS 0.21%
- Veröffentlicht 19.03.2026 22:16:35
- Zuletzt bearbeitet 20.04.2026 13:51:07
OpenClaw versions prior to 2026.2.22 contain incomplete IPv4 special-use range validation in the isPrivateIpv4() function, allowing requests to RFC-reserved ranges to bypass SSRF policy checks. Attackers with network reachability to special-use IPv4 ...
CVE-2026-32020
- EPSS 0.13%
- Veröffentlicht 19.03.2026 22:16:35
- Zuletzt bearbeitet 23.03.2026 18:13:56
OpenClaw versions prior to 2026.2.22 contain a path traversal vulnerability in the static file handler that follows symbolic links, allowing out-of-root file reads. Attackers can place symlinks under the Control UI root directory to bypass directory ...
CVE-2026-32011
- EPSS 0.42%
- Veröffentlicht 19.03.2026 22:16:34
- Zuletzt bearbeitet 23.03.2026 18:29:20
OpenClaw versions prior to 2026.3.2 contain a denial of service vulnerability in webhook handlers for BlueBubbles and Google Chat that parse request bodies before performing authentication and signature validation. Unauthenticated attackers can explo...
CVE-2026-32013
- EPSS 0.64%
- Veröffentlicht 19.03.2026 22:16:34
- Zuletzt bearbeitet 23.03.2026 18:29:35
OpenClaw versions prior to 2026.2.25 contain a symlink traversal vulnerability in the agents.files.get and agents.files.set methods that allows reading and writing files outside the agent workspace. Attackers can exploit symlinked allowlisted files t...