OpenClaw

OpenClaw

666 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.06%
  • Veröffentlicht 31.03.2026 11:17:22
  • Zuletzt bearbeitet 01.04.2026 14:16:53

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

  • EPSS 0.03%
  • Veröffentlicht 31.03.2026 11:17:22
  • Zuletzt bearbeitet 01.04.2026 14:16:54

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

  • EPSS 0.27%
  • Veröffentlicht 31.03.2026 11:17:21
  • Zuletzt bearbeitet 24.07.2026 22:10:00

OpenClaw before 2026.3.8 contains a sender allowlist bypass vulnerability in its Microsoft Teams plugin that allows unauthorized senders to bypass intended authorization checks. When a team/channel route allowlist is configured with an empty groupAll...

  • EPSS 0.08%
  • Veröffentlicht 31.03.2026 11:17:20
  • Zuletzt bearbeitet 25.07.2026 10:10:00

OpenClaw before 2026.3.11 contains a sandbox boundary bypass vulnerability in fs-bridge staged writes where temporary file creation and population are not pinned to a verified parent directory. Attackers can exploit a race condition in parent-path al...

  • EPSS 0.27%
  • Veröffentlicht 31.03.2026 11:17:20
  • Zuletzt bearbeitet 24.07.2026 22:10:00

OpenClaw before 2026.3.12 applies rate limiting only after successful webhook authentication, allowing attackers to bypass rate limits and brute-force webhook secrets. Attackers can submit repeated authentication requests with invalid secrets without...

  • EPSS 0.42%
  • Veröffentlicht 31.03.2026 11:17:19
  • Zuletzt bearbeitet 25.07.2026 10:10:00

OpenClaw before 2026.3.13 contains an information disclosure vulnerability in the fetchRemoteMedia function that exposes Telegram bot tokens in error messages. When media downloads fail, the original Telegram file URLs containing bot tokens are embed...

  • EPSS 0.08%
  • Veröffentlicht 31.03.2026 11:17:18
  • Zuletzt bearbeitet 25.07.2026 10:10:00

OpenClaw before 2026.3.11 contains a sandbox boundary bypass vulnerability in the fs-bridge writeFile commit step that uses an unanchored container path during the final move operation. An attacker can exploit a time-of-check-time-of-use race conditi...

  • EPSS 0.27%
  • Veröffentlicht 31.03.2026 11:17:17
  • Zuletzt bearbeitet 25.07.2026 10:10:00

OpenClaw before 2026.3.11 contains an approval-integrity vulnerability in node-host system.run approvals that displays extracted shell payloads instead of the executed argv. Attackers can place wrapper binaries and induce wrapper-shaped commands to e...

  • EPSS 0.19%
  • Veröffentlicht 31.03.2026 11:17:17
  • Zuletzt bearbeitet 25.07.2026 10:10:00

OpenClaw before 2026.3.11 contains an authorization bypass vulnerability allowing channel commands to mutate protected sibling-account configuration despite configWrites restrictions. Attackers with authorized access on one account can execute channe...

  • EPSS 0.1%
  • Veröffentlicht 31.03.2026 11:17:16
  • Zuletzt bearbeitet 25.07.2026 10:10:00

OpenClaw before 2026.3.11 contains a credential fallback vulnerability where unavailable local gateway.auth.token and gateway.auth.password SecretRefs are treated as unset, allowing fallback to remote credentials in local mode. Attackers can exploit ...