OpenClaw

OpenClaw

666 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.2%
  • Veröffentlicht 31.03.2026 11:17:15
  • Zuletzt bearbeitet 25.07.2026 10:10:00

OpenClaw before 2026.3.8 contains an approval bypass vulnerability in system.run where mutable script operands are not bound across approval and execution phases. Attackers can obtain approval for script execution, modify the approved script file bef...

  • EPSS 0.33%
  • Veröffentlicht 31.03.2026 11:17:14
  • Zuletzt bearbeitet 25.07.2026 10:10:00

OpenClaw before 2026.3.12 automatically discovers and loads plugins from .OpenClaw/extensions/ without explicit trust verification, allowing arbitrary code execution. Attackers can execute malicious code by including crafted workspace plugins in clon...

  • EPSS 0.46%
  • Veröffentlicht 31.03.2026 11:17:13
  • Zuletzt bearbeitet 25.07.2026 10:10:00

OpenClaw versions 2026.3.7 before 2026.3.11 contain an authorization bypass vulnerability where plugin subagent routes execute gateway methods through a synthetic operator client with broad administrative scopes. Remote unauthenticated requests to pl...

  • EPSS 1.97%
  • Veröffentlicht 31.03.2026 11:17:13
  • Zuletzt bearbeitet 25.07.2026 10:10:00

OpenClaw before 2026.3.13 contains a remote command injection vulnerability in the iMessage attachment staging flow that allows attackers to execute arbitrary commands on configured remote hosts. The vulnerability exists because unsanitized remote at...

  • EPSS 0.25%
  • Veröffentlicht 29.03.2026 12:44:32
  • Zuletzt bearbeitet 30.03.2026 15:51:26

OpenClaw before 2026.3.12 embeds long-lived shared gateway credentials directly in pairing setup codes generated by /pair endpoint and OpenClaw qr command. Attackers with access to leaked setup codes from chat history, logs, or screenshots can recove...

  • EPSS 0.3%
  • Veröffentlicht 29.03.2026 12:44:31
  • Zuletzt bearbeitet 30.03.2026 15:51:37

OpenClaw before 2026.3.11 contains an authorization bypass vulnerability in the gateway agent RPC that allows authenticated operators with operator.write permission to override workspace boundaries by supplying attacker-controlled spawnedBy and works...

  • EPSS 0.09%
  • Veröffentlicht 29.03.2026 12:44:31
  • Zuletzt bearbeitet 31.03.2026 17:12:54

OpenClaw before 2026.3.8 contains a path traversal vulnerability in the skills download installer that validates the tools root lexically but reuses the mutable path during archive download and copy operations. A local attacker can rebind the tools-r...

  • EPSS 0.12%
  • Veröffentlicht 29.03.2026 12:44:30
  • Zuletzt bearbeitet 31.03.2026 17:37:29

OpenClaw before 2026.2.17 creates session transcript JSONL files with overly broad default permissions, allowing local users to read transcript contents. Attackers with local access can read transcript files to extract sensitive information including...

  • EPSS 0.35%
  • Veröffentlicht 29.03.2026 12:44:29
  • Zuletzt bearbeitet 31.03.2026 17:53:28

OpenClaw before 2026.3.13 allows bootstrap setup codes to be replayed during device pairing verification in src/infra/device-bootstrap.ts. Attackers can verify a valid bootstrap code multiple times before approval to escalate pending pairing scopes, ...

  • EPSS 0.13%
  • Veröffentlicht 29.03.2026 12:44:28
  • Zuletzt bearbeitet 30.03.2026 15:56:55

OpenClaw before 2026.3.11 contains an approval integrity vulnerability allowing attackers to execute rewritten local code by modifying scripts between approval and execution when exact file binding cannot occur. Remote attackers can change approved l...