OpenClaw

OpenClaw

666 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.1%
  • Veröffentlicht 29.03.2026 12:44:21
  • Zuletzt bearbeitet 31.03.2026 18:09:19

OpenClaw before 2026.3.11 contains a session sandbox escape vulnerability in the session_status tool that allows sandboxed subagents to access parent or sibling session state. Attackers can supply arbitrary sessionKey values to read or modify session...

  • EPSS 0.14%
  • Veröffentlicht 29.03.2026 12:44:20
  • Zuletzt bearbeitet 31.03.2026 18:10:23

OpenClaw before 2026.3.11 contains a sandbox boundary bypass vulnerability allowing leaf subagents to access the subagents control surface and resolve against parent requester scope instead of their own session tree. A low-privilege sandboxed leaf wo...

  • EPSS 0.25%
  • Veröffentlicht 29.03.2026 12:44:19
  • Zuletzt bearbeitet 31.03.2026 18:11:06

OpenClaw before 2026.3.12 contains an insufficient access control vulnerability in the /config and /debug command handlers that allows command-authorized non-owners to access owner-only surfaces. Attackers with command authorization can read or modif...

Exploit
  • EPSS 0.69%
  • Veröffentlicht 26.03.2026 16:36:00
  • Zuletzt bearbeitet 08.10.2026 16:17:13

OpenClaw before 2026.3.28 contains a path traversal vulnerability in media parsing that allows attackers to read arbitrary files by bypassing path validation in the isLikelyLocalPath() and isValidMedia() functions. Attackers can exploit incomplete va...

  • EPSS -
  • Veröffentlicht 23.03.2026 21:36:15
  • Zuletzt bearbeitet 23.03.2026 23:17:12

Rejected reason: This CVE ID has been rejected.

  • EPSS 0.32%
  • Veröffentlicht 23.03.2026 21:36:15
  • Zuletzt bearbeitet 24.03.2026 18:01:44

OpenClaw before 2026.3.7 contains an improper header validation vulnerability in fetchWithSsrFGuard that forwards custom authorization headers across cross-origin redirects. Attackers can trigger redirects to different origins to intercept sensitive ...

  • EPSS -
  • Veröffentlicht 23.03.2026 21:36:14
  • Zuletzt bearbeitet 23.03.2026 23:17:12

Rejected reason: This CVE ID has been rejected.

  • EPSS -
  • Veröffentlicht 23.03.2026 21:36:13
  • Zuletzt bearbeitet 23.03.2026 23:17:12

Rejected reason: This CVE ID has been rejected.

  • EPSS -
  • Veröffentlicht 23.03.2026 21:36:12
  • Zuletzt bearbeitet 23.03.2026 23:17:12

Rejected reason: This CVE ID has been rejected.

  • EPSS -
  • Veröffentlicht 23.03.2026 21:36:12
  • Zuletzt bearbeitet 23.03.2026 23:17:12

Rejected reason: This CVE ID has been rejected.