OpenClaw

OpenClaw

559 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.22%
  • Veröffentlicht 18.03.2026 02:16:22
  • Zuletzt bearbeitet 25.03.2026 15:16:36

OpenClaw versions prior to 2026.3.2 contain a DNS pinning bypass vulnerability in strict URL fetch paths that allows attackers to circumvent SSRF guards when environment proxy variables are configured. When HTTP_PROXY, HTTPS_PROXY, or ALL_PROXY envir...

  • EPSS 0.26%
  • Veröffentlicht 18.03.2026 02:16:21
  • Zuletzt bearbeitet 25.03.2026 15:16:36

OpenClaw versions prior to 2026.2.22 with the optional BlueBubbles plugin contain an access control bypass vulnerability where empty allowFrom configuration causes dmPolicy pairing and allowlist restrictions to be ineffective. Remote attackers can se...

  • EPSS 0.34%
  • Veröffentlicht 18.03.2026 02:16:21
  • Zuletzt bearbeitet 19.03.2026 14:52:49

OpenClaw versions prior to 2026.2.19 contain a path traversal vulnerability in the Feishu media download flow where untrusted media keys are interpolated directly into temporary file paths in extensions/feishu/src/media.ts. An attacker who can contro...

  • EPSS 0.13%
  • Veröffentlicht 18.03.2026 02:16:21
  • Zuletzt bearbeitet 25.03.2026 15:16:36

OpenClaw versions prior to 2026.2.22 inject the x-OpenClaw-relay-token header into Chrome CDP probe traffic on loopback interfaces, allowing local processes to capture the Gateway authentication token. An attacker controlling a loopback port can inte...

  • EPSS 0.33%
  • Veröffentlicht 18.03.2026 02:16:21
  • Zuletzt bearbeitet 19.03.2026 16:06:32

OpenClaw versions prior to 2026.2.23 contain an exec approval bypass vulnerability in allowlist mode where allow-always grants could be circumvented through unrecognized multiplexer shell wrappers like busybox and toybox sh -c commands. Attackers can...

  • EPSS 0.37%
  • Veröffentlicht 18.03.2026 02:16:21
  • Zuletzt bearbeitet 08.04.2026 17:21:14

OpenClaw versions prior to 2026.2.21 fail to filter dangerous process-control environment variables from config env.vars, allowing startup-time code execution. Attackers can inject variables like NODE_OPTIONS or LD_* through configuration to execute ...

  • EPSS 0.41%
  • Veröffentlicht 18.03.2026 02:16:20
  • Zuletzt bearbeitet 19.03.2026 14:48:09

OpenClaw versions prior to 2026.2.21 contain an approval-integrity mismatch vulnerability in system.run that allows authenticated operators to execute arbitrary trailing arguments after cmd.exe /c while approval text reflects only a benign command. A...

  • EPSS 0.2%
  • Veröffentlicht 18.03.2026 02:16:20
  • Zuletzt bearbeitet 25.03.2026 15:16:35

OpenClaw versions prior to 2026.2.22 contain an allowlist bypass vulnerability in the safeBins configuration that allows attackers to invoke external helpers through the compress-program option. When sort is explicitly added to tools.exec.safeBins, r...

  • EPSS 0.15%
  • Veröffentlicht 12.03.2026 21:22:29
  • Zuletzt bearbeitet 24.03.2026 21:36:21

OpenClaw is a personal AI assistant. Prior to 2026.3.11, browser-originated WebSocket connections could bypass origin validation when gateway.auth.mode was set to trusted-proxy and the request arrived with proxy headers. A page served from an untrust...

  • EPSS 0.32%
  • Veröffentlicht 12.03.2026 12:15:59
  • Zuletzt bearbeitet 16.03.2026 18:02:55

A vulnerability was determined in OpenClaw 2026.2.19-2. This vulnerability affects the function applySkillConfigenvOverrides of the component Skill Env Handler. Executing a manipulation can lead to code injection. It is possible to launch the attack ...