OpenClaw

OpenClaw

600 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.64%
  • Veröffentlicht 19.03.2026 22:16:34
  • Zuletzt bearbeitet 23.03.2026 18:29:35

OpenClaw versions prior to 2026.2.25 contain a symlink traversal vulnerability in the agents.files.get and agents.files.set methods that allows reading and writing files outside the agent workspace. Attackers can exploit symlinked allowlisted files t...

  • EPSS 0.19%
  • Veröffentlicht 19.03.2026 22:16:34
  • Zuletzt bearbeitet 23.03.2026 19:09:38

OpenClaw versions prior to 2026.2.26 contain a metadata spoofing vulnerability where reconnect platform and deviceFamily fields are accepted from the client without being bound into the device-auth signature. An attacker with a paired node identity o...

  • EPSS 0.13%
  • Veröffentlicht 19.03.2026 22:16:34
  • Zuletzt bearbeitet 25.03.2026 15:16:43

OpenClaw versions 2026.1.21 prior to 2026.2.19 contain a path hijacking vulnerability in tools.exec.safeBins that allows attackers to bypass allowlist checks by controlling process PATH resolution. Attackers who can influence the gateway process PATH...

  • EPSS 0.3%
  • Veröffentlicht 19.03.2026 22:16:33
  • Zuletzt bearbeitet 24.03.2026 21:22:22

OpenClaw versions prior to 2026.2.26 contain an authorization bypass vulnerability where DM pairing-store identities are incorrectly treated as group allowlist identities when dmPolicy=pairing and groupPolicy=allowlist. Remote attackers can send mess...

  • EPSS 0.36%
  • Veröffentlicht 19.03.2026 22:16:33
  • Zuletzt bearbeitet 24.03.2026 21:22:35

OpenClaw versions prior to 2026.2.23 contain a path traversal vulnerability in the experimental apply_patch tool that allows attackers with sandbox access to modify files outside the workspace directory by exploiting inconsistent enforcement of works...

Exploit
  • EPSS 0.4%
  • Veröffentlicht 19.03.2026 22:16:33
  • Zuletzt bearbeitet 23.03.2026 17:34:08

OpenClaw versions prior to 2026.2.21 contain an improper URL scheme validation vulnerability in the assertBrowserNavigationAllowed() function that allows authenticated users with browser-tool access to navigate to file:// URLs. Attackers can exploit ...

  • EPSS 0.13%
  • Veröffentlicht 19.03.2026 22:16:33
  • Zuletzt bearbeitet 23.03.2026 18:33:03

OpenClaw versions prior to 2026.2.24 contain a policy bypass vulnerability in the safeBins allowlist evaluation that trusts static default directories including writable package-manager paths like /opt/homebrew/bin and /usr/local/bin. An attacker wit...

  • EPSS 0.29%
  • Veröffentlicht 19.03.2026 22:16:33
  • Zuletzt bearbeitet 23.03.2026 18:29:04

OpenClaw versions prior to 2026.2.22 contain an allowlist bypass vulnerability in the safe-bin configuration when sort is manually added to tools.exec.safeBins. Attackers can invoke sort with the --compress-program flag to execute arbitrary external ...

  • EPSS 0.27%
  • Veröffentlicht 19.03.2026 22:16:32
  • Zuletzt bearbeitet 23.03.2026 18:51:27

OpenClaw versions prior to 2026.2.22 contain an authentication bypass vulnerability that allows clients authenticated with a shared gateway token to connect as role=node without device identity verification. Attackers can exploit this by claiming the...

  • EPSS 0.32%
  • Veröffentlicht 19.03.2026 22:16:32
  • Zuletzt bearbeitet 23.03.2026 18:53:37

OpenClaw versions prior to 2026.2.23 contain a sandbox bypass vulnerability in the sandboxed image tool that fails to enforce tools.fs.workspaceOnly restrictions on mounted sandbox paths, allowing attackers to read out-of-workspace files. Attackers c...