CVE-2026-100556
- EPSS 0.28%
- Veröffentlicht 26.09.2026 02:18:50
- Zuletzt bearbeitet 30.09.2026 01:16:34
OpenClaw (npm package openclaw) versions >= 2026.5.2 and < 2026.8.1 contain an incorrect authorization vulnerability in WhatsApp group handling. A group sender who is admitted for ordinary messages but denied by commands.allowFrom or owner command au...
CVE-2026-100554
- EPSS 0.22%
- Veröffentlicht 26.09.2026 02:18:49
- Zuletzt bearbeitet 28.09.2026 18:17:12
OpenClaw (npm package 'openclaw') versions >= 2026.5.12 and < 2026.8.1 do not immediately invalidate Canvas HTTP authorization when a paired node is revoked. Node revocation invalidates the WebSocket client, but Canvas HTTP authorization continues to...
CVE-2026-100555
- EPSS 0.2%
- Veröffentlicht 26.09.2026 02:18:49
- Zuletzt bearbeitet 05.10.2026 15:17:11
OpenClaw is an npm-distributed gateway application. In versions >= 2026.7.1 and < 2026.8.1, Synology Chat attachment delivery could lose DNS pinning: the Gateway validated a single DNS result for a supplied file URL but then passed the original hostn...
CVE-2026-100553
- EPSS 0.22%
- Veröffentlicht 26.09.2026 02:18:48
- Zuletzt bearbeitet 29.09.2026 17:17:02
OpenClaw versions >= 2026.6.9 and < 2026.8.1 do not declare the native chatId parameter as a delivery target in the Feishu unpin feature, so unpin requests can bypass the shared same-provider cross-context target check. When tools.message.crossContex...
CVE-2026-100552
- EPSS 0.26%
- Veröffentlicht 26.09.2026 02:18:47
- Zuletzt bearbeitet 30.09.2026 01:16:34
OpenClaw (npm package 'openclaw') before 2026.8.1 does not correctly enforce per-chat tool policies for Codex app-server runtime tools. A conversation-level tools.allow rule filtered OpenClaw tools but did not restrict the shell, process, file, and p...
- EPSS 0.17%
- Veröffentlicht 26.09.2026 02:18:46
- Zuletzt bearbeitet 05.10.2026 15:17:11
OpenClaw for iOS versions >= 2026.7.1 and < 2026.8.11 do not enforce saved Gateway TLS pins in the Control UI. While native connections enforced the saved Gateway fingerprint, the authenticated Terminal and session Dashboard WebViews omitted it. If a...
CVE-2026-100549
- EPSS 0.28%
- Veröffentlicht 26.09.2026 02:18:45
- Zuletzt bearbeitet 29.09.2026 17:17:02
OpenClaw versions before 2026.8.1 contain a path traversal vulnerability in QQBot voice attachment handling where filenames are decoded twice, allowing encoded traversal segments to reappear after sanitization. Attackers can supply crafted voice atta...
CVE-2026-100550
- EPSS 0.19%
- Veröffentlicht 26.09.2026 02:18:45
- Zuletzt bearbeitet 28.09.2026 18:17:12
OpenClaw (npm package 'openclaw') before 2026.8.1 contains an access-control bypass in the Microsoft Teams integration. When groupPolicy is set to allowlist, a missing or unsupported configured access group produces a denied group-resolution result t...
CVE-2026-100547
- EPSS 0.13%
- Veröffentlicht 26.09.2026 02:18:43
- Zuletzt bearbeitet 05.10.2026 15:17:10
OpenClaw is a coding agent distributed as the npm package `openclaw`. In affected versions (2026.7.1 through 2026.7.2), alternate but valid `file:` URL spellings supplied over the Agent Client Protocol (ACP) were treated as relative paths and were in...
- EPSS 0.25%
- Veröffentlicht 26.09.2026 02:18:43
- Zuletzt bearbeitet 30.09.2026 01:16:33
OpenClaw (npm package 'openclaw') versions >= 2026.3.28 and < 2026.8.1 contain a credential exposure issue in memory embedding failover. When remote embedding fallback is configured and the primary embedding provider fails, the request can be sent to...