OpenClaw

OpenClaw

666 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.28%
  • Veröffentlicht 26.09.2026 02:18:50
  • Zuletzt bearbeitet 30.09.2026 01:16:34

OpenClaw (npm package openclaw) versions >= 2026.5.2 and < 2026.8.1 contain an incorrect authorization vulnerability in WhatsApp group handling. A group sender who is admitted for ordinary messages but denied by commands.allowFrom or owner command au...

  • EPSS 0.22%
  • Veröffentlicht 26.09.2026 02:18:49
  • Zuletzt bearbeitet 28.09.2026 18:17:12

OpenClaw (npm package 'openclaw') versions >= 2026.5.12 and < 2026.8.1 do not immediately invalidate Canvas HTTP authorization when a paired node is revoked. Node revocation invalidates the WebSocket client, but Canvas HTTP authorization continues to...

  • EPSS 0.2%
  • Veröffentlicht 26.09.2026 02:18:49
  • Zuletzt bearbeitet 05.10.2026 15:17:11

OpenClaw is an npm-distributed gateway application. In versions >= 2026.7.1 and < 2026.8.1, Synology Chat attachment delivery could lose DNS pinning: the Gateway validated a single DNS result for a supplied file URL but then passed the original hostn...

  • EPSS 0.22%
  • Veröffentlicht 26.09.2026 02:18:48
  • Zuletzt bearbeitet 29.09.2026 17:17:02

OpenClaw versions >= 2026.6.9 and < 2026.8.1 do not declare the native chatId parameter as a delivery target in the Feishu unpin feature, so unpin requests can bypass the shared same-provider cross-context target check. When tools.message.crossContex...

  • EPSS 0.26%
  • Veröffentlicht 26.09.2026 02:18:47
  • Zuletzt bearbeitet 30.09.2026 01:16:34

OpenClaw (npm package 'openclaw') before 2026.8.1 does not correctly enforce per-chat tool policies for Codex app-server runtime tools. A conversation-level tools.allow rule filtered OpenClaw tools but did not restrict the shell, process, file, and p...

  • EPSS 0.17%
  • Veröffentlicht 26.09.2026 02:18:46
  • Zuletzt bearbeitet 05.10.2026 15:17:11

OpenClaw for iOS versions >= 2026.7.1 and < 2026.8.11 do not enforce saved Gateway TLS pins in the Control UI. While native connections enforced the saved Gateway fingerprint, the authenticated Terminal and session Dashboard WebViews omitted it. If a...

  • EPSS 0.28%
  • Veröffentlicht 26.09.2026 02:18:45
  • Zuletzt bearbeitet 29.09.2026 17:17:02

OpenClaw versions before 2026.8.1 contain a path traversal vulnerability in QQBot voice attachment handling where filenames are decoded twice, allowing encoded traversal segments to reappear after sanitization. Attackers can supply crafted voice atta...

  • EPSS 0.19%
  • Veröffentlicht 26.09.2026 02:18:45
  • Zuletzt bearbeitet 28.09.2026 18:17:12

OpenClaw (npm package 'openclaw') before 2026.8.1 contains an access-control bypass in the Microsoft Teams integration. When groupPolicy is set to allowlist, a missing or unsupported configured access group produces a denied group-resolution result t...

  • EPSS 0.13%
  • Veröffentlicht 26.09.2026 02:18:43
  • Zuletzt bearbeitet 05.10.2026 15:17:10

OpenClaw is a coding agent distributed as the npm package `openclaw`. In affected versions (2026.7.1 through 2026.7.2), alternate but valid `file:` URL spellings supplied over the Agent Client Protocol (ACP) were treated as relative paths and were in...

  • EPSS 0.25%
  • Veröffentlicht 26.09.2026 02:18:43
  • Zuletzt bearbeitet 30.09.2026 01:16:33

OpenClaw (npm package 'openclaw') versions >= 2026.3.28 and < 2026.8.1 contain a credential exposure issue in memory embedding failover. When remote embedding fallback is configured and the primary embedding provider fails, the request can be sent to...