CVE-2026-53820
- EPSS 0.09%
- Veröffentlicht 12.06.2026 22:16:53
- Zuletzt bearbeitet 16.06.2026 02:53:24
OpenClaw before 2026.5.12 contains an exec denylist bypass vulnerability in the bundle MCP loopback session-spawn path that allows authenticated callers to bypass intended command restrictions. Attackers can reach the affected bundled MCP session-spa...
CVE-2026-53821
- EPSS 0.29%
- Veröffentlicht 12.06.2026 22:16:53
- Zuletzt bearbeitet 16.06.2026 02:53:11
OpenClaw before 2026.5.18 accepts WebSocket client-declared operator scopes before binding to server-approved pairing or trusted-proxy authorization baseline. Unpaired or restricted trusted-proxy Control UI clients can obtain cached operator.admin au...
CVE-2026-53822
- EPSS 0.98%
- Veröffentlicht 12.06.2026 22:16:53
- Zuletzt bearbeitet 16.06.2026 02:52:56
OpenClaw before 2026.5.18 contains a command injection vulnerability where shell wrapper argv could change between approval and execution. Attackers can rebuild command arguments after allowlist approval to execute unapproved command shapes, potentia...
CVE-2026-53823
- EPSS 0.21%
- Veröffentlicht 12.06.2026 22:16:53
- Zuletzt bearbeitet 16.06.2026 02:52:26
OpenClaw before 2026.5.3 contains a privilege escalation vulnerability in the allowFrom feature that binds to mutable Slack display names. Attackers with Slack account access can change display name metadata to match policy entries, potentially gaini...
CVE-2026-53824
- EPSS 0.18%
- Veröffentlicht 12.06.2026 22:16:53
- Zuletzt bearbeitet 16.06.2026 02:51:29
OpenClaw before 2026.4.24 contains a token revocation vulnerability allowing callers with revoked slash tokens to continue executing commands during monitor refresh windows. Attackers can exploit stale token acceptance to invoke slash command behavio...
CVE-2026-53825
- EPSS 0.38%
- Veröffentlicht 12.06.2026 22:16:53
- Zuletzt bearbeitet 16.06.2026 02:49:17
OpenClaw before 2026.4.7 contains an arbitrary file read vulnerability in the memory-wiki ingest feature that allows authenticated Gateway operators with operator.write scope to read local files outside intended ingest sources. Attackers with operato...
CVE-2026-53826
- EPSS 0.19%
- Veröffentlicht 12.06.2026 22:16:53
- Zuletzt bearbeitet 16.06.2026 02:48:51
OpenClaw before 2026.4.26 contains an information disclosure vulnerability in sandboxed session spawning that exposes the real workspace path to child prompts. Attackers can exploit this by spawning child sessions from sandboxed parents to reveal hos...
CVE-2026-53819
- EPSS 0.3%
- Veröffentlicht 11.06.2026 20:10:24
- Zuletzt bearbeitet 12.06.2026 20:08:46
OpenClaw before 2026.5.27 contains an arbitrary code execution vulnerability in skill install flows where workspace .env files can override the Homebrew executable selection. Attackers with access to trusted operator workspaces can execute unintended...
CVE-2026-53818
- EPSS 0.1%
- Veröffentlicht 11.06.2026 20:09:57
- Zuletzt bearbeitet 12.06.2026 20:08:06
OpenClaw before 2026.4.24 contains an authorization bypass vulnerability in the MCP loopback feature that allows non-owner callers to skip owner-only tool policies and before-tool-call hooks. Attackers can invoke owner-only behavior through the affec...
CVE-2026-53817
- EPSS 0.31%
- Veröffentlicht 11.06.2026 20:09:38
- Zuletzt bearbeitet 12.06.2026 20:08:17
OpenClaw before 2026.5.22 contains a locality validation vulnerability in Control UI pairing that allows attackers with network access to spoof locality information and obtain durable admin-capable device tokens. Attackers can exploit insufficient lo...