OpenClaw

OpenClaw

666 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.21%
  • Veröffentlicht 21.03.2026 00:42:22
  • Zuletzt bearbeitet 23.03.2026 17:08:52

OpenClaw versions prior to 2026.2.25 contain an access control vulnerability in signal reaction notification handling that allows unauthorized senders to enqueue status events before authorization checks are applied. Attackers can exploit the reactio...

  • EPSS 0.28%
  • Veröffentlicht 21.03.2026 00:42:21
  • Zuletzt bearbeitet 24.03.2026 19:13:59

OpenClaw versions prior to 2026.3.1 fail to enforce sandbox inheritance during cross-agent sessions_spawn operations, allowing sandboxed sessions to create child processes under unsandboxed agents. An attacker with a sandboxed session can exploit thi...

  • EPSS 0.54%
  • Veröffentlicht 21.03.2026 00:42:21
  • Zuletzt bearbeitet 23.03.2026 17:09:08

OpenClaw versions prior to 2026.2.22 fail to consistently enforce configured inbound media byte limits before buffering remote media across multiple channel ingestion paths. Remote attackers can send oversized media payloads to trigger elevated memor...

  • EPSS 0.29%
  • Veröffentlicht 21.03.2026 00:42:20
  • Zuletzt bearbeitet 24.03.2026 19:12:10

OpenClaw versions prior to 2026.2.21 contain an improper sandbox configuration vulnerability that allows attackers to execute arbitrary code by exploiting renderer-side vulnerabilities without requiring a sandbox escape. Attackers can leverage the di...

  • EPSS 0.4%
  • Veröffentlicht 21.03.2026 00:42:19
  • Zuletzt bearbeitet 24.03.2026 21:16:28

OpenClaw versions prior to 2026.2.21 incorrectly apply tokenless Tailscale header authentication to HTTP gateway routes, allowing bypass of token and password requirements. Attackers on trusted networks can exploit this misconfiguration to access HTT...

  • EPSS 0.1%
  • Veröffentlicht 21.03.2026 00:42:18
  • Zuletzt bearbeitet 24.03.2026 19:10:25

OpenClaw versions prior to 2026.2.25 contain a time-of-check-time-of-use vulnerability in approval-bound system.run execution where the cwd parameter is validated at approval time but resolved at execution time. Attackers can retarget a symlinked cwd...

  • EPSS 0.13%
  • Veröffentlicht 21.03.2026 00:42:18
  • Zuletzt bearbeitet 23.03.2026 17:10:11

OpenClaw versions prior to 2026.3.2 contain an archive extraction vulnerability in the tar.bz2 installer path that bypasses safety checks enforced on other archive formats. Attackers can craft malicious tar.bz2 skill archives to bypass special-entry ...

  • EPSS 0.44%
  • Veröffentlicht 21.03.2026 00:42:17
  • Zuletzt bearbeitet 23.03.2026 17:10:21

OpenClaw versions 2026.2.22 prior to 2026.2.25 contain a privilege escalation vulnerability allowing unpaired device identities to bypass operator pairing requirements and self-assign elevated operator scopes including operator.admin. Attackers with ...

  • EPSS 0.51%
  • Veröffentlicht 20.03.2026 14:48:28
  • Zuletzt bearbeitet 24.03.2026 21:20:45

OpenClaw versions prior to 2026.3.12 contain an authorization bypass vulnerability in the WebSocket connect path that allows shared-token or password-authenticated connections to self-declare elevated scopes without server-side binding. Attackers can...

  • EPSS 0.19%
  • Veröffentlicht 19.03.2026 22:16:40
  • Zuletzt bearbeitet 23.03.2026 17:19:19

OpenClaw versions prior to 2026.2.22 contain an authorization bypass vulnerability in the toolsBySender group policy matching that allows attackers to inherit elevated tool permissions through identifier collision attacks. Attackers can exploit untyp...