OpenClaw

OpenClaw

559 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.44%
  • Veröffentlicht 05.03.2026 21:59:53
  • Zuletzt bearbeitet 17.03.2026 18:03:34

OpenClaw versions prior to 2026.2.13 contain a denial of service vulnerability in webhook handlers that buffer request bodies without strict byte or time limits. Remote unauthenticated attackers can send oversized JSON payloads or slow uploads to web...

  • EPSS 0.13%
  • Veröffentlicht 05.03.2026 21:59:52
  • Zuletzt bearbeitet 17.03.2026 18:04:14

OpenClaw versions prior to 2026.2.14 contain an oauth state validation bypass vulnerability in the manual Chutes login flow that allows attackers to bypass CSRF protection. An attacker can convince a user to paste attacker-controlled OAuth callback d...

  • EPSS 0.24%
  • Veröffentlicht 05.03.2026 21:59:51
  • Zuletzt bearbeitet 21.04.2026 14:52:03

OpenClaw versions prior to 2026.2.14 contain a server-side request forgery vulnerability in the optional Tlon Urbit extension that accepts user-provided base URLs for authentication without proper validation. Attackers who can influence the configure...

  • EPSS 0.28%
  • Veröffentlicht 05.03.2026 21:59:50
  • Zuletzt bearbeitet 11.03.2026 16:17:15

OpenClaw versions prior to 2026.2.13 use non-constant-time string comparison for hook token validation, allowing attackers to infer tokens through timing measurements. Remote attackers with network access to the hooks endpoint can exploit timing side...

  • EPSS 0.28%
  • Veröffentlicht 05.03.2026 21:59:49
  • Zuletzt bearbeitet 11.03.2026 16:18:20

OpenClaw versions prior to 2026.2.2 contain an authorization bypass vulnerability where clients with operator.write scope can approve or deny exec approval requests by sending the /approve chat command. The /approve command path invokes exec.approval...

  • EPSS 0.49%
  • Veröffentlicht 05.03.2026 21:59:49
  • Zuletzt bearbeitet 06.05.2026 14:49:59

OpenClaw's Nextcloud Talk plugin versions prior to 2026.2.6 accept equality matching on the mutable actor.name display name field for allowlist validation, allowing attackers to bypass DM and room allowlists. An attacker can change their Nextcloud di...

  • EPSS 0.36%
  • Veröffentlicht 05.03.2026 21:59:48
  • Zuletzt bearbeitet 09.03.2026 20:40:40

OpenClaw versions prior to 2026.2.2 contain a vulnerability in the gateway WebSocket connect handshake in which it allows skipping device identity checks when auth.token is present but not validated. Attackers can connect to the gateway without provi...

  • EPSS 0.23%
  • Veröffentlicht 05.03.2026 21:59:47
  • Zuletzt bearbeitet 11.03.2026 16:18:31

OpenClaw version 2026.1.14-1 prior to 2026.2.2, with the Matrix plugin installed and enabled, contain a vulnerability in which DM allowlist matching could be bypassed by exact-matching against sender display names and localparts without homeserver va...

  • EPSS 0.48%
  • Veröffentlicht 05.03.2026 21:59:46
  • Zuletzt bearbeitet 25.03.2026 15:16:40

OpenClaw versions prior to 2026.2.2 contain an exec approvals (must be enabled) allowlist bypass vulnerability that allows attackers to execute arbitrary commands by injecting command substitution syntax. Attackers can bypass the allowlist protection...

  • EPSS 0.3%
  • Veröffentlicht 05.03.2026 21:59:45
  • Zuletzt bearbeitet 09.03.2026 20:29:33

OpenClaw versions prior to 2026.2.14 contain a webhook routing vulnerability in the Google Chat monitor component that allows cross-account policy context misrouting when multiple webhook targets share the same HTTP path. Attackers can exploit first-...