CVE-2026-32032
- EPSS 0.13%
- Veröffentlicht 19.03.2026 22:16:38
- Zuletzt bearbeitet 25.03.2026 15:16:46
OpenClaw versions prior to 2026.2.22 contain an arbitrary shell execution vulnerability in shell environment fallback that trusts the unvalidated SHELL path from the host environment. An attacker with local environment access can inject a malicious S...
CVE-2026-32033
- EPSS 0.34%
- Veröffentlicht 19.03.2026 22:16:38
- Zuletzt bearbeitet 25.03.2026 15:16:46
OpenClaw versions prior to 2026.2.24 contain a path traversal vulnerability where @-prefixed absolute paths bypass workspace-only file-system boundary validation due to canonicalization mismatch. Attackers can exploit this by crafting @-prefixed path...
CVE-2026-32025
- EPSS 0.29%
- Veröffentlicht 19.03.2026 22:16:37
- Zuletzt bearbeitet 23.03.2026 17:12:07
OpenClaw versions prior to 2026.2.25 contain an authentication hardening gap in browser-origin WebSocket clients that allows attackers to bypass origin checks and auth throttling on loopback deployments. An attacker can trick a user into opening a ma...
CVE-2026-32026
- EPSS 0.34%
- Veröffentlicht 19.03.2026 22:16:37
- Zuletzt bearbeitet 23.03.2026 17:13:41
OpenClaw versions prior to 2026.2.24 contain an improper path validation vulnerability in sandbox media handling that allows absolute paths under the host temporary directory outside the active sandbox root. Attackers can exploit this by providing ma...
CVE-2026-32027
- EPSS 0.24%
- Veröffentlicht 19.03.2026 22:16:37
- Zuletzt bearbeitet 26.03.2026 17:16:35
OpenClaw versions prior to 2026.2.26 contain an authorization bypass vulnerability where DM pairing-store identities are incorrectly eligible for group allowlist authorization checks. Attackers can exploit this cross-context authorization flaw by usi...
CVE-2026-32028
- EPSS 0.2%
- Veröffentlicht 19.03.2026 22:16:37
- Zuletzt bearbeitet 25.03.2026 15:16:45
OpenClaw versions prior to 2026.2.25 fail to enforce dmPolicy and allowFrom authorization checks on Discord direct-message reaction notifications, allowing non-allowlisted users to enqueue reaction-derived system events. Attackers can exploit this in...
CVE-2026-32021
- EPSS 0.21%
- Veröffentlicht 19.03.2026 22:16:36
- Zuletzt bearbeitet 25.03.2026 15:16:44
OpenClaw versions prior to 2026.2.22 contain an authorization bypass vulnerability in the Feishu allowFrom allowlist implementation that accepts mutable sender display names instead of enforcing ID-only matching. An attacker can set a display name eq...
CVE-2026-32022
- EPSS 0.26%
- Veröffentlicht 19.03.2026 22:16:36
- Zuletzt bearbeitet 26.05.2026 14:16:32
OpenClaw versions prior to 2026.2.21 contain a stdin-only policy bypass vulnerability in the grep tool within tools.exec.safeBins that allows attackers to read arbitrary files by supplying a pattern via the -e flag parameter. Attackers can include a ...
CVE-2026-32023
- EPSS 0.28%
- Veröffentlicht 19.03.2026 22:16:36
- Zuletzt bearbeitet 25.03.2026 15:16:45
OpenClaw versions prior to 2026.2.24 contain an approval gating bypass vulnerability in system.run allowlist mode where nested transparent dispatch wrappers can suppress shell-wrapper detection. Attackers can exploit this by chaining multiple dispatc...
CVE-2026-32024
- EPSS 0.33%
- Veröffentlicht 19.03.2026 22:16:36
- Zuletzt bearbeitet 23.03.2026 17:46:50
OpenClaw versions prior to 2026.2.22 contain a symlink traversal vulnerability in avatar handling that allows attackers to read arbitrary files outside the configured workspace boundary. Remote attackers can exploit this by requesting avatar resource...