OpenClaw

OpenClaw

666 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.12%
  • Veröffentlicht 19.03.2026 22:16:35
  • Zuletzt bearbeitet 25.03.2026 15:16:43

OpenClaw versions prior to 2026.2.22 on macOS contain a path validation bypass vulnerability in the exec-approval allowlist mode that allows local attackers to execute unauthorized binaries by exploiting basename-only allowlist entries. Attackers can...

  • EPSS 0.26%
  • Veröffentlicht 19.03.2026 22:16:35
  • Zuletzt bearbeitet 25.03.2026 15:16:44

OpenClaw versions prior to 2026.2.19 contain an allowlist bypass vulnerability in the exec safeBins policy that allows attackers to write arbitrary files using short-option payloads. Attackers can bypass argument validation by attaching short options...

  • EPSS 0.13%
  • Veröffentlicht 19.03.2026 22:16:35
  • Zuletzt bearbeitet 20.04.2026 14:03:44

OpenClaw versions prior to 2026.2.19 contain a race condition vulnerability in concurrent updateRegistry and removeRegistryEntry operations for sandbox containers and browsers. Attackers can exploit unsynchronized read-modify-write operations without...

  • EPSS 0.21%
  • Veröffentlicht 19.03.2026 22:16:35
  • Zuletzt bearbeitet 20.04.2026 13:51:07

OpenClaw versions prior to 2026.2.22 contain incomplete IPv4 special-use range validation in the isPrivateIpv4() function, allowing requests to RFC-reserved ranges to bypass SSRF policy checks. Attackers with network reachability to special-use IPv4 ...

  • EPSS 0.13%
  • Veröffentlicht 19.03.2026 22:16:35
  • Zuletzt bearbeitet 23.03.2026 18:13:56

OpenClaw versions prior to 2026.2.22 contain a path traversal vulnerability in the static file handler that follows symbolic links, allowing out-of-root file reads. Attackers can place symlinks under the Control UI root directory to bypass directory ...

  • EPSS 0.42%
  • Veröffentlicht 19.03.2026 22:16:34
  • Zuletzt bearbeitet 23.03.2026 18:29:20

OpenClaw versions prior to 2026.3.2 contain a denial of service vulnerability in webhook handlers for BlueBubbles and Google Chat that parse request bodies before performing authentication and signature validation. Unauthenticated attackers can explo...

  • EPSS 0.64%
  • Veröffentlicht 19.03.2026 22:16:34
  • Zuletzt bearbeitet 23.03.2026 18:29:35

OpenClaw versions prior to 2026.2.25 contain a symlink traversal vulnerability in the agents.files.get and agents.files.set methods that allows reading and writing files outside the agent workspace. Attackers can exploit symlinked allowlisted files t...

  • EPSS 0.19%
  • Veröffentlicht 19.03.2026 22:16:34
  • Zuletzt bearbeitet 23.03.2026 19:09:38

OpenClaw versions prior to 2026.2.26 contain a metadata spoofing vulnerability where reconnect platform and deviceFamily fields are accepted from the client without being bound into the device-auth signature. An attacker with a paired node identity o...

  • EPSS 0.13%
  • Veröffentlicht 19.03.2026 22:16:34
  • Zuletzt bearbeitet 25.03.2026 15:16:43

OpenClaw versions 2026.1.21 prior to 2026.2.19 contain a path hijacking vulnerability in tools.exec.safeBins that allows attackers to bypass allowlist checks by controlling process PATH resolution. Attackers who can influence the gateway process PATH...

  • EPSS 0.3%
  • Veröffentlicht 19.03.2026 22:16:33
  • Zuletzt bearbeitet 24.03.2026 21:22:22

OpenClaw versions prior to 2026.2.26 contain an authorization bypass vulnerability where DM pairing-store identities are incorrectly treated as group allowlist identities when dmPolicy=pairing and groupPolicy=allowlist. Remote attackers can send mess...