CVE-2026-32007
- EPSS 0.36%
- Veröffentlicht 19.03.2026 22:16:33
- Zuletzt bearbeitet 24.03.2026 21:22:35
OpenClaw versions prior to 2026.2.23 contain a path traversal vulnerability in the experimental apply_patch tool that allows attackers with sandbox access to modify files outside the workspace directory by exploiting inconsistent enforcement of works...
CVE-2026-32008
- EPSS 0.4%
- Veröffentlicht 19.03.2026 22:16:33
- Zuletzt bearbeitet 23.03.2026 17:34:08
OpenClaw versions prior to 2026.2.21 contain an improper URL scheme validation vulnerability in the assertBrowserNavigationAllowed() function that allows authenticated users with browser-tool access to navigate to file:// URLs. Attackers can exploit ...
CVE-2026-32009
- EPSS 0.13%
- Veröffentlicht 19.03.2026 22:16:33
- Zuletzt bearbeitet 23.03.2026 18:33:03
OpenClaw versions prior to 2026.2.24 contain a policy bypass vulnerability in the safeBins allowlist evaluation that trusts static default directories including writable package-manager paths like /opt/homebrew/bin and /usr/local/bin. An attacker wit...
CVE-2026-32010
- EPSS 0.29%
- Veröffentlicht 19.03.2026 22:16:33
- Zuletzt bearbeitet 23.03.2026 18:29:04
OpenClaw versions prior to 2026.2.22 contain an allowlist bypass vulnerability in the safe-bin configuration when sort is manually added to tools.exec.safeBins. Attackers can invoke sort with the --compress-program flag to execute arbitrary external ...
CVE-2026-32001
- EPSS 0.27%
- Veröffentlicht 19.03.2026 22:16:32
- Zuletzt bearbeitet 23.03.2026 18:51:27
OpenClaw versions prior to 2026.2.22 contain an authentication bypass vulnerability that allows clients authenticated with a shared gateway token to connect as role=node without device identity verification. Attackers can exploit this by claiming the...
CVE-2026-32002
- EPSS 0.32%
- Veröffentlicht 19.03.2026 22:16:32
- Zuletzt bearbeitet 23.03.2026 18:53:37
OpenClaw versions prior to 2026.2.23 contain a sandbox bypass vulnerability in the sandboxed image tool that fails to enforce tools.fs.workspaceOnly restrictions on mounted sandbox paths, allowing attackers to read out-of-workspace files. Attackers c...
CVE-2026-32003
- EPSS 0.53%
- Veröffentlicht 19.03.2026 22:16:32
- Zuletzt bearbeitet 23.03.2026 18:57:22
OpenClaw versions prior to 2026.2.22 contain an environment variable injection vulnerability in the system.run function that allows attackers to bypass command allowlist restrictions via SHELLOPTS and PS4 environment variables. An attacker who can in...
CVE-2026-32004
- EPSS 0.3%
- Veröffentlicht 19.03.2026 22:16:32
- Zuletzt bearbeitet 23.03.2026 19:12:08
OpenClaw versions prior to 2026.3.2 contain an authentication bypass vulnerability in the /api/channels route classification due to canonicalization depth mismatch between auth-path classification and route-path canonicalization. Attackers can bypass...
CVE-2026-32005
- EPSS 0.28%
- Veröffentlicht 19.03.2026 22:16:32
- Zuletzt bearbeitet 24.03.2026 21:22:47
OpenClaw versions prior to 2026.2.25 fail to enforce sender authorization checks for interactive callbacks including block_action, view_submission, and view_closed in shared workspace deployments. Unauthorized workspace members can bypass allowFrom r...
CVE-2026-32000
- EPSS 0.62%
- Veröffentlicht 19.03.2026 01:00:57
- Zuletzt bearbeitet 25.03.2026 15:16:43
OpenClaw versions prior to 2026.2.19 contain a command injection vulnerability in the Lobster extension tool execution that uses Windows shell fallback with shell: true after spawn failures. Attackers can inject shell metacharacters in command argume...