OpenClaw

OpenClaw

666 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.13%
  • Veröffentlicht 18.03.2026 02:16:21
  • Zuletzt bearbeitet 25.03.2026 15:16:36

OpenClaw versions prior to 2026.2.22 inject the x-OpenClaw-relay-token header into Chrome CDP probe traffic on loopback interfaces, allowing local processes to capture the Gateway authentication token. An attacker controlling a loopback port can inte...

  • EPSS 0.33%
  • Veröffentlicht 18.03.2026 02:16:21
  • Zuletzt bearbeitet 19.03.2026 16:06:32

OpenClaw versions prior to 2026.2.23 contain an exec approval bypass vulnerability in allowlist mode where allow-always grants could be circumvented through unrecognized multiplexer shell wrappers like busybox and toybox sh -c commands. Attackers can...

  • EPSS 0.37%
  • Veröffentlicht 18.03.2026 02:16:21
  • Zuletzt bearbeitet 08.04.2026 17:21:14

OpenClaw versions prior to 2026.2.21 fail to filter dangerous process-control environment variables from config env.vars, allowing startup-time code execution. Attackers can inject variables like NODE_OPTIONS or LD_* through configuration to execute ...

  • EPSS 0.41%
  • Veröffentlicht 18.03.2026 02:16:20
  • Zuletzt bearbeitet 19.03.2026 14:48:09

OpenClaw versions prior to 2026.2.21 contain an approval-integrity mismatch vulnerability in system.run that allows authenticated operators to execute arbitrary trailing arguments after cmd.exe /c while approval text reflects only a benign command. A...

  • EPSS 0.2%
  • Veröffentlicht 18.03.2026 02:16:20
  • Zuletzt bearbeitet 25.03.2026 15:16:35

OpenClaw versions prior to 2026.2.22 contain an allowlist bypass vulnerability in the safeBins configuration that allows attackers to invoke external helpers through the compress-program option. When sort is explicitly added to tools.exec.safeBins, r...

  • EPSS 0.15%
  • Veröffentlicht 12.03.2026 21:22:29
  • Zuletzt bearbeitet 24.03.2026 21:36:21

OpenClaw is a personal AI assistant. Prior to 2026.3.11, browser-originated WebSocket connections could bypass origin validation when gateway.auth.mode was set to trusted-proxy and the request arrived with proxy headers. A page served from an untrust...

  • EPSS 0.32%
  • Veröffentlicht 12.03.2026 12:15:59
  • Zuletzt bearbeitet 16.03.2026 18:02:55

A vulnerability was determined in OpenClaw 2026.2.19-2. This vulnerability affects the function applySkillConfigenvOverrides of the component Skill Env Handler. Executing a manipulation can lead to code injection. It is possible to launch the attack ...

  • EPSS 0.13%
  • Veröffentlicht 12.03.2026 12:15:59
  • Zuletzt bearbeitet 16.03.2026 18:06:44

A vulnerability was identified in OpenClaw up to 2026.2.17. This issue affects the function tools.exec.safeBins of the component File Existence Handler. The manipulation leads to information exposure through discrepancy. The attack needs to be perfor...

Exploit
  • EPSS 0.8%
  • Veröffentlicht 11.03.2026 16:16:41
  • Zuletzt bearbeitet 17.03.2026 15:51:41

A remote code execution (RCE) vulnerability in OpenClaw Agent Platform v2026.2.6 allows attackers to execute arbitrary code via a Request-Side prompt injection attack.

Exploit
  • EPSS 1.08%
  • Veröffentlicht 11.03.2026 13:32:36
  • Zuletzt bearbeitet 16.03.2026 17:52:56

OpenClaw version 2026.2.19-2 prior to 2026.2.21 contains a command injection vulnerability in systemd unit file generation where attacker-controlled environment values are not validated for CR/LF characters, allowing newline injection to break out of...