OpenClaw

OpenClaw

666 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.43%
  • Veröffentlicht 11.03.2026 13:32:35
  • Zuletzt bearbeitet 26.05.2026 14:16:32

OpenClaw versions 2026.2.21-2 up to, but not including, 2026.2.22, and @openclaw/voice-call versions 2026.2.21 up to, but not including, 2026.2.22 accept media-stream WebSocket upgrades before stream validation, allowing unauthenticated clients to es...

  • EPSS 0.15%
  • Veröffentlicht 11.03.2026 13:32:34
  • Zuletzt bearbeitet 16.03.2026 18:00:12

OpenClaw versions prior to 2026.2.17 contain a path traversal vulnerability in the $include directive resolution that allows reading arbitrary local files outside the config directory boundary. Attackers with config modification capabilities can expl...

  • EPSS 0.74%
  • Veröffentlicht 11.03.2026 13:32:33
  • Zuletzt bearbeitet 16.03.2026 17:39:12

OpenClaw versions prior to 2026.2.14 contain a path traversal vulnerability in apply_patch that allows attackers to write or delete files outside the configured workspace directory. When apply_patch is enabled without filesystem sandbox containment, ...

  • EPSS 0.37%
  • Veröffentlicht 11.03.2026 13:32:32
  • Zuletzt bearbeitet 16.03.2026 17:38:55

OpenClaw version 2026.2.22-2 prior to 2026.2.23 tools.exec.safeBins validation for sort command fails to properly validate GNU long-option abbreviations, allowing attackers to bypass denied-flag checks via abbreviated options. Remote attackers can ex...

  • EPSS 0.41%
  • Veröffentlicht 05.03.2026 22:00:11
  • Zuletzt bearbeitet 11.03.2026 00:43:15

OpenClaw versions prior to 2026.2.12 contain a vulnerability in the BlueBubbles (optional plugin) webhook handler in which it authenticates requests based solely on loopback remoteAddress without validating forwarding headers, allowing bypass of conf...

  • EPSS 0.27%
  • Veröffentlicht 05.03.2026 22:00:10
  • Zuletzt bearbeitet 11.03.2026 00:47:39

OpenClaw versions prior to 2026.2.14 decode base64-backed media inputs into buffers before enforcing decoded-size budget limits, allowing attackers to trigger large memory allocations. Remote attackers can supply oversized base64 payloads to cause me...

  • EPSS 0.29%
  • Veröffentlicht 05.03.2026 22:00:09
  • Zuletzt bearbeitet 11.03.2026 00:58:54

OpenClaw versions prior to 2026.2.14 contain a local file inclusion vulnerability in BlueBubbles extension (must be installed and enabled) media path handling that allows attackers to read arbitrary files from the local filesystem. The sendBlueBubble...

  • EPSS 0.47%
  • Veröffentlicht 05.03.2026 22:00:07
  • Zuletzt bearbeitet 11.03.2026 01:02:58

OpenClaw versions prior to 2026.2.14 contain a command hijacking vulnerability that allows attackers to execute unintended binaries by manipulating PATH environment variables through node-host execution or project-local bootstrapping. Attackers with ...

  • EPSS 0.43%
  • Veröffentlicht 05.03.2026 22:00:06
  • Zuletzt bearbeitet 11.03.2026 01:03:36

OpenClaw versions prior to 2026.2.14 contain a denial of service vulnerability in the fetchWithGuard function that allocates entire response payloads in memory before enforcing maxBytes limits. Remote attackers can trigger memory exhaustion by servin...

  • EPSS 0.29%
  • Veröffentlicht 05.03.2026 22:00:05
  • Zuletzt bearbeitet 11.03.2026 01:10:47

OpenClaw versions prior to 2026.2.14 contain a webhook signature-verification bypass in the voice-call extension that allows unauthenticated requests when the tunnel.allowNgrokFreeTierLoopbackBypass option is explicitly enabled. An external attacker ...