OpenClaw

OpenClaw

666 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.18%
  • Veröffentlicht 26.09.2026 02:18:42
  • Zuletzt bearbeitet 28.09.2026 18:17:12

OpenClaw (npm package `openclaw`) versions >= 2026.7.2 and < 2026.9.2 contain a race condition in the Discord realtime voice transcript path. Concurrent control-classified voice transcripts could consume speaker context belonging to another participa...

  • EPSS 0.21%
  • Veröffentlicht 26.09.2026 02:18:41
  • Zuletzt bearbeitet 29.09.2026 17:17:02

OpenClaw (npm package `openclaw`) before 2026.8.1 incorrectly enforces sender tool policies during session-memory filename generation. In affected versions, filename generation created an embedded helper that retained tools which the originating send...

  • EPSS 0.35%
  • Veröffentlicht 26.09.2026 02:18:40
  • Zuletzt bearbeitet 05.10.2026 15:17:10

OpenClaw (npm package openclaw) before 2026.8.1 could include deterministic hashes computed over the original, unredacted configuration in redacted configuration responses. When the Gateway password had low entropy and the remaining configuration val...

  • EPSS 0.26%
  • Veröffentlicht 26.09.2026 02:18:39
  • Zuletzt bearbeitet 28.09.2026 18:17:12

OpenClaw (npm package 'openclaw') versions >= 2026.5.28 and < 2026.8.1 mishandle archive listings in the tar.bz2 skill installer: bounded command-output suffixes were treated as complete listings of the archive. A crafted .tar.bz2/.tbz2 skill archive...

  • EPSS 0.26%
  • Veröffentlicht 26.09.2026 02:18:37
  • Zuletzt bearbeitet 28.09.2026 18:17:12

OpenClaw (npm package 'openclaw') before 2026.8.1 does not apply the originating sender's global or per-agent toolsBySender policy when handling outbound attachments. A sender that has been explicitly denied filesystem read tools can still cause a kn...

  • EPSS 0.2%
  • Veröffentlicht 26.09.2026 02:18:37
  • Zuletzt bearbeitet 05.10.2026 15:17:10

OpenClaw (npm package 'openclaw') before 2026.8.1 fails to revoke memory tool access when an operator hot-disables memory configuration. Existing memory_search and memory_get tool instances retain the enabled configuration captured at creation time b...

  • EPSS 0.19%
  • Veröffentlicht 26.09.2026 02:18:36
  • Zuletzt bearbeitet 29.09.2026 18:17:05

OpenClaw (npm package 'openclaw') before 2026.8.1 fails to apply the originating requester's effective tool policy during Active Memory automatic recall. In deployments that use Active Memory together with requester-specific tool rules, deterministic...

  • EPSS 0.26%
  • Veröffentlicht 26.09.2026 02:18:35
  • Zuletzt bearbeitet 05.10.2026 15:17:10

OpenClaw (npm package 'openclaw') versions >= 2026.4.5 and < 2026.8.1 can lose the originating requester's restrictions and untrusted provenance when session-derived text is persisted to session memory. In deployments where session-memory capture and...

  • EPSS 0.43%
  • Veröffentlicht 26.09.2026 02:18:35
  • Zuletzt bearbeitet 30.09.2026 01:16:33

OpenClaw versions before 2026.8.1 fail to validate all source fields in structured message attachments, allowing attackers to hide unvalidated host paths behind allowed attachment sources. Attackers can exploit this by providing multiple source field...

  • EPSS 0.27%
  • Veröffentlicht 26.09.2026 02:18:34
  • Zuletzt bearbeitet 28.09.2026 18:17:11

OpenClaw versions before 2026.8.1 contain an authorization bypass vulnerability in webhook TaskFlow cancellation that allows attackers to cancel unrelated sessions. An attacker with a webhook route secret can supply an arbitrary child session key to ...