OpenClaw

OpenClaw

559 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.34%
  • Veröffentlicht 11.06.2026 20:09:15
  • Zuletzt bearbeitet 12.06.2026 20:08:26

OpenClaw before 2026.5.18 contains an insufficient provenance validation vulnerability in node event handling that allows paired nodes to forge exec lifecycle events without system.run authorization. A malicious or compromised paired node can send cr...

  • EPSS 0.22%
  • Veröffentlicht 11.06.2026 20:08:52
  • Zuletzt bearbeitet 12.06.2026 19:24:55

OpenClaw before 2026.5.19 contains an authorization bypass vulnerability in message read actions that skips channel allowlist checks. Lower-trust callers can request messages from channels not intended for them by exploiting insufficient validation i...

  • EPSS 0.28%
  • Veröffentlicht 11.06.2026 20:08:31
  • Zuletzt bearbeitet 12.06.2026 19:25:09

OpenClaw before 2026.5.20 contains a privilege escalation vulnerability where hook-triggered agent runs incorrectly receive owner-scoped MCP loopback authority instead of hook-appropriate scope. Attackers with a valid hook token can exploit the /hook...

  • EPSS 0.11%
  • Veröffentlicht 11.06.2026 20:08:11
  • Zuletzt bearbeitet 12.06.2026 19:25:15

OpenClaw before 2026.4.25 contains a path traversal vulnerability in memory-core artifact loading where workspace state influences local package root resolution. Attackers with access to affected workspaces can load memory-core artifacts from uninten...

  • EPSS 0.25%
  • Veröffentlicht 11.06.2026 20:07:51
  • Zuletzt bearbeitet 12.06.2026 19:25:23

OpenClaw before 2026.5.18 contains a server-side request forgery vulnerability in browser control that allows authenticated users to bypass private-network navigation checks through Playwright act interactions. Attackers can trigger navigation to pri...

  • EPSS 0.31%
  • Veröffentlicht 11.06.2026 20:07:29
  • Zuletzt bearbeitet 12.06.2026 19:32:22

OpenClaw before 2026.5.7 contains a privilege escalation vulnerability in the Matrix allowFrom feature that allows authenticated accounts to match policy entries through mutable display name metadata. Attackers with the ability to change display name...

  • EPSS 0.42%
  • Veröffentlicht 11.06.2026 20:07:04
  • Zuletzt bearbeitet 12.06.2026 19:32:38

OpenClaw before 2026.5.18 contains a code execution vulnerability where marketplace runtime extension metadata can redirect loading toward unscanned package payloads. Attackers with trusted operator access can manipulate extension metadata to load pl...

  • EPSS 0.09%
  • Veröffentlicht 11.06.2026 20:06:43
  • Zuletzt bearbeitet 12.06.2026 19:32:51

OpenClaw before 2026.4.25 contains a policy bypass vulnerability in embedded runner policy that allows requests using provider aliases to compare against aliases instead of canonical provider identities. Attackers can exploit this confusion to select...

  • EPSS 0.19%
  • Veröffentlicht 11.06.2026 20:06:14
  • Zuletzt bearbeitet 12.06.2026 19:32:56

OpenClaw before 2026.5.6 contains an approval policy bypass vulnerability in the Skill Workshop apply flow that allows agent tool calls to set apply: true despite approvalPolicy: pending configuration. Attackers can exploit this by reaching the affec...

  • EPSS 0.31%
  • Veröffentlicht 11.06.2026 20:05:48
  • Zuletzt bearbeitet 12.06.2026 19:33:01

OpenClaw before 2026.5.6 contains an authorization bypass vulnerability in Telegram interactive callbacks that allows authenticated users to skip commands.allowFrom validation. Attackers can invoke affected callbacks to mark themselves as authorized ...