OpenClaw

OpenClaw

666 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.15%
  • Veröffentlicht 05.03.2026 22:00:02
  • Zuletzt bearbeitet 11.03.2026 01:15:08

OpenClaw versions 2026.1.16-2 prior to 2026.2.14 contain a path traversal vulnerability in archive extraction during installation commands that allows arbitrary file writes outside the intended directory. Attackers can craft malicious archives that, ...

  • EPSS 0.2%
  • Veröffentlicht 05.03.2026 21:59:59
  • Zuletzt bearbeitet 11.03.2026 01:28:49

OpenClaw versions 2026.1.5 prior to 2026.2.12 fail to enforce mandatory authentication on the /agent/act browser-control HTTP route, allowing unauthorized local callers to invoke privileged operations. Remote attackers on the local network or local p...

  • EPSS 0.05%
  • Veröffentlicht 05.03.2026 21:59:58
  • Zuletzt bearbeitet 06.03.2026 17:16:32

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

  • EPSS 0.14%
  • Veröffentlicht 05.03.2026 21:59:57
  • Zuletzt bearbeitet 23.03.2026 14:17:48

OpenClaw versions prior to 2026.2.12 construct transcript file paths using unsanitized sessionId parameters and sessionFile paths without enforcing directory containment. Authenticated attackers can exploit path traversal sequences like ../../etc/pas...

  • EPSS 0.26%
  • Veröffentlicht 05.03.2026 21:59:56
  • Zuletzt bearbeitet 17.03.2026 17:43:49

OpenClaw versions 2026.1.30 and earlier, contain an information disclosure vulnerability, patched in 2026.2.1, in the MS Teams attachment downloader (optional extension must be enabled) that leaks bearer tokens to allowlisted suffix domains. When ret...

  • EPSS 0.21%
  • Veröffentlicht 05.03.2026 21:59:55
  • Zuletzt bearbeitet 17.03.2026 17:49:51

OpenClaw versions prior to 2026.2.14 contain an authorization bypass vulnerability where Telegram allowlist matching accepts mutable usernames instead of immutable numeric sender IDs. Attackers can spoof identity by obtaining recycled usernames to by...

  • EPSS 0.18%
  • Veröffentlicht 05.03.2026 21:59:54
  • Zuletzt bearbeitet 17.03.2026 17:58:44

OpenClaw versions prior to 2026.2.15 use SHA-1 to hash sandbox identifier cache keys for Docker and browser sandbox configurations, which is deprecated and vulnerable to collision attacks. An attacker can exploit SHA-1 collisions to cause cache poiso...

  • EPSS 0.44%
  • Veröffentlicht 05.03.2026 21:59:53
  • Zuletzt bearbeitet 17.03.2026 18:03:34

OpenClaw versions prior to 2026.2.13 contain a denial of service vulnerability in webhook handlers that buffer request bodies without strict byte or time limits. Remote unauthenticated attackers can send oversized JSON payloads or slow uploads to web...

  • EPSS 0.13%
  • Veröffentlicht 05.03.2026 21:59:52
  • Zuletzt bearbeitet 17.03.2026 18:04:14

OpenClaw versions prior to 2026.2.14 contain an oauth state validation bypass vulnerability in the manual Chutes login flow that allows attackers to bypass CSRF protection. An attacker can convince a user to paste attacker-controlled OAuth callback d...

  • EPSS 0.24%
  • Veröffentlicht 05.03.2026 21:59:51
  • Zuletzt bearbeitet 21.04.2026 14:52:03

OpenClaw versions prior to 2026.2.14 contain a server-side request forgery vulnerability in the optional Tlon Urbit extension that accepts user-provided base URLs for authentication without proper validation. Attackers who can influence the configure...