OpenClaw

OpenClaw

666 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.37%
  • Veröffentlicht 05.03.2026 21:59:41
  • Zuletzt bearbeitet 17.09.2026 18:16:40

OpenClaw's voice-call plugin versions before 2026.2.3 contain an improper authentication vulnerability in webhook verification that allows remote attackers to bypass verification by supplying untrusted forwarded headers. Attackers can spoof webhook e...

  • EPSS 0.39%
  • Veröffentlicht 05.03.2026 21:59:40
  • Zuletzt bearbeitet 09.03.2026 17:14:04

OpenClaw versions prior to 2026.2.12 use non-constant-time string comparison for hook token validation, allowing attackers to infer tokens through timing measurements. Remote attackers with network access to the hooks endpoint can exploit timing side...

  • EPSS 0.17%
  • Veröffentlicht 05.03.2026 21:59:39
  • Zuletzt bearbeitet 08.04.2026 14:16:27

OpenClaw versions prior to 2026.2.14 contain an arbitrary file read vulnerability in the exec-approvals allowlist validation that checks pre-expansion argv tokens but executes using real shell expansion. Attackers with authorization or through prompt...

  • EPSS 0.43%
  • Veröffentlicht 05.03.2026 21:59:38
  • Zuletzt bearbeitet 09.03.2026 17:32:54

OpenClaw versions prior to 2026.2.13 contain a vulnerability in the browser control API in which it accepts user-supplied output paths for trace and download files without consistently constraining writes to temporary directories. Attackers with API ...

  • EPSS 0.36%
  • Veröffentlicht 05.03.2026 21:59:37
  • Zuletzt bearbeitet 09.03.2026 17:39:46

OpenClaw versions prior to 2026.2.12 fail to validate the sessionFile path parameter, allowing authenticated gateway clients to write transcript data to arbitrary locations on the host filesystem. Attackers can supply a sessionFile path outside the s...

  • EPSS 0.3%
  • Veröffentlicht 05.03.2026 21:59:35
  • Zuletzt bearbeitet 09.03.2026 17:28:40

OpenClaw version 2026.1.20 prior to 2026.2.1 contains a vulnerability in the Browser Relay (extension must be installed and enabled) /cdp WebSocket endpoint in which it does not require authentication tokens, allowing websites to connect via loopback...

  • EPSS 0.13%
  • Veröffentlicht 05.03.2026 21:59:34
  • Zuletzt bearbeitet 09.03.2026 17:43:38

OpenClaw versions prior to 2026.2.14 contain a path traversal vulnerability in sandbox skill mirroring (must be enabled) that uses the skill frontmatter name parameter unsanitized when copying skills into the sandbox workspace. Attackers who provide ...

  • EPSS 0.41%
  • Veröffentlicht 05.03.2026 21:59:32
  • Zuletzt bearbeitet 09.03.2026 18:01:46

OpenClaw versions 2026.1.5 prior to 2026.2.14 contain a vulnerability in the Gateway in which it does not sufficiently constrain configured hook module paths before passing them to dynamic import(), allowing code execution. An attacker with gateway c...

  • EPSS 0.41%
  • Veröffentlicht 05.03.2026 21:59:31
  • Zuletzt bearbeitet 09.03.2026 18:04:19

OpenClaw versions prior to 2026.2.14 fail to validate TAR archive entry paths during extraction, allowing path traversal sequences to write files outside the intended directory. Attackers can craft malicious archives with traversal sequences like ../...

  • EPSS 0.26%
  • Veröffentlicht 05.03.2026 21:59:31
  • Zuletzt bearbeitet 09.03.2026 18:03:30

OpenClaw versions prior to 2026.2.2 fail to validate webhook secrets in Telegram webhook mode (must be enabled), allowing unauthenticated HTTP POST requests to the webhook endpoint that trust attacker-controlled JSON payloads. Remote attackers can fo...