OpenClaw

OpenClaw

666 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.32%
  • Veröffentlicht 05.03.2026 21:59:29
  • Zuletzt bearbeitet 09.03.2026 18:30:09

OpenClaw versions prior to 2026.2.14 contain a denial of service vulnerability in the extractArchive function within src/infra/archive.ts that allows attackers to consume excessive CPU, memory, and disk resources through high-expansion ZIP and TAR ar...

  • EPSS 0.28%
  • Veröffentlicht 05.03.2026 21:59:28
  • Zuletzt bearbeitet 11.03.2026 16:15:12

OpenClaw versions prior to 2026.2.14 contain server-side request forgery vulnerabilities in the Feishu extension that allow attackers to fetch attacker-controlled remote URLs without SSRF protections via sendMediaFeishu function and markdown image pr...

Exploit
  • EPSS 0.44%
  • Veröffentlicht 05.03.2026 21:59:27
  • Zuletzt bearbeitet 11.03.2026 16:02:04

OpenClaw versions 2026.1.29 prior to 2026.2.1 contain a vulnerability in the Twitch plugin (must be installed and enabled) in which it fails to enforce the allowFrom allowlist when allowedRoles is unset or empty, allowing unauthorized Twitch users to...

  • EPSS 0.34%
  • Veröffentlicht 05.03.2026 21:59:27
  • Zuletzt bearbeitet 11.03.2026 16:04:57

OpenClaw versions prior to 2026.2.12 with the optional Nostr plugin enabled expose unauthenticated HTTP endpoints at /api/channels/nostr/:accountId/profile and /api/channels/nostr/:accountId/profile/import that allow reading and modifying Nostr profi...

  • EPSS 0.36%
  • Veröffentlicht 05.03.2026 21:59:26
  • Zuletzt bearbeitet 10.03.2026 19:43:11

OpenClaw versions 2026.1.29-beta.1 prior to 2026.2.1 contain a path traversal vulnerability in plugin installation that allows malicious plugin package names to escape the extensions directory. Attackers can craft scoped package names containing path...

Exploit
  • EPSS 0.65%
  • Veröffentlicht 05.03.2026 21:59:24
  • Zuletzt bearbeitet 11.03.2026 14:16:26

OpenClaw versions prior to 2026.2.1 with the voice-call extension installed and enabled contain an authentication bypass vulnerability in inbound allowlist policy validation that accepts empty caller IDs and uses suffix-based matching instead of stri...

  • EPSS 0.4%
  • Veröffentlicht 05.03.2026 21:59:23
  • Zuletzt bearbeitet 26.05.2026 14:16:31

OpenClaw version 2026.1.14-1 prior to 2026.2.12 contains an improper network binding vulnerability in the Chrome extension (must be installed and enabled) relay server that treats wildcard hosts as loopback addresses, allowing the relay HTTP/WS serve...

  • EPSS 0.44%
  • Veröffentlicht 05.03.2026 21:59:22
  • Zuletzt bearbeitet 11.03.2026 05:17:59

OpenClaw versions 2.0.0-beta3 prior to 2026.2.14 contain a path traversal vulnerability in hook transform module loading that allows arbitrary JavaScript execution. The hooks.mappings[].transform.module parameter accepts absolute paths and traversal ...

  • EPSS 0.39%
  • Veröffentlicht 05.03.2026 21:59:22
  • Zuletzt bearbeitet 09.03.2026 20:28:46

OpenClaw versions prior to 2026.2.15 contain a denial of service vulnerability in the web_fetch tool that allows attackers to crash the Gateway process through memory exhaustion by parsing oversized or deeply nested HTML responses. Remote attackers c...

  • EPSS 0.35%
  • Veröffentlicht 05.03.2026 21:59:20
  • Zuletzt bearbeitet 10.03.2026 20:10:19

OpenClaw versions prior to 2026.2.14 contain a privilege escalation vulnerability in the Slack slash-command handler that incorrectly authorizes any direct message sender when dmPolicy is set to open (must be configured). Attackers can execute privil...