CVE-2026-28391
- EPSS 0.5%
- Veröffentlicht 05.03.2026 21:59:19
- Zuletzt bearbeitet 10.03.2026 18:18:45
OpenClaw versions prior to 2026.2.2 fail to properly validate Windows cmd.exe metacharacters in allowlist-gated exec requests (non-default configuration), allowing attackers to bypass command approval restrictions. Remote attackers can craft command ...
CVE-2026-28363
- EPSS 0.5%
- Veröffentlicht 27.02.2026 03:17:37
- Zuletzt bearbeitet 27.02.2026 19:13:57
In OpenClaw before 2026.2.23, tools.exec.safeBins validation for sort could be bypassed via GNU long-option abbreviations (such as --compress-prog) in allowlist mode, leading to approval-free execution paths that were intended to require approval. On...
- EPSS 0.17%
- Veröffentlicht 21.02.2026 10:16:13
- Zuletzt bearbeitet 23.02.2026 20:39:31
OpenClaw is a personal AI assistant. In versions 2026.2.17 and below, the ACP bridge accepts very large prompt text blocks and can assemble oversized prompt payloads before forwarding them to chat.send. Because ACP runs over local stdio, this mainly ...
CVE-2026-27488
- EPSS 0.33%
- Veröffentlicht 21.02.2026 09:49:04
- Zuletzt bearbeitet 23.02.2026 20:41:07
OpenClaw is a personal AI assistant. In versions 2026.2.17 and below, Cron webhook delivery in src/gateway/server-cron.ts uses fetch() directly, so webhook targets can reach private/metadata/internal endpoints without SSRF policy checks. This issue w...
- EPSS 1.2%
- Veröffentlicht 21.02.2026 09:35:28
- Zuletzt bearbeitet 23.02.2026 20:41:59
OpenClaw is a personal AI assistant. In versions 2026.2.13 and below, when using macOS, the Claude CLI keychain credential refresh path constructed a shell command to write the updated JSON blob into Keychain via security add-generic-password -w .......
CVE-2026-27486
- EPSS 0.29%
- Veröffentlicht 21.02.2026 09:32:45
- Zuletzt bearbeitet 24.02.2026 16:53:20
OpenClaw is a personal AI assistant. In versions 2026.2.13 and below of the OpenClaw CLI, the process cleanup uses system-wide process enumeration and pattern matching to terminate processes without verifying if they are owned by the current OpenClaw...
CVE-2026-27485
- EPSS 0.22%
- Veröffentlicht 21.02.2026 09:27:53
- Zuletzt bearbeitet 23.02.2026 20:43:11
OpenClaw is a personal AI assistant. In versions 2026.2.17 and below, skills/skill-creator/scripts/package_skill.py (a local helper script used when authors package skills) previously followed symlinks while building .skill archives. If an author run...
CVE-2026-27484
- EPSS 0.19%
- Veröffentlicht 21.02.2026 09:21:16
- Zuletzt bearbeitet 23.02.2026 20:44:09
OpenClaw is a personal AI assistant. In versions 2026.2.17 and below, the Discord moderation action handling (timeout, kick, ban) uses sender identity from request parameters in tool-driven flows, instead of trusted runtime sender context. In setups ...
CVE-2026-27009
- EPSS 0.23%
- Veröffentlicht 19.02.2026 23:25:41
- Zuletzt bearbeitet 20.02.2026 17:41:44
OpenClaw is a personal AI assistant. Prior to version 2026.2.15, a atored XSS issue in the OpenClaw Control UI when rendering assistant identity (name/avatar) into an inline `<script>` tag without script-context-safe escaping. A crafted value contain...
CVE-2026-27008
- EPSS 0.17%
- Veröffentlicht 19.02.2026 23:23:32
- Zuletzt bearbeitet 20.02.2026 18:01:28
OpenClaw is a personal AI assistant. Prior to version 2026.2.15, a bug in `download` skill installation allowed `targetDir` values from skill frontmatter to resolve outside the per-skill tools directory if not strictly validated. In the admin-only `s...