OpenClaw

OpenClaw

666 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.49%
  • Veröffentlicht 19.02.2026 22:53:17
  • Zuletzt bearbeitet 23.02.2026 13:47:10

OpenClaw is a personal AI assistant. Prior to version 2026.2.14, a mismatch between `rawCommand` and `command[]` in the node host `system.run` handler could cause allowlist/approval evaluation to be performed on one command while executing a differen...

  • EPSS 0.39%
  • Veröffentlicht 19.02.2026 22:49:24
  • Zuletzt bearbeitet 23.02.2026 18:13:45

OpenClaw is a personal AI assistant. Prior to version 2026.2.14, OpenClaw's SSRF protection could be bypassed using full-form IPv4-mapped IPv6 literals such as `0:0:0:0:0:ffff:7f00:1` (which is `127.0.0.1`). This could allow requests that should be b...

  • EPSS 1.71%
  • Veröffentlicht 19.02.2026 22:47:47
  • Zuletzt bearbeitet 20.02.2026 19:06:15

OpenClaw is a personal AI assistant. Versions 2026.1.8 through 2026.2.13 have a command injection in the maintainer/dev script `scripts/update-clawtributors.ts`. The issue affects contributors/maintainers (or CI) who run `bun scripts/update-clawtribu...

  • EPSS 0.34%
  • Veröffentlicht 19.02.2026 22:33:10
  • Zuletzt bearbeitet 20.02.2026 19:12:17

OpenClaw is a personal AI assistant. Prior to OpenClaw version 2026.2.14, the Gateway tool accepted a tool-supplied `gatewayUrl` without sufficient restrictions, which could cause the OpenClaw host to attempt outbound WebSocket connections to user-sp...

  • EPSS 0.48%
  • Veröffentlicht 19.02.2026 22:28:07
  • Zuletzt bearbeitet 20.02.2026 19:12:08

OpenClaw is a personal AI assistant. Prior to OpenClaw version 2026.2.14, the Feishu extension previously allowed `sendMediaFeishu` to treat attacker-controlled `mediaUrl` values as local filesystem paths and read them directly. If an attacker can in...

  • EPSS 0.43%
  • Veröffentlicht 19.02.2026 22:24:33
  • Zuletzt bearbeitet 20.02.2026 19:09:57

OpenClaw is a personal AI assistant. OpenClaw macOS desktop client registers the `openclaw://` URL scheme. For `openclaw://agent` deep links without an unattended `key`, the app shows a confirmation dialog that previously displayed only the first 240...

  • EPSS 0.28%
  • Veröffentlicht 19.02.2026 22:05:26
  • Zuletzt bearbeitet 20.02.2026 19:03:02

OpenClaw is a personal AI assistant. Versions 2026.2.13 and below allow the optional @openclaw/voice-call plugin Telnyx webhook handler to accept unsigned inbound webhook requests when telnyx.publicKey is not configured, enabling unauthenticated call...

  • EPSS 0.14%
  • Veröffentlicht 19.02.2026 21:34:27
  • Zuletzt bearbeitet 26.02.2026 18:39:50

OpenClaw is a personal AI assistant. Prior to 2026.2.14, browser-facing localhost mutation routes accepted cross-origin browser requests without explicit Origin/Referer validation. Loopback binding reduces remote exposure but does not prevent browser...

  • EPSS 0.32%
  • Veröffentlicht 19.02.2026 21:28:33
  • Zuletzt bearbeitet 24.02.2026 19:59:36

OpenClaw is a personal AI assistant. Prior to 2026.2.13, the optional BlueBubbles iMessage channel plugin could accept webhook requests as authenticated based only on the TCP peer address being loopback (`127.0.0.1`, `::1`, `::ffff:127.0.0.1`) even w...

Exploit
  • EPSS 0.2%
  • Veröffentlicht 19.02.2026 02:38:33
  • Zuletzt bearbeitet 19.02.2026 20:13:13

OpenClaw is a personal AI assistant. In versions 2026.1.30 and below, if channels.telegram.webhookSecret is not set when in Telegram webhook mode, OpenClaw may accept webhook HTTP requests without verifying Telegram’s secret token header. In deployme...