- EPSS 0.29%
- Veröffentlicht 26.09.2026 02:18:33
- Zuletzt bearbeitet 29.09.2026 18:17:05
OpenClaw versions before 2026.8.1 contain a path traversal vulnerability in the tools.fs.workspaceOnly feature where Unicode filename fallback can normalize validated parent directory components. Admitted requesters can exploit canonically equivalent...
CVE-2026-100529
- EPSS 0.21%
- Veröffentlicht 26.09.2026 02:18:31
- Zuletzt bearbeitet 29.09.2026 18:17:05
OpenClaw versions before 2026.8.1 contain an authorization scope widening vulnerability in file-transfer allow-always approvals that allows attackers to reuse standing grants for unreviewed paths. Attackers can exploit glob metacharacter interpretati...
CVE-2026-100530
- EPSS 0.19%
- Veröffentlicht 26.09.2026 02:18:31
- Zuletzt bearbeitet 28.09.2026 18:17:11
OpenClaw versions before 2026.8.1 fail to bind working directory context to reusable exec approvals, allowing approved commands to execute in different directories. Attackers with an allow-always approval can reuse it to run the same command against ...
CVE-2026-100528
- EPSS 0.24%
- Veröffentlicht 26.09.2026 02:18:30
- Zuletzt bearbeitet 30.09.2026 01:16:32
OpenClaw (npm package 'openclaw') before 2026.8.1 could send third-party provider credentials to the wrong endpoint. In affected versions, when a third-party provider uses an OpenAI-compatible API and the resolved model metadata lacks a concrete base...
CVE-2026-100527
- EPSS 0.35%
- Veröffentlicht 26.09.2026 02:18:29
- Zuletzt bearbeitet 05.10.2026 15:17:10
OpenClaw before 2026.8.2 contains a denial of service vulnerability in the Browser extension relay that allows unauthenticated network sources to exhaust pending-authentication capacity. Attackers can hold every pending slot by maintaining silent Web...
CVE-2026-94094
- EPSS 0.27%
- Veröffentlicht 20.09.2026 23:17:03
- Zuletzt bearbeitet 22.09.2026 16:18:17
A flaw has been found in OpenClaw up to 2026.9.5. Affected is the function createCanvasHostHandler of the file extensions/canvas/src/host/server.ts of the component Canvas Host Route. Executing a manipulation can lead to denial of service. The attack...
CVE-2026-62229
- EPSS 0.45%
- Veröffentlicht 17.07.2026 00:07:06
- Zuletzt bearbeitet 30.07.2026 14:49:36
OpenClaw before 2026.5.18 contain an authorization bypass vulnerability in exec allowlist glob matching that allows lower-trust callers to execute actions beyond intended authorization. Attackers can craft input paths that traverse the allowlist glob...
CVE-2026-62227
- EPSS 0.23%
- Veröffentlicht 17.07.2026 00:07:05
- Zuletzt bearbeitet 21.07.2026 20:00:20
OpenClaw 2026.4.14 before 2026.5.26 contain a server-side request forgery vulnerability in browser snapshot routes that fail to validate post-navigation destinations. Attackers with lower-trust access can bypass OpenClaw policy checks to reach networ...
CVE-2026-62228
- EPSS 0.25%
- Veröffentlicht 17.07.2026 00:07:05
- Zuletzt bearbeitet 29.07.2026 19:16:50
OpenClaw before 2026.6.5 contain an authorization bypass vulnerability in node exec approvals that allows lower-trust callers to execute actions beyond their intended authorization by using different gateway and node environments. Attackers can explo...
CVE-2026-62226
- EPSS 0.24%
- Veröffentlicht 17.07.2026 00:07:04
- Zuletzt bearbeitet 21.07.2026 19:57:34
OpenClaw 2026.3.28 before 2026.5.19 contain an authorization bypass vulnerability in the browser act route that fails to properly validate current-tab URL checks. Attackers with lower-trust access or configured input paths can perform actions requiri...