OpenClaw

OpenClaw

666 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.15%
  • Veröffentlicht 17.07.2026 00:07:03
  • Zuletzt bearbeitet 21.07.2026 02:16:23

OpenClaw versions before 2026.5.18 contain an authorization bypass vulnerability in skill command dispatch that allows lower-trust callers to execute or persist actions beyond their intended authorization. Attackers can bypass tool policy restriction...

  • EPSS 0.25%
  • Veröffentlicht 17.07.2026 00:07:02
  • Zuletzt bearbeitet 20.07.2026 16:57:40

OpenClaw before 2026.5.18 contain an authorization bypass vulnerability in the device-pair approval feature that allows lower-trust callers to execute actions beyond their intended authorization. Attackers can exploit misconfigured input paths to exe...

  • EPSS 0.12%
  • Veröffentlicht 17.07.2026 00:07:01
  • Zuletzt bearbeitet 29.07.2026 19:16:50

OpenClaw before 2026.5.22 contain a vulnerability in setup-mode discovery that allows loading of untrusted workspace plugins. Attackers with lower-trust caller access or control over configured input paths can execute or persist actions beyond their ...

  • EPSS 0.29%
  • Veröffentlicht 17.07.2026 00:07:00
  • Zuletzt bearbeitet 21.07.2026 20:01:26

OpenClaw 2026.2.25 before 2026.5.26 allow a lower-trust caller or configured input path to bypass non-browser rate limits on WebSocket authentication attempts. When the affected feature is enabled and reachable by lower-trust input, this can consume ...

  • EPSS 0.14%
  • Veröffentlicht 17.07.2026 00:07:00
  • Zuletzt bearbeitet 21.07.2026 20:00:31

OpenClaw 2026.5.12 before 2026.5.26 contain an incorrect authorization vulnerability in the ClickClack allowFrom feature. When the affected feature is enabled and reachable, a lower-trust caller or configured input path could execute or persist actio...

  • EPSS 0.17%
  • Veröffentlicht 17.07.2026 00:06:59
  • Zuletzt bearbeitet 21.07.2026 19:58:07

OpenClaw 2026.2.12 before 2026.5.26 contain an authorization bypass vulnerability in the hooks allowedAgentIds validation. A lower-trust caller or configured input path can bypass agent ID restrictions by submitting blank agent IDs, allowing actions ...

  • EPSS 0.25%
  • Veröffentlicht 17.07.2026 00:06:58
  • Zuletzt bearbeitet 21.07.2026 19:59:25

OpenClaw 2026.5.14-beta.1 before 2026.5.27 contain an authorization flaw in the QQBot exec approvals feature. When the feature is enabled and reachable, a lower-trust caller or configured input path could execute or persist actions beyond the caller'...

  • EPSS 0.25%
  • Veröffentlicht 17.07.2026 00:06:58
  • Zuletzt bearbeitet 21.07.2026 19:58:34

OpenClaw 2026.1.20 before 2026.5.27 contain an authorization bypass vulnerability in the device.pair.approve feature that allows lower-trust callers to bypass role-management checks. Attackers can perform actions requiring stronger authorization by r...

  • EPSS 0.21%
  • Veröffentlicht 17.07.2026 00:06:57
  • Zuletzt bearbeitet 23.07.2026 20:17:19

OpenClaw 2026.4.20 before 2026.5.28 contain a policy bypass in the QQBot media upload feature. A lower-trust caller or configured input path could cause the media upload to reach network destinations that should have been blocked by OpenClaw policy (...

  • EPSS 0.31%
  • Veröffentlicht 17.07.2026 00:06:56
  • Zuletzt bearbeitet 08.10.2026 16:17:26

OpenClaw versions before 2026.5.28 Bot Framework contains an improper input validation vulnerability that allows lower-trust callers to expose bot tokens and credentials by failing to properly validate serviceUrl parameters. Attackers can supply mali...