OpenClaw

OpenClaw

600 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.45%
  • Veröffentlicht 12.06.2026 22:16:55
  • Zuletzt bearbeitet 23.07.2026 09:10:00

OpenClaw before 2026.5.12 contains an allowlist bypass vulnerability in PowerShell encoded-command handling that allows attackers to execute encoded commands using abbreviated flag aliases not recognized by the allowlist parser. Remote authenticated ...

  • EPSS 0.19%
  • Veröffentlicht 12.06.2026 22:16:55
  • Zuletzt bearbeitet 23.07.2026 09:10:00

OpenClaw before 2026.5.6 contains an improper access control vulnerability in Mattermost event handlers that fails to validate channel type metadata. Attackers can bypass intended DM policy decisions by sending crafted Mattermost events missing chann...

  • EPSS 0.23%
  • Veröffentlicht 12.06.2026 22:16:55
  • Zuletzt bearbeitet 23.07.2026 09:10:00

OpenClaw before 2026.5.27 contains a state mutation vulnerability in node pairing reconnection that allows paired nodes to confuse approval scope decisions. Attackers can exploit reconnection logic to restore or present broader node authority than in...

  • EPSS 0.27%
  • Veröffentlicht 12.06.2026 22:16:55
  • Zuletzt bearbeitet 23.07.2026 09:10:00

OpenClaw before 2026.5.7 contains a hostname validation vulnerability in retry endpoint checks that allows matching hostname prefixes instead of exact hostnames. Attackers can exploit this by crafting a hostname prefix resembling a trusted host to se...

  • EPSS 0.25%
  • Veröffentlicht 12.06.2026 22:16:54
  • Zuletzt bearbeitet 23.07.2026 09:10:00

OpenClaw before 2026.5.2 contains a credential exposure vulnerability in message.action forwarding that allows model-controlled metadata to forward action payloads with Gateway credentials to attacker-supplied loopback URLs. Remote attackers can inte...

  • EPSS 0.27%
  • Veröffentlicht 12.06.2026 22:16:54
  • Zuletzt bearbeitet 23.07.2026 09:10:00

OpenClaw before 2026.5.6 contains an authorization bypass vulnerability in native command handling that allows authenticated senders to execute owner-only commands without proper policy enforcement. Attackers can trigger native command handling to by...

  • EPSS 0.23%
  • Veröffentlicht 12.06.2026 22:16:54
  • Zuletzt bearbeitet 23.07.2026 09:10:00

OpenClaw before 2026.5.18 contains an approval display truncation vulnerability allowing authenticated users to hide command suffixes from approvers. Attackers can submit oversized exec commands with benign prefixes and malicious suffixes to execute ...

  • EPSS 0.21%
  • Veröffentlicht 12.06.2026 22:16:54
  • Zuletzt bearbeitet 23.07.2026 09:10:00

OpenClaw before 2026.4.22 contains a webhook secret revocation bypass vulnerability allowing callers with old Slack and Zalo webhook secrets to remain active after secrets.reload. Attackers can exploit the stale-secret window to deliver webhook event...

  • EPSS 0.2%
  • Veröffentlicht 12.06.2026 22:16:54
  • Zuletzt bearbeitet 23.07.2026 09:10:00

OpenClaw before 2026.5.18 contains a policy enforcement vulnerability in system.run safe-bin allowlist validation that allows shell expansion to modify command interpretation on POSIX nodes. Authenticated operators can exploit shell metacharacters in...

  • EPSS 0.1%
  • Veröffentlicht 12.06.2026 22:16:54
  • Zuletzt bearbeitet 23.07.2026 09:10:00

OpenClaw before 2026.5.18 contains an identity header validation vulnerability allowing local same-host callers to forge trusted-proxy identity headers. Attackers with access to the proxy-facing Gateway port can supply forged identity headers to assu...