OpenClaw

OpenClaw

80 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.04%
  • Veröffentlicht 19.02.2026 22:05:26
  • Zuletzt bearbeitet 20.02.2026 19:03:02

OpenClaw is a personal AI assistant. Versions 2026.2.13 and below allow the optional @openclaw/voice-call plugin Telnyx webhook handler to accept unsigned inbound webhook requests when telnyx.publicKey is not configured, enabling unauthenticated call...

  • EPSS 0.02%
  • Veröffentlicht 19.02.2026 21:34:27
  • Zuletzt bearbeitet 26.02.2026 18:39:50

OpenClaw is a personal AI assistant. Prior to 2026.2.14, browser-facing localhost mutation routes accepted cross-origin browser requests without explicit Origin/Referer validation. Loopback binding reduces remote exposure but does not prevent browser...

  • EPSS 0.07%
  • Veröffentlicht 19.02.2026 21:28:33
  • Zuletzt bearbeitet 24.02.2026 19:59:36

OpenClaw is a personal AI assistant. Prior to 2026.2.13, the optional BlueBubbles iMessage channel plugin could accept webhook requests as authenticated based only on the TCP peer address being loopback (`127.0.0.1`, `::1`, `::ffff:127.0.0.1`) even w...

Exploit
  • EPSS 0.02%
  • Veröffentlicht 19.02.2026 02:38:33
  • Zuletzt bearbeitet 19.02.2026 20:13:13

OpenClaw is a personal AI assistant. In versions 2026.1.30 and below, if channels.telegram.webhookSecret is not set when in Telegram webhook mode, OpenClaw may accept webhook HTTP requests without verifying Telegram’s secret token header. In deployme...

Exploit
  • EPSS 0.03%
  • Veröffentlicht 19.02.2026 01:10:17
  • Zuletzt bearbeitet 19.02.2026 18:30:39

OpenClaw (formerly Clawdbot) is a personal AI assistant users run on their own devices. In versions 2026.2.2 and below, when the Slack integration is enabled, channel metadata (topic/description) can be incorporated into the model's system prompt. Pr...

  • EPSS 0.02%
  • Veröffentlicht 06.02.2026 20:56:02
  • Zuletzt bearbeitet 13.02.2026 14:44:08

OpenClaw is a personal AI assistant. Prior to 2026.1.20, an unauthenticated local client could use the Gateway WebSocket API to write config via config.apply and set unsafe cliPath values that were later used for command discovery, enabling command i...

  • EPSS 0.01%
  • Veröffentlicht 04.02.2026 19:55:38
  • Zuletzt bearbeitet 13.02.2026 14:33:31

OpenClaw is a personal AI assistant. Prior to version 2026.1.29, there is an OS command injection vulnerability via the Project Root Path in sshNodeCommand. The sshNodeCommand function constructed a shell script without properly escaping the user-sup...

Exploit
  • EPSS 0.09%
  • Veröffentlicht 04.02.2026 19:55:36
  • Zuletzt bearbeitet 13.02.2026 14:42:29

OpenClaw is a personal AI assistant. Prior to version 2026.1.30, the isValidMedia() function in src/media/parse.ts allows arbitrary file paths including absolute paths, home directory paths, and directory traversal sequences. An agent can read any fi...

  • EPSS 0.08%
  • Veröffentlicht 02.02.2026 23:16:08
  • Zuletzt bearbeitet 13.02.2026 14:28:51

OpenClaw (formerly Clawdbot) is a personal AI assistant you run on your own devices. Prior to 2026.1.29, a command injection vulnerability existed in OpenClaw’s Docker sandbox execution mechanism due to unsafe handling of the PATH environment variab...

Medienbericht Exploit
  • EPSS 0.05%
  • Veröffentlicht 01.02.2026 22:34:17
  • Zuletzt bearbeitet 13.02.2026 17:41:02

OpenClaw (aka clawdbot or Moltbot) before 2026.1.29 obtains a gatewayUrl value from a query string and automatically makes a WebSocket connection without prompting, sending a token value.