OpenClaw

OpenClaw

666 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.17%
  • Veröffentlicht 17.07.2026 00:06:56
  • Zuletzt bearbeitet 20.07.2026 16:58:30

OpenClaw versions before 2026.6.5 contain an authentication bypass vulnerability in HTTP Canvas responses that allows lower-trust callers to forge trusted A2UI actions. Attackers can perform actions requiring stronger authorization by submitting craf...

  • EPSS 0.26%
  • Veröffentlicht 17.07.2026 00:06:55
  • Zuletzt bearbeitet 08.10.2026 16:17:26

OpenClaw versions before 2026.5.27 contain a token leakage vulnerability in MS Teams outbound requests that allows lower-trust callers to expose Bot Framework tokens. Attackers can access configured input paths to retrieve credentials that should rem...

  • EPSS 0.11%
  • Veröffentlicht 17.07.2026 00:06:54
  • Zuletzt bearbeitet 29.07.2026 21:17:47

OpenClaw versions before 2026.6.1 contain a credential redaction bypass vulnerability in the trajectory export feature that allows lower-trust callers to access data that should remain within trusted boundaries. Attackers can exploit misconfigured in...

  • EPSS 0.17%
  • Veröffentlicht 17.07.2026 00:06:54
  • Zuletzt bearbeitet 20.07.2026 16:59:11

OpenClaw before 2026.5.28 contains a race condition in the MS Teams safeFetch DNS rebinding check. When the affected feature is enabled and reachable, a lower-trust caller or configured input path could win a timing window between the DNS validation ...

  • EPSS 0.31%
  • Veröffentlicht 17.07.2026 00:06:53
  • Zuletzt bearbeitet 23.07.2026 20:17:19

OpenClaw versions before 2026.6.1 contain a denial of service vulnerability where remote media URLs can trigger slow-read attacks that exhaust gateway worker resources. Attackers with access to configured input paths can supply remote media URLs that...

  • EPSS 0.26%
  • Veröffentlicht 17.07.2026 00:06:52
  • Zuletzt bearbeitet 20.07.2026 17:00:44

OpenClaw before 2026.6.5 could forward Authorization headers during MCP SSE redirects. When the affected feature is enabled and reachable, a lower-trust caller or configured input path could execute or persist actions beyond the caller's intended aut...

  • EPSS 0.21%
  • Veröffentlicht 17.07.2026 00:06:52
  • Zuletzt bearbeitet 21.07.2026 19:59:43

OpenClaw versions 2026.5.10-beta.1 before 2026.6.5 contain an authorization bypass in the ClickClack agent-mode dispatch feature, which could ignore the toolsAllow policy check. When the affected feature is enabled and reachable, a lower-trust caller...

  • EPSS 0.3%
  • Veröffentlicht 17.07.2026 00:06:51
  • Zuletzt bearbeitet 29.07.2026 19:16:50

OpenClaw versions before 2026.6.5 contain an authentication bypass vulnerability that allows lower-trust callers to reach admin-scoped tools. Attackers can perform actions requiring stronger authorization by exploiting insufficient policy checks on c...

  • EPSS 0.25%
  • Veröffentlicht 17.07.2026 00:06:50
  • Zuletzt bearbeitet 21.07.2026 20:00:45

OpenClaw versions 2026.4.12-beta.1 before 2026.6.6 contain a missing-authorization vulnerability in the MS Teams message actions feature. When the affected feature is enabled and reachable, a lower-trust caller or a configured input path can perform ...

  • EPSS 0.25%
  • Veröffentlicht 17.07.2026 00:06:50
  • Zuletzt bearbeitet 20.07.2026 17:00:58

OpenClaw versions before 2026.6.9 contain a missing authorization vulnerability in Discord moderation actions. In affected versions, a lower-trust caller or configured input path could perform moderation actions that should have required a stronger a...