Vulnerabilities in OpenClaw

584 results
Vexday analysis

Com 495 CVEs catalogadas e nenhuma confirmada em exploração ativa no momento, o perfil do OpenClaw apresenta taxa de exploração confirmada abaixo da média geral do catálogo KEV. O dado que merece atenção imediata é o volume de 323 vulnerabilidades surgidas nos últimos 90 dias, indicando um ritmo elevado de descobertas recentes que ainda pode não ter atraído atenção de agentes maliciosos, mas amplia consideravelmente a superfície de ataque. O tipo de falha mais comum é CWE-863 (autorização incorreta), o que sugere fragilidades estruturais no controle de acesso — categoria com alto potencial de impacto caso explorada. A CVE mais perigosa identificada atualmente, CVE-2026-25253, apresenta EPSS de 0,0802, e embora não haja PoC pública disponível, equipes de segurança devem monitorar sua evolução dado o contexto de crescimento acelerado no volume de vulnerabilidades do vendor.

CVE-2026-27007MEDIUMOpenClaw's sandbox config hash sorted primitive arrays and suppressed needed container recreationEPSS 0.2%CVE-2026-95815HIGHOpenClaw iOS before 2026.8.11 Credential Exposure via Deep-Link URL LoggingEPSS 0.2%CVE-2026-41376LOWOpenClaw < 2026.3.31 - Matrix Thread Context Allowlist Bypass via Sender ValidationEPSS 0.2%CVE-2026-35673MEDIUMOpenClaw < 2026.4.29 - SSRF Policy Bypass via Browser Debug/Export RoutesEPSS 0.2%CVE-2026-32302HIGHOpenClaw: Untrusted web origins can obtain authenticated operator.admin access in trusted-proxy modeEPSS 0.2%CVE-2026-41357LOWOpenClaw < 2026.3.31 - Unsanitized Environment Variable Leakage in SSH Sandbox BackendsEPSS 0.2%CVE-2026-31991LOWOpenClaw < 2026.2.26 - Authorization Bypass via DM Pairing-Store Leakage in Signal Group AllowlistEPSS 0.2%CVE-2026-28486MEDIUMOpenClaw 2026.1.16-2 < 2026.2.14 - Path Traversal (Zip Slip) in Archive Extraction via Installation CommandsEPSS 0.2%CVE-2026-32923MEDIUMOpenClaw < 2026.3.11 - Authorization Bypass in Discord Guild Reaction Allowlist EnforcementEPSS 0.2%CVE-2026-44999MEDIUMOpenClaw < 2026.4.20 - Improper Trust Labeling in Isolated Cron Awareness EventsEPSS 0.2%CVE-2026-62211MEDIUMOpenClaw < 2026.6.1 Credential Redaction Bypass via Trajectory ExportEPSS 0.1%CVE-2026-41395HIGHOpenClaw < 2026.3.28 - Webhook Replay via Query Parameter Reordering in Plivo V3EPSS 0.1%CVE-2026-32040LOWOpenClaw < 2026.2.23 - HTML Injection via Unvalidated Image MIME Type in Data-URL InterpolationEPSS 0.1%CVE-2026-34507LOWOpenClaw < 2026.4.29 - Policy Bypass in QQBot Admin Commands via DM-only and allowFrom ChecksEPSS 0.1%CVE-2026-27003MEDIUMOpenClaw: Telegram bot token exposure via logsEPSS 0.1%CVE-2026-35667MEDIUMOpenClaw < 2026.3.24 - Improper Process Termination via Unpatched killProcessTree in shell-utils.tsEPSS 0.1%CVE-2026-32061MEDIUMOpenClaw < 2026.2.17 - Arbitrary File Read via $include Directive Path TraversalEPSS 0.1%CVE-2026-45224MEDIUMCrabbox < 0.9.0 Path Traversal via Islo Provider Workspace ResolutionEPSS 0.1%CVE-2026-45004HIGHOpenClaw < 2026.4.23 - Arbitrary Code Execution via setup-api.js in Current Working DirectoryEPSS 0.1%CVE-2026-26317HIGHOpenClaw affected by cross-site request forgery (CSRF) through loopback browser mutation endpointsEPSS 0.1%