Vulnerabilities in openclaw

663 results
Vexday analysis

A OpenClaw apresenta um portfólio de 47 vulnerabilidades, com 10 descobertas nos últimos 90 dias, indicando atividade contínua de risco. Nenhuma vulnerabilidade está sob exploração ativa registrada (KEV), mas a fraqueza dominante em path traversal (CWE-22) é crítica em ambientes com controle de acesso inadequado. Com apenas 1 vulnerabilidade crítica (CVSS), o risco permanece moderado, mas exige monitoramento nas próximas atualizações da plataforma.

CVE-2026-32038CRITICALOpenClaw - Sandbox Network Isolation Bypass via docker.network=container ParameterEPSS 0.5%CVE-2026-29612MEDIUMOpenClaw < 2026.2.14 - Denial of Service via Large Base64 Media File DecodingEPSS 0.5%CVE-2026-28449MEDIUMOpenClaw < 2026.2.25 - Webhook Replay Attack via Missing Durable Replay SuppressionEPSS 0.5%CVE-2026-32008HIGHOpenClaw < 2026.2.21 - Arbitrary Local File Read via Browser Navigation GuardEPSS 0.5%CVE-2026-28467MEDIUMOpenClaw < 2026.2.2 - SSRF via Attachment Media URL HydrationEPSS 0.5%CVE-2026-34510MEDIUMOpenClaw < 2026.3.22 - Remote File URL Acceptance in Windows Media LoadersEPSS 0.5%CVE-2026-42436MEDIUMOpenClaw < 2026.4.14 - Internal Page Content Exposure via Browser Snapshot and Screenshot RoutesEPSS 0.5%CVE-2026-8629HIGHCrabbox < v0.12.0 Privilege Escalation via Agent Ticket EndpointsEPSS 0.5%CVE-2026-53839MEDIUMOpenClaw < 2026.5.7 - Hostname Prefix Matching Bypass in Trusted Retry Endpoint ValidationEPSS 0.5%CVE-2026-32017MEDIUMOpenClaw < 2026.2.19 - Arbitrary File Write via Short-Option Bypass in exec AllowlistEPSS 0.5%CVE-2026-41334HIGHOpenClaw < 2026.3.31 - Decompression Bomb Denial of Service via Image Pixel-Limit Guard BypassEPSS 0.5%CVE-2026-42431HIGHOpenClaw < 2026.4.8 - Persistent Profile Mutation via node.invoke(browser.proxy) BypassEPSS 0.5%CVE-2026-35665MEDIUMOpenClaw < 2026.3.24 - Denial of Service via Feishu Webhook Pre-Auth Body ParsingEPSS 0.5%CVE-2026-43532MEDIUMOpenClaw 2026.4.7 < 2026.4.10 - Sandbox Media Normalization Bypass via Discord Event Cover ImageEPSS 0.5%CVE-2026-35636HIGHOpenClaw 2026.3.11 < 2026.3.25 - Session Isolation Bypass via sessionId ResolutionEPSS 0.5%CVE-2026-32022MEDIUMOpenClaw < 2026.2.21 - Arbitrary File Read via grep -e Flag Policy BypassEPSS 0.5%CVE-2026-28481MEDIUMOpenClaw < 2026.2.1 - Bearer Token Leakage via MS Teams Attachment Downloader Suffix MatchingEPSS 0.5%CVE-2026-43580MEDIUMOpenClaw < 2026.4.10 - Incomplete Navigation Guard Coverage in Browser InteractionsEPSS 0.5%CVE-2026-53861MEDIUMOpenClaw < 2026.5.6 - Allowlist Bypass via Combined POSIX Inline Flags on macOSEPSS 0.5%CVE-2026-34503HIGHOpenClaw < 2026.3.28 - Incomplete WebSocket Session Termination on Device Removal and Token RevocationEPSS 0.5%