Vulnerabilities in openclaw

663 results
Vexday analysis

A OpenClaw apresenta um portfólio de 47 vulnerabilidades, com 10 descobertas nos últimos 90 dias, indicando atividade contínua de risco. Nenhuma vulnerabilidade está sob exploração ativa registrada (KEV), mas a fraqueza dominante em path traversal (CWE-22) é crítica em ambientes com controle de acesso inadequado. Com apenas 1 vulnerabilidade crítica (CVSS), o risco permanece moderado, mas exige monitoramento nas próximas atualizações da plataforma.

CVE-2026-32897MEDIUMOpenClaw < 2026.2.22 - Authentication Token Reuse in Owner ID Prompt Hashing FallbackEPSS 0.5%CVE-2026-53807HIGHOpenClaw < 2026.5.6 - Authorization Bypass in Telegram Interactive Callbacks via commands.allowFromEPSS 0.5%CVE-2026-62218HIGHOpenClaw 2026.1.20 < 2026.5.27 Authorization Bypass via device.pair.approveEPSS 0.5%CVE-2026-28475MEDIUMOpenClaw < 2026.2.13 - Timing Attack via Hook Token ComparisonEPSS 0.5%CVE-2026-62223HIGHOpenClaw < 2026.5.18 Authorization Bypass via Device-pairEPSS 0.5%CVE-2026-41300MEDIUMOpenClaw < 2026.3.31 - Preservation of Attacker-Discovered Endpoints in Remote OnboardingEPSS 0.5%CVE-2026-35674HIGHOpenClaw < 2026.5.18 - Scope Bypass via Inherited chat.send RouteEPSS 0.5%CVE-2026-62228HIGHOpenClaw < 2026.6.5 Authorization Bypass via Node Exec ApprovalsEPSS 0.5%CVE-2026-53828HIGHOpenClaw < 2026.5.6 - Native Command Authorization Bypass via Owner-Command EnforcementEPSS 0.5%CVE-2026-53855HIGHOpenClaw < 2026.4.2 - Shell Positional Parameters Bypass in Inline-Eval ChecksEPSS 0.4%CVE-2026-62210MEDIUMOpenClaw < 2026.6.1 Denial of Service via Remote Media URLsEPSS 0.4%CVE-2026-53866HIGHOpenClaw < 2026.5.12 - Allowlist Bypass in Shell Inline-Command ParsingEPSS 0.4%CVE-2026-28452MEDIUMOpenClaw < 2026.2.14 - Denial of Service via Unguarded Archive Extraction in extractArchiveEPSS 0.4%CVE-2026-53811HIGHOpenClaw < 2026.5.7 - Privilege Escalation via Mutable Display Names in Matrix allowFromEPSS 0.4%CVE-2026-62194HIGHOpenClaw 2026.5.20 < 2026.6.9 Privilege Escalation via Plugin InstallEPSS 0.4%CVE-2026-53817HIGHOpenClaw < 2026.5.22 - Control UI Locality Spoofing in Device PairingEPSS 0.4%CVE-2026-62217HIGHOpenClaw 2026.5.14-beta.1 < 2026.5.27 Authentication Bypass via exec approvalsEPSS 0.4%CVE-2026-32914HIGHOpenClaw < 2026.3.12 - Insufficient Access Control in /config and /debug EndpointsEPSS 0.4%CVE-2026-43577HIGHOpenClaw < 2026.4.9 - Arbitrary File Read via Browser Interaction RoutesEPSS 0.4%CVE-2026-43573MEDIUMOpenClaw < 2026.4.10 - SSRF Policy Bypass in Existing-Session Browser Interaction RoutesEPSS 0.4%