Vulnerabilities in openclaw

663 results
Vexday analysis

A OpenClaw apresenta um portfólio de 47 vulnerabilidades, com 10 descobertas nos últimos 90 dias, indicando atividade contínua de risco. Nenhuma vulnerabilidade está sob exploração ativa registrada (KEV), mas a fraqueza dominante em path traversal (CWE-22) é crítica em ambientes com controle de acesso inadequado. Com apenas 1 vulnerabilidade crítica (CVSS), o risco permanece moderado, mas exige monitoramento nas próximas atualizações da plataforma.

CVE-2026-34511MEDIUMOpenClaw < 2026.4.2 - PKCE Verifier Exposure via OAuth State ParameterEPSS 0.4%CVE-2026-35637MEDIUMOpenClaw < 2026.3.22 - Premature Cite Expansion Before Authorization in Channel and DMEPSS 0.4%CVE-2026-53864HIGHOpenClaw < 2026.5.26 - Insufficient Environment Variable Sanitization in Node.js Control VariablesEPSS 0.4%CVE-2026-28476MEDIUMOpenClaw < 2026.2.14 - Server-Side Request Forgery in Tlon Extension AuthenticationEPSS 0.4%CVE-2026-35635MEDIUMOpenClaw < 2026.3.22 - Webhook Path Route Replacement Vulnerability in Synology ChatEPSS 0.4%CVE-2026-41389MEDIUMOpenClaw 2026.4.7 < 2026.4.15 - Arbitrary File Read via Unvalidated Tool-Result Media PathsEPSS 0.4%CVE-2026-41388MEDIUMOpenClaw < 2026.3.31 - Configuration Rehydration via Empty-Array Revocation HandlingEPSS 0.4%CVE-2026-42429MEDIUMOpenClaw < 2026.4.8 - Privilege Escalation via Gateway Plugin HTTP AuthenticationEPSS 0.4%CVE-2026-41301MEDIUMOpenClaw 2026.3.22 < 2026.3.31 - Forged Nostr DM Pairing State Creation via Signature Verification BypassEPSS 0.4%CVE-2026-53829HIGHOpenClaw < 2026.5.18 - Command Truncation in Exec Approval DisplayEPSS 0.4%CVE-2026-35646MEDIUMOpenClaw < 2026.3.25 - Pre-Authentication Rate-Limit Bypass in Webhook Token ValidationEPSS 0.4%CVE-2026-41333MEDIUMOpenClaw < 2026.3.31 - Authentication Rate Limiting Bypass via Fake DeviceTokenEPSS 0.4%CVE-2026-32027HIGHOpenClaw < 2026.2.26 - Improper Authorization via DM Pairing Store Identity Inheritance in Group AllowlistEPSS 0.4%CVE-2026-45000LOWOpenClaw < 2026.4.20 - Server-Side Request Forgery via Browser CDP Profile CreationEPSS 0.4%CVE-2026-41910LOWOpenClaw < 2026.4.8 - Missing Owner-Only Enforcement in /allowlist Cross-Channel WritesEPSS 0.4%CVE-2026-33577HIGHOpenClaw < 2026.3.28 - Insufficient Scope Validation in node.pair.approveEPSS 0.4%CVE-2026-35670MEDIUMOpenClaw < 2026.3.22 - Webhook Reply Rebinding via Username Resolution in Synology ChatEPSS 0.4%CVE-2026-42438MEDIUMOpenClaw 2026.4.9 < 2026.4.10 - Sender Policy Bypass in Host Media Attachment ReadsEPSS 0.4%CVE-2026-32920HIGHOpenClaw < 2026.3.12 - Arbitrary Code Execution via Auto-Discovery of Workspace PluginsEPSS 0.4%CVE-2026-62192HIGHOpenClaw 2026.6.6 < 2026.6.9 Authorization BypassEPSS 0.4%