Vulnerabilities in openclaw

663 results
Vexday analysis

A OpenClaw apresenta um portfólio de 47 vulnerabilidades, com 10 descobertas nos últimos 90 dias, indicando atividade contínua de risco. Nenhuma vulnerabilidade está sob exploração ativa registrada (KEV), mas a fraqueza dominante em path traversal (CWE-22) é crítica em ambientes com controle de acesso inadequado. Com apenas 1 vulnerabilidade crítica (CVSS), o risco permanece moderado, mas exige monitoramento nas próximas atualizações da plataforma.

CVE-2026-100574HIGHOpenClaw before 2026.8.1 SSRF via Trusted-Host DNSEPSS 0.2%CVE-2026-100578HIGHOpenClaw before 2026.7.1 Authorization Bypass via chat.sendEPSS 0.2%CVE-2026-100579HIGHOpenClaw before 2026.7.1 Authentication Bypass via Spoofed RequesterEPSS 0.2%CVE-2026-32302HIGHOpenClaw: Untrusted web origins can obtain authenticated operator.admin access in trusted-proxy modeEPSS 0.2%CVE-2026-62212MEDIUMOpenClaw < 2026.5.28 Authentication Bypass via safeFetchEPSS 0.2%CVE-2026-44999MEDIUMOpenClaw < 2026.4.20 - Improper Trust Labeling in Isolated Cron Awareness EventsEPSS 0.2%CVE-2026-27009MEDIUMOpenClaw affected by Stored XSS in Control UI via unsanitized assistant name/avatar in inline script injectionEPSS 0.2%CVE-2026-22181MEDIUMOpenClaw < 2026.3.2 - DNS Pinning Bypass via Environment Proxy Configuration in web_fetchEPSS 0.2%CVE-2026-26317HIGHOpenClaw affected by cross-site request forgery (CSRF) through loopback browser mutation endpointsEPSS 0.2%CVE-2026-100554LOWOpenClaw before 2026.8.1 Canvas Capability Revocation BypassEPSS 0.2%CVE-2026-100553MEDIUMOpenClaw 2026.6.9 before 2026.8.1 Cross-Context Policy Bypass via Feishu unpinEPSS 0.2%CVE-2026-31996LOWOpenClaw < 2026.2.19 - safeBins stdin-only bypass via sort output and recursive grep flagsEPSS 0.2%CVE-2026-26972MEDIUMOpenClaw has a Path Traversal in Browser Download FunctionalityEPSS 0.2%CVE-2026-32018LOWOpenClaw < 2026.2.19 - Race Condition in Sandbox Registry Write OperationsEPSS 0.2%CVE-2026-41384HIGHOpenClaw < 2026.3.24 - Environment Variable Injection via Workspace Config in CLI BackendEPSS 0.2%CVE-2026-100582HIGHOpenClaw Channel Plugins before 2026.8.1 Channel Read Allowlist BypassEPSS 0.2%CVE-2026-28468HIGHOpenClaw 2026.1.29-beta.1 < 2026.2.14 - Authentication Bypass in Sandbox Browser Bridge ServerEPSS 0.2%CVE-2026-100576MEDIUMOpenClaw before 2026.8.1 SSRF via Browser Wait PredicatesEPSS 0.2%CVE-2026-35634MEDIUMOpenClaw < 2026.3.23 - Authentication Bypass via Local-Direct Requests in Canvas GatewayEPSS 0.2%CVE-2026-42428HIGHOpenClaw < 2026.4.8 - Missing Integrity Verification in Package DownloadsEPSS 0.2%