Vulnerabilidades en OpenClaw

584 resultados
Análisis Vexday

Com 495 CVEs catalogadas e nenhuma confirmada em exploração ativa no momento, o perfil do OpenClaw apresenta taxa de exploração confirmada abaixo da média geral do catálogo KEV. O dado que merece atenção imediata é o volume de 323 vulnerabilidades surgidas nos últimos 90 dias, indicando um ritmo elevado de descobertas recentes que ainda pode não ter atraído atenção de agentes maliciosos, mas amplia consideravelmente a superfície de ataque. O tipo de falha mais comum é CWE-863 (autorização incorreta), o que sugere fragilidades estruturais no controle de acesso — categoria com alto potencial de impacto caso explorada. A CVE mais perigosa identificada atualmente, CVE-2026-25253, apresenta EPSS de 0,0802, e embora não haja PoC pública disponível, equipes de segurança devem monitorar sua evolução dado o contexto de crescimento acelerado no volume de vulnerabilidades do vendor.

CVE-2026-40037HIGHOpenClaw < 2026.3.31 - Unsafe Request Body Replay via fetchWithSsrFGuard Cross-Origin RedirectsEPSS 0.3%CVE-2026-44996MEDIUMOpenClaw < 2026.4.15 - Arbitrary Local File Read via Webchat Audio EmbeddingEPSS 0.3%CVE-2026-34425MEDIUMOpenClaw - Shell-Bleed Protection Preflight Validation BypassEPSS 0.3%CVE-2026-42420MEDIUMOpenClaw < 2026.4.8 - Improper Base64 Decoding Size ValidationEPSS 0.3%CVE-2026-62219MEDIUMOpenClaw 2026.2.12 < 2026.5.26 Authorization Bypass via Blank Agent IDsEPSS 0.3%CVE-2026-28469HIGHOpenClaw < 2026.2.14 - Cross-Account Policy Context Misrouting via Shared Webhook Path AmbiguityEPSS 0.3%CVE-2026-27486MEDIUMOpenClaw: Process Safety - Unvalidated PID Kill via SIGKILL in Process CleanupEPSS 0.3%CVE-2026-53819HIGHOpenClaw < 2026.5.27 - Arbitrary Homebrew Executable Execution via Workspace .env OverrideEPSS 0.3%CVE-2026-41329CRITICALOpenClaw < 2026.3.31 - Sandbox Bypass via Heartbeat Context Inheritance and senderIsOwner EscalationEPSS 0.3%CVE-2026-35669HIGHOpenClaw < 2026.3.25 - Privilege Escalation via Gateway Plugin HTTP Authentication ScopeEPSS 0.3%CVE-2026-33573HIGHOpenClaw < 2026.3.11 - Workspace Boundary Bypass via Agent RPC ParametersEPSS 0.3%CVE-2026-41331MEDIUMOpenClaw < 2026.3.31 - Resource Consumption via Unauthorized Telegram Audio Preflight TranscriptionEPSS 0.3%CVE-2026-33578MEDIUMOpenClaw < 2026.3.28 - Sender Policy Allowlist Bypass via Policy Downgrade in Google Chat and Zalouser ExtensionsEPSS 0.3%CVE-2026-41335MEDIUMOpenClaw < 2026.3.31 - Information Disclosure via Control UI Bootstrap JSONEPSS 0.3%CVE-2026-32004HIGHOpenClaw < 2026.3.2 - Authentication Bypass via Encoded Path in /api/channels RouteEPSS 0.3%CVE-2026-41345MEDIUMOpenClaw < 2026.3.31 - Authorization Header Leak via Cross-Origin Redirect in Media DownloadEPSS 0.3%CVE-2026-32006LOWOpenClaw < 2026.2.26 - Authorization Bypass via DM Pairing-Store Fallback in Group AllowlistEPSS 0.3%CVE-2026-42433HIGHOpenClaw < 2026.4.10 - Unauthorized Matrix Profile Config Persistence Access via operator.write Message ToolsEPSS 0.3%CVE-2026-28458HIGHOpenClaw 2026.1.20 < 2026.2.1 - Missing Authentication in Browser Relay /cdp WebSocket EndpointEPSS 0.3%CVE-2026-26328MEDIUMOpenClaw iMessage group allowlist authorization inherited DM pairing-store identitiesEPSS 0.3%