Vulnerabilidades en openclaw
663 resultadosAnálisis Vexday
A OpenClaw apresenta um portfólio de 47 vulnerabilidades, com 10 descobertas nos últimos 90 dias, indicando atividade contínua de risco. Nenhuma vulnerabilidade está sob exploração ativa registrada (KEV), mas a fraqueza dominante em path traversal (CWE-22) é crítica em ambientes com controle de acesso inadequado. Com apenas 1 vulnerabilidade crítica (CVSS), o risco permanece moderado, mas exige monitoramento nas próximas atualizações da plataforma.
CVE-2026-43576MEDIUMOpenClaw < 2026.4.5 - Second-hop SSRF via CDP /json/version WebSocket URLEPSS 0.4%CVE-2026-62214MEDIUMOpenClaw < 2026.5.28 Bot Framework SSRF via serviceUrl Parameter ValidationEPSS 0.4%CVE-2026-44996MEDIUMOpenClaw < 2026.4.15 - Arbitrary Local File Read via Webchat Audio EmbeddingEPSS 0.4%CVE-2026-28458HIGHOpenClaw 2026.1.20 < 2026.2.1 - Missing Authentication in Browser Relay /cdp WebSocket EndpointEPSS 0.4%CVE-2026-41372MEDIUMOpenClaw < 2026.4.2 - Loopback Protection Bypass via Trailing-Dot Localhost in CDP DiscoveryEPSS 0.4%CVE-2026-53827MEDIUMOpenClaw < 2026.5.2 - Credential Exposure via Model-Supplied Loopback URLs in message.action ForwardingEPSS 0.4%CVE-2026-43574MEDIUMOpenClaw < 2026.4.12 - Improper Authorization via Empty Approver ListsEPSS 0.4%CVE-2026-41351MEDIUMOpenClaw < 2026.3.31 - Webhook Replay Detection Bypass via Base64 Signature Re-encodingEPSS 0.4%CVE-2026-27488MEDIUMOpenClaw hardened cron webhook delivery against SSRFEPSS 0.4%CVE-2026-32002MEDIUMOpenClaw < 2026.2.23 - Sandbox Boundary Bypass via Image Tool workspaceOnly BypassEPSS 0.4%CVE-2026-43526HIGHOpenClaw < 2026.4.12 - Server-Side Request Forgery via QQBot Reply Media URL HandlingEPSS 0.4%CVE-2026-41359HIGHOpenClaw < 2026.3.28 - Privilege Escalation via operator.write to Admin-Class Telegram Config and Cron PersistenceEPSS 0.4%CVE-2026-33576MEDIUMOpenClaw < 2026.3.28 - Unauthorized Media Download via Zalo ChannelEPSS 0.4%CVE-2026-26322HIGHOpenClaw Gateway tool allowed unrestricted gatewayUrl overrideEPSS 0.4%CVE-2026-32913HIGHOpenClaw < 2026.3.7 - Custom Authorization Header Leakage via Cross-Origin RedirectsEPSS 0.4%CVE-2026-32896MEDIUMOpenClaw < 2026.2.21 - Unauthenticated Webhook Access via Passwordless Fallback in BlueBubbles PluginEPSS 0.4%CVE-2026-100536HIGHOpenClaw before 2026.8.1 Path Traversal via Structured AttachmentsEPSS 0.4%CVE-2026-32974HIGHOpenClaw < 2026.3.12 - Forged Event Injection via Feishu Webhook Verification TokenEPSS 0.4%CVE-2026-35622MEDIUMOpenClaw < 2026.3.22 - Improper Authentication Verification in Google Chat WebhookEPSS 0.4%CVE-2026-33580MEDIUMOpenClaw < 2026.3.28 - Brute Force Attack via Missing Rate Limiting on Webhook Shared Secret AuthenticationEPSS 0.4%