Vulnerabilidades en openclaw

663 resultados
Análisis Vexday

A OpenClaw apresenta um portfólio de 47 vulnerabilidades, com 10 descobertas nos últimos 90 dias, indicando atividade contínua de risco. Nenhuma vulnerabilidade está sob exploração ativa registrada (KEV), mas a fraqueza dominante em path traversal (CWE-22) é crítica em ambientes com controle de acesso inadequado. Com apenas 1 vulnerabilidade crítica (CVSS), o risco permanece moderado, mas exige monitoramento nas próximas atualizações da plataforma.

CVE-2026-53819HIGHOpenClaw < 2026.5.27 - Arbitrary Homebrew Executable Execution via Workspace .env OverrideEPSS 0.4%CVE-2026-33575HIGHOpenClaw < 2026.3.12 - Long-lived Credential Exposure in Pairing Setup CodesEPSS 0.4%CVE-2026-42433HIGHOpenClaw < 2026.4.10 - Unauthorized Matrix Profile Config Persistence Access via operator.write Message ToolsEPSS 0.4%CVE-2026-35655MEDIUMOpenClaw < 2026.3.22 - Identity Spoofing via rawInput Tool in ACP Permission ResolutionEPSS 0.4%CVE-2026-3691MEDIUMOpenClaw Client PKCE Verifier Information Disclosure VulnerabilityEPSS 0.4%CVE-2026-27524LOWOpenClaw < 2026.2.21 - Prototype Pollution via Debug Override PathEPSS 0.4%CVE-2026-41335MEDIUMOpenClaw < 2026.3.31 - Information Disclosure via Control UI Bootstrap JSONEPSS 0.4%CVE-2026-41368HIGHOpenClaw < 2026.3.28 - Environment Variable Disclosure via jq $ENV Filter BypassEPSS 0.4%CVE-2026-35657HIGHOpenClaw < 2026.3.25 - Authorization Bypass in HTTP Session History RouteEPSS 0.4%CVE-2026-32048HIGHOpenClaw < 2026.3.1 - Sandbox Escape via Cross-Agent sessions_spawnEPSS 0.4%CVE-2026-53854MEDIUMOpenClaw < 2026.4.25 - Privilege Escalation via ownerAllowFrom Wildcard Inheritance in Internal/Webchat CommandsEPSS 0.4%CVE-2026-35628MEDIUMOpenClaw < 2026.3.25 - Brute-Force Attack via Missing Telegram Webhook Rate LimitingEPSS 0.4%CVE-2026-32006LOWOpenClaw < 2026.2.26 - Authorization Bypass via DM Pairing-Store Fallback in Group AllowlistEPSS 0.4%CVE-2026-22168HIGHOpenClaw < 2026.2.21 - Command Injection via cmd.exe /c Trailing Arguments in system.runEPSS 0.4%CVE-2026-32010MEDIUMOpenClaw < 2026.2.22 - Allowlist Bypass via sort --compress-program ParameterEPSS 0.4%CVE-2026-32046MEDIUMOpenClaw < 2026.2.21 - OS-level Sandbox Bypass via --no-sandbox FlagEPSS 0.4%CVE-2026-43572MEDIUMOpenClaw 2026.4.10 < 2026.4.14 - Missing Sender Authorization in Microsoft Teams SSO Invoke HandlerEPSS 0.4%CVE-2026-28471MEDIUMOpenClaw 2026.1.14-1 < 2026.2.2 - Allowlist Bypass via displayName and Cross-Homeserver localpart Matching in Matrix PluginEPSS 0.4%CVE-2026-32005HIGHOpenClaw < 2026.2.25 - Authorization Bypass in Interactive Callbacks via Sender Check SkipEPSS 0.4%CVE-2026-44117MEDIUMOpenClaw < 2026.4.20 - Server-Side Request Forgery in QQBot Direct Media UploadEPSS 0.4%