Vulnerabilidades en openclaw

663 resultados
Análisis Vexday

A OpenClaw apresenta um portfólio de 47 vulnerabilidades, com 10 descobertas nos últimos 90 dias, indicando atividade contínua de risco. Nenhuma vulnerabilidade está sob exploração ativa registrada (KEV), mas a fraqueza dominante em path traversal (CWE-22) é crítica em ambientes com controle de acesso inadequado. Com apenas 1 vulnerabilidade crítica (CVSS), o risco permanece moderado, mas exige monitoramento nas próximas atualizações da plataforma.

CVE-2026-44117MEDIUMOpenClaw < 2026.4.20 - Server-Side Request Forgery in QQBot Direct Media UploadEPSS 0.4%CVE-2026-41297MEDIUMOpenClaw < 2026.3.31 - Server-Side Request Forgery via Marketplace Plugin Download RedirectEPSS 0.4%CVE-2026-41302MEDIUMOpenClaw < 2026.3.31 - Server-Side Request Forgery via Unguarded fetch() in Marketplace Plugin DownloadEPSS 0.4%CVE-2026-41406LOWOpenClaw < 2026.3.31 - Sender Allowlist Bypass via Thread History and Quoted MessagesEPSS 0.4%CVE-2026-43535HIGHOpenClaw < 2026.4.14 - Authorization Context Reuse in Collect-Mode Queue BatchesEPSS 0.4%CVE-2026-34425MEDIUMOpenClaw - Shell-Bleed Protection Preflight Validation BypassEPSS 0.4%CVE-2026-42439MEDIUMOpenClaw < 2026.4.10 - SSRF Policy Bypass in Browser Tabs Action RoutesEPSS 0.4%CVE-2026-32972HIGHOpenClaw < 2026.3.11 - Authorization Bypass in Browser Profile Management via browser.requestEPSS 0.4%CVE-2026-32905HIGHOpenClaw < 2026.5.4 - Unauthorized Device-Pairing Bootstrap Code Issuance via Chat CommandEPSS 0.4%CVE-2026-26326MEDIUMOpenClaw skills.status could leak secrets to operator.read clientsEPSS 0.4%CVE-2026-62195HIGHOpenClaw 2026.5.20 < 2026.6.6 Authorization Bypass via MCP loopbackEPSS 0.4%CVE-2026-62196HIGHOpenClaw 2026.3.22 < 2026.6.6 Authorization Bypass via WhatsApp Group IDsEPSS 0.4%CVE-2026-35647MEDIUMOpenClaw < 2026.3.25 - Direct Message Policy Bypass via Verification NoticesEPSS 0.4%CVE-2026-35654MEDIUMOpenClaw < 2026.3.25 - Authorization Bypass in Microsoft Teams Feedback InvokeEPSS 0.4%CVE-2026-53814HIGHOpenClaw < 2026.5.20 - Privilege Escalation via Hook-Triggered CLI MCP Tool AuthorityEPSS 0.4%CVE-2026-62227MEDIUMOpenClaw 2026.4.14 < 2026.5.26 SSRF via Browser SnapshotEPSS 0.4%CVE-2026-53812MEDIUMOpenClaw < 2026.5.18 - Private-Network Navigation Bypass via Browser Act InteractionsEPSS 0.4%CVE-2026-43567HIGHOpenClaw < 2026.4.10 - Path Traversal in screen_record outPath ParameterEPSS 0.4%CVE-2026-28454HIGHOpenClaw < 2026.2.2 - Authorization Bypass via Unauthenticated Telegram WebhookEPSS 0.4%CVE-2026-41407MEDIUMOpenClaw < 2026.4.2 - Timing Side Channel in Shared-Secret ComparisonEPSS 0.4%