Vulnerabilidades en openclaw

663 resultados
Análisis Vexday

A OpenClaw apresenta um portfólio de 47 vulnerabilidades, com 10 descobertas nos últimos 90 dias, indicando atividade contínua de risco. Nenhuma vulnerabilidade está sob exploração ativa registrada (KEV), mas a fraqueza dominante em path traversal (CWE-22) é crítica em ambientes com controle de acesso inadequado. Com apenas 1 vulnerabilidade crítica (CVSS), o risco permanece moderado, mas exige monitoramento nas próximas atualizações da plataforma.

CVE-2026-32050MEDIUMOpenClaw < 2026.2.25 - Unauthorized Reaction Status Event Enqueue via Access Check BypassEPSS 0.4%CVE-2026-32019LOWOpenClaw < 2026.2.22 - Incomplete IPv4 Special-Use Range Blocking in SSRF GuardEPSS 0.4%CVE-2026-53859MEDIUMOpenClaw < 2026.5.26 - Hostname Validation Bypass via Trailing-Dot InconsistencyEPSS 0.4%CVE-2026-53815HIGHOpenClaw < 2026.5.19 - Channel Allowlist Bypass in Message Read ActionsEPSS 0.4%CVE-2026-62201MEDIUMOpenClaw < 2026.6.6 Network Policy Bypass via exec-serverEPSS 0.4%CVE-2026-53844MEDIUMOpenClaw < 2026.4.29 - Session Visibility Check Bypass in Shared Memory SearchEPSS 0.4%CVE-2026-35630HIGHOpenClaw < 2026.5.18 - QQBot Missing Approver Identity Enforcement in Native Approval ButtonsEPSS 0.4%CVE-2026-53830MEDIUMOpenClaw < 2026.4.22 - Webhook Secret Revocation Bypass via secrets.reloadEPSS 0.4%CVE-2026-43581CRITICALOpenClaw < 2026.4.10 - Chrome DevTools Protocol Exposure via Overly Broad CDP Relay BindingEPSS 0.4%CVE-2026-62213MEDIUMOpenClaw < 2026.5.27 Token Leakage via MS Teams Outbound RequestsEPSS 0.4%CVE-2026-62208MEDIUMOpenClaw < 2026.6.5 Authorization Header Forwarding via SSEEPSS 0.4%CVE-2026-41387HIGHOpenClaw < 2026.3.22 - Supply Chain Redirection via Incomplete Host Environment SanitizationEPSS 0.4%CVE-2026-34505MEDIUMOpenClaw < 2026.3.12 - Webhook Rate Limiting Bypass via Pre-Authentication Secret ValidationEPSS 0.4%CVE-2026-41912MEDIUMOpenClaw < 2026.4.8 - Server-Side Request Forgery Policy Bypass via Interaction-Triggered NavigationEPSS 0.4%CVE-2026-62206MEDIUMOpenClaw < 2026.6.9 Authentication Bypass via Moderation ActionsEPSS 0.4%CVE-2026-41371HIGHOpenClaw < 2026.3.28 - Privilege Escalation via chat.send Reset CommandEPSS 0.4%CVE-2026-32021MEDIUMOpenClaw < 2026.2.22 - Authorization Bypass via Display Name Collision in Feishu allowFromEPSS 0.4%CVE-2026-62205MEDIUMOpenClaw 2026.4.12-beta.1 < 2026.6.6 Authorization Bypass via message actionsEPSS 0.4%CVE-2026-41299HIGHOpenClaw < 2026.3.28 - Client Identity Spoofing in chat.send Gateway Provenance GuardEPSS 0.4%CVE-2026-43531HIGHOpenClaw < 2026.4.9 - Environment Variable Injection via Workspace .env FileEPSS 0.4%