Vulnerabilidades en openclaw

663 resultados
Análisis Vexday

A OpenClaw apresenta um portfólio de 47 vulnerabilidades, com 10 descobertas nos últimos 90 dias, indicando atividade contínua de risco. Nenhuma vulnerabilidade está sob exploração ativa registrada (KEV), mas a fraqueza dominante em path traversal (CWE-22) é crítica em ambientes com controle de acesso inadequado. Com apenas 1 vulnerabilidade crítica (CVSS), o risco permanece moderado, mas exige monitoramento nas próximas atualizações da plataforma.

CVE-2026-35629MEDIUMOpenClaw < 2026.3.25 - Server-Side Request Forgery via Unguarded Configured Base URLs in Channel ExtensionsEPSS 0.3%CVE-2026-62197MEDIUMOpenClaw < 2026.6.6 Policy Bypass via CDP DiscoveryEPSS 0.3%CVE-2026-62226MEDIUMOpenClaw 2026.3.28 < 2026.5.19 Authorization Bypass via Browser Act RouteEPSS 0.3%CVE-2026-53834HIGHOpenClaw < 2026.4.27 - Authorization Bypass in QQBot Pre-dispatch Slash CommandsEPSS 0.3%CVE-2026-32921MEDIUMOpenClaw < 2026.3.8 - Script Content Modification via Mutable Operand Binding in system.runEPSS 0.3%CVE-2026-35624LOWOpenClaw < 2026.3.22 - Policy Confusion via Room Name Collision in Nextcloud TalkEPSS 0.3%CVE-2026-22175HIGHOpenClaw < 2026.2.23 - Exec Approval Bypass via Unrecognized Multiplexer Shell WrappersEPSS 0.3%CVE-2026-35644HIGHOpenClaw < 2026.3.22 - Credential Exposure via baseUrl Fields in Gateway SnapshotsEPSS 0.3%CVE-2026-32976HIGHOpenClaw < 2026.3.11 - Account-Scoped configWrites Policy Bypass via Channel CommandsEPSS 0.3%CVE-2026-62186HIGHOpenClaw < 2026.6.8 Authorization Bypass via HTTP Model OverrideEPSS 0.3%CVE-2026-32031MEDIUMOpenClaw < 2026.2.26 - Authentication Bypass via Path Canonicalization Mismatch in /api/channels GatewayEPSS 0.3%CVE-2026-100531HIGHopenclaw Slack before 2026.8.1 Authorization BypassEPSS 0.3%CVE-2026-44991LOWOpenClaw < 2026.4.21 - Authorization Bypass in Owner-Enforced Commands via Wildcard Channel SendersEPSS 0.3%CVE-2026-41296HIGHOpenClaw < 2026.3.31 - Sandbox Escape via TOCTOU Race in Remote FS Bridge readFileEPSS 0.3%CVE-2026-35617LOWOpenClaw < 2026.3.25 - Authorization Bypass via Group Policy Rebinding with Mutable Space displayNameEPSS 0.3%CVE-2026-41377MEDIUMOpenClaw < 2026.3.31 - Fail-Open Security Scan Bypass in Plugin InstallationEPSS 0.3%CVE-2026-35621HIGHOpenClaw < 2026.3.24 - Privilege Escalation via chat.send to Allowlist PersistenceEPSS 0.3%CVE-2026-91836LOWOpenClaw ClawScan Static Scanner static_scanner.go incomplete comparison with missing factorsEPSS 0.3%CVE-2026-53831HIGHOpenClaw < 2026.5.18 - Arbitrary File Read via Shell Expansion in system.run Safe-bin AllowlistEPSS 0.3%CVE-2026-41913MEDIUMOpenClaw < 2026.4.4 - Rate-Limit Bypass via Concurrent Async Authentication AttemptsEPSS 0.3%