Vulnerabilidades en openclaw

663 resultados
Análisis Vexday

A OpenClaw apresenta um portfólio de 47 vulnerabilidades, com 10 descobertas nos últimos 90 dias, indicando atividade contínua de risco. Nenhuma vulnerabilidade está sob exploração ativa registrada (KEV), mas a fraqueza dominante em path traversal (CWE-22) é crítica em ambientes com controle de acesso inadequado. Com apenas 1 vulnerabilidade crítica (CVSS), o risco permanece moderado, mas exige monitoramento nas próximas atualizações da plataforma.

CVE-2026-41298MEDIUMOpenClaw < 2026.4.2 - Authorization Bypass in Session Termination EndpointEPSS 0.3%CVE-2026-41348LOWOpenClaw < 2026.3.31 - Group DM Channel Allowlist Bypass via Discord Slash CommandsEPSS 0.3%CVE-2026-33578MEDIUMOpenClaw < 2026.3.28 - Sender Policy Allowlist Bypass via Policy Downgrade in Google Chat and Zalouser ExtensionsEPSS 0.3%CVE-2026-32037LOWOpenClaw < 2026.2.22 - Redirect Chain Bypass of Media Host Allowlist in MSTeams Attachment HandlingEPSS 0.3%CVE-2026-32895MEDIUMOpenClaw < 2026.2.26 - Sender Authorization Bypass in Slack System Event HandlersEPSS 0.3%CVE-2026-41381LOWOpenClaw < 2026.3.31 - Access Control Bypass in Discord Voice Manager via Channel AllowlistEPSS 0.3%CVE-2026-41382LOWOpenClaw < 2026.3.31 - Discord Voice Ingress Authorization Bypass via Channel and Role Validation GapsEPSS 0.3%CVE-2026-41365MEDIUMOpenClaw < 2026.3.31 - Sender Allowlist Bypass via Graph API Thread HistoryEPSS 0.3%CVE-2026-100599HIGHOpenClaw 2026.5.1 before 2026.7.1 Remote Code Execution via googlemeet.chromeEPSS 0.3%CVE-2026-100541HIGHOpenClaw Matrix before 2026.8.1 Authorization Bypass via Case FoldingEPSS 0.3%CVE-2026-53847MEDIUMOpenClaw < 2026.5.6 - Privilege Escalation via Active Memory Write ScopeEPSS 0.3%CVE-2026-100588HIGHOpenClaw before 2026.7.1 Authentication Bypass via node.invokeEPSS 0.3%CVE-2026-62219MEDIUMOpenClaw 2026.2.12 < 2026.5.26 Authorization Bypass via Blank Agent IDsEPSS 0.3%CVE-2026-32014HIGHOpenClaw < 2026.2.26 - Node Reconnect Metadata Spoofing via Unsigned Platform FieldsEPSS 0.3%CVE-2026-43534CRITICALOpenClaw < 2026.4.10 - Unsanitized External Input in Agent Hook EventsEPSS 0.3%CVE-2026-41909MEDIUMOpenClaw < 2026.4.20 - Improper Authorization in Paired-Device Pairing ActionsEPSS 0.3%CVE-2026-31989MEDIUMOpenClaw < 2026.3.1 - Server-Side Request Forgery via web_search Citation RedirectEPSS 0.3%CVE-2026-32067LOWOpenClaw < 2026.2.26 - Cross-Account Authorization Bypass in DM Pairing StoreEPSS 0.3%CVE-2026-32906LOWOpenClaw < 2026.5.12 - Privilege Escalation in Slack Plugin Approvals via Exec Approver GateEPSS 0.3%CVE-2026-53863MEDIUMOpenClaw < 2026.4.25 - Unvalidated Group ID Acceptance in Tool Group PolicyEPSS 0.3%