Vulnerabilidades en openclaw
663 resultadosAnálisis Vexday
A OpenClaw apresenta um portfólio de 47 vulnerabilidades, com 10 descobertas nos últimos 90 dias, indicando atividade contínua de risco. Nenhuma vulnerabilidade está sob exploração ativa registrada (KEV), mas a fraqueza dominante em path traversal (CWE-22) é crítica em ambientes com controle de acesso inadequado. Com apenas 1 vulnerabilidade crítica (CVSS), o risco permanece moderado, mas exige monitoramento nas próximas atualizações da plataforma.
CVE-2026-100547MEDIUMOpenClaw before 2026.8.1 Authentication Bypass via File URLEPSS 0.1%CVE-2026-22217MEDIUMOpenClaw 2026.2.22 < 2026.2.23 - Arbitrary Binary Execution via $SHELL Environment Variable Trusted Prefix FallbackEPSS 0.1%CVE-2026-31997MEDIUMOpenClaw < 2026.3.1 - Executable Rebind via Unbound PATH-token in system.run ApprovalsEPSS 0.1%CVE-2026-41360MEDIUMOpenClaw < 2026.4.2 - Approval Integrity Bypass in pnpm dlx Local Script BindingEPSS 0.1%CVE-2026-33574MEDIUMOpenClaw < 2026.3.8 - Path Traversal via Tools Root Rebinding in Skills DownloadEPSS 0.1%CVE-2026-26327HIGHOpenClaw allows unauthenticated discovery TXT records to steer routing and TLS pinningEPSS 0.1%CVE-2026-41338MEDIUMOpenClaw < 2026.3.31 - Time-of-Check-Time-of-Use (TOCTOU) Vulnerability in Sandbox File OperationsEPSS 0.1%CVE-2026-100569MEDIUMOpenClaw before 2026.8.1 Credential Exposure via Endpoint OverrideEPSS 0.1%CVE-2026-100598HIGHOpenClaw before 2026.7.1 Approval Binding Logic ErrorEPSS 0.1%CVE-2026-27004MEDIUMOpenClaw session tool visibility hardening and Telegram webhook secret fallbackEPSS 0.1%CVE-2026-27670MEDIUMOpenClaw < 2026.3.2 - Arbitrary File Write via ZIP Extraction Parent Symlink Race ConditionEPSS 0.1%CVE-2026-100573MEDIUMOpenClaw before 2026.8.1 Sandbox Policy Bypass via MCP LoopbackEPSS 0.1%CVE-2026-32988MEDIUMOpenClaw < 2026.3.11 - Sandbox Boundary Bypass via Unvalidated Temporary File CreationEPSS 0.1%CVE-2026-32977MEDIUMOpenClaw < 2026.3.11 - Sandbox Boundary Bypass via Unanchored writeFile Commit PathEPSS 0.1%CVE-2026-43529LOWOpenClaw < 2026.4.10 - Time-of-Check-Time-of-Use (TOCTOU) Race Condition in exec Script Preflight ValidatorEPSS 0.1%CVE-2026-100584MEDIUMOpenClaw before 2026.7.1 Allowlist Bypass via Workspace ShadowsEPSS 0.1%CVE-2026-100597HIGHOpenClaw before 2026.7.1 Path Traversal via Filesystem RaceEPSS 0.1%CVE-2026-100581MEDIUMOpenClaw iOS before 2026.8.11 Credential Storage via Share ExtensionEPSS 0.1%CVE-2026-100603HIGHClawHub before 8c2de6c506 Skill Hiding via Coordinated ReportsEPSS —CVE-2026-100600MEDIUMClawHub before 8c2de6c506 Quota Exhaustion via Anonymous APIEPSS —