Vulnerabilidades en openclaw

584 resultados
Análisis Vexday

A OpenClaw apresenta um portfólio de 47 vulnerabilidades, com 10 descobertas nos últimos 90 dias, indicando atividade contínua de risco. Nenhuma vulnerabilidade está sob exploração ativa registrada (KEV), mas a fraqueza dominante em path traversal (CWE-22) é crítica em ambientes com controle de acesso inadequado. Com apenas 1 vulnerabilidade crítica (CVSS), o risco permanece moderado, mas exige monitoramento nas próximas atualizações da plataforma.

CVE-2026-35626MEDIUMOpenClaw < 2026.3.22 - Unauthenticated Resource Exhaustion via Voice Call WebhookEPSS 0.7%CVE-2026-35666HIGHOpenClaw < 2026.3.22 - Allowlist Bypass via Unregistered Time Dispatch WrapperEPSS 0.7%CVE-2026-26325HIGHOpenClaw Node host system.run rawCommand/command mismatch can bypass allowlist/approvalsEPSS 0.7%CVE-2026-32922CRITICALOpenClaw < 2026.3.11 - Privilege Escalation via Unvalidated Scope in device.token.rotateEPSS 0.7%CVE-2026-43569HIGHOpenClaw < 2026.4.9 - Untrusted Provider Plugin Auto-enablement via Workspace Provider AuthEPSS 0.7%CVE-2026-28464HIGHOpenClaw < 2026.2.12 - Timing Attack in Hooks Token AuthenticationEPSS 0.7%CVE-2026-45223HIGHCrabbox < 0.9.0 Authentication Bypass via Admin Claim InjectionEPSS 0.7%CVE-2026-8621HIGHCrabbox < v0.12.0 Authentication Bypass via Header SpoofingEPSS 0.7%CVE-2026-43571HIGHOpenClaw < 2026.4.10 - Untrusted Workspace Plugin Shadow Resolution in Channel SetupEPSS 0.7%CVE-2026-28465HIGHOpenClaw voice-call < 2026.2.3 - Webhook Verification Bypass via Forwarded HeadersEPSS 0.7%CVE-2026-27002HIGHOpenClaw: Docker container escape via unvalidated bind mount config injectionEPSS 0.7%CVE-2026-28466CRITICALOpenClaw < 2026.2.14 - Remote Code Execution via Node Invoke Approval BypassEPSS 0.7%CVE-2026-35627MEDIUMOpenClaw < 2026.3.22 - Unauthenticated Cryptographic Work in Nostr Inbound DM HandlingEPSS 0.7%CVE-2026-32036HIGHOpenClaw < 2026.2.26- Authentication Bypass via Encoded Dot-Segment Traversal in /api/channelsEPSS 0.7%CVE-2026-35633MEDIUMOpenClaw < 2026.3.22 - Unbounded Memory Allocation via Remote Media Error ResponsesEPSS 0.7%CVE-2026-28462HIGHOpenClaw < 2026.2.13 - Path Traversal in Trace and Download Output PathsEPSS 0.7%CVE-2026-28460MEDIUMOpenClaw < 2026.2.22 - Allowlist Bypass via Shell Line-Continuation Command Substitution in system.runEPSS 0.7%CVE-2026-41374MEDIUMOpenClaw < 2026.3.31 - Resource Consumption via Discord Audio Preflight Before Member AuthorizationEPSS 0.7%CVE-2026-32042HIGHOpenClaw < 2026.2.25 - Privilege Escalation via Unpaired Device Identity in Shared Gateway AuthenticationEPSS 0.6%CVE-2026-41404HIGHOpenClaw < 2026.3.31 - Operator Admin Privilege Escalation via Trusted-Proxy AuthenticationEPSS 0.6%