Vulnerabilidades en openclaw

584 resultados
Análisis Vexday

A OpenClaw apresenta um portfólio de 47 vulnerabilidades, com 10 descobertas nos últimos 90 dias, indicando atividade contínua de risco. Nenhuma vulnerabilidade está sob exploração ativa registrada (KEV), mas a fraqueza dominante em path traversal (CWE-22) é crítica em ambientes com controle de acesso inadequado. Com apenas 1 vulnerabilidade crítica (CVSS), o risco permanece moderado, mas exige monitoramento nas próximas atualizações da plataforma.

CVE-2026-42434HIGHOpenClaw 2026.4.5 < 2026.4.10 - Sandbox Escape via host Parameter Override in Exec RoutingEPSS 0.6%CVE-2026-26320HIGHOpenClaw macOS deep link confirmation truncation can conceal executed agent messageEPSS 0.6%CVE-2026-22176MEDIUMOpenClaw < 2026.2.19 - Command Injection via Unescaped Environment Variables in Windows Scheduled Task Script GenerationEPSS 0.6%CVE-2026-33581HIGHOpenClaw < 2026.3.24 - Arbitrary File Read via mediaUrl and fileUrl ParametersEPSS 0.6%CVE-2026-3690HIGHOpenClaw Canvas Authentication Bypass VulnerabilityEPSS 0.6%CVE-2026-32916CRITICALOpenClaw 2026.3.7 < 2026.3.11 - Authorization Bypass in Plugin Subagent Routes via Synthetic Admin ScopesEPSS 0.6%CVE-2026-22179HIGHOpenClaw < 2026.2.22 - Allowlist Bypass via Command Substitution in system.runEPSS 0.6%CVE-2026-28472CRITICALOpenClaw < 2026.2.2 - Device Identity Check Bypass in Gateway WebSocket Connect HandshakeEPSS 0.6%CVE-2026-32059HIGHOpenClaw 2026.2.22-2 < 2026.2.23 - Allowlist Bypass via sort Long-Option Abbreviation in tools.exec.safeBinsEPSS 0.6%CVE-2026-41397HIGHOpenClaw < 2026.3.31 - Sandbox Escape via Unrestricted File Sync and Symlink TraversalEPSS 0.6%CVE-2026-41408LOWOpenClaw < 2026.3.31 - Disk Exhaustion via Media Download BypassEPSS 0.6%CVE-2026-41370HIGHOpenClaw < 2026.3.31 - Path Traversal via Inbound Channel Attachment Path in ACP DispatchEPSS 0.6%CVE-2026-31992HIGHOpenClaw < 2026.2.23 - Allowlist Exec-Guard Bypass via env -SEPSS 0.6%CVE-2026-43530HIGHOpenClaw 2026.2.23 < 2026.4.12 - Weakened Exec Approval Binding via busybox and toybox Applet ExecutionEPSS 0.6%CVE-2026-53810HIGHOpenClaw < 2026.5.18 - Arbitrary Code Execution via Unscanned Marketplace Runtime Extension MetadataEPSS 0.6%CVE-2026-28461HIGHOpenClaw < 2026.3.1 - Unbounded Memory Growth in Zalo Webhook via Query String Key ChurnEPSS 0.6%CVE-2026-53806HIGHOpenClaw < 2026.5.12 - Shell Option Parsing Bypass in Exec RevalidationEPSS 0.6%CVE-2026-32057MEDIUMOpenClaw < 2026.2.25 - Authentication Bypass via Control UI client.id ParameterEPSS 0.6%CVE-2026-28363CRITICALIn OpenClaw before 2026.2.23, tools.exec.safeBins validation for sort could be bypassed via GNU long-option abbreviations (such as --compresEPSS 0.6%CVE-2026-32987CRITICALOpenClaw < 2026.3.13 - Bootstrap Setup Code Replay via Device PairingEPSS 0.6%