Vulnerabilidades en openclaw
663 resultadosAnálisis Vexday
A OpenClaw apresenta um portfólio de 47 vulnerabilidades, com 10 descobertas nos últimos 90 dias, indicando atividade contínua de risco. Nenhuma vulnerabilidade está sob exploração ativa registrada (KEV), mas a fraqueza dominante em path traversal (CWE-22) é crítica em ambientes com controle de acesso inadequado. Com apenas 1 vulnerabilidade crítica (CVSS), o risco permanece moderado, mas exige monitoramento nas próximas atualizações da plataforma.
CVE-2026-35620MEDIUMOpenClaw < 2026.3.24 - Missing Authorization in /send and /allowlist Chat CommandsEPSS 0.5%CVE-2026-62199HIGHOpenClaw < 2026.6.6 Authentication Bypass via Environment FilteringEPSS 0.5%CVE-2026-62203HIGHOpenClaw < 2026.6.6 Environment Variable Injection via rustupEPSS 0.5%CVE-2026-62200HIGHOpenClaw < 2026.6.6 Authentication Bypass via Git ext transportEPSS 0.5%CVE-2026-32924MEDIUMOpenClaw < 2026.3.12 - Authorization Bypass via Misclassified Reaction Events in FeishuEPSS 0.5%CVE-2026-31993MEDIUMOpenClaw < 2026.2.22 - Allowlist Parsing Mismatch in system.run Shell ChainsEPSS 0.5%CVE-2026-32025HIGHOpenClaw < 2026.2.25 - Password Brute-Force via Browser-Origin WebSocket Authentication BypassEPSS 0.5%CVE-2026-62220MEDIUMOpenClaw 2026.2.25 < 2026.5.26 WebSocket Rate Limit BypassEPSS 0.5%CVE-2026-35663HIGHOpenClaw < 2026.3.25 - Privilege Escalation via Backend Reconnect Scope Self-ClaimEPSS 0.5%CVE-2026-42426HIGHOpenClaw < 2026.4.8 - Improper Authorization in node.pair.approve via operator.write ScopeEPSS 0.5%CVE-2026-35669HIGHOpenClaw < 2026.3.25 - Privilege Escalation via Gateway Plugin HTTP Authentication ScopeEPSS 0.5%CVE-2026-32023MEDIUMOpenClaw < 2026.2.24 - Approval Gating Bypass via Dispatch-Wrapper Depth-Cap Mismatch in system.runEPSS 0.5%CVE-2026-42422HIGHOpenClaw < 2026.4.8 - Role Bypass in device.token.rotate FunctionEPSS 0.5%CVE-2026-41329CRITICALOpenClaw < 2026.3.31 - Sandbox Bypass via Heartbeat Context Inheritance and senderIsOwner EscalationEPSS 0.5%CVE-2026-41363MEDIUMOpenClaw 2026.2.6 < 2026.3.28 - Arbitrary File Read via Feishu upload_image ParameterEPSS 0.5%CVE-2026-35623MEDIUMOpenClaw < 2026.3.25 - Brute-Force Attack via Missing Webhook Password Rate LimitingEPSS 0.5%CVE-2026-33579CRITICALOpenClaw < 2026.3.28 - Privilege Escalation via Missing Caller Scope Validation in Device Pair ApprovalEPSS 0.5%CVE-2026-35645MEDIUMOpenClaw < 2026.3.25 - Privilege Escalation via Synthetic operator.admin in deleteSessionEPSS 0.5%CVE-2026-41331MEDIUMOpenClaw < 2026.3.31 - Resource Consumption via Unauthorized Telegram Audio Preflight TranscriptionEPSS 0.5%CVE-2026-32030HIGHOpenClaw < 2026.2.19 - Sensitive File Disclosure via stageSandboxMedia Path TraversalEPSS 0.5%