Vulnerabilidades em OpenClaw

584 resultados
Análise Vexday

Com 495 CVEs catalogadas e nenhuma confirmada em exploração ativa no momento, o perfil do OpenClaw apresenta taxa de exploração confirmada abaixo da média geral do catálogo KEV. O dado que merece atenção imediata é o volume de 323 vulnerabilidades surgidas nos últimos 90 dias, indicando um ritmo elevado de descobertas recentes que ainda pode não ter atraído atenção de agentes maliciosos, mas amplia consideravelmente a superfície de ataque. O tipo de falha mais comum é CWE-863 (autorização incorreta), o que sugere fragilidades estruturais no controle de acesso — categoria com alto potencial de impacto caso explorada. A CVE mais perigosa identificada atualmente, CVE-2026-25253, apresenta EPSS de 0,0802, e embora não haja PoC pública disponível, equipes de segurança devem monitorar sua evolução dado o contexto de crescimento acelerado no volume de vulnerabilidades do vendor.

CVE-2026-28470CRITICALOpenClaw < 2026.2.2 - Exec Allowlist Bypass via Command Substitution in Double QuotesEPSS 0.5%CVE-2026-29610HIGHOpenClaw < 2026.2.14 - Command Hijacking via Unsafe PATH HandlingEPSS 0.5%CVE-2026-32916CRITICALOpenClaw 2026.3.7 < 2026.3.11 - Authorization Bypass in Plugin Subagent Routes via Synthetic Admin ScopesEPSS 0.5%CVE-2026-41343MEDIUMOpenClaw < 2026.3.31 - Denial of Service via LINE Webhook Handler Pre-Auth ConcurrencyEPSS 0.5%CVE-2026-3691MEDIUMOpenClaw Client PKCE Verifier Information Disclosure VulnerabilityEPSS 0.5%CVE-2026-35639HIGHOpenClaw < 2026.3.22 - Privilege Escalation via device.pair.approve Scope ValidationEPSS 0.5%CVE-2026-35627MEDIUMOpenClaw < 2026.3.22 - Unauthenticated Cryptographic Work in Nostr Inbound DM HandlingEPSS 0.5%CVE-2026-62223HIGHOpenClaw < 2026.5.18 Authorization Bypass via Device-pairEPSS 0.5%CVE-2026-62228HIGHOpenClaw < 2026.6.5 Authorization Bypass via Node Exec ApprovalsEPSS 0.5%CVE-2026-53836HIGHOpenClaw < 2026.5.12 - Allowlist Bypass via PowerShell Encoded-Command AliasesEPSS 0.5%CVE-2026-62218HIGHOpenClaw 2026.1.20 < 2026.5.27 Authorization Bypass via device.pair.approveEPSS 0.5%CVE-2026-62210MEDIUMOpenClaw < 2026.6.1 Denial of Service via Remote Media URLsEPSS 0.4%CVE-2026-62217HIGHOpenClaw 2026.5.14-beta.1 < 2026.5.27 Authentication Bypass via exec approvalsEPSS 0.4%CVE-2026-62194HIGHOpenClaw 2026.5.20 < 2026.6.9 Privilege Escalation via Plugin InstallEPSS 0.4%CVE-2026-41378HIGHOpenClaw < 2026.3.31 - Privilege Escalation to Remote Code Execution via Unrestricted node.event Agent DispatchEPSS 0.4%CVE-2026-28448MEDIUMOpenClaw 2026.1.29 < 2026.2.1 - Authorization Bypass in Twitch Plugin allowFrom Access ControlEPSS 0.4%CVE-2026-26320HIGHOpenClaw macOS deep link confirmation truncation can conceal executed agent messageEPSS 0.4%CVE-2026-35620MEDIUMOpenClaw < 2026.3.24 - Missing Authorization in /send and /allowlist Chat CommandsEPSS 0.4%CVE-2026-62214MEDIUMOpenClaw < 2026.5.28 Bot Framework SSRF via serviceUrl Parameter ValidationEPSS 0.4%CVE-2026-32042HIGHOpenClaw < 2026.2.25 - Privilege Escalation via Unpaired Device Identity in Shared Gateway AuthenticationEPSS 0.4%