Vulnerabilidades em openclaw

584 resultados
Análise Vexday

A OpenClaw apresenta um portfólio de 47 vulnerabilidades, com 10 descobertas nos últimos 90 dias, indicando atividade contínua de risco. Nenhuma vulnerabilidade está sob exploração ativa registrada (KEV), mas a fraqueza dominante em path traversal (CWE-22) é crítica em ambientes com controle de acesso inadequado. Com apenas 1 vulnerabilidade crítica (CVSS), o risco permanece moderado, mas exige monitoramento nas próximas atualizações da plataforma.

CVE-2026-25253HIGHOpenClaw (aka clawdbot or Moltbot) before 2026.1.29 obtains a gatewayUrl value from a query string and automatically makes a WebSocket conneEPSS 24.1%CVE-2026-32917CRITICALOpenClaw < 2026.3.13 - Remote Command Injection via Unsanitized iMessage Attachment Paths in SCPEPSS 3.2%CVE-2026-26323HIGHOpenClaw has a command injection in maintainer clawtributors updaterEPSS 2.1%CVE-2026-53822HIGHOpenClaw < 2026.5.18 - Command Argument Modification via Shell Wrapper Between Approval and ExecutionEPSS 2.0%CVE-2026-27487HIGHOpenClaw: Prevent shell injection in macOS keychain credential writeEPSS 1.9%CVE-2026-32052MEDIUMOpenClaw < 2026.2.24 - Hidden Command Execution via Shell-Wrapper Positional argv CarriersEPSS 1.6%CVE-2026-32063MEDIUMOpenClaw 2026.2.19-2 < 2026.2.21 - Command Injection via Newline in systemd Unit GenerationEPSS 1.3%CVE-2026-44998LOWOpenClaw < 2026.4.20 - Tool Policy Bypass via Bundled MCP/LSP ToolsEPSS 1.2%CVE-2026-44109CRITICALOpenClaw < 2026.4.15 - Authentication Bypass in Feishu Webhook and Card-Action ValidationEPSS 1.1%CVE-2026-32000MEDIUMOpenClaw < 2026.2.19 - Command Injection via Windows Shell Fallback in Lobster Tool ExecutionEPSS 1.1%CVE-2026-41352HIGHOpenClaw < 2026.3.31 - Remote Code Execution via Node Scope Gate BypassEPSS 1.0%CVE-2026-32056HIGHOpenClaw < 2026.2.22 - Remote Code Execution via Shell Startup Environment Variable Injection in system.runEPSS 1.0%CVE-2026-32060HIGHOpenClaw < 2026.2.14 - Path Traversal in apply_patch via Crafted PathsEPSS 1.0%CVE-2026-8634CRITICALCrabbox < v0.12.0 Environment Variable Information DisclosureEPSS 1.0%CVE-2026-28446CRITICALOpenClaw < 2026.2.1 - Inbound Allowlist Policy Bypass in voice-call Extension via Empty Caller ID and Suffix MatchingEPSS 1.0%CVE-2026-25157HIGHOpenClaw/Clawdbot has OS Command Injection via Project Root Path in sshNodeCommandEPSS 1.0%CVE-2026-3689MEDIUMOpenClaw Canvas Path Traversal Information Disclosure VulnerabilityEPSS 1.0%CVE-2026-45006HIGHOpenClaw < 2026.4.23 - Unsafe Config Mutation via Gateway Tool Denylist BypassEPSS 0.9%CVE-2026-41405HIGHOpenClaw < 2026.3.31 - Resource Exhaustion via Unauthenticated MS Teams Webhook Body ParsingEPSS 0.9%CVE-2026-31994MEDIUMOpenClaw < 2026.2.19 - Local Command Injection via Unsafe cmd Argument Handling in Windows Scheduled Task Script GenerationEPSS 0.9%