Vulnerabilidades em openclaw

663 resultados
Análise Vexday

A OpenClaw apresenta um portfólio de 47 vulnerabilidades, com 10 descobertas nos últimos 90 dias, indicando atividade contínua de risco. Nenhuma vulnerabilidade está sob exploração ativa registrada (KEV), mas a fraqueza dominante em path traversal (CWE-22) é crítica em ambientes com controle de acesso inadequado. Com apenas 1 vulnerabilidade crítica (CVSS), o risco permanece moderado, mas exige monitoramento nas próximas atualizações da plataforma.

CVE-2026-41407MEDIUMOpenClaw < 2026.4.2 - Timing Side Channel in Shared-Secret ComparisonEPSS 0.4%CVE-2026-34504MEDIUMOpenClaw < 2026.3.28 - Server-Side Request Forgery via Unguarded Image Download in fal ProviderEPSS 0.4%CVE-2026-44112HIGHOpenClaw < 2026.4.22 - Symlink Swap Race Condition in OpenShell FS Bridge WritesEPSS 0.4%CVE-2026-45001MEDIUMOpenClaw < 2026.4.20 - Gateway Config Mutation Guard Bypass via Agent Tool AccessEPSS 0.4%CVE-2026-44111LOWOpenClaw < 2026.4.15 - Arbitrary Markdown File Read via QMD memory_getEPSS 0.4%CVE-2026-41344MEDIUMOpenClaw < 2026.3.28 - Privilege Escalation via chat.send /verbose ParameterEPSS 0.4%CVE-2026-35649MEDIUMOpenClaw < 2026.3.22 - Settings Reconciliation Bypass via Empty AllowlistEPSS 0.4%CVE-2026-27523MEDIUMOpenClaw < 2026.2.24 - Sandbox Bind Validation Bypass via Symlink-Parent Missing-Leaf PathsEPSS 0.4%CVE-2026-43579MEDIUMOpenClaw < 2026.4.10 - Insufficient Access Control in Nostr Profile Mutation RoutesEPSS 0.4%CVE-2026-32971HIGHOpenClaw < 2026.3.11 - Node-Host Approval UI Mismatch Allows Execution of Unintended CommandsEPSS 0.4%CVE-2026-43568HIGHOpenClaw 2026.4.5 through 2026.4.9 - Privilege Escalation via Memory Dreaming Configuration in /dreaming EndpointEPSS 0.4%CVE-2026-32001MEDIUMOpenClaw < 2026.2.22 - Node Role Device-Identity Bypass via WebSocket AuthenticationEPSS 0.4%CVE-2026-28451MEDIUMOpenClaw < 2026.2.14 - SSRF via Feishu Extension Media FetchingEPSS 0.4%CVE-2026-41916LOWOpenClaw < 2026.4.8 - Stale Authentication State via Config ReloadEPSS 0.4%CVE-2026-44997LOWOpenClaw < 2026.4.22 - Security Envelope Constraint Bypass in ACP Child SessionsEPSS 0.4%CVE-2026-62189HIGHOpenClaw < 2026.6.9 Symlink Following via Mirror SyncEPSS 0.4%CVE-2026-35619MEDIUMOpenClaw < 2026.3.24 - Authorization Bypass via HTTP /v1/models EndpointEPSS 0.4%CVE-2026-43583MEDIUMOpenClaw 2026.4.10 < 2026.4.14 - Loss of Group Tool-Policy Context in Delivery Queue RecoveryEPSS 0.4%CVE-2026-41345MEDIUMOpenClaw < 2026.3.31 - Authorization Header Leak via Cross-Origin Redirect in Media DownloadEPSS 0.4%CVE-2026-31999MEDIUMOpenClaw 2026.2.26 < 2026.3.1 - Current Working Directory Injection via Windows Wrapper Resolution FallbackEPSS 0.4%