Vulnerabilidades em openclaw

663 resultados
Análise Vexday

A OpenClaw apresenta um portfólio de 47 vulnerabilidades, com 10 descobertas nos últimos 90 dias, indicando atividade contínua de risco. Nenhuma vulnerabilidade está sob exploração ativa registrada (KEV), mas a fraqueza dominante em path traversal (CWE-22) é crítica em ambientes com controle de acesso inadequado. Com apenas 1 vulnerabilidade crítica (CVSS), o risco permanece moderado, mas exige monitoramento nas próximas atualizações da plataforma.

CVE-2026-41339MEDIUMOpenClaw < 2026.4.2 - Information Disclosure via Gateway Connect SnapshotEPSS 0.4%CVE-2026-35618HIGHOpenClaw < 2026.3.23 - Replay Identity Drift via Query-Only Variants in Plivo V2 VerificationEPSS 0.4%CVE-2026-27522HIGHOpenClaw < 2026.2.24 - Arbitrary File Read via sendAttachment and setGroupIcon Message ActionsEPSS 0.4%CVE-2026-22177MEDIUMOpenClaw < 2026.2.21 - Environment Variable Injection via Config env.varsEPSS 0.4%CVE-2026-62209HIGHOpenClaw 2026.5.10-beta.1 < 2026.6.5 Authorization Bypass via agent-mode dispatchEPSS 0.4%CVE-2026-27486MEDIUMOpenClaw: Process Safety - Unvalidated PID Kill via SIGKILL in Process CleanupEPSS 0.4%CVE-2026-41908LOWOpenClaw < 2026.4.20 - Scope Enforcement Bypass in Assistant-Media RouteEPSS 0.4%CVE-2026-53838MEDIUMOpenClaw < 2026.5.27 - Node Pairing State Mutation via ReconnectionEPSS 0.4%CVE-2026-41403MEDIUMOpenClaw < 2026.3.31 - Access Control Bypass via Proxied Remote Request MisclassificationEPSS 0.4%CVE-2026-41402LOWOpenClaw < 2026.3.31 - Webhook Replay Cache Cross-Target messageId Scope BypassEPSS 0.4%CVE-2026-62187HIGHOpenClaw < 2026.6.9 Feishu tools Authorization BypassEPSS 0.4%CVE-2026-53857HIGHOpenClaw < 2026.5.3 - Mutable Display Name Binding in Zalo allowFrom PolicyEPSS 0.4%CVE-2026-53823HIGHOpenClaw < 2026.5.3 - Privilege Escalation via Mutable Slack Display Names in allowFromEPSS 0.4%CVE-2026-62188HIGHOpenClaw < 2026.6.9 Feishu Authorization BypassEPSS 0.4%CVE-2026-53849HIGHOpenClaw < 2026.5.7 - Privilege Escalation via Mutable Discord Display Names in allowFromEPSS 0.4%CVE-2026-44993LOWOpenClaw < 2026.4.20 - Direct Message Misclassification in Feishu Card ActionsEPSS 0.4%CVE-2026-35651MEDIUMOpenClaw 2026.2.13 < 2026.3.25 - ANSI Escape Sequence Injection in Approval PromptEPSS 0.4%CVE-2026-28480MEDIUMOpenClaw < 2026.2.14 - Identity Spoofing via Mutable Username in Telegram Allowlist AuthorizationEPSS 0.4%CVE-2026-62191HIGHOpenClaw 2026.6.6 < 2026.6.9 Authorization Bypass via Message MutationsEPSS 0.4%CVE-2026-41914MEDIUMOpenClaw < 2026.4.8 - Server-Side Request Forgery in QQ Bot Media Fetch PathsEPSS 0.4%