Vulnerabilidades em openclaw

663 resultados
Análise Vexday

A OpenClaw apresenta um portfólio de 47 vulnerabilidades, com 10 descobertas nos últimos 90 dias, indicando atividade contínua de risco. Nenhuma vulnerabilidade está sob exploração ativa registrada (KEV), mas a fraqueza dominante em path traversal (CWE-22) é crítica em ambientes com controle de acesso inadequado. Com apenas 1 vulnerabilidade crítica (CVSS), o risco permanece moderado, mas exige monitoramento nas próximas atualizações da plataforma.

CVE-2026-100571MEDIUMOpenClaw before 2026.8.1 SMS Webhook Rate Limit BypassEPSS 0.3%CVE-2026-32898MEDIUMOpenClaw < 2026.2.23 - ACP Permission Auto-Approval Bypass via Untrusted Tool MetadataEPSS 0.3%CVE-2026-100572MEDIUMOpenClaw before 2026.8.1 Denial of Service via Rate LimitEPSS 0.3%CVE-2026-100527MEDIUMOpenClaw before 2026.8.2 Denial of Service via Browser RelayEPSS 0.3%CVE-2026-32029MEDIUMOpenClaw < 2026.2.21 - Client IP Spoofing via X-Forwarded-For Header ParsingEPSS 0.3%CVE-2026-32899MEDIUMOpenClaw < 2026.2.25 - Sender Policy Bypass in Slack Reaction and Pin Event HandlersEPSS 0.3%CVE-2026-35662MEDIUMOpenClaw < 2026.3.22 - Missing controlScope Enforcement in Send ActionEPSS 0.3%CVE-2026-100543HIGHOpenClaw before 2026.8.1 Information Disclosure via Configuration HashEPSS 0.3%CVE-2026-32058LOWOpenClaw < 2026.2.26 - Approval Context-Binding Weakness in system.run via host=nodeEPSS 0.3%CVE-2026-34506LOWOpenClaw < 2026.3.8 - Sender Allowlist Bypass in Microsoft Teams Plugin via Route Allowlist ConfigurationEPSS 0.3%CVE-2026-41350MEDIUMOpenClaw < 2026.3.31 - Session Visibility Bypass via session_status in Unsandboxed InvocationsEPSS 0.3%CVE-2026-32028MEDIUMOpenClaw < 2026.2.25 - Missing Authorization Check in Discord DM Reaction IngressEPSS 0.3%CVE-2026-41379HIGHOpenClaw < 2026.3.28 - Privilege Escalation via chat.send to Admin-Class Talk Voice ConfigEPSS 0.3%CVE-2026-100580HIGHOpenClaw before 2026.7.1 Remote Code Execution via cron toolEPSS 0.3%CVE-2026-53808MEDIUMOpenClaw < 2026.5.6 - Approval Policy Bypass in Skill Workshop Apply FlowEPSS 0.3%CVE-2026-22171HIGHOpenClaw < 2026.2.19 - Path Traversal in Feishu Media Temporary File NamingEPSS 0.3%CVE-2026-35642MEDIUMOpenClaw < 2026.3.25 - Authorization Bypass in Group Reactions via requireMention BypassEPSS 0.3%CVE-2026-32039MEDIUMOpenClaw < 2026.2.22 - Sender Authorization Bypass via Identity Collision in toolsBySenderEPSS 0.3%CVE-2026-27484LOWOpenClaw Discord moderation authorization used untrusted sender identity in tool-driven flowsEPSS 0.3%CVE-2026-44113HIGHOpenClaw < 2026.4.22 - Time-of-Check/Time-of-Use Race Condition in OpenShell FS BridgeEPSS 0.3%