Vulnerabilidades em openclaw

663 resultados
Análise Vexday

A OpenClaw apresenta um portfólio de 47 vulnerabilidades, com 10 descobertas nos últimos 90 dias, indicando atividade contínua de risco. Nenhuma vulnerabilidade está sob exploração ativa registrada (KEV), mas a fraqueza dominante em path traversal (CWE-22) é crítica em ambientes com controle de acesso inadequado. Com apenas 1 vulnerabilidade crítica (CVSS), o risco permanece moderado, mas exige monitoramento nas próximas atualizações da plataforma.

CVE-2026-32978CRITICALOpenClaw < 2026.3.11 - Approval Bypass via Unrecognized Script RunnersEPSS 0.3%CVE-2026-42421LOWOpenClaw < 2026.4.8 - WebSocket Session Persistence via Shared Gateway Token RotationEPSS 0.3%CVE-2026-41356LOWOpenClaw < 2026.3.31 - Incomplete WebSocket Session Termination in device.token.rotateEPSS 0.3%CVE-2026-53851MEDIUMOpenClaw < 2026.5.12 - Slack Reaction Event Notification BypassEPSS 0.3%CVE-2026-62193MEDIUMOpenClaw 2026.6.5 < 2026.6.9 Authentication Bypass via Plugin InstallEPSS 0.3%CVE-2026-53837MEDIUMOpenClaw < 2026.5.6 - Missing Channel Type Validation in Mattermost Event HandlersEPSS 0.3%CVE-2026-100589HIGHOpenClaw before 2026.7.1 Sandbox Bypass via Browser NodeEPSS 0.3%CVE-2026-42424MEDIUMOpenClaw < 2026.4.8 - Local File Exfiltration via Shared Reply MEDIA PathsEPSS 0.3%CVE-2026-41366MEDIUMOpenClaw < 2026.3.31 - Arbitrary Host File Read via appendLocalMediaParentRoots Self-WhitelistingEPSS 0.3%CVE-2026-28479HIGHOpenClaw < 2026.2.15 - Cache Poisoning via Deprecated SHA-1 Hash in Sandbox ConfigurationEPSS 0.3%CVE-2026-41337MEDIUMOpenClaw < 2026.3.31 - Callback Origin Mutation in Plivo Voice-call ReplayEPSS 0.3%CVE-2026-53826LOWOpenClaw < 2026.4.26 - Information Disclosure via Sandboxed Session SpawnEPSS 0.3%CVE-2026-53824MEDIUMMattermost plugin for OpenClaw < 2026.4.24 - Slash Token Revocation Lag via Monitor Refresh DelayEPSS 0.3%CVE-2026-53845LOWOpenClaw < 2026.5.6 - Skill-Command Dispatch Hook Bypass via Before-Tool-Call Hook SkippingEPSS 0.3%CVE-2026-53848LOWOpenClaw < 2026.5.26 - Exec Allowlist Bypass via Transparent Command WrappersEPSS 0.3%CVE-2026-42430MEDIUMOpenClaw < 2026.4.8 - Strict Browser SSRF Bypass via Playwright Redirect HandlingEPSS 0.3%CVE-2026-22178MEDIUMOpenClaw < 2026.2.19 - ReDoS and Regex Injection via Unescaped Feishu Mention MetadataEPSS 0.3%CVE-2026-53840MEDIUMOpenClaw < 2026.5.12 - Custom Header Leakage via MCP Streamable HTTP Cross-Origin RedirectsEPSS 0.3%CVE-2026-35632MEDIUMOpenClaw <= 2026.2.22 - Symlink Traversal via IDENTITY.md appendFile in agents.create/updateEPSS 0.3%CVE-2026-43582MEDIUMOpenClaw < 2026.4.10 - DNS Rebinding SSRF via Hostname Validation BypassEPSS 0.3%