Vulnerabilidades em openclaw

663 resultados
Análise Vexday

A OpenClaw apresenta um portfólio de 47 vulnerabilidades, com 10 descobertas nos últimos 90 dias, indicando atividade contínua de risco. Nenhuma vulnerabilidade está sob exploração ativa registrada (KEV), mas a fraqueza dominante em path traversal (CWE-22) é crítica em ambientes com controle de acesso inadequado. Com apenas 1 vulnerabilidade crítica (CVSS), o risco permanece moderado, mas exige monitoramento nas próximas atualizações da plataforma.

CVE-2026-27007MEDIUMOpenClaw's sandbox config hash sorted primitive arrays and suppressed needed container recreationEPSS 0.2%CVE-2026-27576MEDIUMOpenClaw: ACP prompt-size checks missing in local stdio bridge could reduce responsiveness with very large inputsEPSS 0.2%CVE-2026-41330LOWOpenClaw < 2026.3.31 - Environment Variable Override via Host Exec PolicyEPSS 0.2%CVE-2026-41355MEDIUMOpenClaw < 2026.3.28 - Arbitrary Code Execution via Mirror Mode Sandbox File ConversionEPSS 0.2%CVE-2026-100590MEDIUMOpenClaw before 2026.7.1 Authorization Bypass via voice setEPSS 0.2%CVE-2026-32015HIGHOpenClaw 2026.1.21 < 2026.2.19 - PATH Hijacking Bypass in tools.exec.safeBins Allowlist ValidationEPSS 0.2%CVE-2026-32979HIGHOpenClaw < 2026.3.11 - Unbound Interpreter and Runtime Commands Bypass in node-host ApprovalEPSS 0.2%CVE-2026-62222HIGHOpenClaw < 2026.5.22 Untrusted Plugin Loading via Setup-modeEPSS 0.2%CVE-2026-53865HIGHOpenClaw < 2026.5.2 - Arbitrary Command Execution via Workspace-Derived Service PATHEPSS 0.2%CVE-2026-40045MEDIUMOpenClaw < 2026.4.2 - Cleartext Credential Transmission via Unencrypted WebSocket Gateway EndpointsEPSS 0.2%CVE-2026-31990MEDIUMOpenClaw < 2026.3.2 - Symlink Traversal in stageSandboxMedia DestinationEPSS 0.2%CVE-2026-28457MEDIUMOpenClaw < 2026.2.14 - Path Traversal in Sandbox Skill Mirroring via Name ParameterEPSS 0.2%CVE-2026-100551CRITICALOpenClaw iOS Control UI TLS Pin Enforcement BypassEPSS 0.2%CVE-2026-33572MEDIUMOpenClaw < 2026.2.17 - Insufficient File Permissions in Session Transcript FilesEPSS 0.2%CVE-2026-41391MEDIUMOpenClaw < 2026.3.31 - Environment Variable Bypass in Package Index URL HandlingEPSS 0.2%CVE-2026-41380HIGHOpenClaw < 2026.3.28 - Arbitrary Execution Allowlist via Wrapper Carrier ExecutablesEPSS 0.2%CVE-2026-53846HIGHOpenClaw < 2026.4.29 - Arbitrary Package Manager Execution via Workspace .env npm_execpathEPSS 0.2%CVE-2026-41915MEDIUMOpenClaw < 2026.4.8 - Git Environment Variable Injection via Unfiltered Exec EnvironmentEPSS 0.2%CVE-2026-41347LOWOpenClaw < 2026.3.31 - Cross-Site Request Forgery via Missing Browser-Origin Validation in HTTP Operator EndpointsEPSS 0.2%CVE-2026-32020MEDIUMOpenClaw < 2026.2.22 - Arbitrary File Read via Symlink Following in Static File HandlerEPSS 0.2%