Vulnerabilidades em openclaw
663 resultadosAnálise Vexday
A OpenClaw apresenta um portfólio de 47 vulnerabilidades, com 10 descobertas nos últimos 90 dias, indicando atividade contínua de risco. Nenhuma vulnerabilidade está sob exploração ativa registrada (KEV), mas a fraqueza dominante em path traversal (CWE-22) é crítica em ambientes com controle de acesso inadequado. Com apenas 1 vulnerabilidade crítica (CVSS), o risco permanece moderado, mas exige monitoramento nas próximas atualizações da plataforma.
CVE-2026-53813HIGHOpenClaw < 2026.4.25 - Arbitrary Artifact Loading via Fake Package Root ResolutionEPSS 0.2%CVE-2026-32041HIGHOpenClaw < 2026.3.1 - Unauthenticated Browser Control Access via Failed Auth BootstrapEPSS 0.2%CVE-2026-32016HIGHOpenClaw < 2026.2.22 - Path Traversal via Basename-Only Allowlist Matching on macOSEPSS 0.2%CVE-2026-32054MEDIUMOpenClaw < 2026.2.25 - Symlink Traversal in Browser Trace/Download Path HandlingEPSS 0.2%CVE-2026-41390HIGHOpenClaw < 2026.3.28 - Exec Allowlist Bypass via Unregistered /usr/bin/script WrapperEPSS 0.2%CVE-2026-41392MEDIUMOpenClaw < 2026.3.31 - Exec Allowlist Bypass via Shell Init-File OptionsEPSS 0.2%CVE-2026-32915CRITICALOpenClaw < 2026.3.11 - Sandbox Boundary Bypass via Subagent Control SurfaceEPSS 0.2%CVE-2026-91835LOWOpenClaw ClawScan File Classifier static_scanner.go IsBinaryFile interpretation conflictEPSS 0.2%CVE-2026-100591MEDIUMOpenClaw before 2026.7.1 Authentication Bypass via Active MemoryEPSS 0.2%CVE-2026-100592MEDIUMOpenClaw before 2026.7.1 Authentication Bypass via Memory DreamingEPSS 0.2%CVE-2026-95815HIGHOpenClaw iOS before 2026.8.11 Credential Exposure via Deep-Link URL LoggingEPSS 0.2%CVE-2026-41393MEDIUMOpenClaw < 2026.3.31 - Arbitrary DNS Authority Acceptance and Credential Exfiltration via Wide-Area DiscoveryEPSS 0.2%CVE-2026-44992MEDIUMOpenClaw 2026.4.5 through 2026.4.19 - MiniMax API Host Override via Workspace dotenvEPSS 0.2%CVE-2026-44118HIGHOpenClaw < 2026.4.22 - Owner Context Spoofing via Bearer Token HeaderEPSS 0.2%CVE-2026-41357LOWOpenClaw < 2026.3.31 - Unsanitized Environment Variable Leakage in SSH Sandbox BackendsEPSS 0.2%CVE-2026-27183LOWOpenClaw < 2026.3.7 - Shell Approval Gating Bypass via Dispatch Wrapper Depth MismatchEPSS 0.2%CVE-2026-35667MEDIUMOpenClaw < 2026.3.24 - Improper Process Termination via Unpatched killProcessTree in shell-utils.tsEPSS 0.2%CVE-2026-27646MEDIUMOpenClaw < 2026.3.7 - Sandbox Escape via /acp spawn CommandEPSS 0.2%CVE-2026-27003MEDIUMOpenClaw: Telegram bot token exposure via logsEPSS 0.2%CVE-2026-62211MEDIUMOpenClaw < 2026.6.1 Credential Redaction Bypass via Trajectory ExportEPSS 0.1%