Vulnerabilidades em openclaw

584 resultados
Análise Vexday

A OpenClaw apresenta um portfólio de 47 vulnerabilidades, com 10 descobertas nos últimos 90 dias, indicando atividade contínua de risco. Nenhuma vulnerabilidade está sob exploração ativa registrada (KEV), mas a fraqueza dominante em path traversal (CWE-22) é crítica em ambientes com controle de acesso inadequado. Com apenas 1 vulnerabilidade crítica (CVSS), o risco permanece moderado, mas exige monitoramento nas próximas atualizações da plataforma.

CVE-2026-44994MEDIUMOpenClaw < 2026.4.22 - Authentication Bypass in Gateway Control UI Bootstrap Config EndpointEPSS 0.6%CVE-2026-35656MEDIUMOpenClaw < 2026.3.22 - XFF Loopback Spoofing Bypass in Canvas Authentication and Rate LimiterEPSS 0.6%CVE-2026-26321HIGHOpenClaw has a local file disclosure via sendMediaFeishu in Feishu extensionEPSS 0.5%CVE-2026-42420MEDIUMOpenClaw < 2026.4.8 - Improper Base64 Decoding Size ValidationEPSS 0.5%CVE-2026-41303HIGHOpenClaw < 2026.3.28 - Authorization Bypass in Discord Text Approval CommandsEPSS 0.5%CVE-2026-40037HIGHOpenClaw < 2026.3.31 - Unsafe Request Body Replay via fetchWithSsrFGuard Cross-Origin RedirectsEPSS 0.5%CVE-2026-32004HIGHOpenClaw < 2026.3.2 - Authentication Bypass via Encoded Path in /api/channels RouteEPSS 0.5%CVE-2026-28393HIGHOpenClaw 2.0.0-beta3 < 2026.2.14 - Arbitrary JavaScript Module Loading via Hook Transform Path TraversalEPSS 0.5%CVE-2026-28453HIGHOpenClaw < 2026.2.14 - Zip Slip Path Traversal in TAR Archive ExtractionEPSS 0.5%CVE-2026-32051HIGHOpenClaw < 2026.3.1 - Authorization Bypass in Agent Runs via Owner-Only Tool AccessEPSS 0.5%CVE-2026-32065MEDIUMOpenClaw < 2026.2.25 - Approval Identity Mismatch in system.run Command ExecutionEPSS 0.5%CVE-2026-62202HIGHOpenClaw 2026.6.1 < 2026.6.9 Privilege Escalation via CronEPSS 0.5%CVE-2026-41369HIGHOpenClaw < 2026.3.31 - Insufficient Environment Variable Sanitization in Host ExecutionEPSS 0.5%CVE-2026-35643HIGHOpenClaw < 2026.3.22 - Arbitrary Code Execution via Unvalidated WebView JavascriptInterfaceEPSS 0.5%CVE-2026-28448MEDIUMOpenClaw 2026.1.29 < 2026.2.1 - Authorization Bypass in Twitch Plugin allowFrom Access ControlEPSS 0.5%CVE-2026-43533HIGHOpenClaw < 2026.4.10 - Arbitrary Local File Read via QQBot Media TagsEPSS 0.5%CVE-2026-28459HIGHOpenClaw < 2026.2.12 - Arbitrary File Write via Untrusted sessionFile PathEPSS 0.5%CVE-2026-33573HIGHOpenClaw < 2026.3.11 - Workspace Boundary Bypass via Agent RPC ParametersEPSS 0.5%CVE-2026-44110HIGHOpenClaw < 2026.4.15 - Authorization Bypass in Matrix Room Control Commands via DM Pairing StoreEPSS 0.5%CVE-2026-35638HIGHOpenClaw < 2026.3.22 - Privilege Escalation via Self-Declared Scopes in Trusted-Proxy Control UIEPSS 0.5%