Vulnerabilidades em openclaw
663 resultadosAnálise Vexday
A OpenClaw apresenta um portfólio de 47 vulnerabilidades, com 10 descobertas nos últimos 90 dias, indicando atividade contínua de risco. Nenhuma vulnerabilidade está sob exploração ativa registrada (KEV), mas a fraqueza dominante em path traversal (CWE-22) é crítica em ambientes com controle de acesso inadequado. Com apenas 1 vulnerabilidade crítica (CVSS), o risco permanece moderado, mas exige monitoramento nas próximas atualizações da plataforma.
CVE-2026-32030HIGHOpenClaw < 2026.2.19 - Sensitive File Disclosure via stageSandboxMedia Path TraversalEPSS 0.5%CVE-2026-32026HIGHOpenClaw < 2026.2.24 - Arbitrary File Read via Improper Temporary Path Validation in SandboxEPSS 0.5%CVE-2026-26319HIGHOpenClaw has Missing Webhook Authentication in Telnyx Provider Allowing Unauthenticated RequestsEPSS 0.5%CVE-2026-35658MEDIUMOpenClaw < 2026.3.2 - Filesystem Boundary Bypass in Image ToolEPSS 0.5%CVE-2026-45005MEDIUMOpenClaw < 2026.4.23 - Webhook Route Secret Cache Not Invalidated After RotationEPSS 0.5%CVE-2026-62190HIGHOpenClaw < 2026.6.9 Authorization Bypass via flock wrapperEPSS 0.5%CVE-2026-35660HIGHOpenClaw < 2026.3.23 - Insufficient Access Control in Gateway Agent Session ResetEPSS 0.5%CVE-2026-41394HIGHOpenClaw < 2026.3.31 - Unauthorized Operator Scope Access in Unauthenticated Plugin-Auth RoutesEPSS 0.5%CVE-2026-32982HIGHOpenClaw < 2026.3.13 - Telegram Bot Token Exposure in Media Fetch Error LogsEPSS 0.5%CVE-2026-43527MEDIUMOpenClaw < 2026.4.14 - Server-Side Request Forgery via Private Network NavigationEPSS 0.5%CVE-2026-32033MEDIUMOpenClaw < 2026.2.24 - Path Traversal via @-prefixed Absolute Paths in Workspace Boundary ValidationEPSS 0.5%CVE-2026-28473HIGHOpenClaw < 2026.2.2 - Authorization Bypass via /approve Chat CommandEPSS 0.5%CVE-2026-34512HIGHOpenClaw < 2026.3.25 - Improper Access Control in /sessions/:sessionKey/kill EndpointEPSS 0.5%CVE-2026-28469HIGHOpenClaw < 2026.2.14 - Cross-Account Policy Context Misrouting via Shared Webhook Path AmbiguityEPSS 0.5%CVE-2026-28450HIGHOpenClaw < 2026.2.12 - Unauthenticated Profile Tampering via Nostr Plugin HTTP EndpointsEPSS 0.5%CVE-2026-35661MEDIUMOpenClaw < 2026.3.25 - Telegram DM-Scoped Inline Button Callback Authorization BypassEPSS 0.5%CVE-2026-53816HIGHOpenClaw < 2026.5.18 - Exec Lifecycle Event Forgery via Paired NodeEPSS 0.5%CVE-2026-26329HIGHOpenClaw has a path traversal in browser upload allows local file readEPSS 0.5%CVE-2026-32055HIGHOpenClaw < 2026.2.26 - Workspace Path Boundary Bypass via Non-existent SymlinkEPSS 0.5%CVE-2026-29611HIGHOpenClaw < 2026.2.14 - Local File Inclusion via mediaPath Parameter in BlueBubbles Media HandlingEPSS 0.5%