Vulnerabilities in OpenClaw

581 results
Vexday analysis

Com 495 CVEs catalogadas e nenhuma confirmada em exploração ativa no momento, o perfil do OpenClaw apresenta taxa de exploração confirmada abaixo da média geral do catálogo KEV. O dado que merece atenção imediata é o volume de 323 vulnerabilidades surgidas nos últimos 90 dias, indicando um ritmo elevado de descobertas recentes que ainda pode não ter atraído atenção de agentes maliciosos, mas amplia consideravelmente a superfície de ataque. O tipo de falha mais comum é CWE-863 (autorização incorreta), o que sugere fragilidades estruturais no controle de acesso — categoria com alto potencial de impacto caso explorada. A CVE mais perigosa identificada atualmente, CVE-2026-25253, apresenta EPSS de 0,0802, e embora não haja PoC pública disponível, equipes de segurança devem monitorar sua evolução dado o contexto de crescimento acelerado no volume de vulnerabilidades do vendor.

CVE-2026-53866HIGHOpenClaw < 2026.5.12 - Allowlist Bypass in Shell Inline-Command ParsingEPSS 0.3%CVE-2026-32001MEDIUMOpenClaw < 2026.2.22 - Node Role Device-Identity Bypass via WebSocket AuthenticationEPSS 0.3%CVE-2026-34506LOWOpenClaw < 2026.3.8 - Sender Allowlist Bypass in Microsoft Teams Plugin via Route Allowlist ConfigurationEPSS 0.3%CVE-2026-53828HIGHOpenClaw < 2026.5.6 - Native Command Authorization Bypass via Owner-Command EnforcementEPSS 0.3%CVE-2026-28449MEDIUMOpenClaw < 2026.2.25 - Webhook Replay Attack via Missing Durable Replay SuppressionEPSS 0.3%CVE-2026-53849HIGHOpenClaw < 2026.5.7 - Privilege Escalation via Mutable Discord Display Names in allowFromEPSS 0.3%CVE-2026-41402LOWOpenClaw < 2026.3.31 - Webhook Replay Cache Cross-Target messageId Scope BypassEPSS 0.3%CVE-2026-42436MEDIUMOpenClaw < 2026.4.14 - Internal Page Content Exposure via Browser Snapshot and Screenshot RoutesEPSS 0.3%CVE-2026-32038CRITICALOpenClaw - Sandbox Network Isolation Bypass via docker.network=container ParameterEPSS 0.3%CVE-2026-43576MEDIUMOpenClaw < 2026.4.5 - Second-hop SSRF via CDP /json/version WebSocket URLEPSS 0.3%CVE-2026-53839MEDIUMOpenClaw < 2026.5.7 - Hostname Prefix Matching Bypass in Trusted Retry Endpoint ValidationEPSS 0.3%CVE-2026-44993LOWOpenClaw < 2026.4.20 - Direct Message Misclassification in Feishu Card ActionsEPSS 0.3%CVE-2026-41389MEDIUMOpenClaw 2026.4.7 < 2026.4.15 - Arbitrary File Read via Unvalidated Tool-Result Media PathsEPSS 0.3%CVE-2026-35621HIGHOpenClaw < 2026.3.24 - Privilege Escalation via chat.send to Allowlist PersistenceEPSS 0.3%CVE-2026-43580MEDIUMOpenClaw < 2026.4.10 - Incomplete Navigation Guard Coverage in Browser InteractionsEPSS 0.3%CVE-2026-32897MEDIUMOpenClaw < 2026.2.22 - Authentication Token Reuse in Owner ID Prompt Hashing FallbackEPSS 0.3%CVE-2026-62201MEDIUMOpenClaw < 2026.6.6 Network Policy Bypass via exec-serverEPSS 0.3%CVE-2026-28481MEDIUMOpenClaw < 2026.2.1 - Bearer Token Leakage via MS Teams Attachment Downloader Suffix MatchingEPSS 0.3%CVE-2026-53855HIGHOpenClaw < 2026.4.2 - Shell Positional Parameters Bypass in Inline-Eval ChecksEPSS 0.3%CVE-2026-35651MEDIUMOpenClaw 2026.2.13 < 2026.3.25 - ANSI Escape Sequence Injection in Approval PromptEPSS 0.3%