Vulnerabilities in OpenClaw

581 results
Vexday analysis

Com 495 CVEs catalogadas e nenhuma confirmada em exploração ativa no momento, o perfil do OpenClaw apresenta taxa de exploração confirmada abaixo da média geral do catálogo KEV. O dado que merece atenção imediata é o volume de 323 vulnerabilidades surgidas nos últimos 90 dias, indicando um ritmo elevado de descobertas recentes que ainda pode não ter atraído atenção de agentes maliciosos, mas amplia consideravelmente a superfície de ataque. O tipo de falha mais comum é CWE-863 (autorização incorreta), o que sugere fragilidades estruturais no controle de acesso — categoria com alto potencial de impacto caso explorada. A CVE mais perigosa identificada atualmente, CVE-2026-25253, apresenta EPSS de 0,0802, e embora não haja PoC pública disponível, equipes de segurança devem monitorar sua evolução dado o contexto de crescimento acelerado no volume de vulnerabilidades do vendor.

CVE-2026-34504MEDIUMOpenClaw < 2026.3.28 - Server-Side Request Forgery via Unguarded Image Download in fal ProviderEPSS 0.2%CVE-2026-44111LOWOpenClaw < 2026.4.15 - Arbitrary Markdown File Read via QMD memory_getEPSS 0.2%CVE-2026-41407MEDIUMOpenClaw < 2026.4.2 - Timing Side Channel in Shared-Secret ComparisonEPSS 0.2%CVE-2026-41406LOWOpenClaw < 2026.3.31 - Sender Allowlist Bypass via Thread History and Quoted MessagesEPSS 0.2%CVE-2026-53857HIGHOpenClaw < 2026.5.3 - Mutable Display Name Binding in Zalo allowFrom PolicyEPSS 0.2%CVE-2026-35631HIGHOpenClaw < 2026.3.22 - Missing Authorization Enforcement in Internal ACP Chat CommandsEPSS 0.2%CVE-2026-53840MEDIUMOpenClaw < 2026.5.12 - Custom Header Leakage via MCP Streamable HTTP Cross-Origin RedirectsEPSS 0.2%CVE-2026-41302MEDIUMOpenClaw < 2026.3.31 - Server-Side Request Forgery via Unguarded fetch() in Marketplace Plugin DownloadEPSS 0.2%CVE-2026-44997LOWOpenClaw < 2026.4.22 - Security Envelope Constraint Bypass in ACP Child SessionsEPSS 0.2%CVE-2026-41381LOWOpenClaw < 2026.3.31 - Access Control Bypass in Discord Voice Manager via Channel AllowlistEPSS 0.2%CVE-2026-41908LOWOpenClaw < 2026.4.20 - Scope Enforcement Bypass in Assistant-Media RouteEPSS 0.2%CVE-2026-41382LOWOpenClaw < 2026.3.31 - Discord Voice Ingress Authorization Bypass via Channel and Role Validation GapsEPSS 0.2%CVE-2026-22181MEDIUMOpenClaw < 2026.3.2 - DNS Pinning Bypass via Environment Proxy Configuration in web_fetchEPSS 0.2%CVE-2026-27485MEDIUMOpenClaw affected by Stored XSS in Control UI via unsanitized assistant name/avatar in inline script injectionEPSS 0.2%CVE-2026-43567HIGHOpenClaw < 2026.4.10 - Path Traversal in screen_record outPath ParameterEPSS 0.2%CVE-2026-43535HIGHOpenClaw < 2026.4.14 - Authorization Context Reuse in Collect-Mode Queue BatchesEPSS 0.2%CVE-2026-35648LOWOpenClaw < 2026.3.22 - Policy Bypass via Unvalidated Queued Node ActionsEPSS 0.2%CVE-2026-45001MEDIUMOpenClaw < 2026.4.20 - Gateway Config Mutation Guard Bypass via Agent Tool AccessEPSS 0.2%CVE-2026-41914MEDIUMOpenClaw < 2026.4.8 - Server-Side Request Forgery in QQ Bot Media Fetch PathsEPSS 0.2%CVE-2026-43579MEDIUMOpenClaw < 2026.4.10 - Insufficient Access Control in Nostr Profile Mutation RoutesEPSS 0.2%