Vulnerabilities in OpenClaw

581 results
Vexday analysis

Com 495 CVEs catalogadas e nenhuma confirmada em exploração ativa no momento, o perfil do OpenClaw apresenta taxa de exploração confirmada abaixo da média geral do catálogo KEV. O dado que merece atenção imediata é o volume de 323 vulnerabilidades surgidas nos últimos 90 dias, indicando um ritmo elevado de descobertas recentes que ainda pode não ter atraído atenção de agentes maliciosos, mas amplia consideravelmente a superfície de ataque. O tipo de falha mais comum é CWE-863 (autorização incorreta), o que sugere fragilidades estruturais no controle de acesso — categoria com alto potencial de impacto caso explorada. A CVE mais perigosa identificada atualmente, CVE-2026-25253, apresenta EPSS de 0,0802, e embora não haja PoC pública disponível, equipes de segurança devem monitorar sua evolução dado o contexto de crescimento acelerado no volume de vulnerabilidades do vendor.

CVE-2026-32028MEDIUMOpenClaw < 2026.2.25 - Missing Authorization Check in Discord DM Reaction IngressEPSS 0.2%CVE-2026-53831HIGHOpenClaw < 2026.5.18 - Arbitrary File Read via Shell Expansion in system.run Safe-bin AllowlistEPSS 0.2%CVE-2026-22169HIGHOpenClaw < 2026.2.22 - Allowlist Bypass via sort Configuration in safeBinsEPSS 0.2%CVE-2026-28485HIGHOpenClaw 2026.1.5 < 2026.2.12 - Missing Authentication in Browser Control HTTP EndpointsEPSS 0.2%CVE-2026-32976HIGHOpenClaw < 2026.3.11 - Account-Scoped configWrites Policy Bypass via Channel CommandsEPSS 0.2%CVE-2026-53808MEDIUMOpenClaw < 2026.5.6 - Approval Policy Bypass in Skill Workshop Apply FlowEPSS 0.2%CVE-2026-35644HIGHOpenClaw < 2026.3.22 - Credential Exposure via baseUrl Fields in Gateway SnapshotsEPSS 0.2%CVE-2026-59261HIGHOpenClaw < 2026.5.28 - Credential Override via Workspace Dotenv FilesEPSS 0.2%CVE-2026-35625HIGHOpenClaw < 2026.3.25 - Privilege Escalation via Silent Local Shared-Auth ReconnectEPSS 0.2%CVE-2026-32031MEDIUMOpenClaw < 2026.2.26 - Authentication Bypass via Path Canonicalization Mismatch in /api/channels GatewayEPSS 0.2%CVE-2026-62186HIGHOpenClaw < 2026.6.8 Authorization Bypass via HTTP Model OverrideEPSS 0.2%CVE-2026-32058LOWOpenClaw < 2026.2.26 - Approval Context-Binding Weakness in system.run via host=nodeEPSS 0.2%CVE-2026-53851MEDIUMOpenClaw < 2026.5.12 - Slack Reaction Event Notification BypassEPSS 0.2%CVE-2026-27484LOWOpenClaw Discord moderation authorization used untrusted sender identity in tool-driven flowsEPSS 0.2%CVE-2026-43534CRITICALOpenClaw < 2026.4.10 - Unsanitized External Input in Agent Hook EventsEPSS 0.2%CVE-2026-32039MEDIUMOpenClaw < 2026.2.22 - Sender Authorization Bypass via Identity Collision in toolsBySenderEPSS 0.2%CVE-2026-32014HIGHOpenClaw < 2026.2.26 - Node Reconnect Metadata Spoofing via Unsigned Platform FieldsEPSS 0.2%CVE-2026-32029MEDIUMOpenClaw < 2026.2.21 - Client IP Spoofing via X-Forwarded-For Header ParsingEPSS 0.2%CVE-2026-53837MEDIUMOpenClaw < 2026.5.6 - Missing Channel Type Validation in Mattermost Event HandlersEPSS 0.2%CVE-2026-42430MEDIUMOpenClaw < 2026.4.8 - Strict Browser SSRF Bypass via Playwright Redirect HandlingEPSS 0.2%