Vulnerabilidades en OpenClaw

537 resultados
Análisis Vexday

Com 495 CVEs catalogadas e nenhuma confirmada em exploração ativa no momento, o perfil do OpenClaw apresenta taxa de exploração confirmada abaixo da média geral do catálogo KEV. O dado que merece atenção imediata é o volume de 323 vulnerabilidades surgidas nos últimos 90 dias, indicando um ritmo elevado de descobertas recentes que ainda pode não ter atraído atenção de agentes maliciosos, mas amplia consideravelmente a superfície de ataque. O tipo de falha mais comum é CWE-863 (autorização incorreta), o que sugere fragilidades estruturais no controle de acesso — categoria com alto potencial de impacto caso explorada. A CVE mais perigosa identificada atualmente, CVE-2026-25253, apresenta EPSS de 0,0802, e embora não haja PoC pública disponível, equipes de segurança devem monitorar sua evolução dado o contexto de crescimento acelerado no volume de vulnerabilidades do vendor.

CVE-2026-22180MEDIUMOpenClaw < 2026.3.2 - Path Confinement Bypass in Browser Output and File Write OperationsEPSS 0.1%CVE-2026-44114HIGHOpenClaw < 2026.4.20 - Environment Variable Namespace Collision via Workspace dotenvEPSS 0.1%CVE-2026-32015HIGHOpenClaw 2026.1.21 < 2026.2.19 - PATH Hijacking Bypass in tools.exec.safeBins Allowlist ValidationEPSS 0.1%CVE-2026-32032HIGHOpenClaw < 2026.2.22 - Arbitrary Shell Execution via Unvalidated SHELL Environment VariableEPSS 0.1%CVE-2026-41342HIGHOpenClaw < 2026.3.28 - Unauthenticated Discovery Endpoint Credential Exfiltration via Remote OnboardingEPSS 0.1%CVE-2026-22174MEDIUMOpenClaw < 2026.2.22 - Gateway Token Disclosure via Chrome CDP ProbeEPSS 0.1%CVE-2026-32054MEDIUMOpenClaw < 2026.2.25 - Symlink Traversal in Browser Trace/Download Path HandlingEPSS 0.1%CVE-2026-41396HIGHOpenClaw < 2026.3.31 - Environment Variable Override of Plugin Trust RootEPSS 0.1%CVE-2026-41341LOWOpenClaw < 2026.3.31 - Component Interaction Misclassification in Discord ExtensionEPSS 0.1%CVE-2026-41391MEDIUMOpenClaw < 2026.3.31 - Environment Variable Bypass in Package Index URL HandlingEPSS 0.1%CVE-2026-22217MEDIUMOpenClaw 2026.2.22 < 2026.2.23 - Arbitrary Binary Execution via $SHELL Environment Variable Trusted Prefix FallbackEPSS 0.1%CVE-2026-41330LOWOpenClaw < 2026.3.31 - Environment Variable Override via Host Exec PolicyEPSS 0.1%CVE-2026-41380HIGHOpenClaw < 2026.3.28 - Arbitrary Execution Allowlist via Wrapper Carrier ExecutablesEPSS 0.1%CVE-2026-53858HIGHOpenClaw < 2026.5.2 - Arbitrary Runtime Dependency Loading via STATE_DIRECTORY Environment VariableEPSS 0.1%CVE-2026-41355MEDIUMOpenClaw < 2026.3.28 - Arbitrary Code Execution via Mirror Mode Sandbox File ConversionEPSS 0.1%CVE-2026-32016HIGHOpenClaw < 2026.2.22 - Path Traversal via Basename-Only Allowlist Matching on macOSEPSS 0.1%CVE-2026-33572MEDIUMOpenClaw < 2026.2.17 - Insufficient File Permissions in Session Transcript FilesEPSS 0.1%CVE-2026-44992MEDIUMOpenClaw 2026.4.5 through 2026.4.19 - MiniMax API Host Override via Workspace dotenvEPSS 0.1%CVE-2026-53865HIGHOpenClaw < 2026.5.2 - Arbitrary Command Execution via Workspace-Derived Service PATHEPSS 0.1%CVE-2026-41392MEDIUMOpenClaw < 2026.3.31 - Exec Allowlist Bypass via Shell Init-File OptionsEPSS 0.1%