Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
682 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.7) | 0.25% | — | Openclaw CodexAI | 26/9/2026 | 28/9/2026 | OpenClaw Codex before 2026.7.1 fails to properly enforce owner authorization when creating native conversation bindings. Non-owner channel senders with command access can create bindings to the native Codex runtime and execute host-capable turns with access to files, tools, and processes. | |
| Aplazada | Alta (8.6) | 0.19% | — | OpenclawAI | 26/9/2026 | 29/9/2026 | OpenClaw (npm package `openclaw`) before 2026.7.1 fails to enforce the owner-only authorization requirement for Claude Code permission prompts delivered through the MCP channel bridge. An authorized non-owner channel sender with channel command access can approve or deny a pending permission request intended for the… | |
| Aplazada | Media (5.4) | 0.10% | — | OpenclawAI | 26/9/2026 | 5/10/2026 | OpenClaw is an npm-distributed agent runtime. In versions >= 2026.2.26 and < 2026.7.1, PowerShell command analysis on Windows hosts running in exec allowlist mode could approve an exact executable resolved from PATH but subsequently execute a same-named executable located in the workspace directory. If lower-trust… | |
| Aplazada | Media (5.3) | 0.18% | — | Openclaw DiscordAI | 26/9/2026 | 28/9/2026 | OpenClaw Discord versions before 2026.7.1 contain an authorization bypass vulnerability in guild metadata read actions that allows lower-trust senders to retrieve information excluded by channel allowlists. Attackers can bypass the configured Discord read-target policy to access guild metadata from servers or channels… | |
| Aplazada | Alta (7.1) | 0.21% | — | Openclaw MsteamsAIOpenclaw FeishuAIOpenclaw MatrixAIOpenclaw GooglechatAI | 26/9/2026 | 28/9/2026 | OpenClaw channel plugins (@openclaw/msteams, @openclaw/feishu, @openclaw/matrix, and @openclaw/googlechat) before 2026.8.1 do not enforce the configured channel read allowlist for caller-supplied explicit read targets in message, reaction, pin, member, and related metadata read actions. A lower-trust sender or a… | |
| Aplazada | Media (6.8) | 0.08% | — | OpenclawAI | 26/9/2026 | 29/9/2026 | OpenClaw for iOS before 2026.8.11 stores Gateway credentials as cleartext JSON in App Group UserDefaults instead of the device Keychain. Attackers with access to unencrypted device backups or extracted App Group containers can recover valid Gateway tokens and passwords to authenticate with operator authority. | |
| Aplazada | Alta (8.7) | 0.34% | — | OpenclawAI | 26/9/2026 | 5/10/2026 | OpenClaw (npm package 'openclaw') before 2026.7.1 improperly handles case sensitivity in the model-facing cron tool: a mixed-case payload kind can pass the agent-facing shell-execution guard and later normalize into a command job. An actor able to steer a tool-enabled agent can therefore create a persistent cron job… | |
| Aplazada | Alta (7.2) | 0.23% | — | OpenclawAI | 26/9/2026 | 28/9/2026 | OpenClaw (npm package 'openclaw') before 2026.7.1 incorrectly trusts requester provenance in message.action. In identity-bearing Gateway deployments (authentication modes that honor caller identity and narrower operator scopes), a write-scoped caller can supply another sender's identifier to the channel authorization… | |
| Aplazada | Alta (7.2) | 0.23% | — | OpenclawAI | 26/9/2026 | 28/9/2026 | OpenClaw (npm package `openclaw`) before 2026.7.1 fails to restrict owner-only infrastructure tools exposed through the chat.send endpoint. In Gateway deployments using authentication modes that honor caller identity and narrower operator scopes, a write-scoped non-owner caller can start a chat turn whose tool… | |
| Aplazada | Media (5.3) | 0.14% | — | OpenclawAI | 26/9/2026 | 29/9/2026 | OpenClaw versions before 2026.8.1 fail to validate video asset URLs returned by providers, allowing server-side requests to private destinations. A malicious or compromised provider can return private or loopback URLs to cause the CLI to make requests to internal services accessible from the OpenClaw host. | |
| Aplazada | Media (5.3) | 0.21% | — | OpenclawAI | 26/9/2026 | 5/10/2026 | OpenClaw versions before 2026.8.1 contain a server-side request forgery vulnerability in browser wait predicates that allows attackers to bypass SSRF protections by reaching blocked destinations. Attackers can use the wait --fn function against an existing browser session to request loopback or private destinations… | |
| Aplazada | Alta (8.7) | 0.26% | — | Openclaw SlackAI | 26/9/2026 | 28/9/2026 | OpenClaw Slack versions before 2026.8.1 fail to properly enforce sender allowlists in multi-person direct messages. Disallowed participants can trigger Slack agents and access tools and data granted to those agents by bypassing configured sender policies. | |
| Aplazada | Alta (8.2) | 0.23% | — | OpenclawAI | 26/9/2026 | 29/9/2026 | OpenClaw (npm package 'openclaw') before 2026.8.1 contains a server-side request forgery vulnerability in its trusted-host DNS checks. For fetches that use the trusted-host DNS recheck, a trusted hostname that resolves to an unspecified address (0.0.0.0 or ::) bypasses the SSRF destination validation. An attacker who… | |
| Aplazada | Media (4.8) | 0.11% | — | OpenclawAI | 26/9/2026 | 29/9/2026 | OpenClaw versions before 2026.8.1 contain a sandbox policy bypass vulnerability in the MCP loopback component that allows sandboxed coding-agent sessions to invoke tools explicitly denied by sandbox.tools.deny policy. Attackers can list and invoke denied tools to access data or perform actions the operator intended to… | |
| Aplazada | Media (6.9) | 0.35% | — | OpenclawAI | 26/9/2026 | 5/10/2026 | OpenClaw versions >= 2026.3.25 and < 2026.8.1 apply invalid-token rate limiting for Synology Chat webhooks before authentication and key the limit on the raw proxy socket address. In deployments where OpenClaw sits behind a trusted reverse proxy or tunnel and multiple external clients share a single socket address, an… | |
| Aplazada | Media (6.9) | 0.35% | — | OpenclawAI | 26/9/2026 | 28/9/2026 | OpenClaw (npm package 'openclaw') versions >= 2026.6.6 and < 2026.8.1 apply the SMS webhook invalid-request rate limit before Twilio signature verification and identify clients only by the raw proxy socket address. In deployments where the SMS/Twilio webhook sits behind a trusted reverse proxy or tunnel so that… | |
| Aplazada | Alta (8.5) | 0.13% | — | OpenclawAI | 26/9/2026 | 29/9/2026 | OpenClaw (npm package 'openclaw') versions >= 2026.3.28 and < 2026.8.1 allow an untrusted workspace .env file to set the CLOUDSDK_PYTHON_ARGS environment variable. When an operator starts OpenClaw in attacker-controlled workspace content and then runs the Gmail setup flow, that value is inherited when gcloud is… | |
| Aplazada | Media (6.8) | 0.12% | — | OpenclawAI | 26/9/2026 | 29/9/2026 | OpenClaw is an npm-distributed application. In versions >= 2026.4.25 and < 2026.8.1, the workspace environment-variable filter did not block variables ending in `_ENDPOINT`, so an untrusted workspace `.env` file could set AZURE_SPEECH_ENDPOINT. Azure Speech preferred that value over the configured region, so when a… | |
| Aplazada | Alta (8.7) | 0.25% | — | OpenclawAI | 26/9/2026 | 5/10/2026 | OpenClaw versions before 2026.8.1 fail to properly restrict access to operator command cron jobs, allowing model-visible agent callers to read and execute ownerless command jobs. Attackers can inspect stored environment variables and force-run disabled or unscheduled command jobs to access secrets and execute… | |
| Aplazada | Alta (8.9) | 0.25% | — | OpenclawAI | 26/9/2026 | 28/9/2026 | OpenClaw is an agent gateway distributed as the npm package 'openclaw'. In versions >= 2026.4.5 and < 2026.8.1, the Gateway validated a single DNS resolution result for a configured remote Chrome DevTools Protocol (CDP) hostname, but the raw WebSocket and Playwright transports performed a later, independent DNS… | |
| Aplazada | Media (6.9) | 0.20% | — | Openclaw LineAI | 26/9/2026 | 29/9/2026 | OpenClaw LINE versions before 2026.8.1 contain an access control vulnerability where group allowlist mode silently inherits DM allowFrom values when groupAllowFrom is not explicitly configured. Attackers with group participation can trigger the agent despite configured group allowlist restrictions when DM access is… | |
| Aplazada | Media (5.3) | 0.19% | — | OpenclawAI | 26/9/2026 | 29/9/2026 | OpenClaw versions before 2026.8.1 fail to neutralize spreadsheet formula characters in participant display names within attendance CSV exports. Attackers can inject formula-like cells that execute with spreadsheet user permissions when the export is opened in formula-enabled applications. | |
| Aplazada | Media (5.3) | 0.19% | — | OpenclawAI | 26/9/2026 | 5/10/2026 | OpenClaw (npm package `openclaw`) before 2026.8.1 does not neutralize leading characters that spreadsheet applications interpret as formulas when the Control UI exports session data to CSV. Although session labels were quoted as CSV text, a lower-trust participant who can influence a session label or the first user… | |
| Aplazada | Media (5.3) | 0.19% | — | OpenclawAI | 26/9/2026 | 28/9/2026 | OpenClaw versions before 2026.8.1 contain an authorization bypass vulnerability in the sessions.create endpoint that allows operator.write callers to modify session configurations reserved for operator.admin scope. Attackers with write-scoped credentials can change existing session model, provider, thinking level, and… | |
| Aplazada | Alta (8.6) | 0.25% | — | OpenclawAI | 26/9/2026 | 29/9/2026 | OpenClaw (npm package 'openclaw') versions >= 2026.3.22 and < 2026.8.1 contain an approval-bypass flaw in the exec approval policy: the policy could trust a command-running wrapper without inspecting the command carried in its arguments. After an operator allowlisted or permanently approved a benign wrapper… |