Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
682 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.7) | 0.58% | — | OpenclawAI | 26/9/2026 | 29/9/2026 | OpenClaw versions before 2026.8.1 contain an authorization bypass vulnerability where Allow Always approvals for exact commands persist as path-only grants on macOS and Linux. Attackers can reuse the same executable with different arguments to execute commands without triggering new approval prompts, potentially… | |
| Aplazada | Alta (8.6) | 0.25% | — | OpenclawAI | 26/9/2026 | 5/10/2026 | OpenClaw versions before 2026.8.1 contain a command parser vulnerability where escaped newlines confuse exec allowlist parsing, allowing hidden commands to execute. Attackers can craft input with escaped newlines to bypass allowlist validation and execute additional commands without expected authorization prompts. | |
| Aplazada | Alta (8.7) | 0.28% | — | OpenclawAI | 26/9/2026 | 28/9/2026 | OpenClaw versions before 2026.8.1 contain a resource exhaustion vulnerability in the Gateway listener that allows unauthenticated clients to retain response sockets by sending WebSocket upgrade requests without matching connection semantics. Attackers can repeatedly send malformed upgrade requests to exhaust listener… | |
| Aplazada | Alta (8.7) | 0.24% | — | OpenclawAI | 26/9/2026 | 29/9/2026 | OpenClaw versions before 2026.8.1 contain an authorization bypass vulnerability in skill tool dispatch that fails to carry the sender's owner status. Non-owner senders authorized to invoke skill commands can access owner-only tools and server credentials reserved for owners. | |
| Aplazada | Media (5.3) | 0.28% | — | OpenclawAI | 26/9/2026 | 29/9/2026 | OpenClaw (npm package openclaw) versions >= 2026.5.2 and < 2026.8.1 contain an incorrect authorization vulnerability in WhatsApp group handling. A group sender who is admitted for ordinary messages but denied by commands.allowFrom or owner command authorization can issue the /new <model> command to reset the shared… | |
| Aplazada | Alta (7.1) | 0.20% | — | OpenclawAI | 26/9/2026 | 5/10/2026 | OpenClaw is an npm-distributed gateway application. In versions >= 2026.7.1 and < 2026.8.1, Synology Chat attachment delivery could lose DNS pinning: the Gateway validated a single DNS result for a supplied file URL but then passed the original hostname to the Synology NAS, where it could resolve to a different… | |
| Aplazada | Baja (2.3) | 0.22% | — | OpenclawAI | 26/9/2026 | 28/9/2026 | OpenClaw (npm package 'openclaw') versions >= 2026.5.12 and < 2026.8.1 do not immediately invalidate Canvas HTTP authorization when a paired node is revoked. Node revocation invalidates the WebSocket client, but Canvas HTTP authorization continues to accept and renew the previously granted capability until WebSocket… | |
| Aplazada | Media (5.3) | 0.21% | — | OpenclawAI | 26/9/2026 | 29/9/2026 | OpenClaw versions >= 2026.6.9 and < 2026.8.1 do not declare the native chatId parameter as a delivery target in the Feishu unpin feature, so unpin requests can bypass the shared same-provider cross-context target check. When tools.message.crossContext.allowWithinProvider is disabled, an admitted (authenticated) sender… | |
| Aplazada | Alta (8.7) | 0.26% | — | OpenclawAI | 26/9/2026 | 29/9/2026 | OpenClaw (npm package 'openclaw') before 2026.8.1 does not correctly enforce per-chat tool policies for Codex app-server runtime tools. A conversation-level tools.allow rule filtered OpenClaw tools but did not restrict the shell, process, file, and patch tools owned by the Codex runtime. When a lower-trust… | |
| Aplazada | Crítica (9) | 0.17% | — | OpenclawAI | 26/9/2026 | 5/10/2026 | OpenClaw for iOS versions >= 2026.7.1 and < 2026.8.11 do not enforce saved Gateway TLS pins in the Control UI. While native connections enforced the saved Gateway fingerprint, the authenticated Terminal and session Dashboard WebViews omitted it. If a user had accepted a Gateway fingerprint, an attacker able to… | |
| Aplazada | Media (5.3) | 0.19% | — | OpenclawAI | 26/9/2026 | 28/9/2026 | OpenClaw (npm package 'openclaw') before 2026.8.1 contains an access-control bypass in the Microsoft Teams integration. When groupPolicy is set to allowlist, a missing or unsupported configured access group produces a denied group-resolution result that is not rejected by the final message-admission check, so a Teams… | |
| Aplazada | Media (5.3) | 0.28% | — | OpenclawAI | 26/9/2026 | 29/9/2026 | OpenClaw versions before 2026.8.1 contain a path traversal vulnerability in QQBot voice attachment handling where filenames are decoded twice, allowing encoded traversal segments to reappear after sanitization. Attackers can supply crafted voice attachments that write files outside the intended staging directory to… | |
| Aplazada | Media (6) | 0.25% | — | OpenclawAI | 26/9/2026 | 29/9/2026 | OpenClaw (npm package 'openclaw') versions >= 2026.3.28 and < 2026.8.1 contain a credential exposure issue in memory embedding failover. When remote embedding fallback is configured and the primary embedding provider fails, the request can be sent to a different fallback provider while still reusing the primary… | |
| Aplazada | Media (6.8) | 0.13% | — | OpenclawAI | 26/9/2026 | 5/10/2026 | OpenClaw is a coding agent distributed as the npm package `openclaw`. In affected versions (2026.7.1 through 2026.7.2), alternate but valid `file:` URL spellings supplied over the Agent Client Protocol (ACP) were treated as relative paths and were incorrectly classified as reads scoped to the session working… | |
| Aplazada | Media (6.1) | 0.18% | — | OpenclawAI | 26/9/2026 | 28/9/2026 | OpenClaw (npm package `openclaw`) versions >= 2026.7.2 and < 2026.9.2 contain a race condition in the Discord realtime voice transcript path. Concurrent control-classified voice transcripts could consume speaker context belonging to another participant after an asynchronous control check, causing a transcript to… | |
| Aplazada | Media (6) | 0.21% | — | OpenclawAI | 26/9/2026 | 29/9/2026 | OpenClaw (npm package `openclaw`) before 2026.8.1 incorrectly enforces sender tool policies during session-memory filename generation. In affected versions, filename generation created an embedded helper that retained tools which the originating sender's policy had removed. When session-memory filename generation was… | |
| Aplazada | Alta (8.7) | 0.25% | — | Openclaw Voice CallAI | 26/9/2026 | 29/9/2026 | openclaw's @openclaw/voice-call package before 2026.8.1 launches the configured agent for classic inbound voice calls without propagating the caller's identity or non-owner status. As a result, owner-only tool filtering can fail open and expose the agent's normal tool authority to a remote caller. A caller who is… | |
| Aplazada | Alta (7.7) | 0.35% | — | OpenclawAI | 26/9/2026 | 5/10/2026 | OpenClaw (npm package openclaw) before 2026.8.1 could include deterministic hashes computed over the original, unredacted configuration in redacted configuration responses. When the Gateway password had low entropy and the remaining configuration values were reconstructable, these hashes acted as offline password… | |
| Aplazada | Baja (2.3) | 0.26% | — | OpenclawAI | 26/9/2026 | 28/9/2026 | OpenClaw (npm package 'openclaw') versions >= 2026.5.28 and < 2026.8.1 mishandle archive listings in the tar.bz2 skill installer: bounded command-output suffixes were treated as complete listings of the archive. A crafted .tar.bz2/.tbz2 skill archive can push prohibited entries out of both retained listings so that… | |
| Aplazada | Alta (7.7) | 0.30% | — | Openclaw MatrixAI | 26/9/2026 | 29/9/2026 | OpenClaw's Matrix integration (npm package @openclaw/matrix) versions >= 2026.2.2 and < 2026.8.1 lowercase complete Matrix user IDs — including historical localparts and the case-sensitive server-name portion — when deriving the OpenClaw authorization identity. As a result, distinct authenticated Matrix accounts can… | |
| Aplazada | Alta (7.6) | 0.23% | — | Openclaw FeishuAI | 26/9/2026 | 29/9/2026 | OpenClaw Feishu before 2026.8.1 fails to validate whether a configured default account is disabled before selecting it for model tool operations. Attackers can exploit multi-account setups where a disabled default account retains credentials to read or modify Feishu resources through a revoked identity. | |
| Aplazada | Baja (2.1) | 0.20% | — | OpenclawAI | 26/9/2026 | 5/10/2026 | OpenClaw (npm package 'openclaw') before 2026.8.1 fails to revoke memory tool access when an operator hot-disables memory configuration. Existing memory_search and memory_get tool instances retain the enabled configuration captured at creation time because the execution-time resolver treats explicit disablement like… | |
| Aplazada | Alta (7.1) | 0.26% | — | OpenclawAI | 26/9/2026 | 28/9/2026 | OpenClaw (npm package 'openclaw') before 2026.8.1 does not apply the originating sender's global or per-agent toolsBySender policy when handling outbound attachments. A sender that has been explicitly denied filesystem read tools can still cause a known local file to be read and returned via a final-response media… | |
| Aplazada | Baja (2.3) | 0.19% | — | OpenclawAI | 26/9/2026 | 29/9/2026 | OpenClaw (npm package 'openclaw') before 2026.8.1 fails to apply the originating requester's effective tool policy during Active Memory automatic recall. In deployments that use Active Memory together with requester-specific tool rules, deterministic and hidden recall paths can retrieve durable memory and inject it… | |
| Aplazada | Alta (7.1) | 0.43% | — | OpenclawAI | 26/9/2026 | 29/9/2026 | OpenClaw versions before 2026.8.1 fail to validate all source fields in structured message attachments, allowing attackers to hide unvalidated host paths behind allowed attachment sources. Attackers can exploit this by providing multiple source fields to bypass sandbox path validation and cause Telegram delivery to… |