Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
682 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.7) | 0.26% | — | OpenclawAI | 26/9/2026 | 5/10/2026 | OpenClaw (npm package 'openclaw') versions >= 2026.4.5 and < 2026.8.1 can lose the originating requester's restrictions and untrusted provenance when session-derived text is persisted to session memory. In deployments where session-memory capture and dreaming are enabled, a restricted external sender whose messages… | |
| Aplazada | Baja (2.3) | 0.27% | — | OpenclawAI | 26/9/2026 | 28/9/2026 | OpenClaw versions before 2026.8.1 contain an authorization bypass vulnerability in webhook TaskFlow cancellation that allows attackers to cancel unrelated sessions. An attacker with a webhook route secret can supply an arbitrary child session key to cancel ACP or subagent work outside the route's configured authority. | |
| Aplazada | Media (6) | 0.29% | — | OpenclawAI | 26/9/2026 | 29/9/2026 | OpenClaw versions before 2026.8.1 contain a path traversal vulnerability in the tools.fs.workspaceOnly feature where Unicode filename fallback can normalize validated parent directory components. Admitted requesters can exploit canonically equivalent sibling directories to read files outside the configured workspace… | |
| Aplazada | Alta (7.2) | 0.27% | — | Openclaw WhatsappAI | 26/9/2026 | 29/9/2026 | @openclaw/whatsapp (npm) before 2026.8.1 exposes the WhatsApp login tool through the generic channel-tool path without preserving the originating sender's owner status, so the owner-only tool boundary is not enforced. An admitted non-owner sender able to steer the tool can request a forced login and receive a new QR… | |
| Aplazada | Alta (7.1) | 0.33% | — | Openclaw SlackAI | 26/9/2026 | 5/10/2026 | The @openclaw/slack npm package before 2026.8.1 contains an authorization flaw in its Slack download-file handler: when a file lacks the share metadata used to prove it belongs to the requested conversation, the conversation-authorization check fails open. An authenticated caller restricted to a single conversation… | |
| Aplazada | Alta (8.5) | 0.18% | — | OpenclawAI | 26/9/2026 | 28/9/2026 | OpenClaw versions before 2026.8.1 fail to bind working directory context to reusable exec approvals, allowing approved commands to execute in different directories. Attackers with an allow-always approval can reuse it to run the same command against unreviewed files or repositories with materially different effects. | |
| Aplazada | Alta (7.4) | 0.21% | — | OpenclawAI | 26/9/2026 | 29/9/2026 | OpenClaw versions before 2026.8.1 contain an authorization scope widening vulnerability in file-transfer allow-always approvals that allows attackers to reuse standing grants for unreviewed paths. Attackers can exploit glob metacharacter interpretation and node display name reuse to access sibling paths or different… | |
| Aplazada | Media (5.9) | 0.24% | — | OpenclawAI | 26/9/2026 | 29/9/2026 | OpenClaw (npm package 'openclaw') before 2026.8.1 could send third-party provider credentials to the wrong endpoint. In affected versions, when a third-party provider uses an OpenAI-compatible API and the resolved model metadata lacks a concrete base URL, a pinned session that continues after a model configuration hot… | |
| Aplazada | Media (6.9) | 0.35% | — | OpenclawAI | 26/9/2026 | 5/10/2026 | OpenClaw before 2026.8.2 contains a denial of service vulnerability in the Browser extension relay that allows unauthenticated network sources to exhaust pending-authentication capacity. Attackers can hold every pending slot by maintaining silent WebSocket upgrades, preventing paired extensions from completing Browser… | |
| Aplazada | Media (6) | 0.28% | — | Openclaw DiscordAI | 26/9/2026 | 28/9/2026 | OpenClaw's Discord integration (npm package @openclaw/discord) before version 2026.9.3 could lose the sender-scoped media policy in the emoji and sticker upload actions before loading a local file. A sender permitted to invoke those actions could cause OpenClaw to read a host path that the same sender's configured… | |
| Aplazada | Media (5.3) | 0.24% | — | Openclaw Diagnostics PrometheusAI | 26/9/2026 | 29/9/2026 | The OpenClaw Prometheus diagnostics plugin (@openclaw/diagnostics-prometheus) before version 2026.9.3 does not enforce the operator.read scope on its authenticated metrics endpoint. In deployments using an identity-bearing Gateway authentication mode such as trusted-proxy, a caller whose effective role has no read… | |
| Aplazada | Alta (7.2) | 0.16% | — | Openclaw IOSAI | 22/9/2026 | 24/9/2026 | OpenClaw iOS before 2026.8.11 logs complete agent deep-link URLs including persistent bearer keys to unified logs as public diagnostic data. Attackers who obtain diagnostic archives can recover unrotated keys and replay them in forged deep links to submit agent requests without local confirmation prompts. | |
| Aplazada | Baja (2.1) | 0.47% | — | OpenclawAI | 20/9/2026 | 22/9/2026 | A flaw has been found in OpenClaw up to 2026.9.5. Affected is the function createCanvasHostHandler of the file extensions/canvas/src/host/server.ts of the component Canvas Host Route. Executing a manipulation can lead to denial of service. The attack can be launched remotely. The exploit has been published and may be… | |
| Aplazada | Baja (0.9) | 0.16% | — | Openclaw ClawscanAI | 15/9/2026 | 16/9/2026 | A vulnerability was detected in OpenClaw ClawScan up to 0.1.6. The impacted element is the function IsBinaryFile of the file internal/runner/static_scanner.go of the component File Classifier. The manipulation results in interpretation conflict. Attacking locally is a requirement. The exploit is now public and may be… | |
| Aplazada | Baja (0.9) | 0.33% | — | Openclaw ClawscanAI | 15/9/2026 | 19/9/2026 | A flaw has been found in OpenClaw ClawScan up to 0.1.6. This affects an unknown function of the file internal/runner/static_scanner.go of the component Static Scanner. This manipulation causes incomplete comparison with missing factors. It is possible to launch the attack on the local host. The exploit has been… | |
| Aplazada | Baja (2.1) | 0.43% | — | Mf-yang Openclaw-cnAI | 6/8/2026 | 12/8/2026 | A vulnerability was identified in mf-yang openclaw-cn up to 0.2.1. This issue affects the function assertNoSymlinkEscape of the file src/agents/sandbox-paths.ts of the component apply_patch Tool. Such manipulation leads to link following. It is possible to launch the attack remotely. The exploit is publicly available… | |
| Aplazada | Baja (2.1) | 0.37% | — | Mf-yang Openclaw-cnAI | 6/8/2026 | 12/8/2026 | A vulnerability was determined in mf-yang openclaw-cn up to 0.2.1. This vulnerability affects the function isApprovedElevatedSender of the file src/auto-reply/reply/reply-elevated.ts. This manipulation causes improper privilege management. It is possible to initiate the attack remotely. The exploit has been publicly… | |
| Aplazada | Baja (2.1) | 0.37% | — | Mf-yang Openclaw-cnAI | 6/8/2026 | 12/8/2026 | A vulnerability was found in mf-yang openclaw-cn 2026.2.5. This affects an unknown part of the file src/agents/bash-tools.exec.ts of the component Ggateway Exec Approval Flow. The manipulation results in incorrect authorization. The attack may be performed from remote. The exploit has been made public and could be… | |
| Analizada | Alta (8.8) | 0.63% | 💥 PoC | Tugcantopaloglu Openclaw Agent Dashboard | 30/7/2026 | 3/9/2026 | OpenClaw Dashboard contains a stored cross-site scripting vulnerability that allows unauthenticated remote attackers to execute arbitrary JavaScript in the administrator's browser session by injecting HTML markup into agent transcript messages processed through the sessions API. Attackers can craft a message… | |
| Analizada | Crítica (9.3) | 0.63% | 💥 PoC | Tugcantopaloglu Openclaw Agent Dashboard | 30/7/2026 | 3/9/2026 | OpenClaw Dashboard v3.0.0 contains a stored cross-site scripting vulnerability that allows unauthenticated remote attackers to inject arbitrary HTML and script payloads by submitting a crafted username in a failed login POST request, which is recorded verbatim in the audit log. When an administrator opens the… | |
| Aplazada | Baja (2.1) | 0.40% | — | Mf-yang Openclaw-cnAI | 26/7/2026 | 27/7/2026 | A vulnerability was found in mf-yang openclaw-cn up to 0.2.1. This affects the function clickViaPlaywright of the file src/browser/routes/agent.act.ts of the component Browser Control HTTP API. Performing a manipulation results in server-side request forgery. It is possible to initiate the attack remotely. The exploit… | |
| Aplazada | Baja (2.1) | 0.42% | — | Mf-yang Openclaw-cnAI | 26/7/2026 | 27/7/2026 | A vulnerability has been found in mf-yang openclaw-cn up to 0.2.1. Affected by this issue is the function assertBrowserNavigationAllowed of the file src/browser/navigation-guard.ts of the component Scheme Handler. Such manipulation of the argument url leads to information disclosure. The attack may be performed from… | |
| Aplazada | Alta (8.2) | 0.36% | — | Agenticmail ClaudecodeAIAgenticmail CoreAICodexnotes CodexAIOpenclawAI | 20/7/2026 | 23/7/2026 | AgenticMail gives AI agents real email addresses and phone numbers. In @agenticmail/claudecode prior to version 0.2.39, @agenticmail/codex prior to version 0.1.33, @agenticmail/core prior to version 0.9.43, and @agenticmail/openclaw prior to version 0.5.71, two inbound-mail handlers act on a privileged effect without… | |
| Analizada | Alta (7.7) | 0.72% | — | Openclaw | 17/7/2026 | 30/7/2026 | OpenClaw before 2026.5.18 contain an authorization bypass vulnerability in exec allowlist glob matching that allows lower-trust callers to execute actions beyond intended authorization. Attackers can craft input paths that traverse the allowlist glob patterns to execute or persist unauthorized actions when the… | |
| Analizada | Alta (7.7) | 0.45% | — | Openclaw | 17/7/2026 | 29/7/2026 | OpenClaw before 2026.6.5 contain an authorization bypass vulnerability in node exec approvals that allows lower-trust callers to execute actions beyond their intended authorization by using different gateway and node environments. Attackers can exploit mismatched environment configurations to persist or execute… |