« Volver al listado

Openclaw

Openclaw: vulnerabilidades y CVE

Openclaw tiene 646 vulnerabilidades publicadas, 646 de ellas en los últimos 12 meses. 27 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE646
Últimos 12 meses646
Críticas27
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-102807Media (6)0.23%—29 sept 2026
OpenClaw before 2026.9.4 contains an incorrect authorization vulnerability in the mcp.app.view method that allows read-scoped operators to execute MCP App tools requiring operator.write scope. Attackers with…
CVE-2026-102806Media (6)0.25%—29 sept 2026
OpenClaw before 2026.9.5 contains an incorrect authorization vulnerability in the Gateway's local media root allowlist that breaks filesystem isolation between sandboxed sessions. Sandboxed sessions or untrusted content…
CVE-2026-100599Alta (8.7)0.30%—26 sept 2026
OpenClaw versions 2026.5.1 through 2026.7.0 fail to apply the configured exec approval path to Google Meet node commands. The googlemeet.chrome command accepts caller-supplied audio command arrays and executes them on a…
CVE-2026-100598Alta (7.5)0.11%—26 sept 2026
OpenClaw (npm package openclaw) before 2026.7.1 incorrectly binds Signal approval reactions. In affected versions, a reaction intended to resolve a structured approval request could instead attach to ordinary outbound…
CVE-2026-100597Alta (8.8)0.08%—26 sept 2026
OpenClaw (npm package 'openclaw') before 2026.7.1 is vulnerable to a time-of-check time-of-use race condition in OpenShell local mirror filesystem mutation operations. The remove, mkdir, and rename operations could act…
CVE-2026-100596Alta (8.7)0.25%—26 sept 2026
OpenClaw versions before 2026.7.1 fail to properly authorize non-owner users executing MCP configuration changes through /mcp set and /mcp unset commands. Attackers can persist arbitrary stdio MCP commands that execute…
CVE-2026-100595Alta (7.1)0.24%—26 sept 2026
OpenClaw versions before 2026.7.1 contain an authorization bypass vulnerability in the diagnostics export command that allows non-owner channel senders to access owner-only host diagnostic bundles. Attackers can request…
CVE-2026-100594Alta (7.1)0.24%—26 sept 2026
OpenClaw versions before 2026.7.1 contain an authorization bypass vulnerability in the /export-trajectory endpoint that allows non-owner senders to request and receive owner-only trajectory bundles. Attackers can access…
CVE-2026-100593Media (5.3)0.14%—26 sept 2026
OpenClaw (npm package `openclaw`) before 2026.7.1 does not enforce the documented owner-only requirement for persistent `/activation` policy changes in group channels. An authorized non-owner channel sender can change…
CVE-2026-100592Media (5.3)0.16%—26 sept 2026
OpenClaw is an agent gateway distributed via npm. In versions >= 2026.4.10 and < 2026.7.1, persistent memory dreaming mutations omit owner permission checks. An authorized but non-owner external-channel sender can issue…
CVE-2026-100591Media (5.3)0.16%—26 sept 2026
OpenClaw is an npm-distributed agent gateway. In versions before 2026.7.1, the global Active Memory toggle mutations could omit owner checks. An authorized non-owner external-channel sender could therefore persistently…
CVE-2026-100590Media (5.3)0.18%—26 sept 2026
OpenClaw before 2026.7.1 contains an authorization bypass vulnerability in the /voice set command that allows non-owner external-channel senders to persist Gateway voice configuration. Attackers with command access can…
CVE-2026-100589Alta (8.7)0.32%—26 sept 2026
OpenClaw versions before 2026.7.1 contain a sandbox bypass vulnerability in the browser tool that allows sandboxed sessions to access paired node browser actions despite allowHostControl=false configuration. Attackers…
CVE-2026-100588Alta (8.7)0.30%—26 sept 2026
OpenClaw (npm package 'openclaw') before 2026.7.1 does not enforce the administrator scope requirement on browser control when it is reached through the node.invoke method, although direct browser.request access…
CVE-2026-100587Alta (8.7)0.25%—26 sept 2026
OpenClaw versions before 2026.7.1 fail to properly validate owner authorization in the Codex computer-use installation command. Non-owner channel senders can install arbitrary plugins and execute MCP processes with…
CVE-2026-100585Alta (8.6)0.19%—26 sept 2026
OpenClaw (npm package `openclaw`) before 2026.7.1 fails to enforce the owner-only authorization requirement for Claude Code permission prompts delivered through the MCP channel bridge. An authorized non-owner channel…
CVE-2026-100584Media (5.4)0.10%—26 sept 2026
OpenClaw is an npm-distributed agent runtime. In versions >= 2026.2.26 and < 2026.7.1, PowerShell command analysis on Windows hosts running in exec allowlist mode could approve an exact executable resolved from PATH but…
CVE-2026-100581Media (6.8)0.08%—26 sept 2026
OpenClaw for iOS before 2026.8.11 stores Gateway credentials as cleartext JSON in App Group UserDefaults instead of the device Keychain. Attackers with access to unencrypted device backups or extracted App Group…
CVE-2026-100580Alta (8.7)0.34%—26 sept 2026
OpenClaw (npm package 'openclaw') before 2026.7.1 improperly handles case sensitivity in the model-facing cron tool: a mixed-case payload kind can pass the agent-facing shell-execution guard and later normalize into a…
CVE-2026-100579Alta (7.2)0.23%—26 sept 2026
OpenClaw (npm package 'openclaw') before 2026.7.1 incorrectly trusts requester provenance in message.action. In identity-bearing Gateway deployments (authentication modes that honor caller identity and narrower operator…
CVE-2026-100578Alta (7.2)0.23%—26 sept 2026
OpenClaw (npm package `openclaw`) before 2026.7.1 fails to restrict owner-only infrastructure tools exposed through the chat.send endpoint. In Gateway deployments using authentication modes that honor caller identity…
CVE-2026-100577Media (5.3)0.14%—26 sept 2026
OpenClaw versions before 2026.8.1 fail to validate video asset URLs returned by providers, allowing server-side requests to private destinations. A malicious or compromised provider can return private or loopback URLs…
CVE-2026-100576Media (5.3)0.21%—26 sept 2026
OpenClaw versions before 2026.8.1 contain a server-side request forgery vulnerability in browser wait predicates that allows attackers to bypass SSRF protections by reaching blocked destinations. Attackers can use the…
CVE-2026-100574Alta (8.2)0.23%—26 sept 2026
OpenClaw (npm package 'openclaw') before 2026.8.1 contains a server-side request forgery vulnerability in its trusted-host DNS checks. For fetches that use the trusted-host DNS recheck, a trusted hostname that resolves…
CVE-2026-100573Media (4.8)0.11%—26 sept 2026
OpenClaw versions before 2026.8.1 contain a sandbox policy bypass vulnerability in the MCP loopback component that allows sandboxed coding-agent sessions to invoke tools explicitly denied by sandbox.tools.deny policy.…
CVE-2026-100572Media (6.9)0.35%—26 sept 2026
OpenClaw versions >= 2026.3.25 and < 2026.8.1 apply invalid-token rate limiting for Synology Chat webhooks before authentication and key the limit on the raw proxy socket address. In deployments where OpenClaw sits…
CVE-2026-100571Media (6.9)0.35%—26 sept 2026
OpenClaw (npm package 'openclaw') versions >= 2026.6.6 and < 2026.8.1 apply the SMS webhook invalid-request rate limit before Twilio signature verification and identify clients only by the raw proxy socket address. In…
CVE-2026-100570Alta (8.5)0.13%—26 sept 2026
OpenClaw (npm package 'openclaw') versions >= 2026.3.28 and < 2026.8.1 allow an untrusted workspace .env file to set the CLOUDSDK_PYTHON_ARGS environment variable. When an operator starts OpenClaw in attacker-controlled…
CVE-2026-100569Media (6.8)0.12%—26 sept 2026
OpenClaw is an npm-distributed application. In versions >= 2026.4.25 and < 2026.8.1, the workspace environment-variable filter did not block variables ending in `_ENDPOINT`, so an untrusted workspace `.env` file could…
CVE-2026-100568Alta (8.7)0.25%—26 sept 2026
OpenClaw versions before 2026.8.1 fail to properly restrict access to operator command cron jobs, allowing model-visible agent callers to read and execute ownerless command jobs. Attackers can inspect stored environment…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1210 Exploitation of Remote Services171
  2. T1078 Valid Accounts97
  3. T1059 Command and Scripting Interpreter62
  4. T1190 Exploit Public-Facing Application61
  5. T1203 Exploitation for Client Execution57
  6. T1068 Exploitation for Privilege Escalation43

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Openclaw