Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3043▲ 582 respecto a la semana anterior
Críticas / altas1452▲ 283 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)393▲ 186 respecto a la semana anterior
682 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.7) | 0.68% | — | Openclaw Windows NodeAI | 30/9/2026 | 1/10/2026 | OpenClaw Windows Node before 2026.7.1 contains an incomplete environment-variable sanitizer in system.run that fails to block GIT_CONFIG_*, DOTNET_STARTUP_HOOKS, and JAVA_TOOL_OPTIONS variables. Attackers with gateway or agent access can supply these variables to allowlisted tools like git, dotnet, or java to load… | |
| Aplazada | Media (5.3) | 0.36% | — | Openclaw Windows NodeAI | 30/9/2026 | 1/10/2026 | OpenClaw Windows Node through 2026.9.4 contains a server-side request forgery vulnerability in the canvas.present capability that bypasses URL risk evaluation enforced by canvas.navigate. Attackers with gateway or agent access can issue canvas.present to make the node's WebView send requests to localhost, private… | |
| Aplazada | Alta (8.7) | 0.80% | — | Openclaw Windows NodeAI | 30/9/2026 | 1/10/2026 | OpenClaw Windows Node before 2026.7.1 contains an incomplete validation vulnerability in system.execApprovals.set that accepts wildcard-executable rules and abusable system binaries like mshta, rundll32, and certutil. Remote callers can add broad allow rules to execute arbitrary commands on the Windows host through… | |
| Aplazada | Alta (7.1) | 0.55% | — | Openclaw Windows NodeAI | 30/9/2026 | 1/10/2026 | OpenClaw Windows Node before 2026.7.1 contains an allocation of resources without limits vulnerability in the gateway WebSocket transport that allows connected gateways to exhaust node memory. Attackers can send an unending sequence of WebSocket continuation frames without EndOfMessage to cause unbounded memory growth… | |
| Aplazada | Alta (8.7) | 0.82% | — | Openclaw Windows NodeAI | 30/9/2026 | 1/10/2026 | OpenClaw Windows Node before 2026.7.1 contains an incorrect authorization vulnerability in the system.run exec-approval policy where ExecShellWrapperParser fails to split commands on pipe operators or extract command substitutions. Connected gateways or agents can bypass approval rules by placing denied commands… | |
| Aplazada | Alta (7.1) | 0.49% | — | Openclaw Windows NodeAI | 30/9/2026 | 1/10/2026 | OpenClaw Windows Node before 2026.7.1-3 contains a missing authorization vulnerability in NodeService capture handlers that allows connected gateways or agents to perform screen snapshots, camera snaps, and location captures without consent prompts. Attackers can invoke screen.snapshot, camera.snap, and location.get… | |
| Aplazada | Media (6) | 0.23% | — | OpenclawAI | 29/9/2026 | 29/9/2026 | OpenClaw before 2026.9.4 contains an incorrect authorization vulnerability in the mcp.app.view method that allows read-scoped operators to execute MCP App tools requiring operator.write scope. Attackers with operator.read tokens can obtain a standalone ticket from mcp.app.view and redeem it at the MCP app view… | |
| Aplazada | Media (6) | 0.25% | — | OpenclawAI | 29/9/2026 | 29/9/2026 | OpenClaw before 2026.9.5 contains an incorrect authorization vulnerability in the Gateway's local media root allowlist that breaks filesystem isolation between sandboxed sessions. Sandboxed sessions or untrusted content can cause the Gateway to read files from sibling session sandboxes or shared workspace directories… | |
| Pendiente de análisis | Media (5.3) | 0.27% | — | Openclaw ClawhubAI | 26/9/2026 | 28/9/2026 | ClawHub (openclaw/clawhub) contains an incorrect authorization vulnerability in the ClawHub application/backend: an organization-owned skill retains the ownerUserId of its original publisher, and transfer and lifecycle authorization checks trust that historical user before requiring current organization privileges. An… | |
| Aplazada | Alta (8.7) | 0.29% | — | Openclaw ClawhubAI | 26/9/2026 | 29/9/2026 | ClawHub (openclaw/clawhub) application/backend contains a flaw in the skill report moderation flow: four distinct ordinary authenticated accounts can report a visible skill and trigger automatic hiding (moderationStatus: hidden) of that skill from the catalog without any moderator decision. Because the reporter quota… | |
| Aplazada | Alta (7.1) | 0.29% | — | Openclaw ClawhubAI | 26/9/2026 | 29/9/2026 | ClawHub (openclaw/clawhub application/backend) contains a missing authorization check in the changelog preview feature. A signed-in caller can invoke the public skills:generateChangelogPreview action for a skill they are not authorized to access; the previous version is read without the file-read authorization… | |
| Pendiente de análisis | Media (6.9) | 0.32% | — | Openclaw ClawhubAI | 26/9/2026 | 30/9/2026 | ClawHub (openclaw/clawhub) application/backend contains a server-side request forgery vulnerability in the public profile preview's image fetching. The preview accepts a user-supplied image URL and checks the textual hostname against private-address patterns, but does not validate or pin the resolved network… | |
| Aplazada | Alta (8.7) | 0.30% | — | OpenclawAI | 26/9/2026 | 28/9/2026 | OpenClaw versions 2026.5.1 through 2026.7.0 fail to apply the configured exec approval path to Google Meet node commands. The googlemeet.chrome command accepts caller-supplied audio command arrays and executes them on a paired node without going through the normal system.run approval flow. In deployments with the… | |
| Aplazada | Alta (7.5) | 0.11% | — | OpenclawAI | 26/9/2026 | 28/9/2026 | OpenClaw (npm package openclaw) before 2026.7.1 incorrectly binds Signal approval reactions. In affected versions, a reaction intended to resolve a structured approval request could instead attach to ordinary outbound text when unrelated outbound messages and a pending approval are present in the same conversation. As… | |
| Aplazada | Alta (8.8) | 0.08% | — | OpenclawAI | 26/9/2026 | 29/9/2026 | OpenClaw (npm package 'openclaw') before 2026.7.1 is vulnerable to a time-of-check time-of-use race condition in OpenShell local mirror filesystem mutation operations. The remove, mkdir, and rename operations could act on a different filesystem target after OpenClaw completed its sandbox path-safety check, if the path… | |
| Aplazada | Alta (8.7) | 0.25% | — | OpenclawAI | 26/9/2026 | 28/9/2026 | OpenClaw versions before 2026.7.1 fail to properly authorize non-owner users executing MCP configuration changes through /mcp set and /mcp unset commands. Attackers can persist arbitrary stdio MCP commands that execute with OpenClaw process privileges when configuration loads, compromising host confidentiality,… | |
| Aplazada | Alta (7.1) | 0.24% | — | OpenclawAI | 26/9/2026 | 28/9/2026 | OpenClaw versions before 2026.7.1 contain an authorization bypass vulnerability in the diagnostics export command that allows non-owner channel senders to access owner-only host diagnostic bundles. Attackers can request and receive diagnostic details about the host, configuration, runtime, and connected services… | |
| Aplazada | Alta (7.1) | 0.24% | — | OpenclawAI | 26/9/2026 | 28/9/2026 | OpenClaw versions before 2026.7.1 contain an authorization bypass vulnerability in the /export-trajectory endpoint that allows non-owner senders to request and receive owner-only trajectory bundles. Attackers can access prompts, model messages, tool schemas, runtime events, and local path metadata from affected… | |
| Aplazada | Media (5.3) | 0.14% | — | OpenclawAI | 26/9/2026 | 29/9/2026 | OpenClaw (npm package `openclaw`) before 2026.7.1 does not enforce the documented owner-only requirement for persistent `/activation` policy changes in group channels. An authorized non-owner channel sender can change whether the agent requires mention-based activation, causing the agent to respond more broadly in the… | |
| Aplazada | Media (5.3) | 0.16% | — | OpenclawAI | 26/9/2026 | 28/9/2026 | OpenClaw is an agent gateway distributed via npm. In versions >= 2026.4.10 and < 2026.7.1, persistent memory dreaming mutations omit owner permission checks. An authorized but non-owner external-channel sender can issue the persistent '/dreaming on' and '/dreaming off' commands to enable or disable the Gateway's… | |
| Aplazada | Media (5.3) | 0.16% | — | OpenclawAI | 26/9/2026 | 28/9/2026 | OpenClaw is an npm-distributed agent gateway. In versions before 2026.7.1, the global Active Memory toggle mutations could omit owner checks. An authorized non-owner external-channel sender could therefore persistently enable or disable Active Memory for the Gateway, disabling memory recall for future sessions or… | |
| Aplazada | Media (5.3) | 0.18% | — | OpenclawAI | 26/9/2026 | 28/9/2026 | OpenClaw before 2026.7.1 contains an authorization bypass vulnerability in the /voice set command that allows non-owner external-channel senders to persist Gateway voice configuration. Attackers with command access can change the voice used by Talk responses for the configured provider, affecting configuration… | |
| Aplazada | Alta (8.7) | 0.32% | — | OpenclawAI | 26/9/2026 | 29/9/2026 | OpenClaw versions before 2026.7.1 contain a sandbox bypass vulnerability in the browser tool that allows sandboxed sessions to access paired node browser actions despite allowHostControl=false configuration. Attackers with control over sandboxed agent input can select a paired node and perform host browser operations,… | |
| Aplazada | Alta (8.7) | 0.30% | — | OpenclawAI | 26/9/2026 | 28/9/2026 | OpenClaw (npm package 'openclaw') before 2026.7.1 does not enforce the administrator scope requirement on browser control when it is reached through the node.invoke method, although direct browser.request access requires administrator scope. In Gateway deployments that honor caller identity and narrower operator… | |
| Aplazada | Alta (8.7) | 0.25% | — | OpenclawAI | 26/9/2026 | 28/9/2026 | OpenClaw versions before 2026.7.1 fail to properly validate owner authorization in the Codex computer-use installation command. Non-owner channel senders can install arbitrary plugins and execute MCP processes with OpenClaw user privileges, affecting host confidentiality, integrity, and availability. |