OpenClaw 版本 2026.3.25 及更高版本但低于 2026.8.1 存在以下问题:对于 Synology Chat Webhook 请求,系统在认证之前即应用了“无效令牌速率限制”,并且该限制以原始代理套接字地址作为键进行计数。 在 OpenClaw 部署于可信反向代理或隧道之后,且多个外部客户端共享同一套接字地址的场景下,未认证的发送方可以耗尽共享的无效令牌配额,导致后续的合法 Synology Chat Webhook 回调请求被拒绝,直至速率限制窗口结束。攻击者无法获取有效令牌或读取消息数据;其影
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-100580 | 8.8 HIGH | OpenClaw before 2026.7.1 Remote Code Execution via cron tool |
| CVE-2026-100575 | 8.8 HIGH | OpenClaw Slack before 2026.8.1 Authentication Bypass via Group DM |
| CVE-2026-100596 | 8.8 HIGH | OpenClaw before 2026.7.1 Authorization Bypass via MCP Configuration |
| CVE-2026-100586 | 8.8 HIGH | OpenClaw Codex before 2026.7.1 Authorization Bypass via Bind |
| CVE-2026-100587 | 8.8 HIGH | OpenClaw before 2026.7.1 Authorization Bypass via Codex Install |
| CVE-2026-100544 | 8.8 HIGH | openclaw voice-call before 2026.8.1 Authorization Bypass |
| CVE-2026-100599 | 8.8 HIGH | OpenClaw 2026.5.1 before 2026.7.1 Remote Code Execution via googlemeet.chrome |
| CVE-2026-100552 | 8.8 HIGH | OpenClaw before 2026.8.1 Policy Bypass via Native Tools |
| CVE-2026-100551 | 8.3 HIGH | OpenClaw iOS Control UI TLS Pin Enforcement Bypass |
| CVE-2026-100589 | 8.3 HIGH | OpenClaw before 2026.7.1 Sandbox Bypass via Browser Node |
| CVE-2026-100588 | 8.3 HIGH | OpenClaw before 2026.7.1 Authentication Bypass via node.invoke |
| CVE-2026-100557 | 8.3 HIGH | OpenClaw before 2026.8.1 Authorization Bypass via Skill Tool Dispatch |
| CVE-2026-100568 | 8.3 HIGH | OpenClaw before 2026.8.1 Unauthorized Command Job Access |
| CVE-2026-100567 | 8.2 HIGH | OpenClaw before 2026.8.1 DNS Rebinding via CDP Hostname |
| CVE-2026-100532 | 8.1 HIGH | openclaw WhatsApp before 2026.8.1 Authentication Bypass |
| CVE-2026-100559 | 8.0 HIGH | OpenClaw before 2026.8.1 Command Injection via Escaped Newlines |
| CVE-2026-100561 | 8.0 HIGH | OpenClaw before 2026.8.1 Authentication Bypass via Exec Wrapper |
| CVE-2026-100585 | 8.0 HIGH | OpenClaw before 2026.7.1 Authentication Bypass via MCP Channel |
| CVE-2026-100597 | 7.8 HIGH | OpenClaw before 2026.7.1 Path Traversal via Filesystem Race |
| CVE-2026-100570 | 7.8 HIGH | OpenClaw before 2026.8.1 Remote Code Execution via CLOUDSDK_PYTHON_ARGS |
Showing top 20 of 79 CVEs. View all on vendor page → →
No comments yet