OpenClaw 频道插件(包括 @openclaw/msteams、@openclaw/feishu、@openclaw/matrix 和 @openclaw/googlechat)在版本 2026.8.1 之前存在安全漏洞:在处理消息、反应、固定消息、成员及相关的元数据读取操作时,未对调用者显式提供的读取目标强制执行所配置的频道读取白名单策略。因此,低信任度的发送方或已被引导至具有频道读取权限的代理,可能能够检索到被操作者读取策略排除的频道或房间中的内容或元数据。实际影响程度取决于所连接机器人账号所持有的权限。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-100575 | 8.8 HIGH | OpenClaw Slack before 2026.8.1 Authentication Bypass via Group DM |
| CVE-2026-100580 | 8.8 HIGH | OpenClaw before 2026.7.1 Remote Code Execution via cron tool |
| CVE-2026-100552 | 8.8 HIGH | OpenClaw before 2026.8.1 Policy Bypass via Native Tools |
| CVE-2026-100544 | 8.8 HIGH | openclaw voice-call before 2026.8.1 Authorization Bypass |
| CVE-2026-100586 | 8.8 HIGH | OpenClaw Codex before 2026.7.1 Authorization Bypass via Bind |
| CVE-2026-100587 | 8.8 HIGH | OpenClaw before 2026.7.1 Authorization Bypass via Codex Install |
| CVE-2026-100599 | 8.8 HIGH | OpenClaw 2026.5.1 before 2026.7.1 Remote Code Execution via googlemeet.chrome |
| CVE-2026-100596 | 8.8 HIGH | OpenClaw before 2026.7.1 Authorization Bypass via MCP Configuration |
| CVE-2026-100589 | 8.3 HIGH | OpenClaw before 2026.7.1 Sandbox Bypass via Browser Node |
| CVE-2026-100568 | 8.3 HIGH | OpenClaw before 2026.8.1 Unauthorized Command Job Access |
| CVE-2026-100557 | 8.3 HIGH | OpenClaw before 2026.8.1 Authorization Bypass via Skill Tool Dispatch |
| CVE-2026-100588 | 8.3 HIGH | OpenClaw before 2026.7.1 Authentication Bypass via node.invoke |
| CVE-2026-100551 | 8.3 HIGH | OpenClaw iOS Control UI TLS Pin Enforcement Bypass |
| CVE-2026-100567 | 8.2 HIGH | OpenClaw before 2026.8.1 DNS Rebinding via CDP Hostname |
| CVE-2026-100532 | 8.1 HIGH | openclaw WhatsApp before 2026.8.1 Authentication Bypass |
| CVE-2026-100561 | 8.0 HIGH | OpenClaw before 2026.8.1 Authentication Bypass via Exec Wrapper |
| CVE-2026-100559 | 8.0 HIGH | OpenClaw before 2026.8.1 Command Injection via Escaped Newlines |
| CVE-2026-100585 | 8.0 HIGH | OpenClaw before 2026.7.1 Authentication Bypass via MCP Channel |
| CVE-2026-100597 | 7.8 HIGH | OpenClaw before 2026.7.1 Path Traversal via Filesystem Race |
| CVE-2026-100570 | 7.8 HIGH | OpenClaw before 2026.8.1 Remote Code Execution via CLOUDSDK_PYTHON_ARGS |
Showing top 20 of 79 CVEs. View all on vendor page → →
No comments yet