OpenClaw(npm 包 )在 2026.7.1 版本之前,未能强制执行仅允许所有者审批的 Claude Code 权限提示授权要求,这些提示通过 MCP 通道桥接传递。具有通道命令访问权限的已认证非所有者通道发送者,可以批准或拒绝本应由所有者处理的待处理权限请求,从而导致请求的操作在未经所有者同意的情况下继续执行。实际影响取决于待处理的操作以及 Claude Code 运行时请求的主机能力。该问题已在 2026.7.1 版本中修复。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-100580 | 8.8 HIGH | OpenClaw before 2026.7.1 Remote Code Execution via cron tool |
| CVE-2026-100575 | 8.8 HIGH | OpenClaw Slack before 2026.8.1 Authentication Bypass via Group DM |
| CVE-2026-100544 | 8.8 HIGH | openclaw voice-call before 2026.8.1 Authorization Bypass |
| CVE-2026-100599 | 8.8 HIGH | OpenClaw 2026.5.1 before 2026.7.1 Remote Code Execution via googlemeet.chrome |
| CVE-2026-100586 | 8.8 HIGH | OpenClaw Codex before 2026.7.1 Authorization Bypass via Bind |
| CVE-2026-100587 | 8.8 HIGH | OpenClaw before 2026.7.1 Authorization Bypass via Codex Install |
| CVE-2026-100596 | 8.8 HIGH | OpenClaw before 2026.7.1 Authorization Bypass via MCP Configuration |
| CVE-2026-100552 | 8.8 HIGH | OpenClaw before 2026.8.1 Policy Bypass via Native Tools |
| CVE-2026-100588 | 8.3 HIGH | OpenClaw before 2026.7.1 Authentication Bypass via node.invoke |
| CVE-2026-100568 | 8.3 HIGH | OpenClaw before 2026.8.1 Unauthorized Command Job Access |
| CVE-2026-100551 | 8.3 HIGH | OpenClaw iOS Control UI TLS Pin Enforcement Bypass |
| CVE-2026-100589 | 8.3 HIGH | OpenClaw before 2026.7.1 Sandbox Bypass via Browser Node |
| CVE-2026-100557 | 8.3 HIGH | OpenClaw before 2026.8.1 Authorization Bypass via Skill Tool Dispatch |
| CVE-2026-100567 | 8.2 HIGH | OpenClaw before 2026.8.1 DNS Rebinding via CDP Hostname |
| CVE-2026-100532 | 8.1 HIGH | openclaw WhatsApp before 2026.8.1 Authentication Bypass |
| CVE-2026-100559 | 8.0 HIGH | OpenClaw before 2026.8.1 Command Injection via Escaped Newlines |
| CVE-2026-100561 | 8.0 HIGH | OpenClaw before 2026.8.1 Authentication Bypass via Exec Wrapper |
| CVE-2026-100597 | 7.8 HIGH | OpenClaw before 2026.7.1 Path Traversal via Filesystem Race |
| CVE-2026-100570 | 7.8 HIGH | OpenClaw before 2026.8.1 Remote Code Execution via CLOUDSDK_PYTHON_ARGS |
| CVE-2026-100579 | 7.6 HIGH | OpenClaw before 2026.7.1 Authentication Bypass via Spoofed Requester |
Showing top 20 of 79 CVEs. View all on vendor page → →
No comments yet