ClawHub(openclaw/clawhub 应用程序/后端)在“变更日志预览”功能中存在缺失的授权检查漏洞。已登录用户可以通过调用 操作,访问其无权访问的技能(skill);在获取前一个版本时,未强制执行正常内容访问所需的文件读取权限验证,导致最多 8,000 个字符的隔离内容(quarantined content)被提交给 AI 提供商,并反映在返回给调用者的预览结果中,从而泄露受限的技能内容。 该问题已在修订版本 中得到确认,但尚未完全确定受影响的历史版本范围。该漏洞已通过 PR #3682 修复,该修
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-100580 | 8.8 HIGH | OpenClaw before 2026.7.1 Remote Code Execution via cron tool |
| CVE-2026-100575 | 8.8 HIGH | OpenClaw Slack before 2026.8.1 Authentication Bypass via Group DM |
| CVE-2026-100599 | 8.8 HIGH | OpenClaw 2026.5.1 before 2026.7.1 Remote Code Execution via googlemeet.chrome |
| CVE-2026-100544 | 8.8 HIGH | openclaw voice-call before 2026.8.1 Authorization Bypass |
| CVE-2026-100596 | 8.8 HIGH | OpenClaw before 2026.7.1 Authorization Bypass via MCP Configuration |
| CVE-2026-100586 | 8.8 HIGH | OpenClaw Codex before 2026.7.1 Authorization Bypass via Bind |
| CVE-2026-100587 | 8.8 HIGH | OpenClaw before 2026.7.1 Authorization Bypass via Codex Install |
| CVE-2026-100552 | 8.8 HIGH | OpenClaw before 2026.8.1 Policy Bypass via Native Tools |
| CVE-2026-100551 | 8.3 HIGH | OpenClaw iOS Control UI TLS Pin Enforcement Bypass |
| CVE-2026-100588 | 8.3 HIGH | OpenClaw before 2026.7.1 Authentication Bypass via node.invoke |
| CVE-2026-100589 | 8.3 HIGH | OpenClaw before 2026.7.1 Sandbox Bypass via Browser Node |
| CVE-2026-100568 | 8.3 HIGH | OpenClaw before 2026.8.1 Unauthorized Command Job Access |
| CVE-2026-100557 | 8.3 HIGH | OpenClaw before 2026.8.1 Authorization Bypass via Skill Tool Dispatch |
| CVE-2026-100567 | 8.2 HIGH | OpenClaw before 2026.8.1 DNS Rebinding via CDP Hostname |
| CVE-2026-100532 | 8.1 HIGH | openclaw WhatsApp before 2026.8.1 Authentication Bypass |
| CVE-2026-100585 | 8.0 HIGH | OpenClaw before 2026.7.1 Authentication Bypass via MCP Channel |
| CVE-2026-100561 | 8.0 HIGH | OpenClaw before 2026.8.1 Authentication Bypass via Exec Wrapper |
| CVE-2026-100559 | 8.0 HIGH | OpenClaw before 2026.8.1 Command Injection via Escaped Newlines |
| CVE-2026-100570 | 7.8 HIGH | OpenClaw before 2026.8.1 Remote Code Execution via CLOUDSDK_PYTHON_ARGS |
| CVE-2026-100597 | 7.8 HIGH | OpenClaw before 2026.7.1 Path Traversal via Filesystem Race |
Showing top 20 of 79 CVEs. View all on vendor page → →
No comments yet