OpenClaw Windows Node 在 2026.9.4 及之前版本中存在一个服务器端请求伪造(SSRF)漏洞,该漏洞位于 功能中,能够绕过由 强制执行的 URL 风险评估。拥有网关(gateway)或代理(agent)访问权限的攻击者可以利用 指令,促使节点上的 WebView 从用户机器向 localhost、私有网络或 tailnet 服务发起请求。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| OpenClaw | OpenClaw Windows Node | 0 ~ 2026.9.4 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-101880 | 8.8 HIGH | OpenClaw Windows Node before 2026.7.1 Authorization Bypass |
| CVE-2026-101882 | 8.8 HIGH | OpenClaw Windows Node before 2026.7.1 Remote Code Execution via system.execApprovals.set |
| CVE-2026-101884 | 7.5 HIGH | OpenClaw Windows Node before 2026.7.1 Remote Code Execution via Environment Override |
| CVE-2026-101879 | 6.5 MEDIUM | OpenClaw Windows Node before 2026.7.1-3 Missing Authorization |
| CVE-2026-101881 | 6.5 MEDIUM | OpenClaw Windows Node before 2026.7.1 Denial of Service |
No comments yet