mf-yang openclaw-cn是中国mf-yang个人开发者的一款AI智能助手。 mf-yang openclaw-cn 0.2.1及之前版本存在权限许可和访问控制问题漏洞,该漏洞源于src/auto-reply/reply/reply-elevated.ts文件中的isApprovedElevatedSender函数权限管理不当,可能允许远程攻击者利用该漏洞发起攻击。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| mf-yang | openclaw-cn | 0.2.0 |
affected |
0.2.1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| mf-yang | openclaw-cn | 0.2.0 |
cpe:2.3:a:mf-yang:openclaw-cn:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-19006 | 6.3 MEDIUM | mf-yang openclaw-cn Ggateway Exec Approval Flow bash-tools.exec.ts authorization |
| CVE-2026-19008 | 6.3 MEDIUM | mf-yang openclaw-cn apply_patch Tool sandbox-paths.ts assertNoSymlinkEscape link following |
No comments yet