漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
OpenClaw skills.status could leak secrets to operator.read clients
Vulnerability Description
OpenClaw is a personal AI assistant. Prior to version 2026.2.14, `skills.status` could disclose secrets to `operator.read` clients by returning raw resolved config values in `configChecks` for skill `requires.config` paths. Version 2026.2.14 stops including raw resolved config values in requirement checks (return only `{ path, satisfied }`) and narrows the Discord skill requirement to the token key. In addition to upgrading, users should rotate any Discord tokens that may have been exposed to read-scoped clients.
CVSS Information
N/A
Vulnerability Type
信息暴露
Vulnerability Title
OpenClaw 信息泄露漏洞
Vulnerability Description
OpenClaw是openclaw开源的一个智能人工助理。 OpenClaw 2026.2.14之前版本存在信息泄露漏洞,该漏洞源于skills.status可能通过configChecks返回技能requires.config路径的原始解析配置值,从而向operator.read客户端泄露密钥。
CVSS Information
N/A
Vulnerability Type
N/A