OpenClaw是openclaw开源的一个智能人工助理。 OpenClaw 2026.2.17及之前版本存在安全漏洞,该漏洞源于Discord审核操作处理使用请求参数中的发送者身份,可能导致非管理员用户通过欺骗发送者身份请求审核操作。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-27487 | 7.6 HIGH | OpenClaw: Prevent shell injection in macOS keychain credential write |
| CVE-2026-27576 | OpenClaw: ACP prompt-size checks missing in local stdio bridge could reduce responsiveness | |
| CVE-2026-27488 | OpenClaw hardened cron webhook delivery against SSRF | |
| CVE-2026-27486 | OpenClaw: Process Safety - Unvalidated PID Kill via SIGKILL in Process Cleanup | |
| CVE-2026-27485 | OpenClaw affected by Stored XSS in Control UI via unsanitized assistant name/avatar in inl |
No comments yet