OpenClaw是openclaw开源的一个智能人工助理。 OpenClaw 2026.2.17及之前版本存在安全漏洞,该漏洞源于打包技能时本地帮助脚本遵循符号链接,可能导致本地文件无意泄露。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-27487 | 7.6 HIGH | OpenClaw: Prevent shell injection in macOS keychain credential write |
| CVE-2026-27576 | OpenClaw: ACP prompt-size checks missing in local stdio bridge could reduce responsiveness | |
| CVE-2026-27488 | OpenClaw hardened cron webhook delivery against SSRF | |
| CVE-2026-27486 | OpenClaw: Process Safety - Unvalidated PID Kill via SIGKILL in Process Cleanup | |
| CVE-2026-27484 | OpenClaw Discord moderation authorization used untrusted sender identity in tool-driven fl |
No comments yet