OpenClaw是OpenClaw开源的一个智能人工助理。 OpenClaw 2026.5.4之前版本存在安全漏洞,该漏洞源于捆绑的device-pair插件中存在授权绕过漏洞,允许非所有者授权的聊天发送者在不进行适当范围验证的情况下发布设备配对引导码。具有聊天命令访问权限的攻击者可以创建设置码来注册具有操作员或节点功能的设备,从而获得持久凭证直到手动删除。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-35674 | 8.8 HIGH | OpenClaw < 2026.5.18 - Scope Bypass via Inherited chat.send Route |
| CVE-2026-35630 | 8.0 HIGH | OpenClaw < 2026.5.18 - QQBot Missing Approver Identity Enforcement in Native Approval Butt |
| CVE-2026-35673 | 6.5 MEDIUM | OpenClaw < 2026.4.29 - SSRF Policy Bypass via Browser Debug/Export Routes |
| CVE-2026-34507 | 5.4 MEDIUM | OpenClaw < 2026.4.29 - Policy Bypass in QQBot Admin Commands via DM-only and allowFrom Ch |
| CVE-2026-32906 | 4.3 MEDIUM | OpenClaw < 2026.5.12 - Privilege Escalation in Slack Plugin Approvals via Exec Approver Ga |
No comments yet