OpenClaw是OpenClaw开源的一个智能人工助理。 OpenClaw 2026.5.18之前版本存在安全漏洞,该漏洞源于QQBot原生审批按钮中存在授权绕过漏洞,未能强制实施配置的审批人身份。非审批人用户可以点击审批按钮,在未经适当授权的情况下解决待处理的exec或插件审批请求。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-35674 | 8.8 HIGH | OpenClaw < 2026.5.18 - Scope Bypass via Inherited chat.send Route |
| CVE-2026-32905 | 8.3 HIGH | OpenClaw < 2026.5.4 - Unauthorized Device-Pairing Bootstrap Code Issuance via Chat Command |
| CVE-2026-35673 | 6.5 MEDIUM | OpenClaw < 2026.4.29 - SSRF Policy Bypass via Browser Debug/Export Routes |
| CVE-2026-34507 | 5.4 MEDIUM | OpenClaw < 2026.4.29 - Policy Bypass in QQBot Admin Commands via DM-only and allowFrom Ch |
| CVE-2026-32906 | 4.3 MEDIUM | OpenClaw < 2026.5.12 - Privilege Escalation in Slack Plugin Approvals via Exec Approver Ga |
No comments yet