OpenClaw是OpenClaw开源的一个智能人工助理。 OpenClaw 2026.4.29之前版本存在安全漏洞,该漏洞源于浏览器调试和导出路由中存在SSRF策略绕过漏洞,允许重用已打开的阻止标签页。具有这些路由访问权限的攻击者可以通过重用阻止标签页导出或检查本应受保护的内容,绕过私有网络SSRF策略。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-35674 | 8.8 HIGH | OpenClaw < 2026.5.18 - Scope Bypass via Inherited chat.send Route |
| CVE-2026-32905 | 8.3 HIGH | OpenClaw < 2026.5.4 - Unauthorized Device-Pairing Bootstrap Code Issuance via Chat Command |
| CVE-2026-35630 | 8.0 HIGH | OpenClaw < 2026.5.18 - QQBot Missing Approver Identity Enforcement in Native Approval Butt |
| CVE-2026-34507 | 5.4 MEDIUM | OpenClaw < 2026.4.29 - Policy Bypass in QQBot Admin Commands via DM-only and allowFrom Ch |
| CVE-2026-32906 | 4.3 MEDIUM | OpenClaw < 2026.5.12 - Privilege Escalation in Slack Plugin Approvals via Exec Approver Ga |
No comments yet