OpenClaw是OpenClaw开源的一个智能人工助理。 OpenClaw 2026.5.18之前版本存在安全漏洞,该漏洞源于Gateway chat.send路由中存在范围绕过漏洞,允许有范围限制的客户端执行特权命令。具有operator.write范围的攻击者可以通过继承的外部路由传递命令,绕过operator.approvals和operator.admin范围要求,实现未授权的插件、配置、MCP、允许列表和ACP修改。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-32905 | 8.3 HIGH | OpenClaw < 2026.5.4 - Unauthorized Device-Pairing Bootstrap Code Issuance via Chat Command |
| CVE-2026-35630 | 8.0 HIGH | OpenClaw < 2026.5.18 - QQBot Missing Approver Identity Enforcement in Native Approval Butt |
| CVE-2026-35673 | 6.5 MEDIUM | OpenClaw < 2026.4.29 - SSRF Policy Bypass via Browser Debug/Export Routes |
| CVE-2026-34507 | 5.4 MEDIUM | OpenClaw < 2026.4.29 - Policy Bypass in QQBot Admin Commands via DM-only and allowFrom Ch |
| CVE-2026-32906 | 4.3 MEDIUM | OpenClaw < 2026.5.12 - Privilege Escalation in Slack Plugin Approvals via Exec Approver Ga |
No comments yet