OpenClaw是OpenClaw开源的一个智能人工助理。 OpenClaw 2026.3.31之前版本存在后置链接漏洞,该漏洞源于SSH沙箱tar上传存在符号链接跟随,可能导致远程攻击者上传包含符号链接的tar归档文件以逃逸沙箱并覆盖远程主机上的文件。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-41371 | 8.5 HIGH | OpenClaw < 2026.3.28 - Privilege Escalation via chat.send Reset Command |
| CVE-2026-41368 | 6.5 MEDIUM | OpenClaw < 2026.3.28 - Environment Variable Disclosure via jq $ENV Filter Bypass |
| CVE-2026-41369 | 6.5 MEDIUM | OpenClaw < 2026.3.31 - Insufficient Environment Variable Sanitization in Host Execution |
| CVE-2026-41370 | 6.5 MEDIUM | OpenClaw < 2026.3.31 - Path Traversal via Inbound Channel Attachment Path in ACP Dispatch |
| CVE-2026-41372 | 5.8 MEDIUM | OpenClaw < 2026.4.2 - Loopback Protection Bypass via Trailing-Dot Localhost in CDP Discove |
| CVE-2026-41366 | 5.5 MEDIUM | OpenClaw < 2026.3.31 - Arbitrary Host File Read via appendLocalMediaParentRoots Self-White |
| CVE-2026-41365 | 5.4 MEDIUM | OpenClaw < 2026.3.31 - Sender Allowlist Bypass via Graph API Thread History |
| CVE-2026-41363 | 5.3 MEDIUM | OpenClaw 2026.2.6 < 2026.3.28 - Arbitrary File Read via Feishu upload_image Parameter |
| CVE-2026-41367 | 5.0 MEDIUM | OpenClaw 2026.2.14 < 2026.3.28 - Policy Enforcement Bypass in Discord Component Interactio |
| CVE-2026-41362 | 4.3 MEDIUM | OpenClaw 2026.2.19 through 2026.3.30 - Webhook Replay Dedupe Cache Event Suppression via S |
No comments yet