目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

安全情报专区 186+

精选漏洞公告、利用分析、安全博客、GHSA Advisory 等情报来源,已自动清洗 + 中英双语呈现,持续更新。

213
已接入情报源
93
当前稳定在线
320
24 小时新增
186+
AI 处理情报
持续监听、清洗、翻译并进行 AI 分析 监听情报
示例:RCE · SSRF · GHSA · 反序列化
筛选
清除筛选
精品
High
OpenClaw tools.exec白名单绕过漏洞分析
github.com · 2026-02-27
openclaw/openclaw <= 2026.2.22-2
Read more
High
OpenCode OC-22 技能打包Zip Slip与符号链接绕过修复
OC-22 · github.com · 2026-02-22
openclaw < latest
Read more
High
Claude CLI Shell注入漏洞修复(execFileSync替代execSync)
github.com · 2026-02-22
openclaw/openclaw (pre-commit 66d7178)
Read more
High
macOS keychain凭证写入命令注入漏洞(CWE-78)修复
github.com · 2026-02-22

### 关键信息摘要 #### 漏洞描述 - **类型**:命令注入漏洞 - **位置**:macOS keychain 的凭证写入功能 - **文件**:`src/agents/cli-credentials.{e2e.test,ts}` - **参考编号**:#15924 #### 漏洞细节 - **错误原因**:使用 `execSync` 通过字符串插值构建 shell 命令时,只解决了单引…

Read more
Low
openclaw CVE-2026-27576 提示词注入与资源耗尽漏洞
CVE-2026-27576 · github.com · 2026-02-22
openclaw <= 2026.2.17
Read more
High
Discord GHSA-wh94-p5m6-mr7j: 工具流中未信任发送者身份导致权限绕过
GHSA-wh94-p5m6-mr7j · github.com · 2026-02-22
openclaw <=2026.2.17
Read more
High
Telnyx Webhook签名验证绕过修复
github.com · 2026-02-21
openclaw/openclaw < 29b587e
Read more
High
OpenClaw/Clawdbot 循环接口 CSRF 漏洞 (CVSS 7.1)
github.com · 2026-02-21
clawdbot <=2026.1.24-3 · openclaw <=2026.2.13
Read more
High
OpenClaw GHSA-6hf3-mhgc-cm65 会话可见性越权及Telegram Webhook配置缺陷
GHSA-6hf3-mhgc-cm65 · github.com · 2026-02-21
openclaw <=2026.2.14
Read more
Medium
openclaw GHSA-8mh7-phf8-xgfm 信息泄露漏洞 (CVE-2026-26326)
GHSA-8mh7-phf8-xgfm · github.com · 2026-02-21
openclaw <= 2026.2.13
Read more
High
OpenClaw macOS深度链接截断漏洞(CVE-2026-26320)及修复
CVE-2026-26320 · github.com · 2026-02-21
OpenClaw macOS desktop client versions >= 2026.2.6 and <= 2026.2.13
Read more
High
OpenClaw Gateway 路径穿越漏洞 (CVE-2026-26329) 分析
CVE-2026-26329 · github.com · 2026-02-21
openclaw <2026.2.14
Read more
Medium
openclaw 维护脚本命令注入漏洞 (CVE-2026-26323)
CVE-2026-26323 · github.com · 2026-02-21
openclaw >=2026.1.8 <2026.2.14
Read more
High
OpenClaw gatewayUrl未授权覆盖漏洞(GHSA-g6q9-8fvw-f7rf)
GHSA-g6q9-8fvw-f7rf · github.com · 2026-02-21
openclaw <=2026.2.13
Read more
Medium
CVE-2026-26328: clawdbot/openclaw iMessage群组授权绕过
CVE-2026-26328 · github.com · 2026-02-21
clawdbot <=2026.1.24-3 · openclaw <=2026.2.13
Read more
Critical
OpenClaw CVE-2026-27002: Docker容器逃逸漏洞
CVE-2026-27002 · github.com · 2026-02-21
openclaw <= 2026.2.14
Read more

每篇文章经过自动 HTML→Markdown 清洗 + LLM 去噪 + 中英双语翻译。原始链接保留在文章末尾。

想看哪个安全博客 / 公告源?邮件告诉我们,每周新接 1-2 个。