漏洞列表 360566
CVE ID 标题 严重程度 CVSS 发布时间 受影响产品 数据源 操作
CVE-2026-28477
OpenClaw versions prior to 2026.2.14 contain an oauth state validation bypass vulnerability in the m
MEDIUM 5.9 2026-03-05
未知
NVD
CVE-2026-28476
OpenClaw versions prior to 2026.2.14 contain a server-side request forgery vulnerability in the opti
MEDIUM 5.3 2026-03-05
未知
NVD
CVE-2026-28475
OpenClaw versions prior to 2026.2.13 use non-constant-time string comparison for hook token validati
MEDIUM 4.8 2026-03-05
openclaw openclaw
NVD
CVE-2026-28474
OpenClaw's Nextcloud Talk plugin versions prior to 2026.2.6 accept equality matching on the mutable
CRITICAL 9.8 2026-03-05
未知
NVD
CVE-2026-28473
OpenClaw versions prior to 2026.2.2 contain an authorization bypass vulnerability where clients with
CRITICAL 9.8 2026-03-05
openclaw openclaw
NVD
CVE-2026-28472
OpenClaw versions prior to 2026.2.2 contain a vulnerability in the gateway WebSocket connect handsha
CRITICAL 9.8 2026-03-05
openclaw openclaw
NVD
CVE-2026-28471
OpenClaw version 2026.1.14-1 prior to 2026.2.2, with the Matrix plugin installed and enabled, contai
LOW 3.7 2026-03-05
openclaw openclaw
NVD
CVE-2026-28470
OpenClaw versions prior to 2026.2.2 contain an exec approvals (must be enabled) allowlist bypass vul
CRITICAL 9.8 2026-03-05
openclaw openclaw
NVD
CVE-2026-28469
OpenClaw versions prior to 2026.2.14 contain a webhook routing vulnerability in the Google Chat moni
CRITICAL 9.8 2026-03-05
openclaw openclaw
NVD
CVE-2026-28468
OpenClaw versions 2026.1.29-beta.1 prior to 2026.2.14 contain a vulnerability in the sandbox browser
HIGH 7.8 2026-03-05
openclaw openclaw
NVD
CVE-2026-28467
OpenClaw versions prior to 2026.2.2 contain a server-side request forgery vulnerability in attachmen
MEDIUM 5.3 2026-03-05
openclaw openclaw
NVD
CVE-2026-28466
OpenClaw versions prior to 2026.2.14 contain a vulnerability in the gateway in which it fails to san
HIGH 8.8 2026-03-05
openclaw openclaw
NVD
CVE-2026-28465
OpenClaw's voice-call plugin versions before 2026.2.3 contain an improper authentication vulnerabili
HIGH 7.5 2026-03-05
openclaw openclaw
NVD
CVE-2026-28464
OpenClaw versions prior to 2026.2.12 use non-constant-time string comparison for hook token validati
CRITICAL 9.8 2026-03-05
openclaw openclaw
NVD
CVE-2026-28463
OpenClaw exec-approvals allowlist validation checks pre-expansion argv tokens but execution uses rea
HIGH 8.4 2026-03-05
openclaw openclaw
NVD
CVE-2026-28462
OpenClaw versions prior to 2026.2.13 contain a vulnerability in the browser control API in which it
HIGH 7.5 2026-03-05
openclaw openclaw
NVD
CVE-2026-28459
OpenClaw versions prior to 2026.2.12 fail to validate the sessionFile path parameter, allowing authe
MEDIUM 6.5 2026-03-05
openclaw openclaw
NVD
CVE-2026-28458
OpenClaw version 2026.1.20 prior to 2026.2.1 contains a vulnerability in the Browser Relay (extensio
HIGH 7.5 2026-03-05
openclaw openclaw
NVD
CVE-2026-28457
OpenClaw versions prior to 2026.2.14 contain a path traversal vulnerability in sandbox skill mirrori
MEDIUM 5.3 2026-03-05
openclaw openclaw
NVD
CVE-2026-28456
OpenClaw versions 2026.1.5 prior to 2026.2.14 contain a vulnerability in the Gateway in which it doe
HIGH 8.4 2026-03-05
openclaw openclaw
NVD