Опубликовано: 07 апр. 2026
Источник: github
Github: Прошло ревью
CVSS4: 6.3
CVSS3: 6.5
Описание
OpenClaw: Tlon media downloads can bypass core safety limits and exhaust disk
Summary
Tlon media downloads can bypass core safety limits and exhaust disk
Current Maintainer Triage
- Status: narrow
- Normalized severity: low
- Assessment: Shipped v2026.3.28 Tlon media downloads bypassed core size/count/cleanup limits, but this is availability-only resource exhaustion in a bundled plugin path, so low.
Affected Packages / Versions
- Package:
openclaw(npm) - Latest published npm version:
2026.3.31 - Vulnerable version range:
<=2026.3.28 - Patched versions:
>= 2026.3.31 - First stable tag containing the fix:
v2026.3.31
Fix Commit(s)
2194587d70d2aef863508b945319c5a7c88b12ce— 2026-03-31T19:40:15+09:00
Release Process Note
- The fix is already present in released version
2026.3.31. - This draft looks ready for final maintainer disposition or publication, not additional code-fix work.
Thanks @AntAISecurityLab for reporting.
Ссылки
Пакеты
Наименование
openclaw
npm
Затронутые версииВерсия исправления
<= 2026.3.28
2026.3.31
EPSS
Процентиль: 26%
0.00343
Низкий
6.3 Medium
CVSS4
6.5 Medium
CVSS3
CVE ID
Дефекты
CWE-434
CWE-770
Связанные уязвимости
CVSS3: 4.3
nvd
5 месяцев назад
OpenClaw before 2026.3.31 contains a resource exhaustion vulnerability in media downloads that bypasses core safety limits for file size, count, and cleanup operations. Attackers can exhaust disk space by downloading media files without triggering intended safety restrictions, causing availability impact.
EPSS
Процентиль: 26%
0.00343
Низкий
6.3 Medium
CVSS4
6.5 Medium
CVSS3
CVE ID
Дефекты
CWE-434
CWE-770