Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qhfj-5gcr-fpxq

Опубликовано: 17 июл. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 7.7
CVSS3: 8.8

Описание

OpenClaw versions 2026.6.1 before 2026.6.9 contain a privilege escalation vulnerability in isolated cron jobs that allows lower-trust callers to regain denied execution tools. Attackers can execute or persist actions beyond their intended authorization by leveraging misconfigured input paths in the affected cron feature.

OpenClaw versions 2026.6.1 before 2026.6.9 contain a privilege escalation vulnerability in isolated cron jobs that allows lower-trust callers to regain denied execution tools. Attackers can execute or persist actions beyond their intended authorization by leveraging misconfigured input paths in the affected cron feature.

EPSS

Процентиль: 22%
0.00298
Низкий

7.7 High

CVSS4

8.8 High

CVSS3

Дефекты

CWE-863

Связанные уязвимости

CVSS3: 8.8
nvd
29 дней назад

OpenClaw versions 2026.6.1 before 2026.6.9 contain a privilege escalation vulnerability in isolated cron jobs that allows lower-trust callers to regain denied execution tools. Attackers can execute or persist actions beyond their intended authorization by leveraging misconfigured input paths in the affected cron feature.

EPSS

Процентиль: 22%
0.00298
Низкий

7.7 High

CVSS4

8.8 High

CVSS3

Дефекты

CWE-863