Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-w2cg-vxx6-5xjg

Опубликовано: 18 фев. 2026
Источник: github
Github: Прошло ревью
CVSS4: 6.8
CVSS3: 5.5

Описание

OpenClaw: denial of service through large base64 media files allocating large buffers before limit checks

Summary

Base64-backed media inputs could be decoded into Buffers before enforcing decoded-size budgets. An attacker supplying oversized base64 payloads can force large allocations, causing memory pressure and denial of service.

Attack Scenario Notes

  • Recommended deployments bind the gateway to loopback by default and require gateway auth for HTTP endpoints. In that configuration, this is best modeled as a local/authorized DoS.
  • If an operator exposes the gateway to untrusted networks (or disables/weakens auth and rate limits), treat this as a higher-severity network DoS risk.

Affected Packages / Versions

  • openclaw (npm): <= 2026.2.13
  • clawdbot (npm): <= 2026.1.24-3

Fixed In

  • openclaw (npm): 2026.2.14 (planned)
  • clawdbot (npm): no patched release planned; migrate to openclaw

Fix Commit(s)

  • 31791233d60495725fa012745dde8d6ee69e9595

Credits

Thanks @vincentkoc for reporting.

Пакеты

Наименование

openclaw

npm
Затронутые версииВерсия исправления

< 2026.2.14

2026.2.14

Наименование

clawdbot

npm
Затронутые версииВерсия исправления

<= 2026.1.24-3

Отсутствует

EPSS

Процентиль: 20%
0.00274
Низкий

6.8 Medium

CVSS4

5.5 Medium

CVSS3

Дефекты

CWE-400
CWE-770

Связанные уязвимости

CVSS3: 5.5
nvd
5 месяцев назад

OpenClaw versions prior to 2026.2.14 decode base64-backed media inputs into buffers before enforcing decoded-size budget limits, allowing attackers to trigger large memory allocations. Remote attackers can supply oversized base64 payloads to cause memory pressure and denial of service.

CVSS3: 5.5
fstec
6 месяцев назад

Уязвимость ИИ-агента OpenClaw (ранее - ClawdBot или MoltBot), связанная с неограниченным распределением ресурсов, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 20%
0.00274
Низкий

6.8 Medium

CVSS4

5.5 Medium

CVSS3

Дефекты

CWE-400
CWE-770