Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xq3g-m3j8-2vmm

Опубликовано: 21 мар. 2026
Источник: github
Github: Прошло ревью
CVSS4: 8.7
CVSS3: 7.5

Описание

Duplicate Advisory: OpenClaw's inbound media downloads could exceed configured byte limits before rejection across multiple channels

Duplicate Advisory

This advisory has been withdrawn because it is a duplicate of GHSA-rxxp-482v-7mrh. This link is maintained to preserve external references.

Original Description

OpenClaw versions prior to 2026.2.22 fail to consistently enforce configured inbound media byte limits before buffering remote media across multiple channel ingestion paths. Remote attackers can send oversized media payloads to trigger elevated memory usage and potential process instability.

Пакеты

Наименование

openclaw

npm
Затронутые версииВерсия исправления

Отсутствует

8.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-770

8.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-770