Количество 3
Количество 3
CVE-2026-22169
OpenClaw versions prior to 2026.2.22 contain an allowlist bypass vulnerability in the safeBins configuration that allows attackers to invoke external helpers through the compress-program option. When sort is explicitly added to tools.exec.safeBins, remote attackers can bypass intended safe-bin approval constraints by leveraging the compress-program parameter to execute unauthorized external programs.
GHSA-vmqr-rc7x-3446
OpenClaw's non-default safeBins sort configuration can bypass intended allowlist approval constraints
BDU:2026-05049
Уязвимость конфигурации tools.exec.safeBins ИИ-агента OpenClaw (ранее - ClawdBot или MoltBot), позволяющая нарушителю обойти существующие механизмы безопасности
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-22169 OpenClaw versions prior to 2026.2.22 contain an allowlist bypass vulnerability in the safeBins configuration that allows attackers to invoke external helpers through the compress-program option. When sort is explicitly added to tools.exec.safeBins, remote attackers can bypass intended safe-bin approval constraints by leveraging the compress-program parameter to execute unauthorized external programs. | CVSS3: 6.7 | 0% Низкий | 5 месяцев назад | |
GHSA-vmqr-rc7x-3446 OpenClaw's non-default safeBins sort configuration can bypass intended allowlist approval constraints | CVSS3: 6.4 | 0% Низкий | 5 месяцев назад | |
BDU:2026-05049 Уязвимость конфигурации tools.exec.safeBins ИИ-агента OpenClaw (ранее - ClawdBot или MoltBot), позволяющая нарушителю обойти существующие механизмы безопасности | CVSS3: 7 | 0% Низкий | 6 месяцев назад |
Уязвимостей на страницу