Количество 3
Количество 3
CVE-2026-22179
OpenClaw versions prior to 2026.2.22 in macOS node-host system.run contain an allowlist bypass vulnerability that allows remote attackers to execute non-allowlisted commands by exploiting improper parsing of command substitution tokens. Attackers can craft shell payloads with command substitution syntax within double-quoted text to bypass security restrictions and execute arbitrary commands on the system.
GHSA-9p38-94jf-hgjj
OpenClaw has macOS `system.run` allowlist bypass via quoted command substitution
BDU:2026-05245
Уязвимость режима allowlist ИИ-агента OpenClaw (ранее - ClawdBot или MoltBot), позволяющая нарушителю выполнить произвольные команды
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-22179 OpenClaw versions prior to 2026.2.22 in macOS node-host system.run contain an allowlist bypass vulnerability that allows remote attackers to execute non-allowlisted commands by exploiting improper parsing of command substitution tokens. Attackers can craft shell payloads with command substitution syntax within double-quoted text to bypass security restrictions and execute arbitrary commands on the system. | CVSS3: 7.2 | 1% Низкий | 5 месяцев назад | |
GHSA-9p38-94jf-hgjj OpenClaw has macOS `system.run` allowlist bypass via quoted command substitution | 1% Низкий | 5 месяцев назад | ||
BDU:2026-05245 Уязвимость режима allowlist ИИ-агента OpenClaw (ранее - ClawdBot или MoltBot), позволяющая нарушителю выполнить произвольные команды | CVSS3: 7.2 | 1% Низкий | 6 месяцев назад |
Уязвимостей на страницу