Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 2

Количество 2

nvd логотип

CVE-2026-35653

4 месяца назад

OpenClaw before 2026.3.24 contains an incorrect authorization vulnerability in the POST /reset-profile endpoint that allows authenticated callers with operator.write access to browser.request to bypass profile mutation restrictions. Attackers can invoke POST /reset-profile through the browser.request surface to stop the running browser, close Playwright connections, and move profile directories to Trash, crossing intended privilege boundaries.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-xp9r-prpg-373r

4 месяца назад

OpenClaw: `browser.request` still allows `POST /reset-profile` through the `operator.write` surface

CVSS3: 8.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-35653

OpenClaw before 2026.3.24 contains an incorrect authorization vulnerability in the POST /reset-profile endpoint that allows authenticated callers with operator.write access to browser.request to bypass profile mutation restrictions. Attackers can invoke POST /reset-profile through the browser.request surface to stop the running browser, close Playwright connections, and move profile directories to Trash, crossing intended privilege boundaries.

CVSS3: 8.1
1%
Низкий
4 месяца назад
github логотип
GHSA-xp9r-prpg-373r

OpenClaw: `browser.request` still allows `POST /reset-profile` through the `operator.write` surface

CVSS3: 8.1
1%
Низкий
4 месяца назад

Уязвимостей на страницу