Количество 2
Количество 2
CVE-2026-35653
OpenClaw before 2026.3.24 contains an incorrect authorization vulnerability in the POST /reset-profile endpoint that allows authenticated callers with operator.write access to browser.request to bypass profile mutation restrictions. Attackers can invoke POST /reset-profile through the browser.request surface to stop the running browser, close Playwright connections, and move profile directories to Trash, crossing intended privilege boundaries.
GHSA-xp9r-prpg-373r
OpenClaw: `browser.request` still allows `POST /reset-profile` through the `operator.write` surface
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-35653 OpenClaw before 2026.3.24 contains an incorrect authorization vulnerability in the POST /reset-profile endpoint that allows authenticated callers with operator.write access to browser.request to bypass profile mutation restrictions. Attackers can invoke POST /reset-profile through the browser.request surface to stop the running browser, close Playwright connections, and move profile directories to Trash, crossing intended privilege boundaries. | CVSS3: 8.1 | 1% Низкий | 4 месяца назад | |
GHSA-xp9r-prpg-373r OpenClaw: `browser.request` still allows `POST /reset-profile` through the `operator.write` surface | CVSS3: 8.1 | 1% Низкий | 4 месяца назад |
Уязвимостей на страницу