Количество 2
Количество 2
CVE-2026-41295
OpenClaw before 2026.4.2 contains an improper trust boundary vulnerability allowing untrusted workspace channel shadows to execute during built-in channel setup and login. Attackers can clone a workspace with a malicious plugin claiming a bundled channel id to achieve unintended in-process code execution before the plugin is explicitly trusted.
GHSA-2qrv-rc5x-2g2h
OpenClaw: Untrusted workspace channel shadows could execute during built-in channel setup
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-41295 OpenClaw before 2026.4.2 contains an improper trust boundary vulnerability allowing untrusted workspace channel shadows to execute during built-in channel setup and login. Attackers can clone a workspace with a malicious plugin claiming a bundled channel id to achieve unintended in-process code execution before the plugin is explicitly trusted. | CVSS3: 7.8 | 0% Низкий | 4 месяца назад | |
GHSA-2qrv-rc5x-2g2h OpenClaw: Untrusted workspace channel shadows could execute during built-in channel setup | 0% Низкий | 4 месяца назад |
Уязвимостей на страницу