Количество 3
Количество 3
CVE-2026-28481
OpenClaw versions 2026.1.30 and earlier, contain an information disclosure vulnerability, patched in 2026.2.1, in the MS Teams attachment downloader (optional extension must be enabled) that leaks bearer tokens to allowlisted suffix domains. When retrying downloads after receiving 401 or 403 responses, the application sends Authorization bearer tokens to untrusted hosts matching the permissive suffix-based allowlist, enabling token theft.
GHSA-7vwx-582j-j332
OpenClaw MS Teams inbound attachment downloader leaks bearer tokens to allowlisted suffix domains
BDU:2026-06333
Уязвимость расширения MS Teams ИИ-агента OpenClaw (ранее - ClawdBot или MoltBot), позволяющая нарушителю раскрыть защищаемую информацию
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-28481 OpenClaw versions 2026.1.30 and earlier, contain an information disclosure vulnerability, patched in 2026.2.1, in the MS Teams attachment downloader (optional extension must be enabled) that leaks bearer tokens to allowlisted suffix domains. When retrying downloads after receiving 401 or 403 responses, the application sends Authorization bearer tokens to untrusted hosts matching the permissive suffix-based allowlist, enabling token theft. | CVSS3: 6.5 | 0% Низкий | 5 месяцев назад | |
GHSA-7vwx-582j-j332 OpenClaw MS Teams inbound attachment downloader leaks bearer tokens to allowlisted suffix domains | CVSS3: 7.4 | 0% Низкий | 6 месяцев назад | |
BDU:2026-06333 Уязвимость расширения MS Teams ИИ-агента OpenClaw (ранее - ClawdBot или MoltBot), позволяющая нарушителю раскрыть защищаемую информацию | CVSS3: 6.5 | 0% Низкий | 6 месяцев назад |
Уязвимостей на страницу