Количество 3
Количество 3
CVE-2026-29608
OpenClaw 2026.3.1 contains an approval integrity vulnerability in system.run node-host execution where argv rewriting changes command semantics. Attackers can place malicious local scripts in the working directory to execute unintended code despite operator approval of different command text.
GHSA-h3rm-6x7g-882f
OpenClaw's Node system.run approval hardening wrapper semantic drift can execute unintended local scripts
BDU:2026-05015
Уязвимость сценария src/node-host/invoke-system-run-plan.ts ИИ-агента OpenClaw (ранее - ClawdBot или MoltBot), позволяющая нарушителю выполнить произвольный код
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-29608 OpenClaw 2026.3.1 contains an approval integrity vulnerability in system.run node-host execution where argv rewriting changes command semantics. Attackers can place malicious local scripts in the working directory to execute unintended code despite operator approval of different command text. | CVSS3: 6.7 | 0% Низкий | 5 месяцев назад | |
GHSA-h3rm-6x7g-882f OpenClaw's Node system.run approval hardening wrapper semantic drift can execute unintended local scripts | CVSS3: 6.7 | 0% Низкий | 5 месяцев назад | |
BDU:2026-05015 Уязвимость сценария src/node-host/invoke-system-run-plan.ts ИИ-агента OpenClaw (ранее - ClawdBot или MoltBot), позволяющая нарушителю выполнить произвольный код | CVSS3: 6.7 | 0% Низкий | 5 месяцев назад |
Уязвимостей на страницу