Количество 2
Количество 2
CVE-2026-41352
OpenClaw before 2026.3.31 contains a remote code execution vulnerability where a device-paired node can bypass the node scope gate authentication mechanism. Attackers with device pairing credentials can execute arbitrary node commands on the host system without proper node pairing validation.
GHSA-xj9w-5r6q-x6v4
OpenClaw: Device-Paired Node Skips Node Scope Gate → Host RCE.md
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-41352 OpenClaw before 2026.3.31 contains a remote code execution vulnerability where a device-paired node can bypass the node scope gate authentication mechanism. Attackers with device pairing credentials can execute arbitrary node commands on the host system without proper node pairing validation. | CVSS3: 8.8 | 1% Низкий | 4 месяца назад | |
GHSA-xj9w-5r6q-x6v4 OpenClaw: Device-Paired Node Skips Node Scope Gate → Host RCE.md | CVSS3: 8.8 | 1% Низкий | 4 месяца назад |
Уязвимостей на страницу