Количество 2
Количество 2
CVE-2026-44109
OpenClaw before 2026.4.15 contains an authentication bypass vulnerability in Feishu webhook and card-action validation that allows unauthenticated requests to reach command dispatch. Missing encryptKey configuration and blank callback tokens fail open instead of rejecting requests, enabling attackers to bypass signature verification and replay protection to execute arbitrary commands.
GHSA-xh72-v6v9-mwhc
OpenClaw: Feishu webhook and card-action validation now fail closed
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-44109 OpenClaw before 2026.4.15 contains an authentication bypass vulnerability in Feishu webhook and card-action validation that allows unauthenticated requests to reach command dispatch. Missing encryptKey configuration and blank callback tokens fail open instead of rejecting requests, enabling attackers to bypass signature verification and replay protection to execute arbitrary commands. | CVSS3: 9.8 | 1% Низкий | 3 месяца назад | |
GHSA-xh72-v6v9-mwhc OpenClaw: Feishu webhook and card-action validation now fail closed | CVSS3: 9.8 | 1% Низкий | 4 месяца назад |
Уязвимостей на страницу