检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-RC8F-R29C-CHR6 | Duplicate Advisory: OpenClaw: BlueBubbles Webhook Missing Rate Limiting Enables Brute-Force Password Guessing 已撤回 | 中危 | npmopenclaw | 已审查 | 2026-04-10 08:30 | 2026-04-18 08:48 |
当前筛选结果 998 条 · 时间按北京时间显示
Duplicate Advisory: OpenClaw: Plivo V2 verified replay identity drifts on query-only variants 已撤回 |
| 高危 |
npmopenclaw |
| 已审查 |
| 2026-04-10 08:30 |
| 2026-04-11 04:18 |
| GHSA-J42Q-R6QX-XRFP | Duplicate Advisory: OpenClaw: Google Chat Authz Bypass via Group Policy Rebinding with Mutable Space displayName 已撤回 | 低危 | npmopenclaw | 已审查 | 2026-04-10 08:30 | 2026-04-18 08:48 |
| GHSA-HGWR-WR8H-RXM7 | Duplicate Advisory: OpenClaw: Google Chat app-url webhook auth accepted non-deployment add-on principals 已撤回 | 中危 | npmopenclaw | 已审查 | 2026-04-10 08:30 | 2026-04-18 08:57 |
| GHSA-5F7H-P83X-5VC2 | Duplicate Advisory: OpenClaw: Nextcloud Talk room allowlist matched colliding room names instead of stable room tokens 已撤回 | 低危 | npmopenclaw | 已审查 | 2026-04-10 08:30 | 2026-04-18 08:55 |
| GHSA-PG8G-F2HF-X82M | Duplicate Advisory: OpenClaw: `fetchWithSsrFGuard` replays unsafe request bodies across cross-origin redirects 已撤回 | 高危 | npmopenclaw | 已审查 | 2026-04-09 08:31 | 2026-04-11 04:24 |
| GHSA-C3F2-QG8V-25Q2 | Duplicate Advisory: Unfurl's unbounded zlib decompression allows decompression bomb DoS 已撤回 | 高危 | PyPIdfir-unfurl | 已审查 | 2026-04-09 08:31 | 2026-04-11 01:18 |
| GHSA-GC59-R5JQ-98QW | Duplicate Advisory: Eclipse Jetty: Early return from the JASPIAuthenticator code can potentially no clear ThreadLocal variables 已撤回 | 高危 | Mavenorg.eclipse.jetty.ee10:jetty-ee10 | 已审查 | 2026-04-08 23:31 | 2026-04-14 08:06 |
| GHSA-6JWV-W5XF-7J27 CVE-2026-33817 | Withdrawn Advisory: go.etcd.io/bbolt affected by index out-of-range vulnerability 已撤回 | 中危 | Gogo.etcd.io/bbolt | 已审查 | 2026-04-07 05:31 | 2026-04-14 03:32 |
| GHSA-CH86-PXR9-J9H9 | Duplicate Advisory: OpenClaw: Gemini OAuth exposed the PKCE verifier through the OAuth state parameter 已撤回 | 中危 | npmopenclaw | 已审查 | 2026-04-04 05:31 | 2026-04-07 22:24 |
| GHSA-RF75-G96H-J3RM | Duplicate Advisory: OpenClaw's complex interpreter pipelines could skip exec script preflight validation 已撤回 | 中危 | npmopenclaw | 已审查 | 2026-04-03 05:32 | 2026-04-07 06:53 |
| GHSA-8H8F-7CXM-M38J | Duplicate Advisory: OpenClaw: Windows media loaders accepted remote-host file URLs before local path validation 已撤回 | 中危 | npmopenclaw | 已审查 | 2026-04-03 05:32 | 2026-04-11 04:42 |
| GHSA-GM9M-X74R-8WHG | Duplicate Advisory: OpenClaw's Nextcloud Talk webhook missing rate limiting on shared secret authentication 已撤回 | 中危 | npmopenclaw | 已审查 | 2026-03-31 23:31 | 2026-04-07 06:53 |
| GHSA-F275-5H5C-5WG5 | Duplicate Advisory: OpenClaw: /pair approve command path omitted caller scope subsetting and reopened device pairing escalation 已撤回 | 高危 | npmopenclaw | 已审查 | 2026-03-31 23:31 | 2026-04-07 06:39 |
| GHSA-89HR-6X2P-8XJV | Duplicate Advisory: OpenClaw's device removal and token revocation do not terminate active WebSocket sessions 已撤回 | 高危 | npmopenclaw | 已审查 | 2026-03-31 23:31 | 2026-04-01 07:51 |
| GHSA-3GR8-2752-H46Q | Duplicate Advisory: OpenClaw's message tool media parameter bypasses tool policy filesystem isolation 已撤回 | 高危 | npmopenclaw | 已审查 | 2026-03-31 23:31 | 2026-04-01 07:54 |
| GHSA-35CQ-WV6V-88XF | Duplicate Advisory: OpenClaw affected by SSRF via unguarded image download in fal provider 已撤回 | 中危 | npmopenclaw | 已审查 | 2026-03-31 23:31 | 2026-04-07 06:45 |
| GHSA-XXJ4-96PH-G6J6 | Duplicate Advisory: OpenClaw: Sandbox `writeFile` commit could race outside the validated path 已撤回 | 中危 | npmopenclaw | 已审查 | 2026-03-31 20:31 | 2026-04-07 06:45 |
| GHSA-XG59-F45V-9R9J | Duplicate Advisory: OpenClaw's MS Teams sender allowlist bypass when route allowlist is configured and sender allowlist is empty 已撤回 | 低危 | npmopenclaw | 已审查 | 2026-03-31 20:31 | 2026-04-07 06:45 |
| GHSA-CXFR-3QP8-HPMW | Duplicate Advisory: OpenClaw: Zalo webhook rate limiting could be bypassed before secret validation 已撤回 | 中危 | npmopenclaw | 已审查 | 2026-03-31 20:31 | 2026-04-07 06:50 |
| GHSA-8288-JPQP-95FX CVE-2026-34508 | Duplicate Advisory: OpenClaw has Bypass in Webhook Rate Limiting via Pre-Authentication Secret Validation 已撤回 | 中危 | npmopenclaw | 已审查 | 2026-03-31 20:31 | 2026-04-08 02:04 |
| GHSA-WWRJ-437C-PPQ4 | Duplicate Advisory: OpenClaw's system.run approvals did not bind mutable script operands across approval and execution 已撤回 | 中危 | npmopenclaw | 已审查 | 2026-03-31 20:31 | 2026-04-07 06:37 |
| GHSA-W8RF-7QF8-65WW | Duplicate Advisory: OpenClaw: Node-host approvals could show misleading shell payloads instead of the executed argv 已撤回 | 高危 | npmopenclaw | 已审查 | 2026-03-31 20:31 | 2026-04-07 06:37 |
| GHSA-VM29-7MQ3-9JRG | Duplicate Advisory: OpenClaw: Unavailable local auth SecretRefs could fall through to remote credentials in local mode 已撤回 | 低危 | npmOpenClaw | 已审查 | 2026-03-31 20:31 | 2026-04-08 02:10 |
| GHSA-PHGF-3849-RGJQ | Duplicate Advisory: OpenClaw: Plugin subagent routes could bypass gateway authorization with synthetic admin scopes 已撤回 | 严重 | npmopenclaw | 已审查 | 2026-03-31 20:31 | 2026-04-07 06:49 |