SecBoard
Zurück zur CVE-Übersicht

CVE-2026-41378

HIGH(8.8)

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Risk Signal Score22/100 — NIEDRIG
  • CVSS 8.8 — Hoch

EPSS-Score

0%

Exploit-Wahrscheinlichkeit (30 Tage)

CVSS Score

8.8

Technische Schwere

Beschreibung

OpenClaw before 2026.3.31 contains a privilege escalation vulnerability allowing paired nodes with role=node to dispatch node.event agent requests with unrestricted gateway-side tool access. Attackers with trusted paired node credentials can escalate privileges by leveraging unrestricted agent.request dispatch to achieve remote code execution on the gateway.

GitHub Advisories

GHSA-gjm7-hw8f-73rqHIGH

OpenClaw: Paired node escalates to gateway RCE via unrestricted node.event agent dispatch

npm/openclaw2026.3.31
GitHub Advisory

Referenzen