Zurück zur CVE-Übersicht
CVE-2026-41378
HIGH(8.8)CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Risk Signal Score22/100 — NIEDRIG
- CVSS 8.8 — Hoch
EPSS-Score
0%
Exploit-Wahrscheinlichkeit (30 Tage)
CVSS Score
8.8
Technische Schwere
Beschreibung
OpenClaw before 2026.3.31 contains a privilege escalation vulnerability allowing paired nodes with role=node to dispatch node.event agent requests with unrestricted gateway-side tool access. Attackers with trusted paired node credentials can escalate privileges by leveraging unrestricted agent.request dispatch to achieve remote code execution on the gateway.
GitHub Advisories
GHSA-gjm7-hw8f-73rqHIGH
OpenClaw: Paired node escalates to gateway RCE via unrestricted node.event agent dispatch
npm/openclaw→ 2026.3.31
GitHub Advisory