PT-2026-26018 · Openclaw · Openclaw

·

CVE-2026-27524

·

Publicado

2026-02-21

·

Atualizado

2026-03-18

CVSS v3.1

4.3

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.2.21
Description OpenClaw versions prior to 2026.2.21 are susceptible to prototype pollution attacks due to accepting prototype-reserved keys in runtime /debug set override object values. Authorized /debug set callers can inject keys such as proto, constructor, or prototype to manipulate object prototypes and bypass command gate restrictions. The /debug functionality is disabled by default, and exploitation requires prior authorization. This issue affects runtime in-memory overrides only, which are not persistent and are cleared upon restart or reset. The API endpoint involved is /debug set. Vulnerable parameters include the override object values. Command gates like bash, config, and debug previously relied on inherited prototype values, which has been addressed by requiring own-property boolean flags.
Recommendations Update OpenClaw to version 2026.2.21 or later.

Exploit

Correção

Prototype Pollution

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2026-05247
CVE-2026-27524
GHSA-62F6-MRCJ-V8H5

Produtos afetados

Openclaw