CVE-2026-25593 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

OpenClaw is a personal AI assistant. Prior to 2026.1.20, an unauthenticated local client could use the Gateway WebSocket API to write config via config.apply an…
High CVSS: 8.4

CVE-2026-25593

OpenClaw is a personal AI assistant. Prior to 2026.1.20, an unauthenticated local client could use the Gateway WebSocket API to write config via config.apply and set unsafe cliPath values that were later used for command discovery, enabling command injection as the gateway user. This vulnerability is fixed in 2026.1.20.
Vendor
Openclaw
Product
Openclaw
CWE
CWE-78
Yayın Tarihi
2026-02-06 21:16:17
Güncelleme
2026-02-13 14:44:08
Source Identifier
security-advisories@github.com
KEV Date Added
-

Kategoriler

Referanslar