ended3월 18일· 1 sources
Four Critical CVEs Hit OpenClaw: What You Need to Know (March 2026)
OpenClaw에서 치명적 CVE 4건 발견: 알아야 할 사항 (2026년 3월)
Why it matters
Four security advisories were disclosed for OpenClaw on March 13, 2026, the most severe being a CVSS 9.9 WebSocket privilege escalation that lets any authenticated client gain full admin access. Other vulnerabilities include Feishu webhook forgery (CVSS 8.6), credential exposure via pairing endpoints, and an exec approval bypass. Users who self-host are urged to update to 2026.3.12, rotate gateway credentials, and configure encryptKey for Feishu integrations.
1
Sources
+0
24h
—
Growth
187d
Active
OpenClawCVEWebSocketFeishuCVSS