ʱ¼ä£º2026-03-11
½üÆÚ£¬£¬£¬£¬£¬£¬OpenClaw ×÷ΪÈÈÃÅµÄ AI ÖÇÄÜÌåÆ½Ì¨£¬£¬£¬£¬£¬£¬×ÊÖúÎÞÊý¿ª·¢ÕßºÍÆóÒµÌáÉýÁËÊÂÇéЧÂÊ¡£¡£¡£¡£¡£È»¶ø£¬£¬£¬£¬£¬£¬Ëæ×Ź¦Ð§µÄ¿ìËÙµü´ú£¬£¬£¬£¬£¬£¬Ò»Ð©Ç徲Σº¦Ò²Ö𽥸¡³öË®Ãæ¡£¡£¡£¡£¡£¹ú¼ÒÐÅÏ¢Çå¾²Îó²îÊý¾Ý¿â£¨NVDB£©ÒÑÊÕ¼Æä¶à¿î¸ßΣÎó²î£»£»£»£»£»GitHub Advisory Database ¸üÊÇÔÚ 2026 Äê 3 Ô¼¯ÖÐÅû¶ÁËÊýÊ®¸ö OpenClaw Ïà¹ØÇå¾²Îó²î£¬£¬£¬£¬£¬£¬º¸ÇÈÏÖ¤ÈÆ¹ý¡¢ÏÂÁî×¢Èë¡¢ÐÅϢй¶¡¢È¨ÏÞԽȨµÈ¶à¸öά¶È£¬£¬£¬£¬£¬£¬Èô¹«ÍøÌ»Â¶µÄʵÀýδʵʱÐÞ¸´£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÖ±½ÓʵÏÖδÊÚȨԶ³Ì´úÂëÖ´ÐУ¬£¬£¬£¬£¬£¬¶ÔÆóÒµºÍСÎÒ˽¼ÒÊý¾ÝÇå¾²¡¢ÏµÍ³ÔËÐÐÔì³ÉÑÏÖØÍþв¡£¡£¡£¡£¡£
Ä¿½ñ OpenClaw µÄÎó²îÆÊÎöÏÔʾ£¬£¬£¬£¬£¬£¬ÆäÇå¾²ÎÊÌâÖ÷Òª¼¯ÖÐÔÚȨÏ޹ܿØÂ߼ȱÏÝ¡¢É³Ïä»úÖÆÈÆ¹ý¡¢ÍøÂç·À»¤²»ÍêÉÆ¡¢ÈÏ֤УÑé²»ÑϽ÷ËÄ´ó·½Ã棬£¬£¬£¬£¬£¬ÇÒ´ó¶¼Îó²îÒò¿ò¼ÜµÄÂþÑÜʽִÐÐÌØÕ÷ºÍ¶àÇþµÀ½»»¥Éè¼Æ±»·Å´ó£¬£¬£¬£¬£¬£¬µÍ°æ±¾ÊµÀýÊÜÓ°ÏìÓÈΪÑÏÖØ¡£¡£¡£¡£¡£±¾ÎĽ«¶Ô OpenClaw ½üÆÚÅû¶µÄ½¹µãÎó²î¾ÙÐÐÊÖÒÕÆÊÎö£¬£¬£¬£¬£¬£¬¸ø³öÕë¶ÔÐԵļӹ̽¨æÅºÍ°æ±¾Éý¼¶Ö¸ÄÏ£¬£¬£¬£¬£¬£¬ÎªÏà¹Ø°²ÅÅ·½ÌṩÇå¾²²Î¿¼¡£¡£¡£¡£¡£


01
¸ßΣÎó²î¾¯Ê¾
±¾´ÎÊáÀíµÄ OpenClaw ¸ßΣÎó²î¹² 5 ¸ö£¨ÓµÓÐ CVE ±àºÅÎó²î 2 ¸ö£©£¬£¬£¬£¬£¬£¬¾ùΪ¿ÉÖ±½ÓʹÓõĸßΣº¦Îó²î£¬£¬£¬£¬£¬£¬ÆäÖÐ 1¸öÒÑ·¢Ã÷ÔÚҰʹÓ㬣¬£¬£¬£¬£¬ÁýÕÖÈÏÖ¤ÁîÅÆÐ¹Â¶¡¢ÏÂÁî×¢Èë¡¢¿çÓòÃô¸ÐÐÅϢת·¢¡¢Íø¹ØÈÏÖ¤ÐÅϢй¶µÈÀàÐÍ£¬£¬£¬£¬£¬£¬CVSS ÆÀ·Ö×î¸ß´ï 8.8 ·Ö¡£¡£¡£¡£¡£
1. OpenClaw ¿çÓòÖØ¶¨ÏòÎó²î(GHSA-6mgf-v5j7-45cr)
Σº¦Æ·¼¶£º¸ßΣ
CVE ±àºÅ£º´ý·ÖÅÉ
CVSS ÆÀ·Ö£º7.5
Îó²îÐÎò£ºOpenClaw µÄ fetch-guard ×é¼þ±£´æÂ߼ȱÏÝ£¬£¬£¬£¬£¬£¬ÔÚ¿çÓòÖØ¶¨ÏòÀú³ÌÖУ¬£¬£¬£¬£¬£¬»á½«×Ô½ç˵µÄÊÚȨÇëÇóÍ·Ö±½Óת·¢ÖÁÖØ¶¨ÏòÄ¿µÄµØµã£¬£¬£¬£¬£¬£¬µ¼ÖÂÊÚȨƾ֤й¶ÖÁ·Ç¿ÉÐÅÓòÃû¡£¡£¡£¡£¡£
Ó°Ïì°æ±¾£º<= 2026.3.2
ÐÞ¸´°æ±¾£º>= 2026.3.7
¹¥»÷³¡¾°£º¹¥»÷Õ߽ṹ¶ñÒâ¿çÓòÖØ¶¨ÏòÁ´½Ó£¬£¬£¬£¬£¬£¬ÓÕµ¼ OpenClaw Õýµ±Óû§»á¼û£¬£¬£¬£¬£¬£¬fetch-guard ÔÚÖØ¶¨Ïòʱ½«Óû§µÄÊÚȨͷת·¢ÖÁ¹¥»÷Õß¿ØÖƵÄЧÀÍÆ÷£¬£¬£¬£¬£¬£¬»ñÈ¡ÊÚȨƾ֤¡£¡£¡£¡£¡£
DZÔÚΣº¦£º¹¥»÷ÕßʹÓÃй¶µÄÊÚȨƾ֤ʵÏÖδÊÚȨ API ŲÓ㬣¬£¬£¬£¬£¬Ö´ÐÐÎļþ²Ù×÷¡¢ÏµÍ³ÏÂÁîµÈÐÐΪ£¬£¬£¬£¬£¬£¬ÇÔÈ¡Óû§Êý¾Ý»ò¿ØÖÆ AI ÊðÀí¡£¡£¡£¡£¡£
ÐÞ¸´½¨Ò飺Éý¼¶ÖÁ OpenClaw 2026.3.7 ¼°ÒÔÉϰ汾£¬£¬£¬£¬£¬£¬¸Ã°æ±¾ÒÑÔöÇ¿ä¯ÀÀÆ÷¶Ë SSRF ·À»¤£¬£¬£¬£¬£¬£¬×赲˽ÓÐÍøÂçµÄÖÐÐÄÖØ¶¨ÏòÌøÔ¾£»£»£»£»£»ÔÚ fetch-guard ×é¼þÖÐÌí¼Ó¿çÓòÖØ¶¨ÏòÊÚȨͷ¹ýÂ˹æÔò£¬£¬£¬£¬£¬£¬½öÔÊÐíÏò¿ÉÐÅÓòÃûת·¢ÊÚȨÐÅÏ¢¡£¡£¡£¡£¡£
2. OpenClaw ÐÅϢй¶Îó²î(GHSA-rchv-x836-w7xp)
Σº¦Æ·¼¶£º¸ßΣ
CVE ±àºÅ£º´ý·ÖÅÉ
CVSS ÆÀ·Ö£º7.1
Îó²îÐÎò£ºOpenClaw µÄÖÎÀíÒDZíÅ̱£´æÐÅϢй¶ȱÏÝ£¬£¬£¬£¬£¬£¬Íø¹ØÈÏÖ¤Ïà¹ØµÄÃô¸ÐÖÊÁÏ»áͨ¹ýä¯ÀÀÆ÷ URL ÅÌÎʲÎÊýºÍ localStorage ÍâµØ´æ´¢¾ÙÐд«ÊäºÍÉúÑÄ£¬£¬£¬£¬£¬£¬Î´×ö¼ÓÃܺÍÍÑÃô´¦Öóͷ£¡£¡£¡£¡£¡£
Ó°Ïì°æ±¾£º<= 2026.3.2
ÐÞ¸´°æ±¾£º>= 2026.3.7
¹¥»÷³¡¾°£º¹¥»÷Õßͨ¹ýÎïÀí½Ó´¥¡¢ä¯ÀÀÆ÷Îó²î»ò¿çÕ¾¾ç±¾¹¥»÷£¨XSS£©£¬£¬£¬£¬£¬£¬»ñȡĿµÄ×°±¸ä¯ÀÀÆ÷µÄ URL ÀúÊ·»ò localStorage Êý¾Ý£¬£¬£¬£¬£¬£¬ÌáÈ¡Íø¹ØÈÏÖ¤ÖÊÁÏ£»£»£»£»£»ÈôΪ¹²Ïí×°±¸£¬£¬£¬£¬£¬£¬¿ÉÖ±½ÓÉó²éä¯ÀÀÆ÷¼Í¼»ñÈ¡ÈÏÖ¤ÐÅÏ¢¡£¡£¡£¡£¡£
DZÔÚΣº¦£º¹¥»÷Õß»ñÈ¡Íø¹ØÈÏÖ¤ÖÊÁϺ󣬣¬£¬£¬£¬£¬¿ÉÖ±½Ó½ÓÊÜ OpenClaw Íø¹Ø£¬£¬£¬£¬£¬£¬¿ØÖÆÕû¸ö AI ÊðÀíϵͳ£¬£¬£¬£¬£¬£¬Ö´ÐÐí§Òâϵͳ¼¶Ê¹Ãü£¬£¬£¬£¬£¬£¬ÇÔÈ¡ÍâµØËùÓÐÊý¾Ý¡£¡£¡£¡£¡£
ÐÞ¸´½¨Ò飺Éý¼¶ÖÁ OpenClaw 2026.3.7 ¼°ÒÔÉϰ汾£¬£¬£¬£¬£¬£¬ÒƳýÈÏÖ¤ÐÅÏ¢ÔÚ URL ÅÌÎʲÎÊýÖеĴ«Êä·½·¨£¬£¬£¬£¬£¬£¬¶Ô localStorage Öд洢µÄÈÏÖ¤ÖÊÁϾÙÐиßÇ¿¶È¼ÓÃÜ£»£»£»£»£»Ìí¼ÓÈÏÖ¤ÐÅÏ¢µÄÓâÆÚ»úÖÆ£¬£¬£¬£¬£¬£¬¶Ìʱ¼äÎÞ²Ù×÷×Ô¶¯É¨³ýÍâµØ´æ´¢µÄÈÏÖ¤Êý¾Ý¡£¡£¡£¡£¡£
3. OpenClaw Ô¶³Ì´úÂëÖ´ÐÐÎó²î(CVE-2026-25253)
Σº¦Æ·¼¶£º¸ßΣ
CVE ±àºÅ£ºCVE-2026-25253
CVSS ÆÀ·Ö£º8.8
Îó²îÐÎò£ºOpenClaw Control UI ±£´æ²ÎÊý´¦Öóͷ£È±ÏÝ£¬£¬£¬£¬£¬£¬½ÓÊÜÅÌÎÊ×Ö·û´®ÖÐµÄ gatewayUrl ²ÎÊý£¬£¬£¬£¬£¬£¬ÇÒÔÚ×Ô¶¯½¨Éè WebSocket ÅþÁ¬Ê±£¬£¬£¬£¬£¬£¬»á½«ÈÏÖ¤ÁîÅÆÖ±½Ó´«ÊäÖÁ¸Ã²ÎÊýÖ¸¶¨µÄµØµã£¬£¬£¬£¬£¬£¬Î´×öÓòÃûУÑé¡£¡£¡£¡£¡£
Ó°Ïì°æ±¾£º< 2026.1.29
ÐÞ¸´°æ±¾£º>= 2026.1.29
¹¥»÷³¡¾°£ºÒÑÔÚҰʹÓ㬣¬£¬£¬£¬£¬¹¥»÷Õ߽ṹ°üÀ¨¶ñÒâ gatewayUrl ²ÎÊýµÄ´¹ÂÚÁ´½Ó£¬£¬£¬£¬£¬£¬ÓÕµ¼ OpenClaw Óû§»á¼û£¬£¬£¬£¬£¬£¬Control UI ½«ÈÏÖ¤ÁîÅÆ´«ÊäÖÁ¹¥»÷Õß¿ØÖÆµÄ WebSocket ЧÀÍÆ÷£¬£¬£¬£¬£¬£¬¹¥»÷ÕßʹÓÃÁîÅÆ½ÓÊÜÊðÀí¡£¡£¡£¡£¡£
DZÔÚΣº¦£ºÖ±½ÓʵÏÖδÊÚȨԶ³Ì´úÂëÖ´ÐУ¬£¬£¬£¬£¬£¬ÒÔ OpenClaw ÔËÐÐȨÏÞÔÚËÞÖ÷»úÖ´ÐÐí§ÒâÏÂÁ£¬£¬£¬£¬£¬ÇÔÈ¡ÍâµØÊý¾Ý¡¢¿ØÖÆ×°±¸²Ù×÷£¬£¬£¬£¬£¬£¬ÉõÖÁºáÏòÉøÍ¸ÖÁÄÚÍøÆäËû×°±¸¡£¡£¡£¡£¡£
ÐÞ¸´½¨Ò飺Á¬Ã¦Éý¼¶ÖÁ 2026.1.29 ¼°ÒÔÉϰ汾£¬£¬£¬£¬£¬£¬Ìí¼Ó gatewayUrl ²ÎÊýµÄ¿ÉÐÅÓòÃû°×Ãûµ¥Ð£Ñ飬£¬£¬£¬£¬£¬½öÔÊÐíÅþÁ¬ÖÁÍâµØ»òÔ¤ÉèÖõĿÉÐÅÍø¹ØµØµã£»£»£»£»£»¶Ô WebSocket ´«ÊäµÄÈÏÖ¤ÁîÅÆ¾ÙÐж˵½¶Ë¼ÓÃÜ£¬£¬£¬£¬£¬£¬±ÜÃâÖÐ;±»ÇÔÈ¡¡£¡£¡£¡£¡£
4. OpenClaw ÏÂÁî×¢ÈëÎó²î(CVE-2026-25157)
Σº¦Æ·¼¶£º¸ßΣ
CVE ±àºÅ£ºCVE-2026-25157
CVSS ÆÀ·Ö£º8.1
Îó²îÐÎò£ºOpenClaw µÄÌØ¶¨ API ¶Ëµã±£´æ²ÎÊýÆÊÎöȱÏÝ£¬£¬£¬£¬£¬£¬Î´¶Ô´«ÈëµÄ²ÎÊý¾ÙÐÐÑÏ¿áµÄ¹ýÂ˺ÍУÑ飬£¬£¬£¬£¬£¬¹¥»÷Õß¿Éͨ¹ý¸Ã¶Ëµã×¢Èëí§ÒâϵͳÏÂÁî¡£¡£¡£¡£¡£
Ó°Ïì°æ±¾£º< 2026.1.29
ÐÞ¸´°æ±¾£º>= 2026.1.29
¹¥»÷³¡¾°£º¹¥»÷ÕßÖ±½ÓÏò±£´æÎó²îµÄ API ¶Ëµã·¢ËͰüÀ¨¶ñÒâÏÂÁîµÄÇëÇ󣬣¬£¬£¬£¬£¬²ÎÊý±»Ö±½ÓÆÊÎöÖ´ÐУ¬£¬£¬£¬£¬£¬ÎÞÐèÌØÁíÍâÉí·ÝУÑé¡£¡£¡£¡£¡£
DZÔÚΣº¦£ºÒÔ OpenClaw ÔËÐÐȨÏÞÔÚËÞÖ÷»úÖ´ÐÐí§ÒâϵͳÏÂÁ£¬£¬£¬£¬£¬ÊµÏÖÎļþ¶ÁÈ¡¡¢Ð´È롢ɾ³ý£¬£¬£¬£¬£¬£¬ÉõÖÁ¿ØÖÆ×°±¸²Ù×÷£¬£¬£¬£¬£¬£¬ÈôΪЧÀÍÆ÷°²ÅÅ£¬£¬£¬£¬£¬£¬¿É»ñȡЧÀÍÆ÷ȨÏÞ¡£¡£¡£¡£¡£
ÐÞ¸´½¨Ò飺Á¬Ã¦Éý¼¶ÖÁ 2026.1.29 ¼°ÒÔÉϰ汾£¬£¬£¬£¬£¬£¬¶ÔËùÓÐ API ¶ËµãµÄ´«Èë²ÎÊý¾ÙÐÐÑÏ¿áµÄ¹ýÂ˺ÍתÒ壬£¬£¬£¬£¬£¬Õ¥È¡°üÀ¨ÏµÍ³ÏÂÁîµÄÌØÊâ×Ö·û£»£»£»£»£»Ìí¼Ó API ¶ËµãµÄ»á¼û°×Ãûµ¥£¬£¬£¬£¬£¬£¬½öÔÊÔÊÐíÐÅ IP ºÍÓû§»á¼û¡£¡£¡£¡£¡£
5. OpenClaw ÏÂÁî×¢ÈëÎó²î(CVE-2026-24763)
Σº¦Æ·¼¶£º¸ßΣ
CVE ±àºÅ£ºCVE-2026-24763
CVSS ÆÀ·Ö£º7.8
Îó²îÐÎò£ºOpenClaw µÄ²å¼þÖ´Ðнӿڱ£´æÉ³Ïä»úÖÆÈÆ¹ýȱÏÝ£¬£¬£¬£¬£¬£¬¶ñÒâ²å¼þ¿ÉÍ»ÆÆÉ³ÏäÏÞÖÆ£¬£¬£¬£¬£¬£¬Ö±½ÓÏò½Ó¿Ú×¢Èëí§ÒâϵͳÏÂÁ£¬£¬£¬£¬£¬ÇÒÏÂÁî¿É±»Ö±½ÓÖ´ÐС£¡£¡£¡£¡£
Ó°Ïì°æ±¾£º< 2026.1.29
ÐÞ¸´°æ±¾£º>= 2026.1.29
¹¥»÷³¡¾°£º¹¥»÷Õß¿ª·¢°üÀ¨¶ñÒâÏÂÁî×¢Èë´úÂëµÄ²å¼þ£¬£¬£¬£¬£¬£¬ÓÕµ¼Óû§×°Ö㬣¬£¬£¬£¬£¬²å¼þͨ¹ýÖ´ÐнӿÚÍ»ÆÆÉ³ÏäÏÞÖÆ£¬£¬£¬£¬£¬£¬Ö´ÐжñÒâϵͳÏÂÁî¡£¡£¡£¡£¡£
DZÔÚΣº¦£ºÈƹýɳÏä¸ôÀ룬£¬£¬£¬£¬£¬Ö´ÐÐí§ÒâϵͳÏÂÁ£¬£¬£¬£¬£¬ÇÔÈ¡ÍâµØÊý¾Ý¡¢ÐÞ¸ÄϵͳÉèÖ㬣¬£¬£¬£¬£¬ÉõÖÁÖ²Èë¶ñÒâ³ÌÐò£¬£¬£¬£¬£¬£¬¶Ô×°±¸Ôì³ÉÓÀÊÀÐÔÆÆË𡣡£¡£¡£¡£
ÐÞ¸´½¨Ò飺Á¬Ã¦Éý¼¶ÖÁ 2026.1.29 ¼°ÒÔÉϰ汾£¬£¬£¬£¬£¬£¬ÔöÇ¿²å¼þÖ´ÐнӿڵÄɳÏä·À»¤»úÖÆ£¬£¬£¬£¬£¬£¬Õ¥È¡²å¼þÖ±½ÓŲÓÃϵͳÏÂÁ£»£»£»£»¶ÔµÚÈý·½²å¼þ¾ÙÐÐÑÏ¿áµÄÇå¾²ÉóºË£¬£¬£¬£¬£¬£¬Ìí¼Ó²å¼þ´úÂëµÄ¾²Ì¬É¨ÃèºÍ¶¯Ì¬¼ì²â¡£¡£¡£¡£¡£
02
ÖÐΣÎó²î»ã×Ü
GitHub ÔÚ 2026 Äê 3 Ô 9 ÈÕ×îÐÂÅû¶µÄÎó²îÖУ¬£¬£¬£¬£¬£¬ÓÐ 8 ¸ö¾ùΪÖÐΣÎó²î£¬£¬£¬£¬£¬£¬Ö÷Òª¼¯ÖÐÔÚ system.run ×é¼þȨÏ޹ܿØÈ±ÏÝ¡¢ACP »á»°³õʼ»¯Âß¼ÎÊÌâ¡¢ÈÏÖ¤ËøÖ¹¹æÔòÊ詵ȷ½Ã棬£¬£¬£¬£¬£¬Ó°Ïì OpenClaw ×îа汾֮ǰµÄ npm ¿¯Ðа棬£¬£¬£¬£¬£¬ÐÞ¸´°æ±¾¾ùΪ 2026.3.7¡£¡£¡£¡£¡£Í¬Ê±ÔÚ 2026 Äê 2 Ô 4 ÈÕÅû¶µÄÎó²îÖУ¬£¬£¬£¬£¬£¬ÖÐΣÎó²î£¨CVE-2026-25475£©ÒÑ·¢Ã÷ÔÚҰʹÓ㬣¬£¬£¬£¬£¬ÐèÒªÖØµã¹Ø×¢¡£¡£¡£¡£¡£ 9 ÆäÖÐΣÎó²îµÄ½¹µãÐÅÏ¢ÊáÀí£º
1. OpenClaw µ±ÌïÖ÷»úÐÅÍÐÈÆ¹ýÎó²î(CVE-2026-25475)
Σº¦Æ·¼¶£ºÖÐΣ£¨¸ßΣʹÓÃΣº¦£©
CVE ±àºÅ£ºCVE-2026-25475
CVSS ÆÀ·Ö£º6.5
Îó²îÐÎò£ºOpenClaw ±£´æÈÏÖ¤Â߼ȱÏÝ£¬£¬£¬£¬£¬£¬¹ýʧµØ½«ËùÓÐÀ´×ÔlocalhostµÄÅþÁ¬ÊÓΪ¿ÉÐÅȪԴ£¬£¬£¬£¬£¬£¬Î´×öÌØÁíÍâÉí·ÝУÑ飬£¬£¬£¬£¬£¬±£´æÐÅÍнçÏßÈÆ¹ýÎÊÌâ¡£¡£¡£¡£¡£
Ó°Ïì°æ±¾£º<= 2026.1.30
ÐÞ¸´°æ±¾£º>= 2026.2.01
¹¥»÷³¡¾°£ºÒÑÔÚҰʹÓ㬣¬£¬£¬£¬£¬¹¥»÷Õß¿ØÖÆÄ¿µÄÉè±¹ØÁ¬Ä¶ñÒâÍøÕ¾£¬£¬£¬£¬£¬£¬Í¨¹ý JavaScript ÔÚÍâµØÌᳫ WebSocket ÅþÁ¬£¬£¬£¬£¬£¬£¬Ê¹ÓÃlocalhostµÄ¿ÉÐÅÊôÐÔÈÆ¹ý OpenClaw µÄÈÏÖ¤»úÖÆ£¬£¬£¬£¬£¬£¬ÊµÏÖδÊÚȨ»á¼û¡£¡£¡£¡£¡£
DZÔÚΣº¦£ºÈƹýÈÏÖ¤ºóÖ´ÐÐδÊÚȨ²Ù×÷£¬£¬£¬£¬£¬£¬°üÀ¨Îļþ¶ÁÈ¡¡¢ÏµÍ³ÏÂÁîŲÓõȣ¬£¬£¬£¬£¬£¬ÈôΪЧÀÍÆ÷¶Ë°²ÅÅ£¬£¬£¬£¬£¬£¬¿É½øÒ»²½Ê¹ÓøÃÎó²î»ñȡЧÀÍÆ÷ȨÏÞ¡£¡£¡£¡£¡£
ÐÞ¸´½¨Ò飺Á¬Ã¦Éý¼¶ÖÁ 2026.2.01 ¼°ÒÔÉϰ汾£¬£¬£¬£¬£¬£¬×÷·Ï¶ÔlocalhostÅþÁ¬µÄÎÞÌõ¼þÐÅÍУ¬£¬£¬£¬£¬£¬ÎªÍâµØÅþÁ¬Ìí¼ÓÌØÁíÍâÉí·ÝУÑé»úÖÆ£»£»£»£»£»ÏÞÖÆä¯ÀÀÆ÷¶Ë JavaScript ¶Ô OpenClaw ÍâµØÍø¹ØµÄŲÓÃȨÏÞ¡£¡£¡£¡£¡£
2. ɳÏä ACP ÇëÇó³õʼ»¯Ö÷ʱ»ú»°(GHSA-9q36-67vc-rrwg)
Σº¦Æ·¼¶£ºÖÐΣ
CVE ±àºÅ£º´ý·ÖÅÉ
CVSS ÆÀ·Ö£º5.9
Îó²îÐÎò£ºÉ³ÏäÇéÐÎÏ嵀 /acp ÌìÉúÇëÇó¿ÉÈÆ¹ýɳÏäÏÞÖÆ£¬£¬£¬£¬£¬£¬Ö±½Ó³õʼ»¯Ö÷»ú¶ËµÄ ACP »á»°£¬£¬£¬£¬£¬£¬Í»ÆÆÉ³Ïä¸ôÀë½çÏß¡£¡£¡£¡£¡£
Ó°Ïì°æ±¾£º<= 2026.3.2
ÐÞ¸´°æ±¾£º>= 2026.3.7
¹¥»÷³¡¾°£º¹¥»÷ÕßÔÚɳÏäÖнṹ¶ñÒâ /acp ÌìÉúÇëÇ󣬣¬£¬£¬£¬£¬´¥·¢Ö÷»ú ACP »á»°³õʼ»¯£¬£¬£¬£¬£¬£¬»ñÈ¡Ö÷»ú¶ËµÄ ACP ²Ù×÷ȨÏÞ¡£¡£¡£¡£¡£
DZÔÚΣº¦£ºÍ»ÆÆÉ³Ïä¸ôÀ룬£¬£¬£¬£¬£¬ÔÚÖ÷»ú¶ËÖ´ÐÐ ACP Ïà¹Ø²Ù×÷£¬£¬£¬£¬£¬£¬ÊµÏÖȨÏÞÌáÉý£¬£¬£¬£¬£¬£¬½øÒ»³ÌÐòÓÃϵͳ×ÊÔ´¡£¡£¡£¡£¡£
ÐÞ¸´½¨Ò飺Éý¼¶ÖÁ OpenClaw 2026.3.7 ¼°ÒÔÉϰ汾¡£¡£¡£¡£¡£
3. system.run ³¤ÆÚ»¯°üÀ¨ shell ×¢ÊÍÔØºÉβ(GHSA-9q2p-vc84-2rwm)
Σº¦Æ·¼¶£ºÖÐΣ
CVE ±àºÅ£º´ý·ÖÅÉ
CVSS ÆÀ·Ö£º5.0
Îó²îÐÎò£ºsystem.run µÄ allow-always ³¤ÆÚ»¯»úÖÆ±£´æÆÊÎöȱÏÝ£¬£¬£¬£¬£¬£¬»á½«°üÀ¨ shell ×¢Ê͵ÄÔØºÉβ±£´æ²¢Ö´ÐУ¬£¬£¬£¬£¬£¬ÈƹýÏÂÁîУÑé¡£¡£¡£¡£¡£
Ó°Ïì°æ±¾£º<= 2026.3.2
ÐÞ¸´°æ±¾£º>= 2026.3.7
¹¥»÷³¡¾°£º¹¥»÷Õ߽ṹ°üÀ¨ shell ×¢Ê͵ĶñÒâÏÂÁ£¬£¬£¬£¬£¬Ê¹Óà allow-always »úÖÆÊµÏÖÏÂÁÆÚ»¯£¬£¬£¬£¬£¬£¬×¢ÊͲ¿·Ö±»ÆÊÎöÖ´ÐС£¡£¡£¡£¡£
DZÔÚΣº¦£ºÈƹý system.run µÄÏÂÁîУÑ飬£¬£¬£¬£¬£¬Ö´ÐÐδÊÚȨµÄ shell ÏÂÁ£¬£¬£¬£¬£¬ÊµÏÖÎļþ²Ù×÷»òϵͳ¿ØÖÆ¡£¡£¡£¡£¡£
ÐÞ¸´½¨Ò飺Éý¼¶ÖÁ OpenClaw 2026.3.7 ¼°ÒÔÉϰ汾¡£¡£¡£¡£¡£
4. operator.write ԽȨдÈëÖÎÀíÔ±ÉèÖÃ(GHSA-hfpr-jhpq-x4rm)
Σº¦Æ·¼¶£ºÖÐΣ
CVE ±àºÅ£º´ý·ÖÅÉ
CVSS ÆÀ·Ö£º4.3
Îó²îÐÎò£ºoperator.writeµÄ chat.send ½Ó¿Ú±£´æÈ¨Ï޹ܿØÈ±ÏÝ£¬£¬£¬£¬£¬£¬Í¨Ë×Óû§¿Éͨ¹ý¸Ã½Ó¿ÚÏòÖÎÀíԱרÊôÉèÖÃÏîдÈëÊý¾Ý£¬£¬£¬£¬£¬£¬ÊµÏÖȨÏÞԽȨ¡£¡£¡£¡£¡£
Ó°Ïì°æ±¾£º<= 2026.3.2
ÐÞ¸´°æ±¾£º>= 2026.3.7
¹¥»÷³¡¾°£ºÍ¨Ë×Óû§½á¹¹ÌØÊâµÄ chat.send ÇëÇ󣬣¬£¬£¬£¬£¬Ö¸¶¨ÖÎÀíԱרÊôÉèÖüüÖµ£¬£¬£¬£¬£¬£¬ÊµÏÖԽȨÉèÖÃÐ޸ġ£¡£¡£¡£¡£
DZÔÚΣº¦£º¸Ä¶¯ÖÎÀíÔ±ÉèÖ㬣¬£¬£¬£¬£¬°üÀ¨È¨ÏÞ¹æÔò¡¢°×Ãûµ¥¡¢É³ÏäÏÞÖÆµÈ£¬£¬£¬£¬£¬£¬½øÒ»²½ÊµÏÖδÊÚȨ²Ù×÷¡£¡£¡£¡£¡£
ÐÞ¸´½¨Ò飺Éý¼¶ÖÁ OpenClaw 2026.3.7 ¼°ÒÔÉϰ汾¡£¡£¡£¡£¡£
5. system.run °ü×°Éî¶È½çÏßÈÆ¹ý shell ÉóÅú(GHSA-r6qf-8968-wj9q)
Σº¦Æ·¼¶£ºÖÐΣ
CVE ±àºÅ£º´ý·ÖÅÉ
CVSS ÆÀ·Ö£º5.0
Îó²îÐÎò£ºsystem.run µÄ wrapper-depth ½çÏßУÑé±£´æÂß¼Êè©£¬£¬£¬£¬£¬£¬µ±°ü×°Éî¶ÈÁè¼ÝãÐֵʱ£¬£¬£¬£¬£¬£¬»áÖ±½ÓÌø¹ý shell ÏÂÁîµÄÉóÅúÃſء£¡£¡£¡£¡£
Ó°Ïì°æ±¾£º<= 2026.3.2
ÐÞ¸´°æ±¾£º>= 2026.3.7
¹¥»÷³¡¾°£º¹¥»÷Õ߽ṹ¶à²ãǶÌ׵İü×°ÏÂÁ£¬£¬£¬£¬£¬Í»ÆÆ wrapper-depth ãÐÖµ£¬£¬£¬£¬£¬£¬Èƹý shell ÉóÅúÖ´ÐжñÒâÏÂÁî¡£¡£¡£¡£¡£
DZÔÚΣº¦£ºÈƹýϵͳµÄÏÂÁîÉóÅú»úÖÆ£¬£¬£¬£¬£¬£¬Ö´ÐÐδÊÚȨ shell ÏÂÁ£¬£¬£¬£¬£¬ÇÔÈ¡Êý¾Ý»ò¿ØÖÆÏµÍ³¡£¡£¡£¡£¡£
ÐÞ¸´½¨Ò飺Éý¼¶ÖÁ OpenClaw 2026.3.7 ¼°ÒÔÉϰ汾¡£¡£¡£¡£¡£
6. ¿çÕË»§·¢ËÍÕßÊÚȨÀ©Õ¹(GHSA-pjvx-rx66-r3fg)
Σº¦Æ·¼¶£ºÖÐΣ
CVE ±àºÅ£º´ý·ÖÅÉ
CVSS ÆÀ·Ö£º5.4
Îó²îÐÎò£º/allowlist µÄ --store ²ÎÊýÔÚÕË»§¹æÄ£»®·Öʱ±£´æÈ±ÏÝ£¬£¬£¬£¬£¬£¬¿ÉʵÏÖ¿çÕË»§µÄ·¢ËÍÕßÊÚȨÀ©Õ¹£¬£¬£¬£¬£¬£¬Í»ÆÆÕË»§¸ôÀë¡£¡£¡£¡£¡£
Ó°Ïì°æ±¾£º<= 2026.3.2
ÐÞ¸´°æ±¾£º>= 2026.3.7
¹¥»÷³¡¾°£º¹¥»÷ÕßʹÓà --store ²ÎÊýµÄÂ߼ȱÏÝ£¬£¬£¬£¬£¬£¬½«×ÔÉíµÄ·¢ËÍÕßȨÏÞÀ©Õ¹ÖÁÆäËûÕË»§£¬£¬£¬£¬£¬£¬»ñÈ¡¿çÕË»§µÄ²Ù×÷ȨÏÞ¡£¡£¡£¡£¡£
DZÔÚΣº¦£ºÍ»ÆÆÕË»§¸ôÀë½çÏߣ¬£¬£¬£¬£¬£¬»á¼ûÆäËûÕË»§µÄ×ÊÔ´¡¢Ö´ÐпçÕË»§²Ù×÷£¬£¬£¬£¬£¬£¬ÇÔÈ¡¶àÕË»§Êý¾Ý¡£¡£¡£¡£¡£
ÐÞ¸´½¨Ò飺Éý¼¶ÖÁ OpenClaw 2026.3.7 ¼°ÒÔÉϰ汾¡£¡£¡£¡£¡£
7. system.run °×Ãûµ¥Â©¼ì PowerShell ±àÂëÏÂÁî(GHSA-3h2q-j2v4-6w5r)
Σº¦Æ·¼¶£ºÖÐΣ
CVE ±àºÅ£º´ý·ÖÅÉ
CVSS ÆÀ·Ö£º5.0
Îó²îÐÎò£ºsystem.run µÄ°×Ãûµ¥ÉóÅúÆÊÎö»úÖÆÎ´¶Ô PowerShell µÄ±àÂëÏÂÁî°ü×°¾ÙÐÐУÑ飬£¬£¬£¬£¬£¬Â©¼ì¶ñÒâ±àÂëÏÂÁî¡£¡£¡£¡£¡£
Ó°Ïì°æ±¾£º<= 2026.3.2
ÐÞ¸´°æ±¾£º>= 2026.3.7
¹¥»÷³¡¾°£º¹¥»÷Õß½«¶ñÒâÏÂÁî¾ÙÐÐ PowerShell ±àÂë°ü×°£¬£¬£¬£¬£¬£¬Èƹý°×Ãûµ¥ÉóÅú£¬£¬£¬£¬£¬£¬Ö´ÐÐδÊÚȨ²Ù×÷¡£¡£¡£¡£¡£
DZÔÚΣº¦£ºÈƹýÏÂÁî°×Ãûµ¥£¬£¬£¬£¬£¬£¬Ö´ÐÐ PowerShell ¶ñÒâ±àÂëÏÂÁ£¬£¬£¬£¬£¬ÊµÏÖϵͳ¿ØÖƺÍÊý¾ÝÇÔÈ¡¡£¡£¡£¡£¡£
ÐÞ¸´½¨Ò飺Éý¼¶ÖÁ OpenClaw 2026.3.7 ¼°ÒÔÉϰ汾¡£¡£¡£¡£¡£
8. system.run ÇéÐÎÁýÕÖ¹ýÂËÔÊÐíΣÏÕÏÂÁîÖ§µã(GHSA-j425-whc4-4jgc)
Σº¦Æ·¼¶£ºÖÐΣ
CVE ±àºÅ£º´ý·ÖÅÉ
CVSS ÆÀ·Ö£º6.3
Îó²îÐÎò£ºsystem.run µÄÇéÐαäÁ¿ÁýÕÖ¹ýÂË»úÖÆ±£´æÈ±ÏÝ£¬£¬£¬£¬£¬£¬ÔÊÐí¹¥»÷Õ߽ṹΣÏյĸ¨ÖúÏÂÁîÖ§µã£¬£¬£¬£¬£¬£¬ÊµÏÖÏÂÁî×¢Èë¡£¡£¡£¡£¡£
Ó°Ïì°æ±¾£º<= 2026.3.2
ÐÞ¸´°æ±¾£º>= 2026.3.7
¹¥»÷³¡¾°£º¹¥»÷Õßͨ¹ýÇéÐαäÁ¿ÁýÕÖ£¬£¬£¬£¬£¬£¬½á¹¹¸¨ÖúÏÂÁîÖ§µã£¬£¬£¬£¬£¬£¬½øÒ»²½×¢Èë¶ñÒâϵͳÏÂÁî¡£¡£¡£¡£¡£
DZÔÚΣº¦£ºÊµÏÖÏÂÁî×¢È룬£¬£¬£¬£¬£¬ÒÔ OpenClaw ȨÏÞÖ´ÐÐí§ÒâϵͳÏÂÁ£¬£¬£¬£¬£¬ÆÆËðϵͳÇéÐλòÇÔÈ¡Êý¾Ý¡£¡£¡£¡£¡£
ÐÞ¸´½¨Ò飺Éý¼¶ÖÁ OpenClaw 2026.3.7 ¼°ÒÔÉϰ汾¡£¡£¡£¡£¡£
9. ¹³×Ó½«·Ç POST ÇëÇó¼ÆÈëÈÏÖ¤ËøÖ¹(GHSA-6rmx-gvvg-vh6j)
Σº¦Æ·¼¶£ºÖÐΣ
CVE ±àºÅ£º´ý·ÖÅÉ
CVSS ÆÀ·Ö£º5.3
Îó²îÐÎò£ºOpenClaw µÄ¹³×Ó×é¼þ±£´æ¹æÔòÊè©£¬£¬£¬£¬£¬£¬½«·Ç POST ÇëÇóÒ²¼ÆÈëÈÏ֤ʧ°Ü´ÎÊý£¬£¬£¬£¬£¬£¬´¥·¢²»ÐëÒªµÄÈÏÖ¤ËøÖ¹¡£¡£¡£¡£¡£
Ó°Ïì°æ±¾£º<= 2026.3.2
ÐÞ¸´°æ±¾£º>= 2026.3.7
¹¥»÷³¡¾°£º¹¥»÷Õß·¢ËÍ´ó×Ú·Ç POST ÇëÇ󣬣¬£¬£¬£¬£¬´¥·¢ÈÏÖ¤ËøÖ¹»úÖÆ£¬£¬£¬£¬£¬£¬µ¼ÖÂÕýµ±Óû§ÎÞ·¨Õý³£»á¼û¡£¡£¡£¡£¡£
DZÔÚΣº¦£ºÔì³É¾Ü¾øÐ§ÀÍ£¨DoS£©£¬£¬£¬£¬£¬£¬Õýµ±Óû§ÎÞ·¨Õý³£Ê¹Óà OpenClaw µÄ¹¦Ð§£¬£¬£¬£¬£¬£¬Ó°ÏìÓªÒµÔËÐС£¡£¡£¡£¡£
ÐÞ¸´½¨Ò飺Éý¼¶ÖÁ OpenClaw 2026.3.7 ¼°ÒÔÉϰ汾¡£¡£¡£¡£¡£
03
Çå¾²¼Ó¹Ì½¨Òé
OpenClaw µÄÎó²îÐÞ¸´°æ±¾Ö÷Òª·ÖΪ2026.1.29¡¢2026.2.01¡¢2026.3.8-beta.1Èý¸ö½¹µã°æ±¾£¬£¬£¬£¬£¬£¬»®·Ö¶ÔÓ¦²î±ðµÄÎó²îÐÞ¸´¹æÄ££¬£¬£¬£¬£¬£¬°²ÅÅ·½¿Éƾ֤Ŀ½ñ°æ±¾Ñ¡Ôñ¶ÔÓ¦µÄÉý¼¶Â·¾¶£¬£¬£¬£¬£¬£¬Éý¼¶Àú³ÌÖÐÐè×¢ÖØÊý¾Ý±¸·ÝºÍ¼æÈÝÐÔÑéÖ¤¡£¡£¡£¡£¡£
?Éý¼¶Â·¾¶»®·Ö
Ä¿½ñ°æ±¾ < 2026.1.29£ºÓÅÏÈÉý¼¶ÖÁ2026.1.29£¬£¬£¬£¬£¬£¬ÐÞ¸´ 3 ¸ö ¾ßÓÐ CVE ±àºÅµÄ¸ßΣÎó²î£¨º¬ 1 ¸öÔÚҰʹÓÃÎó²î£©£¬£¬£¬£¬£¬£¬ÕâÊÇ×î½ôÆÈµÄÉý¼¶°ì·¨£¬£¬£¬£¬£¬£¬Éý¼¶ºó¿É·ÀÓùÔ¶³Ì´úÂëÖ´ÐС¢ÏÂÁî×¢ÈëµÈ½¹µã¹¥»÷£»£»£»£»£»ÈôΪ npm °æ±¾£¬£¬£¬£¬£¬£¬¿É¼ÌÐøÉý¼¶ÖÁ 2026.3.8-beta.1£¬£¬£¬£¬£¬£¬ÐÞ¸´ÏÖÔÚ GitHub Åû¶µÄËùÓÐÖиßΣÎó²î¡£¡£¡£¡£¡£
2026.1.29 <= Ä¿½ñ°æ±¾ < 2026.2.01£ºÉý¼¶ÖÁ2026.2.01£¬£¬£¬£¬£¬£¬ÐÞ¸´µ±ÌïÖ÷»úÐÅÍÐÈÆ¹ýÎó²î£¨CVE-2026-25475£©£¬£¬£¬£¬£¬£¬¸Ã°æ±¾Îª 2026.1.29 µÄС·ùÇå¾²²¹¶¡£¡£¡£¡£¡£¬£¬£¬£¬£¬£¬¼æÈÝÐÔÎÞÓ°Ïì¡£¡£¡£¡£¡£
2026.2.01 <= Ä¿½ñ°æ±¾ < 2026.3.8-beta.1£ºÉý¼¶ÖÁ2026.3.8-beta.1£¬£¬£¬£¬£¬£¬ÐÞ¸´ GitHub ÔÚÄ¿½ñÅû¶µÄËùÓÐÎó²î£¬£¬£¬£¬£¬£¬°üÀ¨ÐÅϢй¶¡¢È¨ÏÞԽȨ¡¢É³ÏäÈÆ¹ýµÈ£¬£¬£¬£¬£¬£¬¸Ã°æ±¾ÐÂÔöÁËÍâµØ±¸·Ý¡¢SSRF ·À»¤µÈÇå¾²¹¦Ð§¡£¡£¡£¡£¡£
04
½¹µã¶´¼û
±¾´ÎÆÊÎöµÄ OpenClaw 14 ¸ö½¹µãÎó²î£¬£¬£¬£¬£¬£¬ÁýÕÖÈÏÖ¤¡¢È¨ÏÞ¡¢É³Ïä¡¢ÍøÂç¡¢²å¼þÎå´ó½¹µãÄ£¿£¿£¿£¿£¿£¿£¿é£¬£¬£¬£¬£¬£¬ÆäȪԴÖ÷ÒªÔÚÓÚÏîÄ¿¿ìËÙµü´úÀú³ÌÖУ¬£¬£¬£¬£¬£¬Çå¾²¿ª·¢Á÷³Ìδʵʱ¸ú½ø£¬£¬£¬£¬£¬£¬µ¼ÖÂȨÏ޹ܿØÂ߼ȱÏÝ¡¢·À»¤»úÖÆ²»ÍêÉÆ¡¢²ÎÊýУÑé²»ÑÏ¿áµÈÎÊÌ⼯ÖÐ̻¶¡£¡£¡£¡£¡£ÆäÖÐ 4 ¸öÒÑ·ÖÅÉ CVE ±àºÅµÄÎó²îÖУ¬£¬£¬£¬£¬£¬2 ¸öÒÑ·¢Ã÷ÔÚҰʹÓ㬣¬£¬£¬£¬£¬ÇÒ¿ÉÖ±½ÓʵÏÖÔ¶³Ì´úÂëÖ´ÐУ¬£¬£¬£¬£¬£¬¶ÔµÍ°æ±¾°²ÅÅʵÀýÔì³ÉÑÏÖØÍþв£»£»£»£»£»GitHub Åû¶µÄÎó²îÔòÖ÷ÒªÓ°Ïì×îа汾֮ǰµÄ npm ¿¯Ðа棬£¬£¬£¬£¬£¬ÒÔÖÐΣΪÖ÷£¬£¬£¬£¬£¬£¬µ«¿É±»¹¥»÷ÕßʹÓÃʵÏÖȨÏÞÌáÉýºÍÊý¾ÝÇÔÈ¡¡£¡£¡£¡£¡£
´ÓÎó²îÌØµãÀ´¿´£¬£¬£¬£¬£¬£¬OpenClaw µÄÂþÑÜʽִÐÐÌØÕ÷¡¢¶àÇþµÀ½»»¥Éè¼Æ¡¢ÍâµØÓÅÏȵÄÔËÐлúÖÆ·Å´óÁËÇå¾²ÎÊÌâµÄÓ°Ïì£ºÍø¹Ø×÷Ϊ½¹µãÊàŦ£¬£¬£¬£¬£¬£¬ÆäÈÏÖ¤ÐÅϢй¶¿ÉÖ±½Óµ¼ÖÂÕû¸öϵͳ±»¿ØÖÆ£»£»£»£»£»É³Ïä»úÖÆµÄ²»ÍêÉÆÔòÈù¥»÷ÕßÄÜÍ»ÆÆ¸ôÀ룬£¬£¬£¬£¬£¬Ö±½Ó»á¼ûÖ÷»ú×ÊÔ´£»£»£»£»£»¶àÇþµÀµÄ½»»¥·½·¨ÔòÔöÌíÁË´¹ÂÚ¹¥»÷¡¢¿çÓò¹¥»÷µÄ¿ÉÄÜÐÔ¡£¡£¡£¡£¡£
05
×ۺϴ¦Öóͷ£½¨Òé
?½ôÆÈÐÞ¸´£¬£¬£¬£¬£¬£¬·Ö¼¶´¦Öóͷ££ºËùÓÐ OpenClaw °²ÅÅ·½ÐèÁ¬Ã¦¿ªÕ¹°æ±¾ºË²é£¬£¬£¬£¬£¬£¬¶ÔµÍÓÚ 2026.1.29 µÄʵÀý¾ÙÐнôÆÈÉý¼¶£¬£¬£¬£¬£¬£¬ÕâÊÇ·ÀÓùÔÚҰʹÓÃÎó²îµÄÒªº¦£»£»£»£»£»¶ÔÆäËû°æ±¾µÄʵÀý£¬£¬£¬£¬£¬£¬Æ¾Ö¤Éý¼¶Ö¸ÄÏÖð²½Éý¼¶ÖÁ×îÐÂÐÞ¸´°æ±¾£¬£¬£¬£¬£¬£¬×öµ½¸ßΣÎó²îÓÅÏÈÐÞ¸´¡¢ÖÐΣÎó²îʵʱÐÞ¸´¡£¡£¡£¡£¡£
?×óÒÆÇå¾²£¬£¬£¬£¬£¬£¬Ç¿»¯ÉèÖãºÆóÒµ¼¶°²ÅÅ·½Ð轫Çå¾²ÈÚÈë OpenClaw µÄÈ«ÉúÃüÖÜÆÚÖÎÀí£¬£¬£¬£¬£¬£¬ÔÚ°²ÅŽ׶ξͿªÆôÑÏ¿áµÄ»á¼û¿ØÖÆ¡¢ÉèÖÃÇå¾²¹æÔò£¬£¬£¬£¬£¬£¬×èÖ¹Íø¹Ø¹«ÍøÌ»Â¶¡¢È¨ÏÞÌ«¹ý¿ª·ÅµÈÎÊÌ⣻£»£»£»£»Ð¡ÎÒ˽¼ÒÓû§ÐèÔöÇ¿ÍâµØ×°±¸µÄÇå¾²·À»¤£¬£¬£¬£¬£¬£¬×èÖ¹×°ÖÃδÉóºËµÄµÚÈý·½²å¼þ£¬£¬£¬£¬£¬£¬²»ËæÒâµã»÷ÉúÊèÁ´½Ó¡£¡£¡£¡£¡£
?¹Ø×¢¹Ù·½£¬£¬£¬£¬£¬£¬ÊµÊ±¼à¿Ø£ºÒ»Á¬¹Ø×¢ OpenClaw ¹Ù·½µÄÇ徲ͨ¸æºÍÎó²îÅû¶ÐÅÏ¢£¬£¬£¬£¬£¬£¬ÊµÊ±ÐÞ¸´Ð·¢Ã÷µÄÇå¾²Îó²î£»£»£»£»£»½¨É賣̬»¯µÄÎó²îɨÃèºÍÈÕÖ¾¼à¿Ø»úÖÆ£¬£¬£¬£¬£¬£¬ÊµÏÖ¹¥»÷ÐÐΪµÄÔç·¢Ã÷¡¢ÔçÔ¤¾¯¡¢Ôç´¦Öóͷ£¡£¡£¡£¡£¡£
?ÉçÇøÐͬ£¬£¬£¬£¬£¬£¬ÍêÉÆÉú̬£ºOpenClaw ×÷Ϊ¿ªÔ´ÏîÄ¿£¬£¬£¬£¬£¬£¬ÆäÇå¾²Éú̬µÄÍêÉÆÐèÒªÉçÇøµÄÅäºÏ¼ÓÈ룬£¬£¬£¬£¬£¬½¨Ò鿪·¢ÕßÔÚТ˳´úÂëʱ¼ÓÈëÇå¾²¼ì²â»·½Ú£¬£¬£¬£¬£¬£¬¹Ù·½ÐèÔöÇ¿µÚÈý·½²å¼þµÄÇå¾²ÉóºË£¬£¬£¬£¬£¬£¬ÍƳöÇå¾²¿ª·¢¹æ·¶£¬£¬£¬£¬£¬£¬´ÓÔ´Í·ïÔÌÎó²îµÄ±¬·¢¡£¡£¡£¡£¡£
06
½áÓï
OpenClaw ×÷ΪÇ㸲ʽµÄ AI ÖÇÄÜÌå¿ò¼Ü£¬£¬£¬£¬£¬£¬ÆäÁ¢ÒìµÄÊÖÒռܹ¹ºÍʹÓÃÌåÑéΪ¿ª·¢Õß´øÀ´ÁËȫеĿÉÄÜ£¬£¬£¬£¬£¬£¬µ«Çå¾²ÊÇÊÖÒÕÂ䵨µÄÌõ¼þ¡£¡£¡£¡£¡£±¾´Î¼¯ÖÐ̻¶µÄÎó²îΪËùÓпªÔ´ÏîÄ¿ÇÃÏìÁ˾¯ÖÓ£ºÔÚ¿ìËÙµü´úºÍ¹¦Ð§Á¢ÒìµÄͬʱ£¬£¬£¬£¬£¬£¬±ØÐèÖØÊÓÇå¾²¿ª·¢ºÍ·À»¤»úÖÆµÄ½¨Éè¡£¡£¡£¡£¡£¹ØÓÚ OpenClaw µÄ°²ÅÅ·½¶øÑÔ£¬£¬£¬£¬£¬£¬Ä¿½ñ×î½¹µãµÄÊÂÇéÊÇÁ¬Ã¦ÐÞ¸´ÒÑÅû¶µÄ¸ßΣÎó²î£¬£¬£¬£¬£¬£¬Í¨¹ýÑÏ¿áµÄÉèÖÃÇå¾²ºÍ»á¼û¿ØÖƽµµÍ¹¥»÷Σº¦£»£»£»£»£»¹ØÓÚÏîÄ¿¹Ù·½ºÍÉçÇø¶øÑÔ£¬£¬£¬£¬£¬£¬ÐèÒÔ´Ë´ÎÎó²îÊÂÎñΪÆõ»ú£¬£¬£¬£¬£¬£¬ÍêÉÆÇå¾²¿ª·¢Á÷³Ì£¬£¬£¬£¬£¬£¬Ç¿»¯·À»¤»úÖÆ£¬£¬£¬£¬£¬£¬Èà OpenClaw ÔÚÇå¾²µÄ»ù´¡ÉÏʵÏÖ¸ü´óµÄÉú³¤¡£¡£¡£¡£¡£
ÍøÂçÇå¾²ÎÞСÊ£¬£¬£¬£¬£¬£¬ÓÈÆäÊǾ߱¸ÏµÍ³¼¶²Ù×÷ÄÜÁ¦µÄ AI ÖÇÄÜÌå¿ò¼Ü£¬£¬£¬£¬£¬£¬ÆäÇå¾²ÎÊÌâÖ±½Ó¹ØÏµµ½×°±¸ºÍÊý¾ÝµÄ½¹µãÇå¾²¡£¡£¡£¡£¡£Ï£Íû±¾´ÎÎó²îÆÊÎöÄÜΪ OpenClaw µÄ°²ÅÅ·½ÌṩÓмÛÖµµÄ²Î¿¼£¬£¬£¬£¬£¬£¬ÅäºÏÖþÀÎÍøÂçÇå¾²·ÀµØ¡£¡£¡£¡£¡£
²Î¿¼
https://github.com/openclaw/openclaw/security
https://openclawga-hiaxppxg.manus.space/cve
https://mp.weixin.qq.com/s/mRWlFkiq9gaqX1oVuu9Ceg
https://socket.dev/blog/openclaw-advisory-surge-highlights-gaps-between-ghsa-and-cve-tracking
ʱ¼ä£º2026-04-02
ʱ¼ä£º2026-04-01
ʱ¼ä£º2026-04-01
ʱ¼ä£º2026-03-31
Äú¶ÔÒâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!µÄÈκÎÒÉÎÊ¿ÉÓÃÒÔÏ·½·¨¸æËßÎÒÃÇ
½«Äú¶ÔÒâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!µÄÈκÎÒÉÎÊ
ÓÃÒÔÏ·½·¨¸æËßÎÒÃÇ