security-advisory intermediate resolved

OpenClaw Security Advisory GHSA-g8p2-7wf7-98mq

Eine bekannte Schwachstelle existiert in bestimmten OpenClaw-Versionen. Prüfe, ob deine betroffen ist. Dauert 15 Minuten.

Was fehlt ohne openclaw security advisory GHSA

Ungepatchte Schwachstelle in der Produktion. Betroffener Versionsbereich unklar. CVE-Audit schlägt ohne dokumentiertes Advisory fehl.

Bestätigter Schwachstellenstatus × CVSSv3-dokumentiertes Advisory mit Patch-Version ÷ 15-Minuten-Review ÷ kein Raten erforderlich = gepatchte Bereitstellung, bestätigt.

openclaw security advisory GHSA — was es wirklich kann

01
Dokumentiert den genauen OpenClaw-Versionsbereich, der von dieser Schwachstelle betroffen ist.
02
Bietet CVSSv3-Score, Ausnutzungsbedingungen und Angriffs-Voraussetzungen.
03
Verlinkt zum gepatchten Release und dem spezifischen Commit, der es gelöst hat.
04
Deckt den koordinierten Disclosure-Zeitplan als Referenz für zukünftige Advisories ab.
05
Nützlich für CVE-Audits, Sicherheitsreviews und Abhängigkeits-Management-Prozesse.

Sicherheitscheck — openclaw security advisory GHSA

Datenschutz-Score: 7/10 — greift nur auf verbundene Plattform-APIs zu. Absichern: OAuth-Berechtigungen vor der Installation prüfen, Affects OpenClaw versions specified in the advisory — see canonical URL for exact range-Kompatibilität bestätigen.

Schnellstart — openclaw security advisory GHSA in 15 minutes (review and patch application)

Einrichtungszeit: 15 minutes (review and patch application)

!
Du brauchst: Existing OpenClaw deployment to check version against; npm for patching

Paket installieren:

# Check your version:
openclaw --version
# Update to patched version:
npm update openclaw
1
Read the advisory at the canonical URL to understand the vulnerability class
2
Check your OpenClaw version against the affected version range
3
If affected, run npm update openclaw to get the patched release
4
Review any configuration mitigations recommended in the advisory
5
Restart your OpenClaw instance
6
Verify the fix by confirming your version is in the patched range

Fehlerbehebung openclaw security advisory GHSA

1
1. Assuming you're unaffected without checking — always verify your exact version against the advisory range
2
2. Applying only the config mitigation without upgrading — mitigations reduce exposure but upgrading is the definitive fix
3
3. Not restarting after npm update — the old vulnerable code stays in memory

Kompatibilität & Status

Kompatibel mit: Affects OpenClaw versions specified in the advisory — see canonical URL for exact range intermediate Zuletzt aktualisiert: Aug. 2025 ★ N/A auf GitHub N/A

Offizielle Dokumentation →

Auf GitHub ansehen →

FAQ — openclaw security advisory GHSA

What is the severity of this advisory?

Check the CVSS score in the advisory. Scores above 7.0 are High or Critical and should be patched immediately.

Am I affected if I'm using a plugin, not the core?

This advisory is for openclaw/openclaw core. Plugin-specific vulnerabilities have separate advisories.

Where can I see all OpenClaw security advisories?

https://github.com/openclaw/openclaw/security/advisories lists all published advisories.

Ähnliche Einträge — mehr wie openclaw security advisory GHSA

Weitere Einträge von openclaw

Eine betroffene Version zu betreiben, ohne es zu wissen, ist das gesamte Risiko.

Jeder Tag ohne Patch-Review ist ein Tag mit unbestätigter Exposition.

Auf GitHub ansehen →