¡¾·ì϶¹«¸æ¡¿OpenClaw δÊÚȨ½Ó¼û·ì϶(CVE-2026-32914)
°ä²¼¹¦·ò 2026-03-30Ò»¡¢·ì϶¸ÅÊö
·ìϼûû³Æ | OpenClaw δÊÚȨ½Ó¼û·ì϶ | ||
CVE ID | CVE-2026-32914 | ||
·ì϶ÀàÐÍ | δÊÚȨ½Ó¼û | ·¢ÏÖ¹¦·ò | 2026-3-30 |
·ì϶ÆÀ·Ö | 8.7 | ·ì϶µÈ¼¶ | ¸ßΣ |
¹¥»÷ÏòÁ¿ | ÍøÂç | ËùÐèȨÏÞ | µÍ |
ÀûÓÃÄÑ¶È | µÍ | Óû§½»»¥ | ²»±ØÒª |
PoC/EXP | δ¹«¿ª | ÔÚÒ°ÀûÓà | δ·¢ÏÖ |
OpenClawÊÇÒ»¿îÃæÏò×Ô¶¯»¯¹¤×÷Ö´ÐÐÓëÖÇÄÜ´úÀíµ÷¶ÈµÄ¿ªÔ´Æ½Ì¨£¬Ö§³Öͨ¹ýºÅÁîÇý¶¯·½Ê½ÖÎÀí¹¤×÷Ö´ÐÓעϵͳÅäÖü°µ÷ÊÔÁ÷³Ì¡£ÏµÍ³¾ß±¸²å¼þÀ©´óÄÜÁ¦¡¢È¨ÏÞ½ÚÔì»úÔì¼°¶à½ÇÉ«ºÏ×÷ÄÜÁ¦£¬¿í·ºÀûÓÃÓÚ×Ô¶¯»¯ÔËά¡¢AI Agentµ÷¶È¼°¸´ÔÓ¹¤×÷Á÷±àÅŵȳ¡¾°¡£
2026Äê3ÔÂ30ÈÕ£¬±¦ÔËÀ³¹Ù·½ÍøÕ¾°²È«Ó¦¼±ÏìÓ¦ÖÐÐÄ£¨VSRC£©¼à²âµ½OpenClaw δÊÚȨ½Ó¼û·ì϶¡£¸Ã·ì϶ԴÓÚ/configÓë/debugµÈÃô¸ÐºÅÁî½Ó¿ÚÔÚʵÏÖ¹ý³ÌÖнöУÑéŲÓ÷½ÊÇ·ñ¾ß±¸command-authorizedȨÏÞ£¬¶øÎ´½øÒ»²½ÑéÖ¤ÊÇ·ñΪownerÉí·Ý£¬µ¼ÖÂȨÏÞ½ÚÔìÂ߼ȱʧ¡£¹¥»÷Õß¿ÉÀûÓøÃȱµã£¬Í¨¹ý¾ß±¸»ù´¡ºÅÁîÖ´ÐÐȨÏÞµÄÕ˺ŽӼû±¾Ó¦½öÏÞownerµÄÅäÖÃÓëµ÷ÊÔ½Ó¿Ú£¬¶ÁÈ¡»ò´Û¸Äϵͳ¹Ø¼üÅäÖòÎÊý£¬ÉõÖÁ»ñÈ¡Ãô¸Ðµ÷ÊÔÐÅÏ¢¡£¸Ã·ì϶¿ÉÄܱ»ÓÃÓÚȨÏÞÌáÉý¡¢ÏµÍ³ÅäÖô۸ļ°½øÒ»²½¹¥»÷Á´¹¹½¨£¬Ó°ÏìϵͳÆëÈ«ÐÔÓë±£ÃÜÐÔ£¬²¢¿ÉÄÜÎ¥·´ÓйØÊý¾Ý°²È«ÓëºÏ¹æÒªÇ󣬶Ô×éÖ¯ÒµÎñ°²È«Ôì³É½Ï´ó·çÏÕ¡£
¶þ¡¢Ó°ÏìÁìÓò
openclaw <= 2026.3.11
Èý¡¢°²È«´ëÊ©
3.1 Éý¼¶°æ±¾
ÏÂÔØÁ´½Ó£ºhttps://github.com/openclaw/openclaw/releases/
3.2 һʱ´ëÊ©
ÔÝÎÞ¡£


¾©¹«Íø°²±¸11010802024551ºÅ