¡¾·ì϶¹«¸æ¡¿OpenClaw δÊÚȨ½Ó¼û·ì϶(CVE-2026-32914)
°ä²¼¹¦·ò 2026-03-30Ò»¡¢·ì϶¸ÅÊö
·ì϶Ãû³Æ | OpenClaw δÊÚȨ½Ó¼û·ì϶ | ||
CVE ID | CVE-2026-32914 | ||
·ì϶ÀàÐÍ | δÊÚȨ½Ó¼û | ·¢ÏÖ¹¦·ò | 2026-3-30 |
·ì϶ÆÀ·Ö | 8.7 | ·ì϶µÈ¼¶ | ¸ßΣ |
¹¥»÷ÏòÁ¿ | ÍøÂç | ËùÐèȨÏÞ | µÍ |
ÀûÓÃÄÑ¶È | µÍ | Óû§½»»¥ | ²»±ØÒª |
PoC/EXP | δ¹«¿ª | ÔÚÒ°ÀûÓà | δ·¢ÏÖ |
OpenClawÊÇÒ»¿îÃæÏò×Ô¶¯»¯¹¤×÷Ö´ÐÐÓëÖÇÄÜ´úÀíµ÷¶ÈµÄ¿ªÔ´Æ½Ì¨£¬Ö§³Öͨ¹ýºÅÁîÇý¶¯·½Ê½ÖÎÀí¹¤×÷Ö´ÐС¢ÏµÍ³ÅäÖü°µ÷ÊÔÁ÷³Ì¡£¡£¡£ÏµÍ³¾ß±¸²å¼þÀ©´óÄÜÁ¦¡¢È¨ÏÞ½ÚÖÆ»úÖÆ¼°¶à½ÇÉ«ºÏ×÷ÄÜÁ¦£¬¿í·ºÀûÓÃÓÚ×Ô¶¯»¯ÔËά¡¢AI Agentµ÷¶È¼°¸´ÔÓ¹¤×÷Á÷±àÅŵȳ¡¾°¡£¡£¡£
2026Äê3ÔÂ30ÈÕ£¬OG¶«·½Ìü°²È«Ó¦¼±ÏìÓ¦ÖÐÐÄ£¨VSRC£©¼à²âµ½OpenClaw δÊÚȨ½Ó¼û·ì϶¡£¡£¡£¸Ã·ì϶ԴÓÚ/configÓë/debugµÈÃô¸ÐºÅÁî½Ó¿ÚÔÚʵÏÖ¹ý³ÌÖнöУÑéŲÓ÷½ÊÇ·ñ¾ß±¸command-authorizedȨÏÞ£¬¶øÎ´½øÒ»²½ÑéÖ¤ÊÇ·ñΪownerÉí·Ý£¬µ¼ÖÂȨÏÞ½ÚÖÆÂ߼ȱʧ¡£¡£¡£¹¥»÷Õß¿ÉÀûÓøÃȱµã£¬Í¨¹ý¾ß±¸»ù´¡ºÅÁîÖ´ÐÐȨÏÞµÄÕ˺ŽӼû±¾Ó¦½öÏÞownerµÄÅäÖÃÓëµ÷ÊÔ½Ó¿Ú£¬¶ÁÈ¡»ò´Û¸Äϵͳ¹Ø¼üÅäÖòÎÊý£¬ÉõÖÁ»ñÈ¡Ãô¸Ðµ÷ÊÔÐÅÏ¢¡£¡£¡£¸Ã·ì϶¿ÉÄܱ»ÓÃÓÚȨÏÞÌáÉý¡¢ÏµÍ³ÅäÖô۸ļ°½øÒ»²½¹¥»÷Á´¹¹½¨£¬Ó°ÏìϵͳÆëÈ«ÐÔÓë±£ÃÜÐÔ£¬²¢¿ÉÄÜÎ¥·´ÓйØÊý¾Ý°²È«ÓëºÏ¹æÒªÇ󣬶Ô×éÖ¯ÒµÎñ°²È«Ôì³É½Ï´ó·çÏÕ¡£¡£¡£
¶þ¡¢Ó°ÏìÁìÓò
openclaw <= 2026.3.11
Èý¡¢°²È«´ëÊ©
3.1 Éý¼¶°æ±¾
ÏÂÔØÁ´½Ó£ºhttps://github.com/openclaw/openclaw/releases/
3.2 һʱ´ëÊ©
ÔÝÎÞ¡£¡£¡£


¾©¹«Íø°²±¸11010802024551ºÅ