¡¾¸´ÏÖ¡¿OpenClawÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2026-28466£©

Ðû²¼Ê±¼ä 2026-03-13

OpenClawÒÀ¸½Æä¸»ºñµÄ¹¦Ð§ºÍÎÞаÐÔ£¬£¬ £¬ÔÚ2026Äê³ÉΪ¿ªÔ´È˹¤ÖÇÄÜÊðÀíÉú̬ϵͳÖеÄÃ÷ÐÇÏîÄ¿¡£¡£¡£¡£¡£×÷Ϊһ¸ö̸Ìì»úеÈËÆ½Ì¨£¬£¬ £¬OpenClawÔÊÐíÓû§Í¨¹ýWeb½çÃæ»ò¼´Ê±Í¨Ñ¶Æ½Ì¨Ï´ï×ÔÈ»ÓïÑÔÖ¸Á£¬ £¬Íê³ÉÓʼþÖÎÀí¡¢ÈÕÀúµ÷Àí¡¢ä¯ÀÀÆ÷×Ô¶¯»¯¡¢Îļþ²Ù×÷ÒÔ¼°shellÏÂÁîÖ´ÐеȸßȨÏÞʹÃü¡£¡£¡£¡£¡£


¿ËÈÕ£¬£¬ £¬OpenClawÐÞ¸´ÁËÒ»¸öCVSSÆÀ·ÖΪ9.4µÄÑÏÖØÎó²îCVE-2026-28466£¬£¬ £¬¸ÃÎó²îÊÇÔÚGatewayת·¢node.invokeÇëÇóʱ£¬£¬ £¬Î´¶ÔÓû§´«ÈëµÄ²ÎÊý×öÈκιýÂË£¬£¬ £¬µ¼Ö¾­ÓÉÈÏÖ¤µÄ¿Í»§¶Ë¿ÉÒÔÈÆ¹ýÖ´ÐÐÉóÅú»úÖÆ¡£¡£¡£¡£¡£ÓµÓÐÓÐÓÃÍø¹ØÆ¾Ö¤µÄ¹¥»÷Õß¿ÉÒÔ×¢ÈëÉóÅú¿ØÖÆ×ֶΣ¬£¬ £¬ÔÚÅþÁ¬µÄ½ÚµãÖ÷»úÉÏÖ´ÐÐí§ÒâÏÂÁ£¬ £¬ÀÖ³ÉʹÓý«µ¼ÖÂÍêÈ«¿ØÖƽڵãÖ÷»ú¡£¡£¡£¡£¡£Æ¾Ö¤ÍøÂç¿Õ¼ä²â»æÒýÇæFOFAµÄÊý¾Ý£¬£¬ £¬×èÖ¹2026Äê3ÔÂ13ÈÕ£¬£¬ £¬»¥ÁªÍøÉϱ£´æ116,672¸öDZÔÚµÄÒ×Êܹ¥»÷OpenClawʵÀý¡£¡£¡£¡£¡£


Îó²îÐÎò


GatewayÊÇOpenClawµÄ½¹µãЧÀÍ£¬£¬ £¬ÈÏÕæÖÎÀíËùÓÐÐÂÎÅͨµÀ¡¢»á»°µ÷ÀíºÍAgent±àÅÅ£¬£¬ £¬¶ÔÍâÌṩWebSocket API¡£¡£¡£¡£¡£NodeÊÇÅþÁ¬µ½GatewayµÄÖÕ¶Ë×°±¸£¨È磺macOS/iOS/Android Ó¦ÓûòÏÂÁîÐÐÀú³Ì£©£¬£¬ £¬ÎªÏµÍ³ÌṩÍâµØÖ´ÐÐÄÜÁ¦£¬£¬ £¬°üÀ¨ÔËÐÐShellÏÂÁî¡¢²Ù¿Øä¯ÀÀÆ÷¡¢»á¼ûÉãÏñÍ·µÈ×°±¸¹¦Ð§¡£¡£¡£¡£¡£Gatewayͨ¹ýnode.invoke½«Ö´ÐÐÇëÇó·¢Ë͵½Ä¿µÄNode£¬£¬ £¬NodeÔÚÍâµØÍê³ÉÖ´Ðкó½«Ð§¹û»Ø´«¸øGateway£¬£¬ £¬Õû¸öÀú³Ìͨ¹ýWebSocketµÄÇëÇó-ÏìÓ¦»úÖÆÍê³É¡£¡£¡£¡£¡£


2026.2.14֮ǰ°æ±¾µÄOpenClawÖУ¬£¬ £¬GatewayÔÚת·¢node.invokeÇëÇóʱδ¶Ôparams²ÎÊý¾ÙÐйýÂË£¬£¬ £¬¾­ÓÉÉí·ÝÈÏÖ¤µÄÓû§¿ÉÒÔÔÚŲÓòÎÊýÖÐ×¢ÈëapprovedÄÚ²¿¿ØÖÆ×ֶΣ¬£¬ £¬ÈƹýNodeÖ÷»úµÄÖ´ÐÐÉóÅú»úÖÆ£¬£¬ £¬Í¨¹ýsystem.runÔÚNodeÉÏÖ´ÐÐí§ÒâshellÏÂÁî¡£¡£¡£¡£¡£


Ó°Ïì°æ±¾


OpenClaw<2026.2.14


Îó²îÔ­Àí



¸ÃÎó²îµÄ¸ùÒòÔÚÓÚ´ÓGatewayµ½NodeµÄÕûÌõŲÓÃÁ´Â·ÉÏ£¬£¬ £¬¾ùδ¶ÔÓû§¿É¿ØµÄ²ÎÊý×ֶξÙÐÐУÑé»ò¹ýÂË¡£¡£¡£¡£¡£


£¨1£©Gateway¶Ë£ºÔ­Ñùת·¢£¬£¬ £¬²»¹ýÂËÄÚ²¿×Ö¶Î


GatewayµÄnode.invoke´¦Öóͷ£º¯Êý½«¿Í»§¶Ë´«ÈëµÄparamsÖ±½Óת´ï¸ønodeRegistry.invoke()£¬£¬ £¬Î´×öÈκÎ×ֶΰþÀë¡£¡£¡£¡£¡£



ͼƬ1.jpg


£¨2£©Node Registry£ºÐòÁл¯ºóÖ±½Ó·¢ËÍ


params±»ÐòÁл¯ÎªparamsJSONºóÖ±½Óͨ¹ýWebSocket·¢Ë͸øNode£¬£¬ £¬Í¬ÑùûÓйýÂË¡£¡£¡£¡£¡£


ͼƬ2.jpg


£¨3£©Node¶Ë£ºÖ±½ÓÐÅÈÎparamsÖеÄÉóÅú×Ö¶Î


Node·´ÐòÁл¯ºóµÄ²ÎÊýÖаüÀ¨ÉóÅú¿ØÖÆ×ֶΣ¬£¬ £¬ÉóÅúÅжÏÂß¼­Ö±½Ó¶ÁÈ¡¸Ã×Ö¶ÎÇÒÎÞÈκÎȪԴÑéÖ¤¡£¡£¡£¡£¡£µ±¸Ã×ֶα»ÉèΪͨ¹ý״̬ʱ£¬£¬ £¬ÉóÅú¼ì²éºÍ°×Ãûµ¥Ð£Ñé¾ù±»Ìø¹ý£¬£¬ £¬ÏÂÁîÖ±½ÓÖ´ÐУ¬£¬ £¬Óû§²»»á¿´µ½ÈκÎÉóÅúÌáÐÑ¡£¡£¡£¡£¡£


ͼƬ3.jpg


Îó²îΣº¦


¸ÃÎó²îÔÊÐíÈκξ­ÓÉGatewayÉí·ÝÈÏÖ¤µÄÓû§ÔÚδ¾­NodeÖ÷»úËùÓÐÕßÅú×¼µÄÇéÐÎÏ£¬£¬ £¬Ô¶³ÌÖ´ÐÐí§ÒâShellÏÂÁî¡£¡£¡£¡£¡£¹¥»÷Õ߿ɽè´Ë£º


    ? ÍêÈ«¿ØÖÆNode×°±¸£º¶ÁÈ¡¡¢¸Ä¶¯»òɾ³ý Node Ö÷»úÉϵÄí§ÒâÎļþ¡£¡£¡£¡£¡£

    ? ÇÔÈ¡Ãô¸ÐÊý¾Ý£º»ñÈ¡NodeÉè±¹ØÁ¬Äƾ֤¡¢ÃÜÔ¿¡¢Òþ˽ÎļþµÈ¡£¡£¡£¡£¡£

    ? ºáÏòÒÆ¶¯£ºÒÔNodeÖ÷»úÎªÌø°å£¬£¬ £¬½øÒ»²½ÉøÍ¸ËùÔÚÍøÂçµÄÆäËûϵͳ¡£¡£¡£¡£¡£

    ? ³¤ÆÚ»¯×¤Áô£ºÖ²ÈëºóÃųÌÐò»ò׼ʱʹÃü£¬£¬ £¬Î¬³Ö¶ÔNode×°±¸µÄºã¾Ã»á¼û¡£¡£¡£¡£¡£


Îó²î¸´ÏÖ


ͼƬ4.jpg


Çå¾²½¨Òé


£¨1£©Á¬Ã¦Éý¼¶


OpenClaw¹Ù·½ÒÑÐû²¼Ç徲ͨ¸æ²¢Ðû²¼ÁËÐÞ¸´°æ±¾£¬£¬ £¬Ç뾡¿ìÉý¼¶ÖÁ×îа汾¡£¡£¡£¡£¡£


£¨2£©ÔÝʱ»º½â²½·¥


    ? È·ÈÏGatewayδ̻¶µ½¹«Íø£ºGatewayĬÈϽö¼àÌý±¾»ú£¨127.0.0.1£©£¬£¬ £¬È·ÈÏÆô¶¯²ÎÊýÖÐδʹÓý«¶Ë¿Ú̻¶ÖÁÍâ²¿ÍøÂçµÄÉèÖᣡ£¡£¡£¡£

    ? Éó²éÀúÊ·Ö´Ðмͼ£ºÅŲéNodeÖ÷»úÉÏÊÇ·ñ±£´æÒì³£µÄsystem.runŲÓ㬣¬ £¬ÖØµã¹Ø×¢Î´¾­Õý³£ÉóÅúÁ÷³Ì¡¢Ö±½ÓЯ´øapproved: trueµÄÇëÇ󡣡£¡£¡£¡£

    ? ×îСȨÏÞÔËÐУºÒÔ×îµÍÐëҪȨÏÞÔËÐÐNodeÀú³Ì£¬£¬ £¬×èֹʹÓÃroot»òÖÎÀíÔ±ÕË»§£¬£¬ £¬½µµÍÏÂÁîÖ´ÐкóµÄÓ°Ïì¹æÄ£¡£¡£¡£¡£¡£


×èÖ¹ÏÖÔÚ£¬£¬ £¬OpenClawÏîÄ¿ÖÐÒÑÀۼƷ¢Ã÷283¸öÇå¾²Îó²î¡£¡£¡£¡£¡£±¾ÎÄÆÊÎöµÄÉóÅúÈÆ¹ýÎó²îÊÇÒ»¸öµä·¶°¸Àý£º¹¦Ð§Âß¼­ÍêÕû£¬£¬ £¬µ«Î´ÑéÖ¤"ÉóÅúЧ¹ûÊÇ·ñÕæÊµÀ´×ÔÓû§"¡£¡£¡£¡£¡£ÕâÒ²·´Ó¦ÁËAI AgentÔÚÇå¾²Éè¼ÆÉϱ£´æ¶Ì°å£ºÏµÍ³ÍùÍùÇãÏòÓÚÐÅÈÎÊäÈ룬£¬ £¬ÓÅÏÈʵÏÖ¹¦Ð§¶øºöÊÓÁ˽çÏßÌõ¼þºÍÇ徲УÑé¡£¡£¡£¡£¡£ÌØÊâÊÇÔÚÉæ¼°È¨ÏÞУÑé¡¢ÐÅÈνçÏßµÈÇå¾²Òªº¦Â·¾¶Ê±£¬£¬ £¬ºöÊÓÕâЩϸ½Ú¿ÉÄÜ´øÀ´ÑÏÖØµÄÇ徲Σº¦¡£¡£¡£¡£¡£Òò´Ë£¬£¬ £¬Óû§ÔÚʹÓÃAI AgentʱӦ¼á³ÖÉóÉ÷£¬£¬ £¬È·±£¶ÔDZÔÚµÄÇå¾²ÍþвºÍÎó²î¾ÙÐгä·ÖµÄʶ±ðÓëÌá·À¡£¡£¡£¡£¡£


²Î¿¼Á´½Ó£º

[1]https://github.com/advisories/GHSA-gv46-4xfq-jv58

[2]https://nvd.nist.gov/vuln/detail/CVE-2026-28466