¡¾¸´ÏÖ¡¿OpenClawÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2026-28466£©

Ðû²¼Ê±¼ä 2026-03-13

OpenClawÒÀ¸½Æä¸»ºñµÄ¹¦Ð§ºÍÎÞаÐÔ£¬£¬£¬£¬ £¬ÔÚ2026Äê³ÉΪ¿ªÔ´È˹¤ÖÇÄÜÊðÀíÉú̬ϵͳÖеÄÃ÷ÐÇÏîÄ¿¡£¡£¡£¡£¡£¡£¡£×÷Ϊһ¸ö̸Ìì»úеÈËÆ½Ì¨£¬£¬£¬£¬ £¬OpenClawÔÊÐíÓû§Í¨¹ýWeb½çÃæ»ò¼´Ê±Í¨Ñ¶Æ½Ì¨Ï´ï×ÔÈ»ÓïÑÔÖ¸Á£¬£¬£¬ £¬Íê³ÉÓʼþÖÎÀí¡¢ÈÕÀúµ÷Àí¡¢ä¯ÀÀÆ÷×Ô¶¯»¯¡¢Îļþ²Ù×÷ÒÔ¼°shellÏÂÁîÖ´ÐеȸßȨÏÞʹÃü¡£¡£¡£¡£¡£¡£¡£


¿ËÈÕ£¬£¬£¬£¬ £¬OpenClawÐÞ¸´ÁËÒ»¸öCVSSÆÀ·ÖΪ9.4µÄÑÏÖØÎó²îCVE-2026-28466£¬£¬£¬£¬ £¬¸ÃÎó²îÊÇÔÚGatewayת·¢node.invokeÇëÇóʱ£¬£¬£¬£¬ £¬Î´¶ÔÓû§´«ÈëµÄ²ÎÊý×öÈκιýÂË£¬£¬£¬£¬ £¬µ¼Ö¾­ÓÉÈÏÖ¤µÄ¿Í»§¶Ë¿ÉÒÔÈÆ¹ýÖ´ÐÐÉóÅú»úÖÆ¡£¡£¡£¡£¡£¡£¡£ÓµÓÐÓÐÓÃÍø¹ØÆ¾Ö¤µÄ¹¥»÷Õß¿ÉÒÔ×¢ÈëÉóÅú¿ØÖÆ×ֶΣ¬£¬£¬£¬ £¬ÔÚÅþÁ¬µÄ½ÚµãÖ÷»úÉÏÖ´ÐÐí§ÒâÏÂÁ£¬£¬£¬ £¬ÀÖ³ÉʹÓý«µ¼ÖÂÍêÈ«¿ØÖƽڵãÖ÷»ú¡£¡£¡£¡£¡£¡£¡£Æ¾Ö¤ÍøÂç¿Õ¼ä²â»æÒýÇæFOFAµÄÊý¾Ý£¬£¬£¬£¬ £¬×èÖ¹2026Äê3ÔÂ13ÈÕ£¬£¬£¬£¬ £¬»¥ÁªÍøÉϱ£´æ116,672¸öDZÔÚµÄÒ×Êܹ¥»÷OpenClawʵÀý¡£¡£¡£¡£¡£¡£¡£


Îó²îÐÎò


GatewayÊÇOpenClawµÄ½¹µãЧÀÍ£¬£¬£¬£¬ £¬ÈÏÕæÖÎÀíËùÓÐÐÂÎÅͨµÀ¡¢»á»°µ÷ÀíºÍAgent±àÅÅ£¬£¬£¬£¬ £¬¶ÔÍâÌṩWebSocket API¡£¡£¡£¡£¡£¡£¡£NodeÊÇÅþÁ¬µ½GatewayµÄÖÕ¶Ë×°±¸£¨È磺macOS/iOS/Android Ó¦ÓûòÏÂÁîÐÐÀú³Ì£©£¬£¬£¬£¬ £¬ÎªÏµÍ³ÌṩÍâµØÖ´ÐÐÄÜÁ¦£¬£¬£¬£¬ £¬°üÀ¨ÔËÐÐShellÏÂÁî¡¢²Ù¿Øä¯ÀÀÆ÷¡¢»á¼ûÉãÏñÍ·µÈ×°±¸¹¦Ð§¡£¡£¡£¡£¡£¡£¡£Gatewayͨ¹ýnode.invoke½«Ö´ÐÐÇëÇó·¢Ë͵½Ä¿µÄNode£¬£¬£¬£¬ £¬NodeÔÚÍâµØÍê³ÉÖ´Ðкó½«Ð§¹û»Ø´«¸øGateway£¬£¬£¬£¬ £¬Õû¸öÀú³Ìͨ¹ýWebSocketµÄÇëÇó-ÏìÓ¦»úÖÆÍê³É¡£¡£¡£¡£¡£¡£¡£


2026.2.14֮ǰ°æ±¾µÄOpenClawÖУ¬£¬£¬£¬ £¬GatewayÔÚת·¢node.invokeÇëÇóʱδ¶Ôparams²ÎÊý¾ÙÐйýÂË£¬£¬£¬£¬ £¬¾­ÓÉÉí·ÝÈÏÖ¤µÄÓû§¿ÉÒÔÔÚŲÓòÎÊýÖÐ×¢ÈëapprovedÄÚ²¿¿ØÖÆ×ֶΣ¬£¬£¬£¬ £¬ÈƹýNodeÖ÷»úµÄÖ´ÐÐÉóÅú»úÖÆ£¬£¬£¬£¬ £¬Í¨¹ýsystem.runÔÚNodeÉÏÖ´ÐÐí§ÒâshellÏÂÁî¡£¡£¡£¡£¡£¡£¡£


Ó°Ïì°æ±¾


OpenClaw<2026.2.14


Îó²îÔ­Àí



¸ÃÎó²îµÄ¸ùÒòÔÚÓÚ´ÓGatewayµ½NodeµÄÕûÌõŲÓÃÁ´Â·ÉÏ£¬£¬£¬£¬ £¬¾ùδ¶ÔÓû§¿É¿ØµÄ²ÎÊý×ֶξÙÐÐУÑé»ò¹ýÂË¡£¡£¡£¡£¡£¡£¡£


£¨1£©Gateway¶Ë£ºÔ­Ñùת·¢£¬£¬£¬£¬ £¬²»¹ýÂËÄÚ²¿×Ö¶Î


GatewayµÄnode.invoke´¦Öóͷ£º¯Êý½«¿Í»§¶Ë´«ÈëµÄparamsÖ±½Óת´ï¸ønodeRegistry.invoke()£¬£¬£¬£¬ £¬Î´×öÈκÎ×ֶΰþÀë¡£¡£¡£¡£¡£¡£¡£



ͼƬ1.jpg


£¨2£©Node Registry£ºÐòÁл¯ºóÖ±½Ó·¢ËÍ


params±»ÐòÁл¯ÎªparamsJSONºóÖ±½Óͨ¹ýWebSocket·¢Ë͸øNode£¬£¬£¬£¬ £¬Í¬ÑùûÓйýÂË¡£¡£¡£¡£¡£¡£¡£


ͼƬ2.jpg


£¨3£©Node¶Ë£ºÖ±½ÓÐÅÈÎparamsÖеÄÉóÅú×Ö¶Î


Node·´ÐòÁл¯ºóµÄ²ÎÊýÖаüÀ¨ÉóÅú¿ØÖÆ×ֶΣ¬£¬£¬£¬ £¬ÉóÅúÅжÏÂß¼­Ö±½Ó¶ÁÈ¡¸Ã×Ö¶ÎÇÒÎÞÈκÎȪԴÑéÖ¤¡£¡£¡£¡£¡£¡£¡£µ±¸Ã×ֶα»ÉèΪͨ¹ý״̬ʱ£¬£¬£¬£¬ £¬ÉóÅú¼ì²éºÍ°×Ãûµ¥Ð£Ñé¾ù±»Ìø¹ý£¬£¬£¬£¬ £¬ÏÂÁîÖ±½ÓÖ´ÐУ¬£¬£¬£¬ £¬Óû§²»»á¿´µ½ÈκÎÉóÅúÌáÐÑ¡£¡£¡£¡£¡£¡£¡£


ͼƬ3.jpg


Îó²îΣº¦


¸ÃÎó²îÔÊÐíÈκξ­ÓÉGatewayÉí·ÝÈÏÖ¤µÄÓû§ÔÚδ¾­NodeÖ÷»úËùÓÐÕßÅú×¼µÄÇéÐÎÏ£¬£¬£¬£¬ £¬Ô¶³ÌÖ´ÐÐí§ÒâShellÏÂÁî¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õ߿ɽè´Ë£º


    ? ÍêÈ«¿ØÖÆNode×°±¸£º¶ÁÈ¡¡¢¸Ä¶¯»òɾ³ý Node Ö÷»úÉϵÄí§ÒâÎļþ¡£¡£¡£¡£¡£¡£¡£

    ? ÇÔÈ¡Ãô¸ÐÊý¾Ý£º»ñÈ¡NodeÉè±¹ØÁ¬Äƾ֤¡¢ÃÜÔ¿¡¢Òþ˽ÎļþµÈ¡£¡£¡£¡£¡£¡£¡£

    ? ºáÏòÒÆ¶¯£ºÒÔNodeÖ÷»úÎªÌø°å£¬£¬£¬£¬ £¬½øÒ»²½ÉøÍ¸ËùÔÚÍøÂçµÄÆäËûϵͳ¡£¡£¡£¡£¡£¡£¡£

    ? ³¤ÆÚ»¯×¤Áô£ºÖ²ÈëºóÃųÌÐò»ò׼ʱʹÃü£¬£¬£¬£¬ £¬Î¬³Ö¶ÔNode×°±¸µÄºã¾Ã»á¼û¡£¡£¡£¡£¡£¡£¡£


Îó²î¸´ÏÖ


ͼƬ4.jpg


Çå¾²½¨Òé


£¨1£©Á¬Ã¦Éý¼¶


OpenClaw¹Ù·½ÒÑÐû²¼Ç徲ͨ¸æ²¢Ðû²¼ÁËÐÞ¸´°æ±¾£¬£¬£¬£¬ £¬Ç뾡¿ìÉý¼¶ÖÁ×îа汾¡£¡£¡£¡£¡£¡£¡£


£¨2£©ÔÝʱ»º½â²½·¥


    ? È·ÈÏGatewayδ̻¶µ½¹«Íø£ºGatewayĬÈϽö¼àÌý±¾»ú£¨127.0.0.1£©£¬£¬£¬£¬ £¬È·ÈÏÆô¶¯²ÎÊýÖÐδʹÓý«¶Ë¿Ú̻¶ÖÁÍâ²¿ÍøÂçµÄÉèÖᣡ£¡£¡£¡£¡£¡£

    ? Éó²éÀúÊ·Ö´Ðмͼ£ºÅŲéNodeÖ÷»úÉÏÊÇ·ñ±£´æÒì³£µÄsystem.runŲÓ㬣¬£¬£¬ £¬ÖØµã¹Ø×¢Î´¾­Õý³£ÉóÅúÁ÷³Ì¡¢Ö±½ÓЯ´øapproved: trueµÄÇëÇ󡣡£¡£¡£¡£¡£¡£

    ? ×îСȨÏÞÔËÐУºÒÔ×îµÍÐëҪȨÏÞÔËÐÐNodeÀú³Ì£¬£¬£¬£¬ £¬×èֹʹÓÃroot»òÖÎÀíÔ±ÕË»§£¬£¬£¬£¬ £¬½µµÍÏÂÁîÖ´ÐкóµÄÓ°Ïì¹æÄ£¡£¡£¡£¡£¡£¡£¡£


×èÖ¹ÏÖÔÚ£¬£¬£¬£¬ £¬OpenClawÏîÄ¿ÖÐÒÑÀۼƷ¢Ã÷283¸öÇå¾²Îó²î¡£¡£¡£¡£¡£¡£¡£±¾ÎÄÆÊÎöµÄÉóÅúÈÆ¹ýÎó²îÊÇÒ»¸öµä·¶°¸Àý£º¹¦Ð§Âß¼­ÍêÕû£¬£¬£¬£¬ £¬µ«Î´ÑéÖ¤"ÉóÅúЧ¹ûÊÇ·ñÕæÊµÀ´×ÔÓû§"¡£¡£¡£¡£¡£¡£¡£ÕâÒ²·´Ó¦ÁËAI AgentÔÚÇå¾²Éè¼ÆÉϱ£´æ¶Ì°å£ºÏµÍ³ÍùÍùÇãÏòÓÚÐÅÈÎÊäÈ룬£¬£¬£¬ £¬ÓÅÏÈʵÏÖ¹¦Ð§¶øºöÊÓÁ˽çÏßÌõ¼þºÍÇ徲УÑé¡£¡£¡£¡£¡£¡£¡£ÌØÊâÊÇÔÚÉæ¼°È¨ÏÞУÑé¡¢ÐÅÈνçÏßµÈÇå¾²Òªº¦Â·¾¶Ê±£¬£¬£¬£¬ £¬ºöÊÓÕâЩϸ½Ú¿ÉÄÜ´øÀ´ÑÏÖØµÄÇ徲Σº¦¡£¡£¡£¡£¡£¡£¡£Òò´Ë£¬£¬£¬£¬ £¬Óû§ÔÚʹÓÃAI AgentʱӦ¼á³ÖÉóÉ÷£¬£¬£¬£¬ £¬È·±£¶ÔDZÔÚµÄÇå¾²ÍþвºÍÎó²î¾ÙÐгä·ÖµÄʶ±ðÓëÌá·À¡£¡£¡£¡£¡£¡£¡£


²Î¿¼Á´½Ó£º

[1]https://github.com/advisories/GHSA-gv46-4xfq-jv58

[2]https://nvd.nist.gov/vuln/detail/CVE-2026-28466