¡¾¸´ÏÖ¡¿OpenClawÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2026-28466£©

Ðû²¼Ê±¼ä 2026-03-13

OpenClawÒÀ¸½Æä¸»ºñµÄ¹¦Ð§ºÍÎÞаÐÔ£¬£¬£¬£¬ÔÚ2026Äê³ÉΪ¿ªÔ´È˹¤ÖÇÄÜÊðÀíÉú̬ϵͳÖеÄÃ÷ÐÇÏîÄ¿¡£¡£¡£¡£×÷Ϊһ¸ö̸Ìì»úеÈËÆ½Ì¨£¬£¬£¬£¬OpenClawÔÊÐíÓû§Í¨¹ýWeb½çÃæ»ò¼´Ê±Í¨Ñ¶Æ½Ì¨Ï´ï×ÔÈ»ÓïÑÔÖ¸Á£¬£¬£¬Íê³ÉÓʼþÖÎÀí¡¢ÈÕÀúµ÷Àí¡¢ä¯ÀÀÆ÷×Ô¶¯»¯¡¢Îļþ²Ù×÷ÒÔ¼°shellÏÂÁîÖ´ÐеȸßȨÏÞʹÃü¡£¡£¡£¡£


¿ËÈÕ£¬£¬£¬£¬OpenClawÐÞ¸´ÁËÒ»¸öCVSSÆÀ·ÖΪ9.4µÄÑÏÖØÎó²îCVE-2026-28466£¬£¬£¬£¬¸ÃÎó²îÊÇÔÚGatewayת·¢node.invokeÇëÇóʱ£¬£¬£¬£¬Î´¶ÔÓû§´«ÈëµÄ²ÎÊý×öÈκιýÂË£¬£¬£¬£¬µ¼Ö¾­ÓÉÈÏÖ¤µÄ¿Í»§¶Ë¿ÉÒÔÈÆ¹ýÖ´ÐÐÉóÅú»úÖÆ¡£¡£¡£¡£ÓµÓÐÓÐÓÃÍø¹ØÆ¾Ö¤µÄ¹¥»÷Õß¿ÉÒÔ×¢ÈëÉóÅú¿ØÖÆ×ֶΣ¬£¬£¬£¬ÔÚÅþÁ¬µÄ½ÚµãÖ÷»úÉÏÖ´ÐÐí§ÒâÏÂÁ£¬£¬£¬ÀÖ³ÉʹÓý«µ¼ÖÂÍêÈ«¿ØÖƽڵãÖ÷»ú¡£¡£¡£¡£Æ¾Ö¤ÍøÂç¿Õ¼ä²â»æÒýÇæFOFAµÄÊý¾Ý£¬£¬£¬£¬×èÖ¹2026Äê3ÔÂ13ÈÕ£¬£¬£¬£¬»¥ÁªÍøÉϱ£´æ116,672¸öDZÔÚµÄÒ×Êܹ¥»÷OpenClawʵÀý¡£¡£¡£¡£


Îó²îÐÎò


GatewayÊÇOpenClawµÄ½¹µãЧÀÍ£¬£¬£¬£¬ÈÏÕæÖÎÀíËùÓÐÐÂÎÅͨµÀ¡¢»á»°µ÷ÀíºÍAgent±àÅÅ£¬£¬£¬£¬¶ÔÍâÌṩWebSocket API¡£¡£¡£¡£NodeÊÇÅþÁ¬µ½GatewayµÄÖÕ¶Ë×°±¸£¨È磺macOS/iOS/Android Ó¦ÓûòÏÂÁîÐÐÀú³Ì£©£¬£¬£¬£¬ÎªÏµÍ³ÌṩÍâµØÖ´ÐÐÄÜÁ¦£¬£¬£¬£¬°üÀ¨ÔËÐÐShellÏÂÁî¡¢²Ù¿Øä¯ÀÀÆ÷¡¢»á¼ûÉãÏñÍ·µÈ×°±¸¹¦Ð§¡£¡£¡£¡£Gatewayͨ¹ýnode.invoke½«Ö´ÐÐÇëÇó·¢Ë͵½Ä¿µÄNode£¬£¬£¬£¬NodeÔÚÍâµØÍê³ÉÖ´Ðкó½«Ð§¹û»Ø´«¸øGateway£¬£¬£¬£¬Õû¸öÀú³Ìͨ¹ýWebSocketµÄÇëÇó-ÏìÓ¦»úÖÆÍê³É¡£¡£¡£¡£


2026.2.14֮ǰ°æ±¾µÄOpenClawÖУ¬£¬£¬£¬GatewayÔÚת·¢node.invokeÇëÇóʱδ¶Ôparams²ÎÊý¾ÙÐйýÂË£¬£¬£¬£¬¾­ÓÉÉí·ÝÈÏÖ¤µÄÓû§¿ÉÒÔÔÚŲÓòÎÊýÖÐ×¢ÈëapprovedÄÚ²¿¿ØÖÆ×ֶΣ¬£¬£¬£¬ÈƹýNodeÖ÷»úµÄÖ´ÐÐÉóÅú»úÖÆ£¬£¬£¬£¬Í¨¹ýsystem.runÔÚNodeÉÏÖ´ÐÐí§ÒâshellÏÂÁî¡£¡£¡£¡£


Ó°Ïì°æ±¾


OpenClaw<2026.2.14


Îó²îÔ­Àí



¸ÃÎó²îµÄ¸ùÒòÔÚÓÚ´ÓGatewayµ½NodeµÄÕûÌõŲÓÃÁ´Â·ÉÏ£¬£¬£¬£¬¾ùδ¶ÔÓû§¿É¿ØµÄ²ÎÊý×ֶξÙÐÐУÑé»ò¹ýÂË¡£¡£¡£¡£


£¨1£©Gateway¶Ë£ºÔ­Ñùת·¢£¬£¬£¬£¬²»¹ýÂËÄÚ²¿×Ö¶Î


GatewayµÄnode.invoke´¦Öóͷ£º¯Êý½«¿Í»§¶Ë´«ÈëµÄparamsÖ±½Óת´ï¸ønodeRegistry.invoke()£¬£¬£¬£¬Î´×öÈκÎ×ֶΰþÀë¡£¡£¡£¡£



ͼƬ1.jpg


£¨2£©Node Registry£ºÐòÁл¯ºóÖ±½Ó·¢ËÍ


params±»ÐòÁл¯ÎªparamsJSONºóÖ±½Óͨ¹ýWebSocket·¢Ë͸øNode£¬£¬£¬£¬Í¬ÑùûÓйýÂË¡£¡£¡£¡£


ͼƬ2.jpg


£¨3£©Node¶Ë£ºÖ±½ÓÐÅÈÎparamsÖеÄÉóÅú×Ö¶Î


Node·´ÐòÁл¯ºóµÄ²ÎÊýÖаüÀ¨ÉóÅú¿ØÖÆ×ֶΣ¬£¬£¬£¬ÉóÅúÅжÏÂß¼­Ö±½Ó¶ÁÈ¡¸Ã×Ö¶ÎÇÒÎÞÈκÎȪԴÑéÖ¤¡£¡£¡£¡£µ±¸Ã×ֶα»ÉèΪͨ¹ý״̬ʱ£¬£¬£¬£¬ÉóÅú¼ì²éºÍ°×Ãûµ¥Ð£Ñé¾ù±»Ìø¹ý£¬£¬£¬£¬ÏÂÁîÖ±½ÓÖ´ÐУ¬£¬£¬£¬Óû§²»»á¿´µ½ÈκÎÉóÅúÌáÐÑ¡£¡£¡£¡£


ͼƬ3.jpg


Îó²îΣº¦


¸ÃÎó²îÔÊÐíÈκξ­ÓÉGatewayÉí·ÝÈÏÖ¤µÄÓû§ÔÚδ¾­NodeÖ÷»úËùÓÐÕßÅú×¼µÄÇéÐÎÏ£¬£¬£¬£¬Ô¶³ÌÖ´ÐÐí§ÒâShellÏÂÁî¡£¡£¡£¡£¹¥»÷Õ߿ɽè´Ë£º


    ? ÍêÈ«¿ØÖÆNode×°±¸£º¶ÁÈ¡¡¢¸Ä¶¯»òɾ³ý Node Ö÷»úÉϵÄí§ÒâÎļþ¡£¡£¡£¡£

    ? ÇÔÈ¡Ãô¸ÐÊý¾Ý£º»ñÈ¡NodeÉè±¹ØÁ¬Äƾ֤¡¢ÃÜÔ¿¡¢Òþ˽ÎļþµÈ¡£¡£¡£¡£

    ? ºáÏòÒÆ¶¯£ºÒÔNodeÖ÷»úÎªÌø°å£¬£¬£¬£¬½øÒ»²½ÉøÍ¸ËùÔÚÍøÂçµÄÆäËûϵͳ¡£¡£¡£¡£

    ? ³¤ÆÚ»¯×¤Áô£ºÖ²ÈëºóÃųÌÐò»ò׼ʱʹÃü£¬£¬£¬£¬Î¬³Ö¶ÔNode×°±¸µÄºã¾Ã»á¼û¡£¡£¡£¡£


Îó²î¸´ÏÖ


ͼƬ4.jpg


Çå¾²½¨Òé


£¨1£©Á¬Ã¦Éý¼¶


OpenClaw¹Ù·½ÒÑÐû²¼Ç徲ͨ¸æ²¢Ðû²¼ÁËÐÞ¸´°æ±¾£¬£¬£¬£¬Ç뾡¿ìÉý¼¶ÖÁ×îа汾¡£¡£¡£¡£


£¨2£©ÔÝʱ»º½â²½·¥


    ? È·ÈÏGatewayδ̻¶µ½¹«Íø£ºGatewayĬÈϽö¼àÌý±¾»ú£¨127.0.0.1£©£¬£¬£¬£¬È·ÈÏÆô¶¯²ÎÊýÖÐδʹÓý«¶Ë¿Ú̻¶ÖÁÍâ²¿ÍøÂçµÄÉèÖᣡ£¡£¡£

    ? Éó²éÀúÊ·Ö´Ðмͼ£ºÅŲéNodeÖ÷»úÉÏÊÇ·ñ±£´æÒì³£µÄsystem.runŲÓ㬣¬£¬£¬ÖØµã¹Ø×¢Î´¾­Õý³£ÉóÅúÁ÷³Ì¡¢Ö±½ÓЯ´øapproved: trueµÄÇëÇ󡣡£¡£¡£

    ? ×îСȨÏÞÔËÐУºÒÔ×îµÍÐëҪȨÏÞÔËÐÐNodeÀú³Ì£¬£¬£¬£¬×èֹʹÓÃroot»òÖÎÀíÔ±ÕË»§£¬£¬£¬£¬½µµÍÏÂÁîÖ´ÐкóµÄÓ°Ïì¹æÄ£¡£¡£¡£¡£


×èÖ¹ÏÖÔÚ£¬£¬£¬£¬OpenClawÏîÄ¿ÖÐÒÑÀۼƷ¢Ã÷283¸öÇå¾²Îó²î¡£¡£¡£¡£±¾ÎÄÆÊÎöµÄÉóÅúÈÆ¹ýÎó²îÊÇÒ»¸öµä·¶°¸Àý£º¹¦Ð§Âß¼­ÍêÕû£¬£¬£¬£¬µ«Î´ÑéÖ¤"ÉóÅúЧ¹ûÊÇ·ñÕæÊµÀ´×ÔÓû§"¡£¡£¡£¡£ÕâÒ²·´Ó¦ÁËAI AgentÔÚÇå¾²Éè¼ÆÉϱ£´æ¶Ì°å£ºÏµÍ³ÍùÍùÇãÏòÓÚÐÅÈÎÊäÈ룬£¬£¬£¬ÓÅÏÈʵÏÖ¹¦Ð§¶øºöÊÓÁ˽çÏßÌõ¼þºÍÇ徲УÑé¡£¡£¡£¡£ÌØÊâÊÇÔÚÉæ¼°È¨ÏÞУÑé¡¢ÐÅÈνçÏßµÈÇå¾²Òªº¦Â·¾¶Ê±£¬£¬£¬£¬ºöÊÓÕâЩϸ½Ú¿ÉÄÜ´øÀ´ÑÏÖØµÄÇ徲Σº¦¡£¡£¡£¡£Òò´Ë£¬£¬£¬£¬Óû§ÔÚʹÓÃAI AgentʱӦ¼á³ÖÉóÉ÷£¬£¬£¬£¬È·±£¶ÔDZÔÚµÄÇå¾²ÍþвºÍÎó²î¾ÙÐгä·ÖµÄʶ±ðÓëÌá·À¡£¡£¡£¡£


²Î¿¼Á´½Ó£º

[1]https://github.com/advisories/GHSA-gv46-4xfq-jv58

[2]https://nvd.nist.gov/vuln/detail/CVE-2026-28466