¡¾¸´ÏÖ¡¿OpenClawÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2026-28466£©
Ðû²¼Ê±¼ä 2026-03-13OpenClawÒÀ¸½Æä¸»ºñµÄ¹¦Ð§ºÍÎÞаÐÔ£¬£¬£¬£¬ÔÚ2026Äê³ÉΪ¿ªÔ´È˹¤ÖÇÄÜÊðÀíÉú̬ϵͳÖеÄÃ÷ÐÇÏîÄ¿¡£¡£¡£¡£×÷Ϊһ¸ö̸Ìì»úеÈËÆ½Ì¨£¬£¬£¬£¬OpenClawÔÊÐíÓû§Í¨¹ýWeb½çÃæ»ò¼´Ê±Í¨Ñ¶Æ½Ì¨Ï´ï×ÔÈ»ÓïÑÔÖ¸Á£¬£¬£¬Íê³ÉÓʼþÖÎÀí¡¢ÈÕÀúµ÷Àí¡¢ä¯ÀÀÆ÷×Ô¶¯»¯¡¢Îļþ²Ù×÷ÒÔ¼°shellÏÂÁîÖ´ÐеȸßȨÏÞʹÃü¡£¡£¡£¡£
¿ËÈÕ£¬£¬£¬£¬OpenClawÐÞ¸´ÁËÒ»¸öCVSSÆÀ·ÖΪ9.4µÄÑÏÖØÎó²îCVE-2026-28466£¬£¬£¬£¬¸ÃÎó²îÊÇÔÚGatewayת·¢node.invokeÇëÇóʱ£¬£¬£¬£¬Î´¶ÔÓû§´«ÈëµÄ²ÎÊý×öÈκιýÂË£¬£¬£¬£¬µ¼Ö¾ÓÉÈÏÖ¤µÄ¿Í»§¶Ë¿ÉÒÔÈÆ¹ýÖ´ÐÐÉóÅú»úÖÆ¡£¡£¡£¡£ÓµÓÐÓÐÓÃÍø¹ØÆ¾Ö¤µÄ¹¥»÷Õß¿ÉÒÔ×¢ÈëÉóÅú¿ØÖÆ×ֶΣ¬£¬£¬£¬ÔÚÅþÁ¬µÄ½ÚµãÖ÷»úÉÏÖ´ÐÐí§ÒâÏÂÁ£¬£¬£¬ÀÖ³ÉʹÓý«µ¼ÖÂÍêÈ«¿ØÖƽڵãÖ÷»ú¡£¡£¡£¡£Æ¾Ö¤ÍøÂç¿Õ¼ä²â»æÒýÇæFOFAµÄÊý¾Ý£¬£¬£¬£¬×èÖ¹2026Äê3ÔÂ13ÈÕ£¬£¬£¬£¬»¥ÁªÍøÉϱ£´æ116,672¸öDZÔÚµÄÒ×Êܹ¥»÷OpenClawʵÀý¡£¡£¡£¡£
Îó²îÐÎò
GatewayÊÇOpenClawµÄ½¹µãЧÀÍ£¬£¬£¬£¬ÈÏÕæÖÎÀíËùÓÐÐÂÎÅͨµÀ¡¢»á»°µ÷ÀíºÍAgent±àÅÅ£¬£¬£¬£¬¶ÔÍâÌṩWebSocket API¡£¡£¡£¡£NodeÊÇÅþÁ¬µ½GatewayµÄÖÕ¶Ë×°±¸£¨È磺macOS/iOS/Android Ó¦ÓûòÏÂÁîÐÐÀú³Ì£©£¬£¬£¬£¬ÎªÏµÍ³ÌṩÍâµØÖ´ÐÐÄÜÁ¦£¬£¬£¬£¬°üÀ¨ÔËÐÐShellÏÂÁî¡¢²Ù¿Øä¯ÀÀÆ÷¡¢»á¼ûÉãÏñÍ·µÈ×°±¸¹¦Ð§¡£¡£¡£¡£Gatewayͨ¹ýnode.invoke½«Ö´ÐÐÇëÇó·¢Ë͵½Ä¿µÄNode£¬£¬£¬£¬NodeÔÚÍâµØÍê³ÉÖ´Ðкó½«Ð§¹û»Ø´«¸øGateway£¬£¬£¬£¬Õû¸öÀú³Ìͨ¹ýWebSocketµÄÇëÇó-ÏìÓ¦»úÖÆÍê³É¡£¡£¡£¡£
2026.2.14֮ǰ°æ±¾µÄOpenClawÖУ¬£¬£¬£¬GatewayÔÚת·¢node.invokeÇëÇóʱδ¶Ôparams²ÎÊý¾ÙÐйýÂË£¬£¬£¬£¬¾ÓÉÉí·ÝÈÏÖ¤µÄÓû§¿ÉÒÔÔÚŲÓòÎÊýÖÐ×¢ÈëapprovedÄÚ²¿¿ØÖÆ×ֶΣ¬£¬£¬£¬ÈƹýNodeÖ÷»úµÄÖ´ÐÐÉóÅú»úÖÆ£¬£¬£¬£¬Í¨¹ýsystem.runÔÚNodeÉÏÖ´ÐÐí§ÒâshellÏÂÁî¡£¡£¡£¡£
Ó°Ïì°æ±¾
OpenClaw<2026.2.14
Îó²îÔÀí
¸ÃÎó²îµÄ¸ùÒòÔÚÓÚ´ÓGatewayµ½NodeµÄÕûÌõŲÓÃÁ´Â·ÉÏ£¬£¬£¬£¬¾ùδ¶ÔÓû§¿É¿ØµÄ²ÎÊý×ֶξÙÐÐУÑé»ò¹ýÂË¡£¡£¡£¡£
£¨1£©Gateway¶Ë£ºÔÑùת·¢£¬£¬£¬£¬²»¹ýÂËÄÚ²¿×Ö¶Î
GatewayµÄnode.invoke´¦Öóͷ£º¯Êý½«¿Í»§¶Ë´«ÈëµÄparamsÖ±½Óת´ï¸ønodeRegistry.invoke()£¬£¬£¬£¬Î´×öÈκÎ×ֶΰþÀë¡£¡£¡£¡£

£¨2£©Node Registry£ºÐòÁл¯ºóÖ±½Ó·¢ËÍ
params±»ÐòÁл¯ÎªparamsJSONºóÖ±½Óͨ¹ýWebSocket·¢Ë͸øNode£¬£¬£¬£¬Í¬ÑùûÓйýÂË¡£¡£¡£¡£

£¨3£©Node¶Ë£ºÖ±½ÓÐÅÈÎparamsÖеÄÉóÅú×Ö¶Î
Node·´ÐòÁл¯ºóµÄ²ÎÊýÖаüÀ¨ÉóÅú¿ØÖÆ×ֶΣ¬£¬£¬£¬ÉóÅúÅжÏÂß¼Ö±½Ó¶ÁÈ¡¸Ã×Ö¶ÎÇÒÎÞÈκÎȪԴÑéÖ¤¡£¡£¡£¡£µ±¸Ã×ֶα»ÉèΪͨ¹ý״̬ʱ£¬£¬£¬£¬ÉóÅú¼ì²éºÍ°×Ãûµ¥Ð£Ñé¾ù±»Ìø¹ý£¬£¬£¬£¬ÏÂÁîÖ±½ÓÖ´ÐУ¬£¬£¬£¬Óû§²»»á¿´µ½ÈκÎÉóÅúÌáÐÑ¡£¡£¡£¡£

Îó²îΣº¦
¸ÃÎó²îÔÊÐíÈκξÓÉGatewayÉí·ÝÈÏÖ¤µÄÓû§ÔÚδ¾NodeÖ÷»úËùÓÐÕßÅú×¼µÄÇéÐÎÏ£¬£¬£¬£¬Ô¶³ÌÖ´ÐÐí§ÒâShellÏÂÁî¡£¡£¡£¡£¹¥»÷Õ߿ɽè´Ë£º
? ÍêÈ«¿ØÖÆNode×°±¸£º¶ÁÈ¡¡¢¸Ä¶¯»òɾ³ý Node Ö÷»úÉϵÄí§ÒâÎļþ¡£¡£¡£¡£
? ÇÔÈ¡Ãô¸ÐÊý¾Ý£º»ñÈ¡NodeÉè±¹ØÁ¬Äƾ֤¡¢ÃÜÔ¿¡¢Òþ˽ÎļþµÈ¡£¡£¡£¡£
? ºáÏòÒÆ¶¯£ºÒÔNodeÖ÷»úÎªÌø°å£¬£¬£¬£¬½øÒ»²½ÉøÍ¸ËùÔÚÍøÂçµÄÆäËûϵͳ¡£¡£¡£¡£
? ³¤ÆÚ»¯×¤Áô£ºÖ²ÈëºóÃųÌÐò»ò׼ʱʹÃü£¬£¬£¬£¬Î¬³Ö¶ÔNode×°±¸µÄºã¾Ã»á¼û¡£¡£¡£¡£
Îó²î¸´ÏÖ

Çå¾²½¨Òé
£¨1£©Á¬Ã¦Éý¼¶
OpenClaw¹Ù·½ÒÑÐû²¼Ç徲ͨ¸æ²¢Ðû²¼ÁËÐÞ¸´°æ±¾£¬£¬£¬£¬Ç뾡¿ìÉý¼¶ÖÁ×îа汾¡£¡£¡£¡£
£¨2£©ÔÝʱ»º½â²½·¥
? È·ÈÏGatewayδ̻¶µ½¹«Íø£ºGatewayĬÈϽö¼àÌý±¾»ú£¨127.0.0.1£©£¬£¬£¬£¬È·ÈÏÆô¶¯²ÎÊýÖÐδʹÓý«¶Ë¿Ú̻¶ÖÁÍâ²¿ÍøÂçµÄÉèÖᣡ£¡£¡£
? Éó²éÀúÊ·Ö´Ðмͼ£ºÅŲéNodeÖ÷»úÉÏÊÇ·ñ±£´æÒì³£µÄsystem.runŲÓ㬣¬£¬£¬ÖØµã¹Ø×¢Î´¾Õý³£ÉóÅúÁ÷³Ì¡¢Ö±½ÓЯ´øapproved: trueµÄÇëÇ󡣡£¡£¡£
? ×îСȨÏÞÔËÐУºÒÔ×îµÍÐëҪȨÏÞÔËÐÐNodeÀú³Ì£¬£¬£¬£¬×èֹʹÓÃroot»òÖÎÀíÔ±ÕË»§£¬£¬£¬£¬½µµÍÏÂÁîÖ´ÐкóµÄÓ°Ïì¹æÄ£¡£¡£¡£¡£
×èÖ¹ÏÖÔÚ£¬£¬£¬£¬OpenClawÏîÄ¿ÖÐÒÑÀۼƷ¢Ã÷283¸öÇå¾²Îó²î¡£¡£¡£¡£±¾ÎÄÆÊÎöµÄÉóÅúÈÆ¹ýÎó²îÊÇÒ»¸öµä·¶°¸Àý£º¹¦Ð§Âß¼ÍêÕû£¬£¬£¬£¬µ«Î´ÑéÖ¤"ÉóÅúЧ¹ûÊÇ·ñÕæÊµÀ´×ÔÓû§"¡£¡£¡£¡£ÕâÒ²·´Ó¦ÁËAI AgentÔÚÇå¾²Éè¼ÆÉϱ£´æ¶Ì°å£ºÏµÍ³ÍùÍùÇãÏòÓÚÐÅÈÎÊäÈ룬£¬£¬£¬ÓÅÏÈʵÏÖ¹¦Ð§¶øºöÊÓÁ˽çÏßÌõ¼þºÍÇ徲УÑé¡£¡£¡£¡£ÌØÊâÊÇÔÚÉæ¼°È¨ÏÞУÑé¡¢ÐÅÈνçÏßµÈÇå¾²Òªº¦Â·¾¶Ê±£¬£¬£¬£¬ºöÊÓÕâЩϸ½Ú¿ÉÄÜ´øÀ´ÑÏÖØµÄÇ徲Σº¦¡£¡£¡£¡£Òò´Ë£¬£¬£¬£¬Óû§ÔÚʹÓÃAI AgentʱӦ¼á³ÖÉóÉ÷£¬£¬£¬£¬È·±£¶ÔDZÔÚµÄÇå¾²ÍþвºÍÎó²î¾ÙÐгä·ÖµÄʶ±ðÓëÌá·À¡£¡£¡£¡£
²Î¿¼Á´½Ó£º
[1]https://github.com/advisories/GHSA-gv46-4xfq-jv58
[2]https://nvd.nist.gov/vuln/detail/CVE-2026-28466


¾©¹«Íø°²±¸11010802024551ºÅ