¡¾¸´ÏÖ¡¿OpenClawÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2026-28466£©
°ä²¼¹¦·ò 2026-03-13OpenClawƾ½èÆä·á˶µÄÖ°ÄܺͽýÝÐÔ£¬£¬£¬£¬£¬£¬ÔÚ2026Äê³ÉΪ¿ªÔ´ÈËΪÖÇÄÜ´úÀíÉú̬ϵͳÖеÄÃ÷ÐÇÏîÄ¿¡£¡£¡£¡£¡£¡£×÷Ϊһ¸ö̸Ìì»úеÈËÆ½Ì¨£¬£¬£¬£¬£¬£¬OpenClawÔÊÐíÓû§Í¨¹ýWeb½çÃæ»ò¼´Ê±Í¨Ñ¶Æ½Ì¨Ï´ïÌìȻ˵»°Ö¸Á£¬£¬£¬£¬£¬ÊµÏÖÓʼþÖÎÀí¡¢ÈÕÀúµ÷¶È¡¢ä¯ÀÀÆ÷×Ô¶¯»¯¡¢Îļþ²Ù×÷ÒÔ¼°shellºÅÁîÖ´ÐеȸßȨÏÞ¹¤×÷¡£¡£¡£¡£¡£¡£
½üÈÕ£¬£¬£¬£¬£¬£¬OpenClaw½¨¸´ÁËÒ»¸öCVSSÆÀ·ÖΪ9.4µÄÑϳÁ·ì϶CVE-2026-28466£¬£¬£¬£¬£¬£¬¸Ã·ì϶ÊÇÔÚGatewayת·¢node.invokeÒªÇóʱ£¬£¬£¬£¬£¬£¬Î´¶ÔÓû§´«ÈëµÄ²ÎÊý×öÈκιýÂË£¬£¬£¬£¬£¬£¬µ¼Ö¾¹ýÈÏÖ¤µÄ¿Í»§¶ËÄܹ»ÈƹýÖ´ÐÐÉóÅú»úÔì¡£¡£¡£¡£¡£¡£Õ¼ÓÐÓÐÐ§Íø¹ØÆ¾Ö¤µÄ¹¥»÷ÕßÄܹ»×¢ÈëÉóÅú½ÚÔì×ֶΣ¬£¬£¬£¬£¬£¬ÔÚÏνӵĽڵãÖ÷»úÉÏÖ´ÐÐËÁÒâºÅÁ£¬£¬£¬£¬£¬³É¹¦ÀûÓý«µ¼ÖÂÆëÈ«½ÚÔì½ÚµãÖ÷»ú¡£¡£¡£¡£¡£¡£Æ¾¾ÝÍøÂç¿Õ¼ä²â»æÒýÇæFOFAµÄÊý¾Ý£¬£¬£¬£¬£¬£¬½ØÖÁ2026Äê3ÔÂ13ÈÕ£¬£¬£¬£¬£¬£¬»¥ÁªÍøÉÏ´æÔÚ116,672¸öDZÔÚµÄÒ×Êܹ¥»÷OpenClawÊ·ý¡£¡£¡£¡£¡£¡£
·ìϼûèÊö
GatewayÊÇOpenClawµÄÖ÷Ìâ·þÎñ£¬£¬£¬£¬£¬£¬ÕƹÜÖÎÀíËùÓÐÐÂÎÅͨ·¡¢»á»°µ÷¶ÈºÍAgent±àÅÅ£¬£¬£¬£¬£¬£¬¶Ô±íÌṩWebSocket API¡£¡£¡£¡£¡£¡£NodeÊÇÏνӵ½GatewayµÄÖÕ¶ËÉ豸£¨È磺macOS/iOS/Android ÀûÓûòºÅÁîǰ¹ý³Ì£©£¬£¬£¬£¬£¬£¬ÎªÏµÍ³Ìṩ±¾µØÖ´ÐÐÄÜÁ¦£¬£¬£¬£¬£¬£¬Ô̺¬ÔËÐÐShellºÅÁî¡¢²Ù¿Øä¯ÀÀÆ÷¡¢½Ó¼ûÉãÏñÓŵÈÉ豸ְÄÜ¡£¡£¡£¡£¡£¡£Gatewayͨ¹ýnode.invoke½«Ö´ÐÐÒªÇó·¢Ë͵½Ö¸±êNode£¬£¬£¬£¬£¬£¬NodeÔÚ±¾µØÊµÏÖÖ´Ðкó½«Á˾ֻش«¸øGateway£¬£¬£¬£¬£¬£¬Õû¸ö¹ý³Ìͨ¹ýWebSocketµÄÒªÇó-ÏìÓ¦»úÔìʵÏÖ¡£¡£¡£¡£¡£¡£
2026.2.14֮ǰ°æ±¾µÄOpenClawÖУ¬£¬£¬£¬£¬£¬GatewayÔÚת·¢node.invokeÒªÇóʱδ¶Ôparams²ÎÊý½øÐйýÂË£¬£¬£¬£¬£¬£¬¾¹ýÉí·ÝÈÏÖ¤µÄÓû§Äܹ»ÔÚŲÓòÎÊýÖÐ×¢ÈëapprovedÄÚ²¿½ÚÔì×ֶΣ¬£¬£¬£¬£¬£¬ÈƹýNodeÖ÷»úµÄÖ´ÐÐÉóÅú»úÔ죬£¬£¬£¬£¬£¬Í¨¹ýsystem.runÔÚNodeÉÏÖ´ÐÐËÁÒâshellºÅÁî¡£¡£¡£¡£¡£¡£
Ó°Ïì°æ±¾
OpenClaw<2026.2.14
·ì϶µÀÀí
¸Ã·ì϶µÄ¸ùÒòÔÚÓÚ´ÓGatewayµ½NodeµÄÕûÌõŲÓÃÁ´Â·ÉÏ£¬£¬£¬£¬£¬£¬¾ùδ¶ÔÓû§¿É¿ØµÄ²ÎÊý×ֶνøÐÐУÑé»ò¹ýÂË¡£¡£¡£¡£¡£¡£
£¨1£©Gateway¶Ë£ºÔÑùת·¢£¬£¬£¬£¬£¬£¬²»ÍâÂËÄÚ²¿×Ö¶Î
GatewayµÄnode.invoke´¦Öú¯Êý½«¿Í»§¶Ë´«ÈëµÄparamsÖ±½Ó´«µÝ¸ønodeRegistry.invoke()£¬£¬£¬£¬£¬£¬Î´×öÈκÎ×ֶΰþÀë¡£¡£¡£¡£¡£¡£

£¨2£©Node Registry£ºÐòÁл¯ºóÖ±½Ó·¢ËÍ
params±»ÐòÁл¯ÎªparamsJSONºóÖ±½Óͨ¹ýWebSocket·¢Ë͸øNode£¬£¬£¬£¬£¬£¬Í¬ÑùûÓйýÂË¡£¡£¡£¡£¡£¡£

£¨3£©Node¶Ë£ºÖ±½ÓÐÅÀµparamsÖеÄÉóÅú×Ö¶Î
Node·´ÐòÁл¯ºóµÄ²ÎÊýÖÐÔ̺¬ÉóÅú½ÚÔì×ֶΣ¬£¬£¬£¬£¬£¬ÉóÅúÆÀÒéÂß¼Ö±½Ó¶ÁÈ¡¸Ã×Ö¶ÎÇÒÎÞÈÎºÎÆðÔ´ÑéÖ¤¡£¡£¡£¡£¡£¡£µ±¸Ã×ֶα»ÉèΪͨ¹ý״̬ʱ£¬£¬£¬£¬£¬£¬ÉóÅú²é³ºÍ°×Ãûµ¥Ð£Ñé¾ù±»Ìø¹ý£¬£¬£¬£¬£¬£¬ºÅÁîÖ±½ÓÖ´ÐУ¬£¬£¬£¬£¬£¬Óû§²»»á¿´µ½ÈκÎÉóÅúÌáÐÑ¡£¡£¡£¡£¡£¡£

·ì϶·çÏÕ
¸Ã·ì϶ÔÊÐíÈκξ¹ýGatewayÉí·ÝÈÏÖ¤µÄÓû§ÔÚδ¾NodeÖ÷»úËùÓÐÕߺË×¼µÄÇé¿öÏ£¬£¬£¬£¬£¬£¬Ô¶³ÌÖ´ÐÐËÁÒâShellºÅÁî¡£¡£¡£¡£¡£¡£¹¥»÷Õ߿ɽè´Ë£º
? ÆëÈ«½ÚÔìNodeÉ豸£º¶ÁÈ¡¡¢´Û¸Ä»òɾ³ý Node Ö÷»úÉϵÄËÁÒâÎļþ¡£¡£¡£¡£¡£¡£
? ÇÔÈ¡Ãô¸ÐÊý¾Ý£º»ñÈ¡NodeÉ豸ÉϵÄÍ´´¦¡¢ÃÜÔ¿¡¢ÒþÖÔÎļþµÈ¡£¡£¡£¡£¡£¡£
? ºáÏòÒÆ¶¯£ºÒÔNodeÖ÷»úÎªÌø°å£¬£¬£¬£¬£¬£¬½øÒ»²½ÉøÈëµØµãÍøÂçµÄÆäËûϵͳ¡£¡£¡£¡£¡£¡£
? ÓÆ¾Ã»¯×¤Áô£ºÖ²ÈëºóÃÅ·¨Ê½»ò°´Ê±¹¤×÷£¬£¬£¬£¬£¬£¬Î¬³Ö¶ÔNodeÉ豸µÄ³Ö¾Ã½Ó¼û¡£¡£¡£¡£¡£¡£
·ì϶¸´ÏÖ

°²È«½¨Òé
£¨1£©Á¢¼´Éý¼¶
OpenClaw¹Ù·½ÒѰ䲼°²È«¹«¸æ²¢°ä²¼Á˽¨¸´°æ±¾£¬£¬£¬£¬£¬£¬Ç뾡¿ìÉý¼¶ÖÁ×îа汾¡£¡£¡£¡£¡£¡£
£¨2£©Ò»Ê±»º½â´ëÊ©
? È·ÈÏGatewayδ¶³öµ½¹«Íø£ºGatewayĬÈϽö¼àÌý±¾»ú£¨127.0.0.1£©£¬£¬£¬£¬£¬£¬È·ÈÏÆô¶¯²ÎÊýÖÐδʹÓý«¶Ë¿Ú¶³öÖÁ±í²¿ÍøÂçµÄÅäÖᣡ£¡£¡£¡£¡£
? Éó²éº¹ÇàÖ´Ðмͼ£ºÅŲéNodeÖ÷»úÉÏÊÇ·ñ´æÔÚÒì³£µÄsystem.runŲÓ㬣¬£¬£¬£¬£¬³Áµã¹Ø×¢Î´¾Õý³£ÉóÅúÁ÷³Ì¡¢Ö±½ÓЯ´øapproved: trueµÄÒªÇ󡣡£¡£¡£¡£¡£
? ×îÓ×ȨÏÞÔËÐУºÒÔ×îµÍ±ØÒªÈ¨ÏÞÔËÐÐNode¹ý³Ì£¬£¬£¬£¬£¬£¬Ô¤·ÀʹÓÃroot»òÖÎÀíÔ¹ØË»§£¬£¬£¬£¬£¬£¬½µµÍºÅÁîÖ´ÐкóµÄÓ°ÏìÁìÓò¡£¡£¡£¡£¡£¡£
½ØÖÁĿǰ£¬£¬£¬£¬£¬£¬OpenClawÏîÄ¿ÖÐÒÑÀۼƷ¢ÏÖ283¸ö°²È«·ì϶¡£¡£¡£¡£¡£¡£±¾ÎÄ·ÖÎöµÄÉóÅúÈÆ¹ý·ì϶ÊÇÒ»¸öµäÐͰ¸Àý£ºÖ°ÄÜÂß¼ÆëÈ«£¬£¬£¬£¬£¬£¬µ«Î´ÑéÖ¤"ÉóÅúÁ˾ÖÊÇ·ñÕæÊ·´×ÔÓû§"¡£¡£¡£¡£¡£¡£ÕâÒ²·´Ó³ÁËAI AgentÔÚ°²È«Éè¼ÆÉÏ´æÔڶ̰壺ϵͳÍùÍùÆ«²îÓÚÐÅÀµÊäÈ룬£¬£¬£¬£¬£¬ÓÅÏÈʵÏÖÖ°ÄܶøºöÊÓÁËÌìǵǰÌáºÍ°²È«Ð£Ñé¡£¡£¡£¡£¡£¡£³ö¸ñÊÇÔÚÉæ¼°È¨ÏÞУÑé¡¢ÐÅÀµÌìǵµÈ°²È«¹Ø¼üõ辶ʱ£¬£¬£¬£¬£¬£¬ºöÊÓÕâЩϸ½Ú¿ÉÄÜ´øÀ´ÑϳÁµÄ°²È«·çÏÕ¡£¡£¡£¡£¡£¡£Òò¶ø£¬£¬£¬£¬£¬£¬Óû§ÔÚʹÓÃAI AgentʱӦά³ÖÉóÉ÷£¬£¬£¬£¬£¬£¬È·±£¶ÔDZÔڵݲȫÍþвºÍ·ì϶½øÐгä·ÖµÄ¼ø±ðÓë·À±¸¡£¡£¡£¡£¡£¡£
²Î¿¼Á´½Ó£º
[1]https://github.com/advisories/GHSA-gv46-4xfq-jv58
[2]https://nvd.nist.gov/vuln/detail/CVE-2026-28466


¾©¹«Íø°²±¸11010802024551ºÅ