¡¾¸´ÏÖ¡¿OpenClawÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2026-28466£©
Ðû²¼Ê±¼ä 2026-03-13OpenClawÒÀ¸½Æä¸»ºñµÄ¹¦Ð§ºÍÎÞаÐÔ£¬£¬£¬£¬£¬ÔÚ2026Äê³ÉΪ¿ªÔ´È˹¤ÖÇÄÜÊðÀíÉú̬ϵͳÖеÄÃ÷ÐÇÏîÄ¿¡£¡£¡£¡£¡£¡£×÷Ϊһ¸ö̸Ìì»úеÈËÆ½Ì¨£¬£¬£¬£¬£¬OpenClawÔÊÐíÓû§Í¨¹ýWeb½çÃæ»ò¼´Ê±Í¨Ñ¶Æ½Ì¨Ï´ï×ÔÈ»ÓïÑÔÖ¸Á£¬£¬£¬£¬Íê³ÉÓʼþÖÎÀí¡¢ÈÕÀúµ÷Àí¡¢ä¯ÀÀÆ÷×Ô¶¯»¯¡¢Îļþ²Ù×÷ÒÔ¼°shellÏÂÁîÖ´ÐеȸßȨÏÞʹÃü¡£¡£¡£¡£¡£¡£
¿ËÈÕ£¬£¬£¬£¬£¬OpenClawÐÞ¸´ÁËÒ»¸öCVSSÆÀ·ÖΪ9.4µÄÑÏÖØÎó²îCVE-2026-28466£¬£¬£¬£¬£¬¸ÃÎó²îÊÇÔÚGatewayת·¢node.invokeÇëÇóʱ£¬£¬£¬£¬£¬Î´¶ÔÓû§´«ÈëµÄ²ÎÊý×öÈκιýÂË£¬£¬£¬£¬£¬µ¼Ö¾ÓÉÈÏÖ¤µÄ¿Í»§¶Ë¿ÉÒÔÈÆ¹ýÖ´ÐÐÉóÅú»úÖÆ¡£¡£¡£¡£¡£¡£ÓµÓÐÓÐÓÃÍø¹ØÆ¾Ö¤µÄ¹¥»÷Õß¿ÉÒÔ×¢ÈëÉóÅú¿ØÖÆ×ֶΣ¬£¬£¬£¬£¬ÔÚÅþÁ¬µÄ½ÚµãÖ÷»úÉÏÖ´ÐÐí§ÒâÏÂÁ£¬£¬£¬£¬ÀÖ³ÉʹÓý«µ¼ÖÂÍêÈ«¿ØÖƽڵãÖ÷»ú¡£¡£¡£¡£¡£¡£Æ¾Ö¤ÍøÂç¿Õ¼ä²â»æÒýÇæFOFAµÄÊý¾Ý£¬£¬£¬£¬£¬×èÖ¹2026Äê3ÔÂ13ÈÕ£¬£¬£¬£¬£¬»¥ÁªÍøÉϱ£´æ116,672¸öDZÔÚµÄÒ×Êܹ¥»÷OpenClawʵÀý¡£¡£¡£¡£¡£¡£
Îó²îÐÎò
GatewayÊÇOpenClawµÄ½¹µãЧÀÍ£¬£¬£¬£¬£¬ÈÏÕæÖÎÀíËùÓÐÐÂÎÅͨµÀ¡¢»á»°µ÷ÀíºÍAgent±àÅÅ£¬£¬£¬£¬£¬¶ÔÍâÌṩWebSocket API¡£¡£¡£¡£¡£¡£NodeÊÇÅþÁ¬µ½GatewayµÄÖÕ¶Ë×°±¸£¨È磺macOS/iOS/Android Ó¦ÓûòÏÂÁîÐÐÀú³Ì£©£¬£¬£¬£¬£¬ÎªÏµÍ³ÌṩÍâµØÖ´ÐÐÄÜÁ¦£¬£¬£¬£¬£¬°üÀ¨ÔËÐÐShellÏÂÁî¡¢²Ù¿Øä¯ÀÀÆ÷¡¢»á¼ûÉãÏñÍ·µÈ×°±¸¹¦Ð§¡£¡£¡£¡£¡£¡£Gatewayͨ¹ýnode.invoke½«Ö´ÐÐÇëÇó·¢Ë͵½Ä¿µÄNode£¬£¬£¬£¬£¬NodeÔÚÍâµØÍê³ÉÖ´Ðкó½«Ð§¹û»Ø´«¸øGateway£¬£¬£¬£¬£¬Õû¸öÀú³Ìͨ¹ýWebSocketµÄÇëÇó-ÏìÓ¦»úÖÆÍê³É¡£¡£¡£¡£¡£¡£
2026.2.14֮ǰ°æ±¾µÄOpenClawÖУ¬£¬£¬£¬£¬GatewayÔÚת·¢node.invokeÇëÇóʱδ¶Ôparams²ÎÊý¾ÙÐйýÂË£¬£¬£¬£¬£¬¾ÓÉÉí·ÝÈÏÖ¤µÄÓû§¿ÉÒÔÔÚŲÓòÎÊýÖÐ×¢ÈëapprovedÄÚ²¿¿ØÖÆ×ֶΣ¬£¬£¬£¬£¬ÈƹýNodeÖ÷»úµÄÖ´ÐÐÉóÅú»úÖÆ£¬£¬£¬£¬£¬Í¨¹ýsystem.runÔÚNodeÉÏÖ´ÐÐí§ÒâshellÏÂÁî¡£¡£¡£¡£¡£¡£
Ó°Ïì°æ±¾
OpenClaw<2026.2.14
Îó²îÔÀí
¸ÃÎó²îµÄ¸ùÒòÔÚÓÚ´ÓGatewayµ½NodeµÄÕûÌõŲÓÃÁ´Â·ÉÏ£¬£¬£¬£¬£¬¾ùδ¶ÔÓû§¿É¿ØµÄ²ÎÊý×ֶξÙÐÐУÑé»ò¹ýÂË¡£¡£¡£¡£¡£¡£
£¨1£©Gateway¶Ë£ºÔÑùת·¢£¬£¬£¬£¬£¬²»¹ýÂËÄÚ²¿×Ö¶Î
GatewayµÄnode.invoke´¦Öóͷ£º¯Êý½«¿Í»§¶Ë´«ÈëµÄparamsÖ±½Óת´ï¸ønodeRegistry.invoke()£¬£¬£¬£¬£¬Î´×öÈκÎ×ֶΰþÀë¡£¡£¡£¡£¡£¡£

£¨2£©Node Registry£ºÐòÁл¯ºóÖ±½Ó·¢ËÍ
params±»ÐòÁл¯ÎªparamsJSONºóÖ±½Óͨ¹ýWebSocket·¢Ë͸øNode£¬£¬£¬£¬£¬Í¬ÑùûÓйýÂË¡£¡£¡£¡£¡£¡£

£¨3£©Node¶Ë£ºÖ±½ÓÐÅÈÎparamsÖеÄÉóÅú×Ö¶Î
Node·´ÐòÁл¯ºóµÄ²ÎÊýÖаüÀ¨ÉóÅú¿ØÖÆ×ֶΣ¬£¬£¬£¬£¬ÉóÅúÅжÏÂß¼Ö±½Ó¶ÁÈ¡¸Ã×Ö¶ÎÇÒÎÞÈκÎȪԴÑéÖ¤¡£¡£¡£¡£¡£¡£µ±¸Ã×ֶα»ÉèΪͨ¹ý״̬ʱ£¬£¬£¬£¬£¬ÉóÅú¼ì²éºÍ°×Ãûµ¥Ð£Ñé¾ù±»Ìø¹ý£¬£¬£¬£¬£¬ÏÂÁîÖ±½ÓÖ´ÐУ¬£¬£¬£¬£¬Óû§²»»á¿´µ½ÈκÎÉóÅúÌáÐÑ¡£¡£¡£¡£¡£¡£

Îó²îΣº¦
¸ÃÎó²îÔÊÐíÈκξÓÉGatewayÉí·ÝÈÏÖ¤µÄÓû§ÔÚδ¾NodeÖ÷»úËùÓÐÕßÅú×¼µÄÇéÐÎÏ£¬£¬£¬£¬£¬Ô¶³ÌÖ´ÐÐí§ÒâShellÏÂÁî¡£¡£¡£¡£¡£¡£¹¥»÷Õ߿ɽè´Ë£º
? ÍêÈ«¿ØÖÆNode×°±¸£º¶ÁÈ¡¡¢¸Ä¶¯»òɾ³ý Node Ö÷»úÉϵÄí§ÒâÎļþ¡£¡£¡£¡£¡£¡£
? ÇÔÈ¡Ãô¸ÐÊý¾Ý£º»ñÈ¡NodeÉè±¹ØÁ¬Äƾ֤¡¢ÃÜÔ¿¡¢Òþ˽ÎļþµÈ¡£¡£¡£¡£¡£¡£
? ºáÏòÒÆ¶¯£ºÒÔNodeÖ÷»úÎªÌø°å£¬£¬£¬£¬£¬½øÒ»²½ÉøÍ¸ËùÔÚÍøÂçµÄÆäËûϵͳ¡£¡£¡£¡£¡£¡£
? ³¤ÆÚ»¯×¤Áô£ºÖ²ÈëºóÃųÌÐò»ò׼ʱʹÃü£¬£¬£¬£¬£¬Î¬³Ö¶ÔNode×°±¸µÄºã¾Ã»á¼û¡£¡£¡£¡£¡£¡£
Îó²î¸´ÏÖ

Çå¾²½¨Òé
£¨1£©Á¬Ã¦Éý¼¶
OpenClaw¹Ù·½ÒÑÐû²¼Ç徲ͨ¸æ²¢Ðû²¼ÁËÐÞ¸´°æ±¾£¬£¬£¬£¬£¬Ç뾡¿ìÉý¼¶ÖÁ×îа汾¡£¡£¡£¡£¡£¡£
£¨2£©ÔÝʱ»º½â²½·¥
? È·ÈÏGatewayδ̻¶µ½¹«Íø£ºGatewayĬÈϽö¼àÌý±¾»ú£¨127.0.0.1£©£¬£¬£¬£¬£¬È·ÈÏÆô¶¯²ÎÊýÖÐδʹÓý«¶Ë¿Ú̻¶ÖÁÍâ²¿ÍøÂçµÄÉèÖᣡ£¡£¡£¡£¡£
? Éó²éÀúÊ·Ö´Ðмͼ£ºÅŲéNodeÖ÷»úÉÏÊÇ·ñ±£´æÒì³£µÄsystem.runŲÓ㬣¬£¬£¬£¬ÖØµã¹Ø×¢Î´¾Õý³£ÉóÅúÁ÷³Ì¡¢Ö±½ÓЯ´øapproved: trueµÄÇëÇ󡣡£¡£¡£¡£¡£
? ×îСȨÏÞÔËÐУºÒÔ×îµÍÐëҪȨÏÞÔËÐÐNodeÀú³Ì£¬£¬£¬£¬£¬×èֹʹÓÃroot»òÖÎÀíÔ±ÕË»§£¬£¬£¬£¬£¬½µµÍÏÂÁîÖ´ÐкóµÄÓ°Ïì¹æÄ£¡£¡£¡£¡£¡£¡£
×èÖ¹ÏÖÔÚ£¬£¬£¬£¬£¬OpenClawÏîÄ¿ÖÐÒÑÀۼƷ¢Ã÷283¸öÇå¾²Îó²î¡£¡£¡£¡£¡£¡£±¾ÎÄÆÊÎöµÄÉóÅúÈÆ¹ýÎó²îÊÇÒ»¸öµä·¶°¸Àý£º¹¦Ð§Âß¼ÍêÕû£¬£¬£¬£¬£¬µ«Î´ÑéÖ¤"ÉóÅúЧ¹ûÊÇ·ñÕæÊµÀ´×ÔÓû§"¡£¡£¡£¡£¡£¡£ÕâÒ²·´Ó¦ÁËAI AgentÔÚÇå¾²Éè¼ÆÉϱ£´æ¶Ì°å£ºÏµÍ³ÍùÍùÇãÏòÓÚÐÅÈÎÊäÈ룬£¬£¬£¬£¬ÓÅÏÈʵÏÖ¹¦Ð§¶øºöÊÓÁ˽çÏßÌõ¼þºÍÇ徲УÑé¡£¡£¡£¡£¡£¡£ÌØÊâÊÇÔÚÉæ¼°È¨ÏÞУÑé¡¢ÐÅÈνçÏßµÈÇå¾²Òªº¦Â·¾¶Ê±£¬£¬£¬£¬£¬ºöÊÓÕâЩϸ½Ú¿ÉÄÜ´øÀ´ÑÏÖØµÄÇ徲Σº¦¡£¡£¡£¡£¡£¡£Òò´Ë£¬£¬£¬£¬£¬Óû§ÔÚʹÓÃAI AgentʱӦ¼á³ÖÉóÉ÷£¬£¬£¬£¬£¬È·±£¶ÔDZÔÚµÄÇå¾²ÍþвºÍÎó²î¾ÙÐгä·ÖµÄʶ±ðÓëÌá·À¡£¡£¡£¡£¡£¡£
²Î¿¼Á´½Ó£º
[1]https://github.com/advisories/GHSA-gv46-4xfq-jv58
[2]https://nvd.nist.gov/vuln/detail/CVE-2026-28466


¾©¹«Íø°²±¸11010802024551ºÅ