CVE WATCH / VULNERABILITY DETAIL

CVE-2026-100561

HIGHCVSS 8NVD feed

Published 26 September 2026 · tracked since 26 September 2026

Description

OpenClaw (npm package 'openclaw') versions >= 2026.3.22 and < 2026.8.1 contain an approval-bypass flaw in the exec approval policy: the policy could trust a command-running wrapper without inspecting the command carried in its arguments. After an operator allowlisted or permanently approved a benign

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

CVE-2026-100561 — Vulnerability Details | Logic Encoder
CVE WATCH / VULNERABILITY DETAIL

CVE-2026-100561

HIGHCVSS 8NVD feed

Published 26 September 2026 · tracked since 26 September 2026

Description

OpenClaw (npm package 'openclaw') versions >= 2026.3.22 and < 2026.8.1 contain an approval-bypass flaw in the exec approval policy: the policy could trust a command-running wrapper without inspecting the command carried in its arguments. After an operator allowlisted or permanently approved a benign

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

[an error occurred while processing this directive]