GHSA-xjhq-663j-6f87HighCVSS 8.8
OpenClaw Codex before 2026.7.1 fails to properly enforce owner authorization when creating native...
🔗 CVE IDs covered (1)
📋 Description
OpenClaw Codex before 2026.7.1 fails to properly enforce owner authorization when creating native conversation bindings. Non-owner channel senders with command access can create bindings to the native Codex runtime and execute host-capable turns with access to files, tools, and processes.