GHSA-xp58-99vr-2354HighCVSS 7.5

OpenClaw versions before 2026.8.1 contain an authorization bypass vulnerability where Allow...

Published
September 26, 2026
Last Modified
September 26, 2026

🔗 CVE IDs covered (1)

📋 Description

OpenClaw versions before 2026.8.1 contain an authorization bypass vulnerability where Allow Always approvals for exact commands persist as path-only grants on macOS and Linux. Attackers can reuse the same executable with different arguments to execute commands without triggering new approval prompts, potentially accessing files or internal services.

🔗 References (4)