🚨 CVE-2026-100541
OpenClaw's Matrix integration (npm package @openclaw/matrix) versions >= 2026.2.2 and < 2026.8.1 lowercase complete Matrix user IDs — including historical localparts and the case-sensitive server-name portion — when deriving the OpenClaw authorization identity. As a result, distinct authenticated Matrix accounts can normalize to the same authorization identity. A Matrix participant controlling a colliding account identifier (a protocol-valid identifier that differs from the configured one only by characters OpenClaw case/Unicode folds; display-name matching is not required) can inherit allowlist, owner-command, exec-approval, or plugin-approval authority configured for another account. The issue is fixed in 2026.8.1.
🎖@cveNotify
OpenClaw's Matrix integration (npm package @openclaw/matrix) versions >= 2026.2.2 and < 2026.8.1 lowercase complete Matrix user IDs — including historical localparts and the case-sensitive server-name portion — when deriving the OpenClaw authorization identity. As a result, distinct authenticated Matrix accounts can normalize to the same authorization identity. A Matrix participant controlling a colliding account identifier (a protocol-valid identifier that differs from the configured one only by characters OpenClaw case/Unicode folds; display-name matching is not required) can inherit allowlist, owner-command, exec-approval, or plugin-approval authority configured for another account. The issue is fixed in 2026.8.1.
🎖@cveNotify
GitHub
Matrix authorization could conflate case-distinct user IDs
### Summary
Matrix authorization lowercased complete user IDs, including historical localparts and the case-sensitive server-name portion. Distinct authenticated Matrix accounts could therefore no...
Matrix authorization lowercased complete user IDs, including historical localparts and the case-sensitive server-name portion. Distinct authenticated Matrix accounts could therefore no...
🚨 CVE-2026-100542
OpenClaw (npm package 'openclaw') versions >= 2026.5.28 and < 2026.8.1 mishandle archive listings in the tar.bz2 skill installer: bounded command-output suffixes were treated as complete listings of the archive. A crafted .tar.bz2/.tbz2 skill archive can push prohibited entries out of both retained listings so that entry-count and size checks pass, and the archive is then extracted in full. If an operator approves installation of such a malicious or compromised skill archive, over-limit files or entry counts are persisted in the skill tools directory, consuming disk space or inodes. The issue bypasses OpenClaw's extraction budgets but does not by itself execute archive contents. Fixed in 2026.8.1.
🎖@cveNotify
OpenClaw (npm package 'openclaw') versions >= 2026.5.28 and < 2026.8.1 mishandle archive listings in the tar.bz2 skill installer: bounded command-output suffixes were treated as complete listings of the archive. A crafted .tar.bz2/.tbz2 skill archive can push prohibited entries out of both retained listings so that entry-count and size checks pass, and the archive is then extracted in full. If an operator approves installation of such a malicious or compromised skill archive, over-limit files or entry counts are persisted in the skill tools directory, consuming disk space or inodes. The issue bypasses OpenClaw's extraction budgets but does not by itself execute archive contents. Fixed in 2026.8.1.
🎖@cveNotify
GitHub
Truncated tar listings could bypass extraction limits
### Summary
The `tar.bz2` skill installer treated bounded command-output suffixes as complete archive listings. A crafted archive could push prohibited entries out of both retained listings, pass ...
The `tar.bz2` skill installer treated bounded command-output suffixes as complete archive listings. A crafted archive could push prohibited entries out of both retained listings, pass ...
🚨 CVE-2026-100543
OpenClaw (npm package openclaw) before 2026.8.1 could include deterministic hashes computed over the original, unredacted configuration in redacted configuration responses. When the Gateway password had low entropy and the remaining configuration values were reconstructable, these hashes acted as offline password verifiers: a caller able to obtain the redacted configuration (for example via config.get) could test password candidates offline without going through the rate-limited Gateway authentication path. Recovering the password could grant the documented shared-secret operator authority. Secret references were not affected in the same way. The issue is fixed in 2026.8.1.
🎖@cveNotify
OpenClaw (npm package openclaw) before 2026.8.1 could include deterministic hashes computed over the original, unredacted configuration in redacted configuration responses. When the Gateway password had low entropy and the remaining configuration values were reconstructable, these hashes acted as offline password verifiers: a caller able to obtain the redacted configuration (for example via config.get) could test password candidates offline without going through the rate-limited Gateway authentication path. Recovering the password could grant the documented shared-secret operator authority. Secret references were not affected in the same way. The issue is fixed in 2026.8.1.
🎖@cveNotify
GitHub
Config revision hashes could expose password verifiers
### Summary
Redacted configuration responses could include deterministic hashes computed over the original unredacted configuration. When a Gateway password had low entropy and the rest of the con...
Redacted configuration responses could include deterministic hashes computed over the original unredacted configuration. When a Gateway password had low entropy and the rest of the con...
🚨 CVE-2026-100544
openclaw's @openclaw/voice-call package before 2026.8.1 launches the configured agent for classic inbound voice calls without propagating the caller's identity or non-owner status. As a result, owner-only tool filtering can fail open and expose the agent's normal tool authority to a remote caller. A caller who is admitted by the configured inbound-call policy (open, pairing, or allowlist) on a deployment with inbound calling enabled can therefore drive tools intended for the trusted owner, potentially reading data, modifying files, executing commands, or controlling connected services depending on the agent's configuration. The issue is fixed in 2026.8.1.
🎖@cveNotify
openclaw's @openclaw/voice-call package before 2026.8.1 launches the configured agent for classic inbound voice calls without propagating the caller's identity or non-owner status. As a result, owner-only tool filtering can fail open and expose the agent's normal tool authority to a remote caller. A caller who is admitted by the configured inbound-call policy (open, pairing, or allowlist) on a deployment with inbound calling enabled can therefore drive tools intended for the trusted owner, potentially reading data, modifying files, executing commands, or controlling connected services depending on the agent's configuration. The issue is fixed in 2026.8.1.
🎖@cveNotify
GitHub
Inbound voice calls could inherit owner tool authority
### Summary
Classic inbound voice calls could launch the configured agent without carrying the caller's identity or non-owner status. Owner-only filtering could therefore fail open and expose ...
Classic inbound voice calls could launch the configured agent without carrying the caller's identity or non-owner status. Owner-only filtering could therefore fail open and expose ...
🚨 CVE-2026-100546
OpenClaw (npm package `openclaw`) versions >= 2026.7.2 and < 2026.9.2 contain a race condition in the Discord realtime voice transcript path. Concurrent control-classified voice transcripts could consume speaker context belonging to another participant after an asynchronous control check, causing a transcript to inherit another speaker's owner status. In Discord agent-proxy voice sessions using the affected realtime control path, an utterance from a non-owner participant could reach the downstream agent boundary marked as owner, so owner-sensitive behavior is applied to the wrong speaker. Exploitation depends on concurrent transcript timing and on the tools and commands available to the affected agent. The issue is fixed in 2026.9.2; as a workaround, disable Discord realtime voice for agents that distinguish owner and non-owner senders.
🎖@cveNotify
OpenClaw (npm package `openclaw`) versions >= 2026.7.2 and < 2026.9.2 contain a race condition in the Discord realtime voice transcript path. Concurrent control-classified voice transcripts could consume speaker context belonging to another participant after an asynchronous control check, causing a transcript to inherit another speaker's owner status. In Discord agent-proxy voice sessions using the affected realtime control path, an utterance from a non-owner participant could reach the downstream agent boundary marked as owner, so owner-sensitive behavior is applied to the wrong speaker. Exploitation depends on concurrent transcript timing and on the tools and commands available to the affected agent. The issue is fixed in 2026.9.2; as a workaround, disable Discord realtime voice for agents that distinguish owner and non-owner senders.
🎖@cveNotify
GitHub
Discord realtime transcripts could inherit another speaker's owner status
### Summary
Discord realtime transcripts could inherit another speaker's owner status. In affected versions, concurrent control-classified voice transcripts could consume speaker context belon...
Discord realtime transcripts could inherit another speaker's owner status. In affected versions, concurrent control-classified voice transcripts could consume speaker context belon...
🚨 CVE-2026-100547
OpenClaw is a coding agent distributed as the npm package `openclaw`. In affected versions (2026.7.1 through 2026.7.2), alternate but valid `file:` URL spellings supplied over the Agent Client Protocol (ACP) were treated as relative paths and were incorrectly classified as reads scoped to the session working directory. When an operator connected `openclaw acp client` to an untrusted or compromised ACP peer, that peer could request a read of a file outside the session working directory without the approval prompt normally required for that path, resulting in disclosure of local file contents. The demonstrated impact is limited to file confidentiality; mutating and command-capable tool classes are not affected. This issue is fixed in OpenClaw 2026.8.1.
🎖@cveNotify
OpenClaw is a coding agent distributed as the npm package `openclaw`. In affected versions (2026.7.1 through 2026.7.2), alternate but valid `file:` URL spellings supplied over the Agent Client Protocol (ACP) were treated as relative paths and were incorrectly classified as reads scoped to the session working directory. When an operator connected `openclaw acp client` to an untrusted or compromised ACP peer, that peer could request a read of a file outside the session working directory without the approval prompt normally required for that path, resulting in disclosure of local file contents. The demonstrated impact is limited to file confidentiality; mutating and command-capable tool classes are not affected. This issue is fixed in OpenClaw 2026.8.1.
🎖@cveNotify
GitHub
ACP file URLs could skip out-of-cwd read approval
### Summary
ACP file URLs could skip out-of-cwd read approval. In affected versions, alternate but valid `file:` URL spellings were treated as relative paths and incorrectly classified as reads sc...
ACP file URLs could skip out-of-cwd read approval. In affected versions, alternate but valid `file:` URL spellings were treated as relative paths and incorrectly classified as reads sc...
🚨 CVE-2026-100548
OpenClaw (npm package 'openclaw') versions >= 2026.3.28 and < 2026.8.1 contain a credential exposure issue in memory embedding failover. When remote embedding fallback is configured and the primary embedding provider fails, the request can be sent to a different fallback provider while still reusing the primary provider's configured API key, causing that credential to be transmitted as a bearer token to an unintended vendor. The practical impact depends on the configured providers, whether failover occurs, and the privileges attached to the primary provider key. The issue is fixed in 2026.8.1; as a workaround, disable cross-provider embedding fallback or configure each provider with separate, narrowly scoped credentials.
🎖@cveNotify
OpenClaw (npm package 'openclaw') versions >= 2026.3.28 and < 2026.8.1 contain a credential exposure issue in memory embedding failover. When remote embedding fallback is configured and the primary embedding provider fails, the request can be sent to a different fallback provider while still reusing the primary provider's configured API key, causing that credential to be transmitted as a bearer token to an unintended vendor. The practical impact depends on the configured providers, whether failover occurs, and the privileges attached to the primary provider key. The issue is fixed in 2026.8.1; as a workaround, disable cross-provider embedding fallback or configure each provider with separate, narrowly scoped credentials.
🎖@cveNotify
GitHub
Embedding fallback could forward a provider key across vendors
### Summary
Embedding fallback could forward a provider key across vendors. In affected versions, memory embedding failover could reuse the primary provider's configured API key while sending ...
Embedding fallback could forward a provider key across vendors. In affected versions, memory embedding failover could reuse the primary provider's configured API key while sending ...
🚨 CVE-2026-100549
OpenClaw versions before 2026.8.1 contain a path traversal vulnerability in QQBot voice attachment handling where filenames are decoded twice, allowing encoded traversal segments to reappear after sanitization. Attackers can supply crafted voice attachments that write files outside the intended staging directory to other process-writable locations.
🎖@cveNotify
OpenClaw versions before 2026.8.1 contain a path traversal vulnerability in QQBot voice attachment handling where filenames are decoded twice, allowing encoded traversal segments to reappear after sanitization. Attackers can supply crafted voice attachments that write files outside the intended staging directory to other process-writable locations.
🎖@cveNotify
GitHub
QQBot voice filenames could escape the staging directory
### Summary
QQBot voice filenames could escape the staging directory. In affected versions, voice attachment filenames were decoded twice, allowing encoded traversal segments to reappear after fil...
QQBot voice filenames could escape the staging directory. In affected versions, voice attachment filenames were decoded twice, allowing encoded traversal segments to reappear after fil...
🚨 CVE-2026-100550
OpenClaw (npm package 'openclaw') before 2026.8.1 contains an access-control bypass in the Microsoft Teams integration. When groupPolicy is set to allowlist, a missing or unsupported configured access group produces a denied group-resolution result that is not rejected by the final message-admission check, so a Teams member who is not on the allowlist can still trigger the configured agent despite the administrator's group boundary. The impact depends on the conversations, tools, and data available to that agent. The issue is fixed in version 2026.8.1.
🎖@cveNotify
OpenClaw (npm package 'openclaw') before 2026.8.1 contains an access-control bypass in the Microsoft Teams integration. When groupPolicy is set to allowlist, a missing or unsupported configured access group produces a denied group-resolution result that is not rejected by the final message-admission check, so a Teams member who is not on the allowlist can still trigger the configured agent despite the administrator's group boundary. The impact depends on the conversations, tools, and data available to that agent. The issue is fixed in version 2026.8.1.
🎖@cveNotify
GitHub
Microsoft Teams access-group failures could admit unlisted senders
### Summary
Microsoft Teams access-group failures could admit unlisted senders. In affected versions, missing or unsupported configured access groups produced denied results that were not rejected...
Microsoft Teams access-group failures could admit unlisted senders. In affected versions, missing or unsupported configured access groups produced denied results that were not rejected...
🚨 CVE-2026-100551
OpenClaw for iOS versions >= 2026.7.1 and < 2026.8.11 do not enforce saved Gateway TLS pins in the Control UI. While native connections enforced the saved Gateway fingerprint, the authenticated Terminal and session Dashboard WebViews omitted it. If a user had accepted a Gateway fingerprint, an attacker able to redirect the same host and port and present a different certificate that is accepted by iOS system trust can serve a replacement Control UI page; opening the Terminal or a session Dashboard then allows that page to read the injected Gateway token or password. The stolen credential can grant operator access, including reading sensitive Gateway state and invoking host-capable tools. This issue is fixed in 2026.8.11.
🎖@cveNotify
OpenClaw for iOS versions >= 2026.7.1 and < 2026.8.11 do not enforce saved Gateway TLS pins in the Control UI. While native connections enforced the saved Gateway fingerprint, the authenticated Terminal and session Dashboard WebViews omitted it. If a user had accepted a Gateway fingerprint, an attacker able to redirect the same host and port and present a different certificate that is accepted by iOS system trust can serve a replacement Control UI page; opening the Terminal or a session Dashboard then allows that page to read the injected Gateway token or password. The stolen credential can grant operator access, including reading sensitive Gateway state and invoking host-capable tools. This issue is fixed in 2026.8.11.
🎖@cveNotify
GitHub
iOS Control UI did not enforce saved Gateway TLS pins
### Summary
The iOS Control UI did not enforce saved Gateway TLS pins. In affected versions, authenticated Terminal and session Dashboard WebViews omitted the saved Gateway fingerprint even though...
The iOS Control UI did not enforce saved Gateway TLS pins. In affected versions, authenticated Terminal and session Dashboard WebViews omitted the saved Gateway fingerprint even though...
🚨 CVE-2026-100552
OpenClaw (npm package 'openclaw') before 2026.8.1 does not correctly enforce per-chat tool policies for Codex app-server runtime tools. A conversation-level tools.allow rule filtered OpenClaw tools but did not restrict the shell, process, file, and patch tools owned by the Codex runtime. When a lower-trust conversation was assigned to a Codex runtime and restricted with a per-chat tool allowlist, a participant able to trigger that agent could still reach native command and file tools, bypassing the configured allowlist. The practical impact depends on the runtime's host permissions and sandbox configuration. The issue is fixed in 2026.8.1.
🎖@cveNotify
OpenClaw (npm package 'openclaw') before 2026.8.1 does not correctly enforce per-chat tool policies for Codex app-server runtime tools. A conversation-level tools.allow rule filtered OpenClaw tools but did not restrict the shell, process, file, and patch tools owned by the Codex runtime. When a lower-trust conversation was assigned to a Codex runtime and restricted with a per-chat tool allowlist, a participant able to trigger that agent could still reach native command and file tools, bypassing the configured allowlist. The practical impact depends on the runtime's host permissions and sandbox configuration. The issue is fixed in 2026.8.1.
🎖@cveNotify
GitHub
Codex native tools could ignore per-chat policy
### Summary
Codex native tools could ignore per-chat policy. In affected versions, a conversation-level `tools.allow` rule filtered OpenClaw tools but did not restrict shell, process, file, and pa...
Codex native tools could ignore per-chat policy. In affected versions, a conversation-level `tools.allow` rule filtered OpenClaw tools but did not restrict shell, process, file, and pa...
🚨 CVE-2026-100553
OpenClaw versions >= 2026.6.9 and < 2026.8.1 do not declare the native chatId parameter as a delivery target in the Feishu unpin feature, so unpin requests can bypass the shared same-provider cross-context target check. When tools.message.crossContext.allowWithinProvider is disabled, an admitted (authenticated) sender can remove a pin from another Feishu group that the sender and the configured account are otherwise permitted to access, bypassing the intended cross-context message mutation policy. Feishu membership and group authorization still apply, and the demonstrated impact is limited to message mutation (pin removal). The issue is fixed in 2026.8.1.
🎖@cveNotify
OpenClaw versions >= 2026.6.9 and < 2026.8.1 do not declare the native chatId parameter as a delivery target in the Feishu unpin feature, so unpin requests can bypass the shared same-provider cross-context target check. When tools.message.crossContext.allowWithinProvider is disabled, an admitted (authenticated) sender can remove a pin from another Feishu group that the sender and the configured account are otherwise permitted to access, bypassing the intended cross-context message mutation policy. Feishu membership and group authorization still apply, and the demonstrated impact is limited to message mutation (pin removal). The issue is fixed in 2026.8.1.
🎖@cveNotify
GitHub
Feishu unpin could miss cross-context policy
### Summary
Feishu unpin could miss cross-context policy. In affected versions, the native `chatId` parameter was not declared as a delivery target, so `unpin` could avoid the shared same-provider...
Feishu unpin could miss cross-context policy. In affected versions, the native `chatId` parameter was not declared as a delivery target, so `unpin` could avoid the shared same-provider...
🚨 CVE-2026-100554
OpenClaw (npm package 'openclaw') versions >= 2026.5.12 and < 2026.8.1 do not immediately invalidate Canvas HTTP authorization when a paired node is revoked. Node revocation invalidates the WebSocket client, but Canvas HTTP authorization continues to accept and renew the previously granted capability until WebSocket close cleanup completes. As a result, a revoked paired node can continue exercising its Canvas capability against the capability's configured routes during the close grace period. The issue is fixed in 2026.8.1; as a workaround, restart the Gateway after revoking a node that has Canvas access.
🎖@cveNotify
OpenClaw (npm package 'openclaw') versions >= 2026.5.12 and < 2026.8.1 do not immediately invalidate Canvas HTTP authorization when a paired node is revoked. Node revocation invalidates the WebSocket client, but Canvas HTTP authorization continues to accept and renew the previously granted capability until WebSocket close cleanup completes. As a result, a revoked paired node can continue exercising its Canvas capability against the capability's configured routes during the close grace period. The issue is fixed in 2026.8.1; as a workaround, restart the Gateway after revoking a node that has Canvas access.
🎖@cveNotify
GitHub
Revoked Canvas capability could remain active during disconnect
### Summary
Revoked Canvas capability could remain active during disconnect. In affected versions, node revocation invalidated the WebSocket client but Canvas HTTP authorization continued acceptin...
Revoked Canvas capability could remain active during disconnect. In affected versions, node revocation invalidated the WebSocket client but Canvas HTTP authorization continued acceptin...
🚨 CVE-2026-100555
OpenClaw is an npm-distributed gateway application. In versions >= 2026.7.1 and < 2026.8.1, Synology Chat attachment delivery could lose DNS pinning: the Gateway validated a single DNS result for a supplied file URL but then passed the original hostname to the Synology NAS, where it could resolve to a different destination. When attachment delivery accepted a remotely influenced hostname, an attacker could use DNS rebinding to make the NAS fetch a private or otherwise policy-denied resource and return its contents to the addressed conversation (server-side request forgery). Practical impact depends on NAS routing, resolver behavior, and the response available at the private destination. The issue is fixed in 2026.8.1; as a workaround, disable remote URL attachment forwarding in Synology Chat.
🎖@cveNotify
OpenClaw is an npm-distributed gateway application. In versions >= 2026.7.1 and < 2026.8.1, Synology Chat attachment delivery could lose DNS pinning: the Gateway validated a single DNS result for a supplied file URL but then passed the original hostname to the Synology NAS, where it could resolve to a different destination. When attachment delivery accepted a remotely influenced hostname, an attacker could use DNS rebinding to make the NAS fetch a private or otherwise policy-denied resource and return its contents to the addressed conversation (server-side request forgery). Practical impact depends on NAS routing, resolver behavior, and the response available at the private destination. The issue is fixed in 2026.8.1; as a workaround, disable remote URL attachment forwarding in Synology Chat.
🎖@cveNotify
GitHub
Synology file delivery could lose DNS pinning
### Summary
Synology file delivery could lose DNS pinning. In affected versions, the Gateway validated one DNS result for a file URL but passed the original hostname to the NAS, where it could res...
Synology file delivery could lose DNS pinning. In affected versions, the Gateway validated one DNS result for a file URL but passed the original hostname to the NAS, where it could res...
🚨 CVE-2026-100556
OpenClaw (npm package openclaw) versions >= 2026.5.2 and < 2026.8.1 contain an incorrect authorization vulnerability in WhatsApp group handling. A group sender who is admitted for ordinary messages but denied by commands.allowFrom or owner command authorization can issue the /new <model> command to reset the shared group session and persist a provider and model override. This allows a command-denied group member to select a provider and model already permitted by the operator for subsequent turns in the shared group session, potentially changing provider routing, cost, data flow, or availability. It does not allow adding a new provider or host command execution. The issue is fixed in version 2026.8.1.
🎖@cveNotify
OpenClaw (npm package openclaw) versions >= 2026.5.2 and < 2026.8.1 contain an incorrect authorization vulnerability in WhatsApp group handling. A group sender who is admitted for ordinary messages but denied by commands.allowFrom or owner command authorization can issue the /new <model> command to reset the shared group session and persist a provider and model override. This allows a command-denied group member to select a provider and model already permitted by the operator for subsequent turns in the shared group session, potentially changing provider routing, cost, data flow, or availability. It does not allow adding a new provider or host command execution. The issue is fixed in version 2026.8.1.
🎖@cveNotify
GitHub
WhatsApp session resets could bypass command authorization
### Summary
WhatsApp session resets could bypass command authorization. In affected versions, a group sender admitted for ordinary messages could use `/new <model>` to reset the shared group...
WhatsApp session resets could bypass command authorization. In affected versions, a group sender admitted for ordinary messages could use `/new <model>` to reset the shared group...
🚨 CVE-2026-100557
OpenClaw versions before 2026.8.1 contain an authorization bypass vulnerability in skill tool dispatch that fails to carry the sender's owner status. Non-owner senders authorized to invoke skill commands can access owner-only tools and server credentials reserved for owners.
🎖@cveNotify
OpenClaw versions before 2026.8.1 contain an authorization bypass vulnerability in skill tool dispatch that fails to carry the sender's owner status. Non-owner senders authorized to invoke skill commands can access owner-only tools and server credentials reserved for owners.
🎖@cveNotify
GitHub
Skill tool dispatch could skip owner-only policy
### Summary
Skill tool dispatch could skip owner-only policy. In affected versions, an allowlisted non-owner invoking a skill-backed command could reach owner-only tools because the dispatch path ...
Skill tool dispatch could skip owner-only policy. In affected versions, an allowlisted non-owner invoking a skill-backed command could reach owner-only tools because the dispatch path ...
🚨 CVE-2026-100558
OpenClaw versions before 2026.8.1 contain a resource exhaustion vulnerability in the Gateway listener that allows unauthenticated clients to retain response sockets by sending WebSocket upgrade requests without matching connection semantics. Attackers can repeatedly send malformed upgrade requests to exhaust listener resources and cause denial of service without consuming the WebSocket pre-auth connection budget.
🎖@cveNotify
OpenClaw versions before 2026.8.1 contain a resource exhaustion vulnerability in the Gateway listener that allows unauthenticated clients to retain response sockets by sending WebSocket upgrade requests without matching connection semantics. Attackers can repeatedly send malformed upgrade requests to exhaust listener resources and cause denial of service without consuming the WebSocket pre-auth connection budget.
🎖@cveNotify
GitHub
Gateway upgrade-like requests could retain unauthenticated sockets
### Summary
Gateway upgrade-like requests could retain unauthenticated sockets. In affected versions, an HTTP request carrying a WebSocket upgrade header without the matching connection semantics ...
Gateway upgrade-like requests could retain unauthenticated sockets. In affected versions, an HTTP request carrying a WebSocket upgrade header without the matching connection semantics ...
🚨 CVE-2026-100559
OpenClaw versions before 2026.8.1 contain a command parser vulnerability where escaped newlines confuse exec allowlist parsing, allowing hidden commands to execute. Attackers can craft input with escaped newlines to bypass allowlist validation and execute additional commands without expected authorization prompts.
🎖@cveNotify
OpenClaw versions before 2026.8.1 contain a command parser vulnerability where escaped newlines confuse exec allowlist parsing, allowing hidden commands to execute. Attackers can craft input with escaped newlines to bypass allowlist validation and execute additional commands without expected authorization prompts.
🎖@cveNotify
GitHub
Escaped newlines could confuse exec allowlist parsing
### Summary
Escaped newlines could confuse exec allowlist parsing. In affected versions, the command parser could describe and authorize one visible shell word sequence while execution included an...
Escaped newlines could confuse exec allowlist parsing. In affected versions, the command parser could describe and authorize one visible shell word sequence while execution included an...
🚨 CVE-2026-100560
OpenClaw versions before 2026.8.1 contain an authorization bypass vulnerability where Allow Always approvals for exact commands persist as path-only grants on macOS and Linux. Attackers can reuse the same executable with different arguments to execute commands without triggering new approval prompts, potentially accessing files or internal services.
🎖@cveNotify
OpenClaw versions before 2026.8.1 contain an authorization bypass vulnerability where Allow Always approvals for exact commands persist as path-only grants on macOS and Linux. Attackers can reuse the same executable with different arguments to execute commands without triggering new approval prompts, potentially accessing files or internal services.
🎖@cveNotify
GitHub
Reusable exec approvals could authorize changed arguments
### Summary
Reusable exec approvals could authorize changed arguments. In affected versions on macOS and Linux, selecting Allow Always for one exact command persisted a path-only grant. Later uses...
Reusable exec approvals could authorize changed arguments. In affected versions on macOS and Linux, selecting Allow Always for one exact command persisted a path-only grant. Later uses...
🚨 CVE-2026-100561
OpenClaw (npm package 'openclaw') versions >= 2026.3.22 and < 2026.8.1 contain an approval-bypass flaw in the exec approval policy: the policy could trust a command-running wrapper without inspecting the command carried in its arguments. After an operator allowlisted or permanently approved a benign wrapper invocation, a later agent turn could substitute an arbitrary inner command and execute it with the OpenClaw process's host privileges without a further approval prompt. Exploitation requires the relevant wrapper to resolve on the host and a prior operator decision allowing that wrapper. Transparent shell carriers and opaque utilities such as process monitors, tracers, namespace tools, and proxy wrappers were affected through related trust-resolution gaps. Fixed in 2026.8.1.
🎖@cveNotify
OpenClaw (npm package 'openclaw') versions >= 2026.3.22 and < 2026.8.1 contain an approval-bypass flaw in the exec approval policy: the policy could trust a command-running wrapper without inspecting the command carried in its arguments. After an operator allowlisted or permanently approved a benign wrapper invocation, a later agent turn could substitute an arbitrary inner command and execute it with the OpenClaw process's host privileges without a further approval prompt. Exploitation requires the relevant wrapper to resolve on the host and a prior operator decision allowing that wrapper. Transparent shell carriers and opaque utilities such as process monitors, tracers, namespace tools, and proxy wrappers were affected through related trust-resolution gaps. Fixed in 2026.8.1.
🎖@cveNotify
GitHub
Exec wrapper allowlists could trust arbitrary inner commands
### Summary
Exec approval policy could trust a command-running wrapper without inspecting the command carried in its arguments. After an operator allowlisted or permanently approved a benign wrapp...
Exec approval policy could trust a command-running wrapper without inspecting the command carried in its arguments. After an operator allowlisted or permanently approved a benign wrapp...
🚨 CVE-2026-100562
OpenClaw versions before 2026.8.1 contain an authorization bypass vulnerability in the sessions.create endpoint that allows operator.write callers to modify session configurations reserved for operator.admin scope. Attackers with write-scoped credentials can change existing session model, provider, thinking level, and auth-profile settings to redirect traffic and bypass administrative access controls.
🎖@cveNotify
OpenClaw versions before 2026.8.1 contain an authorization bypass vulnerability in the sessions.create endpoint that allows operator.write callers to modify session configurations reserved for operator.admin scope. Attackers with write-scoped credentials can change existing session model, provider, thinking level, and auth-profile settings to redirect traffic and bypass administrative access controls.
🎖@cveNotify
GitHub
sessions.create could miss admin scope for keyed reconfiguration
### Summary
`sessions.create` could miss admin scope for keyed reconfiguration. In affected versions, an `operator.write` caller could target an existing session key while supplying model or think...
`sessions.create` could miss admin scope for keyed reconfiguration. In affected versions, an `operator.write` caller could target an existing session key while supplying model or think...