Impact
OpenClaw implementations prior to version 2026.8.1 incorrectly allow an approved command to be executed in any working directory, because the working directory context is not bound to the approval. When an attacker obtains an "allow‑always" approval, the same approved command can be reused to target files or repositories that were not originally reviewed, potentially producing harmful results or further privilege escalation. The flaw is a direct impact on execution control, allowing attackers to execute arbitrary code or commands under a different context than intended.
Affected Systems
The vulnerability affects all OpenClaw versions before 2026.8.1. No additional version qualifiers are provided, so any installation with a version number lower than 2026.8.1 is at risk.
Risk and Exploitability
The vulnerability has a CVSS score of 8.5, indicating high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the attack vector is likely local or relies on administrative privilege to obtain an "allow‑always" approval. An attacker who can grant themselves or gain this approval can reuse it to execute approved commands in arbitrary directories, impacting confidentiality, integrity, and availability in the affected environment.
OpenCVE Enrichment