Impact
The vulnerability resides in the src/agents/bash-tools.exec.ts file of the Ggateway Exec Approval Flow component. Manipulating inputs causes the authorization logic to fail, allowing an attacker to trigger privileged bash-tool executions without proper approval. This creates a significant breach of confidentiality and integrity by granting unauthorized command execution privileges.
Affected Systems
Affected systems include the mf-yang openclaw-cn platform, version 2026.2.5, which incorporates the vulnerable component. Users running this specific release are exposed.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, but the lack of an available EPSS score and the absence from the CISA KEV catalog do not diminish the potential risk. The description confirms that the attack can be performed remotely and a public exploit exists, implying that malicious actors could use detailed instructions or scripts to abuse the flaw. Organizations still need to assess the criticality of the affected component within their infrastructure and consider mitigation right away.
OpenCVE Enrichment