Description
A vulnerability was found in mf-yang openclaw-cn 2026.2.5. This affects an unknown part of the file src/agents/bash-tools.exec.ts of the component Ggateway Exec Approval Flow. The manipulation results in incorrect authorization. The attack may be performed from remote. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet.
Published: 2026-08-06
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in the src/agents/bash-tools.exec.ts file of the Ggateway Exec Approval Flow component. Manipulating inputs causes the authorization logic to fail, allowing an attacker to trigger privileged bash-tool executions without proper approval. This creates a significant breach of confidentiality and integrity by granting unauthorized command execution privileges.

Affected Systems

Affected systems include the mf-yang openclaw-cn platform, version 2026.2.5, which incorporates the vulnerable component. Users running this specific release are exposed.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity, but the lack of an available EPSS score and the absence from the CISA KEV catalog do not diminish the potential risk. The description confirms that the attack can be performed remotely and a public exploit exists, implying that malicious actors could use detailed instructions or scripts to abuse the flaw. Organizations still need to assess the criticality of the affected component within their infrastructure and consider mitigation right away.

Generated by OpenCVE AI on August 6, 2026 at 07:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Seek an official patch or upgrade from mf-yang as soon as it becomes available
  • Restrict or block remote execution of bash-tools.exec.ts from untrusted IP ranges or networks
  • Monitor system logs for unexpected or unauthorized executions of the bash-tools.exec.ts module

Generated by OpenCVE AI on August 6, 2026 at 07:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 06 Aug 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 06 Aug 2026 06:30:00 +0000

Type Values Removed Values Added
Description A vulnerability was found in mf-yang openclaw-cn 2026.2.5. This affects an unknown part of the file src/agents/bash-tools.exec.ts of the component Ggateway Exec Approval Flow. The manipulation results in incorrect authorization. The attack may be performed from remote. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet.
Title mf-yang openclaw-cn Ggateway Exec Approval Flow bash-tools.exec.ts authorization
First Time appeared Mf-yang
Mf-yang openclaw-cn
Weaknesses CWE-285
CWE-863
CPEs cpe:2.3:a:mf-yang:openclaw-cn:*:*:*:*:*:*:*:*
Vendors & Products Mf-yang
Mf-yang openclaw-cn
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Mf-yang Openclaw-cn
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-08-06T12:02:14.691Z

Reserved: 2026-08-05T20:03:52.232Z

Link: CVE-2026-19006

cve-icon Vulnrichment

Updated: 2026-08-06T11:57:41.481Z

cve-icon NVD

Status : Deferred

Published: 2026-08-06T07:16:29.780

Modified: 2026-08-12T21:00:37.147

Link: CVE-2026-19006

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-06T08:15:03Z

Weaknesses