Impact
OpenClaw versions before 2026.6.6 contain a flaw in host execution environment filtering that could be abused when the Git ext transport feature is enabled and reachable. A lower‑trust caller or an attacker can provide a crafted input path that allows execution or persistence of actions beyond the intended authorization, effectively bypassing authentication controls for Git ext transport operations.
Affected Systems
The affected product is OpenClaw by the OpenClaw team. Versions older than 2026.6.6 are vulnerable. Any installation of OpenClaw running a pre‑2026.6.6 release that has the Git ext transport feature enabled and reachable is at risk.
Risk and Exploitability
The CVSS score of 8.7 indicates a high severity impact. The EPSS score is currently reported as <1% and the vulnerability is not listed in CISA’s KEV catalog, implying limited exploitation data. Exploitation requires the Git ext transport feature to be enabled and externally reachable, so a remote attacker with network access to the service could abuse the flaw. No public exploit code has been disclosed, but the combination of high severity and remote accessibility means the risk warrants prompt action.
OpenCVE Enrichment