Description
OpenClaw versions before 2026.6.6 contain a flaw in host exec environment filtering that could allow Git ext transport to be abused. When the affected feature is enabled and reachable, a lower-trust caller or configured input path could execute or persist actions beyond the caller's intended authorization.
Published: 2026-07-13
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

OpenClaw versions before 2026.6.6 contain a flaw in host execution environment filtering that could be abused when the Git ext transport feature is enabled and reachable. A lower‑trust caller or an attacker can provide a crafted input path that allows execution or persistence of actions beyond the intended authorization, effectively bypassing authentication controls for Git ext transport operations.

Affected Systems

The affected product is OpenClaw by the OpenClaw team. Versions older than 2026.6.6 are vulnerable. Any installation of OpenClaw running a pre‑2026.6.6 release that has the Git ext transport feature enabled and reachable is at risk.

Risk and Exploitability

The CVSS score of 8.7 indicates a high severity impact. The EPSS score is currently reported as <1% and the vulnerability is not listed in CISA’s KEV catalog, implying limited exploitation data. Exploitation requires the Git ext transport feature to be enabled and externally reachable, so a remote attacker with network access to the service could abuse the flaw. No public exploit code has been disclosed, but the combination of high severity and remote accessibility means the risk warrants prompt action.

Generated by OpenCVE AI on July 31, 2026 at 11:10 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade OpenClaw to version 2026.6.6 or later.
  • Disable the Git ext transport feature if it is not required for your environment.
  • Ensure that any paths or inputs used with Git ext transport are strictly validated and restricted to trusted sources.

Generated by OpenCVE AI on July 31, 2026 at 11:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 14 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Description OpenClaw versions before 2026.6.1 contain a flaw in host exec environment filtering that could allow Git ext transport to be abused. When the affected feature is enabled and reachable, a lower-trust caller or configured input path could execute or persist actions beyond the caller's intended authorization. OpenClaw versions before 2026.6.6 contain a flaw in host exec environment filtering that could allow Git ext transport to be abused. When the affected feature is enabled and reachable, a lower-trust caller or configured input path could execute or persist actions beyond the caller's intended authorization.

Mon, 13 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description OpenClaw versions before 2026.6.1 contain a flaw in host exec environment filtering that could allow Git ext transport to be abused. When the affected feature is enabled and reachable, a lower-trust caller or configured input path could execute or persist actions beyond the caller's intended authorization.
Title OpenClaw < 2026.6.6 Authentication Bypass via Git ext transport
First Time appeared Openclaw
Openclaw openclaw
Weaknesses CWE-184
CPEs cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*
Vendors & Products Openclaw
Openclaw openclaw
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Openclaw Openclaw
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-07-15T04:00:24.757Z

Reserved: 2026-07-13T16:38:58.353Z

Link: CVE-2026-62200

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T11:15:05Z

Weaknesses
  • CWE-184

    Incomplete List of Disallowed Inputs