Impact
OpenClaw versions prior to 2026.6.5 contain an authorization bypass flaw in the node exec approvals mechanism. The vulnerability permits callers with lower trust levels to execute actions that exceed their approved permissions by manipulating gateway and node environment settings. This flaw can be exploited to persist processes or perform operations beyond the intended scope, effectively providing an unauthorized privilege increase that may compromise the confidentiality and integrity of the system.
Affected Systems
All releases of OpenClaw before 2026.6.5 are affected, regardless of the underlying Node.js version. The flaw is present in the OpenClaw application itself and is tied to the node exec approvals component, so any deployment that uses a matching gateway and node environment configuration is potentially vulnerable.
Risk and Exploitability
With a CVSS score of 7.7, the issue is considered moderate‑severe. The EPSS score of less than 1% indicates a very low current exploitation probability, and it has not yet been listed in the CISA KEV catalog. The likely attack vector involves altering or misaligning gateway and node environment settings to trigger the exec approval logic, requiring the attacker to have some level of access to the application or its deployment configuration. If successful, the attacker can execute privileged actions beyond their intended authorization, potentially leading to data manipulation or persistence mechanisms.
OpenCVE Enrichment