NVD HIGH: CVE-2026-100552 — OpenClaw (npm package 'openclaw') before 2026.8.1 does not correctly enforce per...
OpenClaw (npm package 'openclaw') before 2026.8.1 does not correctly enforce per-chat tool policies for Codex app-server runtime tools. A conversation-level tools.allow rule filtered OpenClaw tools but did not restrict the shell, process, file, and patch tools owned by the Codex runtime. When a lower-trust conversation was assigned to a Codex runtime and restricted with a per-chat tool allowlist,
CVE-2026-100552