NVD HIGH: CVE-2026-100561 — OpenClaw (npm package 'openclaw') versions >= 2026.3.22 and < 2026.8.1 contain a...
OpenClaw (npm package 'openclaw') versions >= 2026.3.22 and < 2026.8.1 contain an approval-bypass flaw in the exec approval policy: the policy could trust a command-running wrapper without inspecting the command carried in its arguments. After an operator allowlisted or permanently approved a benign wrapper invocation, a later agent turn could substitute an arbitrary inner command and execute it w
CVE-2026-100561