NVD HIGH: CVE-2026-100580 — OpenClaw (npm package 'openclaw') before 2026.7.1 improperly handles case sensit...
OpenClaw (npm package 'openclaw') before 2026.7.1 improperly handles case sensitivity in the model-facing cron tool: a mixed-case payload kind can pass the agent-facing shell-execution guard and later normalize into a command job. An actor able to steer a tool-enabled agent can therefore create a persistent cron job that executes attacker-selected commands with the privileges of the OpenClaw proce
CVE-2026-100580