NVD HIGH: CVE-2026-100585 — OpenClaw (npm package `openclaw`) before 2026.7.1 fails to enforce the owner-onl...
OpenClaw (npm package `openclaw`) before 2026.7.1 fails to enforce the owner-only authorization requirement for Claude Code permission prompts delivered through the MCP channel bridge. An authorized non-owner channel sender with channel command access can approve or deny a pending permission request intended for the owner, causing the requested action to proceed without owner consent. The practica
CVE-2026-100585