NVD HIGH: CVE-2026-100588 — OpenClaw (npm package 'openclaw') before 2026.7.1 does not enforce the administr...
OpenClaw (npm package 'openclaw') before 2026.7.1 does not enforce the administrator scope requirement on browser control when it is reached through the node.invoke method, although direct browser.request access requires administrator scope. In Gateway deployments that honor caller identity and narrower operator scopes, a write-scoped caller with access to a connected browser-capable node can insp
CVE-2026-100588