ACVE-2026-0433
OpenClaw below 2026.8.1, running with a standing execution approval, could reuse an approved command in a different working directory against files the operator had not reviewed.
Exposure
Reproducibility: partial (trigger not published)
Claims
Confirmed means the statement matches the cited primary source. Nothing on this page has been reproduced.
| Claim | Status | Source | Checked |
|---|---|---|---|
| Identifier GHSA-3mq7-q27j-mq7q | Confirmed | api.github.com | 2026-09-24 |
| Upgrade target 2026.8.1 | Confirmed | registry.npmjs.org | 2026-09-24 |
| Latest affected version 2026.7.35 (below fixed 2026.8.1) is still installable from npm | Confirmed | registry.npmjs.org | 2026-09-24 |
In the wild
demonstrated · vendor
Description
What
The OpenClaw advisory says reusable exec approvals matched command arguments without binding the working directory. An approval obtained for one directory could therefore apply later in another directory with materially different read or write effects.
Detection
Recorded from the OpenClaw security advisory. Not recreated in a lab.
Fix
Upgrade OpenClaw to 2026.8.1 or later and review standing approvals.
Fix
Upgrade OpenClaw to 2026.8.1 or later and bind approvals to the reviewed directory.
- Upgrade
npm:openclawto2026.8.1. First stable patched version in the advisory. Owner: operator