{
  "schema_version": "1.6.0",
  "id": "ACVE-2026-0433",
  "aliases": [
    "GHSA-3mq7-q27j-mq7q"
  ],
  "published": "2026-09-11T00:00:00Z",
  "modified": "2026-09-25T00:00:00Z",
  "summary": "OpenClaw below 2026.8.1, running with a standing execution approval, could reuse an approved command in a different working directory against files the operator had not reviewed.",
  "details": "## What\n\nThe OpenClaw advisory says reusable exec approvals matched command arguments without binding the working directory. An approval obtained for one directory could therefore apply later in another directory with materially different read or write effects.\n\n## Detection\n\nRecorded from the OpenClaw security advisory. Not recreated in a lab.\n\n## Fix\n\nUpgrade OpenClaw to 2026.8.1 or later and review standing approvals.",
  "affected": [
    {
      "package": {
        "ecosystem": "npm",
        "name": "openclaw",
        "purl": "pkg:npm/openclaw"
      },
      "ranges": [
        {
          "type": "ECOSYSTEM",
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "2026.8.1"
            }
          ]
        }
      ]
    }
  ],
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://github.com/openclaw/openclaw/security/advisories/GHSA-3mq7-q27j-mq7q"
    }
  ],
  "database_specific": {
    "severity": "HIGH",
    "acve": {
      "specVersion": 1,
      "status": "candidate",
      "kind": "code",
      "vulnClasses": [
        "unsafe-permission-mode",
        "over-privileged-combination"
      ],
      "cwe": [
        "CWE-863"
      ],
      "taxonomy": {
        "owasp_asi": [
          "ASI03",
          "ASI02"
        ]
      },
      "cveBoundary": "user-configured",
      "exploitation": {
        "status": "demonstrated",
        "checkedAt": "2026-09-24T00:00:00Z",
        "sources": [
          {
            "url": "https://github.com/openclaw/openclaw/security/advisories/GHSA-3mq7-q27j-mq7q",
            "type": "vendor"
          }
        ],
        "kev": {
          "listed": false
        }
      },
      "fix": {
        "summary": "Upgrade OpenClaw to 2026.8.1 or later and bind approvals to the reviewed directory.",
        "actions": [
          {
            "type": "upgrade",
            "target": "npm:openclaw",
            "to": "2026.8.1",
            "why": "First stable patched version in the advisory.",
            "owner": "operator"
          }
        ]
      },
      "exposure": {
        "harness": {
          "value": "OpenClaw below 2026.8.1",
          "any": false,
          "status": "confirmed",
          "source": "https://github.com/openclaw/openclaw/security/advisories/GHSA-3mq7-q27j-mq7q"
        },
        "model": {
          "value": "any",
          "any": true,
          "status": "unconfirmed"
        },
        "goal": {
          "value": "Any task that uses an approved exec command",
          "stated": false,
          "status": "unconfirmed"
        },
        "tools": {
          "value": "Reusable exec approvals and the working directory in which the command runs",
          "status": "confirmed",
          "source": "https://github.com/openclaw/openclaw/security/advisories/GHSA-3mq7-q27j-mq7q"
        },
        "approval": {
          "value": "An allow-always approval can outlive the working directory that was reviewed",
          "mode": "always-allow",
          "status": "confirmed",
          "source": "https://github.com/openclaw/openclaw/security/advisories/GHSA-3mq7-q27j-mq7q"
        },
        "inputControl": "operator",
        "agentAction": "The agent reuses an approved command in a different working directory.",
        "harm": "harmful-action",
        "divergence": "none",
        "reach": {
          "value": "Files and repositories in the later working directory",
          "kinds": [
            "project-files",
            "private-repositories"
          ],
          "status": "confirmed",
          "source": "https://github.com/openclaw/openclaw/security/advisories/GHSA-3mq7-q27j-mq7q"
        }
      },
      "claims": [
        {
          "kind": "identifier",
          "statement": "Identifier GHSA-3mq7-q27j-mq7q",
          "value": "GHSA-3mq7-q27j-mq7q",
          "status": "confirmed",
          "source": "https://api.github.com/repos/openclaw/openclaw/security-advisories/GHSA-3mq7-q27j-mq7q",
          "result": "match",
          "observed": "GitHub repository security advisory: record found",
          "method": "machine",
          "checkedAt": "2026-09-24T18:58:27Z"
        },
        {
          "kind": "fixed-version",
          "statement": "Upgrade target 2026.8.1",
          "value": "2026.8.1",
          "status": "confirmed",
          "source": "https://registry.npmjs.org/openclaw/2026.8.1",
          "result": "match",
          "observed": "npm: version exists",
          "method": "machine",
          "checkedAt": "2026-09-24T18:58:27Z"
        },
        {
          "kind": "installable",
          "statement": "Latest affected version 2026.7.35 (below fixed 2026.8.1) is still installable from npm",
          "value": "2026.7.35",
          "status": "confirmed",
          "source": "https://registry.npmjs.org/openclaw/2026.7.35",
          "result": "match",
          "observed": "npm: version exists",
          "method": "machine",
          "checkedAt": "2026-09-24T18:58:27Z"
        }
      ],
      "reproducibility": {
        "status": "partial",
        "axesComplete": true,
        "componentsObtainable": true,
        "triggerPublished": false,
        "observableStated": true,
        "demonstrated": "researcher-demonstrated",
        "missing": [
          "trigger not published"
        ]
      }
    }
  }
}
