High severity7.3NVD Advisory· Published Sep 26, 2026
CVE-2026-100530
CVE-2026-100530
Description
OpenClaw versions before 2026.8.1 fail to bind working directory context to reusable exec approvals, allowing approved commands to execute in different directories. Attackers with an allow-always approval can reuse it to run the same command against unreviewed files or repositories with materially different effects.
Affected products
1Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.