medium · CVSS v3 6.3 · CVSS v4 5.3 · EPSS 0.00278
CVE-2026-100556
CVE-2026-100556 affects the OpenClaw npm package, allowing a command‑denied group member to override the provider and model used in a shared
Overview
CVE-2026-100556 affects the OpenClaw npm package, allowing a command‑denied group member to override the provider and model used in a shared session. This can alter routing, cost, and data flow without granting new execution privileges. The flaw is fixed in version 2026.8.1.
Description
OpenClaw (npm package openclaw) versions >= 2026.5.2 and command to reset the shared group session and persist a provider and model override. This allows a command-denied group member to select a provider and model already permitted by the operator for subsequent turns in the shared group session, potentially changing provider routing, cost, data flow, or availability. It does not allow adding a new provider or host command execution. The issue is fixed in version 2026.8.1.
Impact
The vulnerability compromises confidentiality, integrity, and availability of the shared session’s provider configuration. Defenders are impacted if they rely on OpenClaw for multi‑provider orchestration, as unauthorized members could redirect traffic or incur unexpected costs.
Remediation
Upgrade OpenClaw to version 2026.8.1 or later. If an upgrade is not immediately possible, restrict group member permissions to prevent provider/model selection or isolate the shared session from sensitive data flows.
Risk context
The issue carries a medium CVSS v3 score of 6.3 and an EPSS of 0.00278, indicating a low probability of exploitation but moderate potential impact if exploited.
Affected products
- OpenClaw (npm package)
Scores
- Severity
- medium
- CVSS v2
- 6.5
- CVSS v3
- 6.3
- CVSS v4
- 5.3
- EPSS
- 0.00278