rootpwn

medium · CVSS v3 6.3 · CVSS v4 5.3 · EPSS 0.00278

CVE-2026-100556

CVE-2026-100556 affects the OpenClaw npm package, allowing a command‑denied group member to override the provider and model used in a shared

Overview

CVE-2026-100556 affects the OpenClaw npm package, allowing a command‑denied group member to override the provider and model used in a shared session. This can alter routing, cost, and data flow without granting new execution privileges. The flaw is fixed in version 2026.8.1.

Description

OpenClaw (npm package openclaw) versions >= 2026.5.2 and command to reset the shared group session and persist a provider and model override. This allows a command-denied group member to select a provider and model already permitted by the operator for subsequent turns in the shared group session, potentially changing provider routing, cost, data flow, or availability. It does not allow adding a new provider or host command execution. The issue is fixed in version 2026.8.1.

Impact

The vulnerability compromises confidentiality, integrity, and availability of the shared session’s provider configuration. Defenders are impacted if they rely on OpenClaw for multi‑provider orchestration, as unauthorized members could redirect traffic or incur unexpected costs.

Remediation

Upgrade OpenClaw to version 2026.8.1 or later. If an upgrade is not immediately possible, restrict group member permissions to prevent provider/model selection or isolate the shared session from sensitive data flows.

Risk context

The issue carries a medium CVSS v3 score of 6.3 and an EPSS of 0.00278, indicating a low probability of exploitation but moderate potential impact if exploited.

Affected products

  • OpenClaw (npm package)

Scores

Severity
medium
CVSS v2
6.5
CVSS v3
6.3
CVSS v4
5.3
EPSS
0.00278

npm openclaw provider-override command-denied medium EPSS

← All CVEs