critical · CVSS v3 8 · CVSS v4 8.6 · EPSS 0.00193
CVE-2026-100585
OpenClaw npm package openclaw before 2026.7.1 fails to enforce owner-only authorization for Claude Code permission prompts via the MCP chann
Overview
OpenClaw npm package openclaw before 2026.7.1 fails to enforce owner-only authorization for Claude Code permission prompts via the MCP channel bridge. An authorized non‑owner channel sender can approve or deny pending requests, allowing actions to proceed without owner consent. This flaw could enable unauthorized code execution or data access.
Description
OpenClaw (npm package `openclaw`) before 2026.7.1 fails to enforce the owner-only authorization requirement for Claude Code permission prompts delivered through the MCP channel bridge. An authorized non-owner channel sender with channel command access can approve or deny a pending permission request intended for the owner, causing the requested action to proceed without owner consent. The practical impact depends on the pending action and the host capabilities requested by the Claude Code run. The issue is fixed in version 2026.7.1.
Impact
Confidentiality, integrity, and availability can be compromised for users of OpenClaw when non‑owner channel senders manipulate permission prompts. Defenders should monitor for unauthorized permission approvals and restrict channel command access to owners only.
Remediation
Upgrade to version 2026.7.1 or later. If upgrade is not possible, restrict channel command access to owners, disable the MCP channel bridge, or enforce a manual approval workflow for permission requests.
Risk context
Critical severity with an EPSS of 0.00193 indicates a rare but high‑impact vulnerability. Defenders should prioritize patching or mitigation promptly.
Affected products
- OpenClaw
- openclaw npm package
Scores
- Severity
- critical
- CVSS v2
- 9
- CVSS v3
- 8
- CVSS v4
- 8.6
- EPSS
- 0.00193