Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wfxc-2q5g-mm98

Опубликовано: 14 июл. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 6.9
CVSS3: 4.9

Описание

OpenClaw versions 2026.6.5 before 2026.6.9 contain a vulnerability in the plugin install wrappers that could skip the install policy (authorization) check. When the affected feature is enabled and reachable, a lower-trust caller or a configured input path could execute or persist actions beyond the caller's intended authorization. Impact depends on the operator's configuration and whether lower-trust input can reach the affected path. The issue is fixed in 2026.6.9.

OpenClaw versions 2026.6.5 before 2026.6.9 contain a vulnerability in the plugin install wrappers that could skip the install policy (authorization) check. When the affected feature is enabled and reachable, a lower-trust caller or a configured input path could execute or persist actions beyond the caller's intended authorization. Impact depends on the operator's configuration and whether lower-trust input can reach the affected path. The issue is fixed in 2026.6.9.

EPSS

Процентиль: 8%
0.00184
Низкий

6.9 Medium

CVSS4

4.9 Medium

CVSS3

Дефекты

CWE-863

Связанные уязвимости

CVSS3: 4.9
nvd
около 1 месяца назад

OpenClaw versions 2026.6.5 before 2026.6.9 contain a vulnerability in the plugin install wrappers that could skip the install policy (authorization) check. When the affected feature is enabled and reachable, a lower-trust caller or a configured input path could execute or persist actions beyond the caller's intended authorization. Impact depends on the operator's configuration and whether lower-trust input can reach the affected path. The issue is fixed in 2026.6.9.

EPSS

Процентиль: 8%
0.00184
Низкий

6.9 Medium

CVSS4

4.9 Medium

CVSS3

Дефекты

CWE-863