Policy Bypass Vulnerability in OpenClaw npm Package by OpenClaw
CVE-2026-100552

8.7HIGH

Key Information:

Vendor

Openclaw

Status
Vendor
CVE Published:
26 September 2026

What is CVE-2026-100552?

The OpenClaw npm package prior to version 2026.8.1 contains a critical flaw that fails to properly enforce per-chat tool policies for Codex app-server runtime tools. Specifically, while the tools.allow rule manages access to OpenClaw tools, it does not extend these restrictions to shell, process, file, and patch tools that are part of the Codex runtime environment. This oversight can allow users, under lower-trust settings, to bypass the configured allowlist and access native commands and files, exposing potential security risks based on the host permissions and the sandbox configuration of the runtime.

Affected Version(s)

OpenClaw 0 < 2026.8.1

OpenClaw 2026.8.1

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.