Authorization Vulnerability in OpenClaw NPM Package by OpenClaw
CVE-2026-100556
5.3MEDIUM
What is CVE-2026-100556?
The OpenClaw NPM package exhibits an authorization bypass vulnerability in its handling of WhatsApp group interactions. A group member, initially granted permission for basic messaging but restricted from executing commands, could exploit this flaw to utilize the /new command. This command enables unauthorized group members to reset the shared group session, thus overriding the specified provider and model settings. Consequently, this may alter routing, cost, data flow, or availability within the session, while it does not permit the addition of new providers or execute host commands. The issue has been resolved in version 2026.8.1.
Affected Version(s)
OpenClaw 2026.5.2 < 2026.8.1
OpenClaw 2026.8.1
