Remote Code Execution Vulnerability in OpenClaw by OpenClaw Inc.
CVE-2026-100599

8.7HIGH

Key Information:

Vendor

Openclaw

Status
Vendor
CVE Published:
26 September 2026

What is CVE-2026-100599?

OpenClaw versions 2026.5.1 through 2026.7.0 exhibit a security flaw where the exec approval path is not applied to commands executed within the Google Meet plugin. The vulnerable googlemeet.chrome command accepts user-supplied audio commands which can be executed on a connected node without proper approval. This places systems at risk, allowing unauthorized processes to run on the paired node, compromising files, user credentials, browser profiles, and overall system stability. To mitigate risk, users are advised to upgrade to version 2026.7.1 or to temporarily disable the Google Meet plugin or remove googlemeet.chrome from allowed node commands.

Affected Version(s)

OpenClaw 2026.5.1 < 2026.7.1

OpenClaw 2026.7.1

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

wwwvwwvwwwwwvwwvw
.