Approval Timeout Bypass Vulnerability in OpenClaw Product by OpenClaw
CVE-2026-42423
7.7HIGH
What is CVE-2026-42423?
OpenClaw prior to version 2026.4.8 contains a flaw in its approval-timeout fallback mechanism that allows attackers to bypass the strictInlineEval explicit approval requirement. This vulnerability enables unauthorized execution of inline eval commands on gateway and node execution hosts, circumventing intended security measures designed to protect user data and system integrity.
Affected Version(s)
OpenClaw 0 < 2026.4.8
OpenClaw 2026.4.8
