{"data":{"id":"6b38eac5-e570-4106-8065-6528e631be02","title":"CVE-2026-100585: OpenClaw (npm package `openclaw`) before 2026.7.1 fails to enforce the owner-only authorization requirement for Claude C","summary":"OpenClaw (an npm package) versions before 2026.7.1 have a bug where it doesn't properly check who is allowed to approve permission requests for Claude Code (a code execution feature). This means someone with basic channel access could approve or deny requests that should only be decided by the owner, potentially allowing code to run without the owner's permission.","solution":"Update OpenClaw to version 2026.7.1 or later, where the issue is fixed.","labels":["security"],"sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-100585","publishedAt":"2026-09-26T03:17:06.517Z","cveId":"CVE-2026-100585","cweIds":["CWE-862"],"cvssScore":"8","cvssSeverity":"high","severity":"high","attackType":[],"issueType":"vulnerability","affectedPackages":null,"affectedVendors":["Anthropic"],"affectedVendorsRaw":["Anthropic","Claude","OpenClaw"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H","attackVector":"network","attackComplexity":"low","privilegesRequired":"low","userInteraction":"required","exploitMaturity":"unknown","epssScore":0.00193,"patchAvailable":null,"disclosureDate":"2026-09-26T03:17:06.517Z","capecIds":["CAPEC-122"],"crossRefCount":0,"attackSophistication":"moderate","impactType":["integrity","safety"],"aiComponentTargeted":"api","llmSpecific":true,"classifierConfidence":0.92,"researchCategory":null,"atlasIds":null}}