CVE-2026-100585: OpenClaw (npm package `openclaw`) before 2026.7.1 fails to enforce the owner-only authorization requirement for Claude C
Summary
OpenClaw (an npm package) versions before 2026.7.1 have a bug where it doesn't properly check who is allowed to approve permission requests for Claude Code (a code execution feature). This means someone with basic channel access could approve or deny requests that should only be decided by the owner, potentially allowing code to run without the owner's permission.
Solution / Mitigation
Update OpenClaw to version 2026.7.1 or later, where the issue is fixed.
Vulnerability Details
8(high)
EPSS: 0.2%
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
network
low
low
required
September 25, 2026
Classification
Affected Vendors
Related Issues
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-100585
First tracked: September 26, 2026 at 02:07 AM
Classified by LLM (prompt v3) · confidence: 92%