Incorrect authorization in OpenClaw - CVE-2026-41360
Published: April 30, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a local user to execute modified script contents without invalidating a prior approval.
The vulnerability exists due to incorrect authorization in the node-host command-planning path when processing local script operands through a pnpm dlx approval flow. A local user can replace an approved local script before execution to execute modified script contents without invalidating a prior approval.