Incorrect authorization in OpenClaw - #VU128797
Published: May 1, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a remote user to bypass an execution approval prompt.
The vulnerability exists due to incorrect authorization in the allowlist evaluator when resolving path-scoped executables under skill auto-allow handling. A remote user can invoke a path-scoped executable whose basename collides with an allowed skill name to bypass an execution approval prompt.
This issue occurs only in non-default configurations with autoAllowSkills enabled, system.run using security=allowlist, and ask=on-miss.