Incorrect authorization in OpenClaw - #VU149037
Published: September 12, 2026
Vulnerability details
The vulnerability allows a remote user to access or modify unreviewed files or repositories.
The vulnerability exists due to incorrect authorization in reusable exec approvals when reusing an approved command in a different working directory. A remote user can obtain an allow-always approval for a command and reuse it in a directory with materially different read or write effects to access or modify unreviewed files or repositories.
User interaction is required for the operator\'s initial approval.