PT-2026-32077 · Npm · Openclaw

Published

2026-04-01

·

Updated

2026-04-01

CVSS v3.1

7.3

High

VectorAV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

Summary

Allow-always persistence could trust wrapper carrier executables instead of the actual invoked target when commands were routed through dispatch wrappers.

Impact

A one-time approval could persist a broader future allowlist entry than the operator intended, weakening execution approval boundaries.

Affected Component

src/infra/exec-approvals-allowlist.ts

Fixed Versions

  • Affected: <= 2026.3.24
  • Patched: >= 2026.3.28
  • Latest stable 2026.3.28 contains the fix.

Fix

Fixed by commit 9ec44fad39 (Exec approvals: reject wrapper carrier allow-always targets).

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

GHSA-P4X4-2R7F-WJXG

Affected Products

Openclaw