PT-2026-35802 · Openclaw · Openclaw

Keensecuritylab

·

Published

2026-04-28

·

Updated

2026-04-28

·

CVE-2026-42423

CVSS v3.1

7.5

High

AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
OpenClaw before 2026.4.8 contains an approval-timeout fallback mechanism that bypasses strictInlineEval explicit-approval requirements on gateway and node exec hosts. Attackers can exploit this timeout fallback to execute inline eval commands that should require explicit user approval, circumventing the intended security boundary.

Fix

Weakness Enumeration

Related Identifiers

CVE-2026-42423

Affected Products

Openclaw