PT-2026-37015 · Openclaw · Openclaw

Nullpointerexcepted

·

Published

2026-04-17

·

Updated

2026-05-05

·

CVE-2026-43530

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenClaw versions 2026.2.23 through 2026.4.11
Description An issue exists in the execution of busybox and toybox applets where weakened exec approval binding allows attackers to obscure which applet is actually running. By exploiting opaque multi-call binaries (binaries that provide multiple tools within a single executable), attackers can bypass exec approval mechanisms and weaken the risk classification of unsafe applet invocations.
Recommendations Update to version 2026.4.12 or newer.

Fix

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-43530
GHSA-2CQ5-MF3V-MX44

Affected Products

Openclaw