HIGH
OpenClaw < 2026.3.28 - Arbitrary Execution Allowlist via Wrapper Carrier Executables
Published Apr 28, 2026
7.0
HIGHCVSS 4.0
EPSS 0.17%
Description
OpenClaw before 2026.3.28 contains an execution approval vulnerability in exec-approvals-allowlist.ts that allows allow-always persistence to trust wrapper carrier executables instead of invoked targets. Attackers can exploit positional carrier executable routing through dispatch wrappers to establish broader allowlist entries than intended, weakening execution approval boundaries.
Affected products
-
- Version 0StatusaffectedConstraints<2026.3.28
- Version 2026.3.28StatusunaffectedConstraints-
- Version
No data.
No Red Hat product state for this CVE.
openclaw
npm
Introduced 0 Fixed 2026.3.28
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | openclaw | 0 | 2026.3.28 |
Remediation
No remediation recorded yet.
Weaknesses (2)
References (6)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-26089 Advisory
- https://github.com/advisories/GHSA-p4x4-2r7f-wjxg Advisory
- https://github.com/openclaw/openclaw/commit/9ec44fad390f0bc1c29c3cc418b322560cb0222b
- https://github.com/openclaw/openclaw/releases/tag/v2026.3.28
- https://github.com/openclaw/openclaw/security/advisories/GHSA-p4x4-2r7f-wjxg vendor-advisoryVendor Advisory
- https://www.vulncheck.com/advisories/openclaw-arbitrary-execution-allowlist-via-wrapper-carrier-executables third-party-advisoryThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-26089 | Advisory | |
| https://github.com/advisories/GHSA-p4x4-2r7f-wjxg | Advisory | |
| https://github.com/openclaw/openclaw/commit/9ec44fad390f0bc1c29c3cc418b322560cb0222b | ||
| https://github.com/openclaw/openclaw/releases/tag/v2026.3.28 | ||
| https://github.com/openclaw/openclaw/security/advisories/GHSA-p4x4-2r7f-wjxg | vendor-advisoryVendor Advisory | |
| https://www.vulncheck.com/advisories/openclaw-arbitrary-execution-allowlist-via-wrapper-carrier-executables | third-party-advisoryThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Apr 28, 2026
Updated Apr 29, 2026
Reserved Apr 20, 2026
Link CVE-2026-41380
CISA Vulnrichment
Updated Apr 29, 2026
ENISA EUVD
EUVD-2026-26089 GHSA-P4X4-2R7F-WJXG Assigner VulnCheck
Published Apr 28, 2026
Updated Apr 29, 2026
Exploited since n/a
Link EUVD-2026-26089