Executive brief
OpenClaw, a tool used for managing bot interactions, contains a security flaw in its QQBot integration. Unauthorized users who can see approval buttons in a chat can bypass security checks to approve restricted commands or plugin actions. This could allow an attacker to execute unauthorized code or modify system settings that should be restricted to administrators.
Technical details
An authorization bypass vulnerability (CWE-862) exists in OpenClaw's QQBot channel implementation. While text-based approval commands correctly verify the user's identity, the callback path for native QQBot approval buttons fails to enforce the configured approver identity. An attacker with low privileges (a user present in the QQ conversation) can interact with these buttons to authorize pending 'exec' or plugin requests. This allows for unauthorized execution of actions that should require administrative approval. The issue is resolved in version 2026.5.18.
Affected products
- OpenClaw openclaw < 2026.5.18
Timeline
- 2026-05-28: advisory: GitHub Security Advisory published
- 2026-05-29: disclosed: NVD publication date
- 2026-05-18: patched: First stable patched version released