Executive brief
OpenClaw, an automation and agent framework, contains a flaw in its Skill Workshop feature that allows configuration changes to be applied without required human approval. Even when the system is configured to require a 'pending' status for review, an automated tool call can bypass this check and force changes to take effect immediately. This could allow unauthorized modifications to system settings or workflows if an attacker can influence the input reaching the Skill Workshop.
Technical details
An incorrect authorization vulnerability (CWE-863) exists in OpenClaw's Skill Workshop apply flow. The vulnerability allows agent tool calls to explicitly set the 'apply' parameter to true, overriding the 'approvalPolicy: pending' configuration that should mandate manual intervention. An attacker can exploit this by reaching the affected apply path, typically requiring some form of user interaction or lower-trust input to trigger the agent tool call. This results in the unauthorized application of workshop changes before the mandatory approval step. The issue is resolved in version 2026.5.6.
Affected products
- OpenClaw OpenClaw <= 2026.5.5
Timeline
- 2026-05-28: advisory: GitHub Security Advisory published
- 2026-06-11: disclosed: NVD publication date