Executive brief
OpenClaw, an open-source automation or gateway tool, contains a security flaw in its 'flock' wrapper component. This vulnerability allows users with low-level access to bypass security approvals and execute unauthorized actions or commands. If exploited, an attacker could gain full control over the system, potentially leading to data theft, service disruption, or unauthorized persistent access to the environment.
Technical details
An authorization bypass vulnerability exists in OpenClaw's flock wrapper due to incorrect resource resolution (CWE-706) and improper authorization checks (CWE-863). The flaw allows an authenticated attacker with low privileges to leverage specific input paths to bypass 'durable exec approval binding,' a mechanism intended to restrict command execution. By manipulating these paths, an attacker can execute unauthorized operations or persist actions beyond their assigned permissions. The vulnerability is reachable over the network when the affected feature is enabled. A fix is available in version 2026.6.9, and users are advised to restrict the feature to trusted operators or disable it until patched.
Affected products
- OpenClaw OpenClaw < 2026.6.9
Timeline
- 2026-06-30: advisory: GitHub Security Advisory published
- 2026-07-13: disclosed: CVE published to NVD