OpenClaw Execution Approval Vulnerability Allowing Arbitrary Trust in Wrapper Executables
Vulnerability
A vulnerability in OpenClaw versions prior to 2026.3.28 allows for improper execution approval by trusting wrapper carrier executables instead of the actual invoked targets. This flaw, located in 'exec-approvals-allowlist.ts', enables attackers to manipulate executable routing through dispatch wrappers, creating broader allowlist entries than intended and undermining execution approval boundaries. The vulnerability requires user interaction and could lead to unauthorized execution of commands.
Impact
Exploitation of this vulnerability could result in unauthorized persistence of execution approvals, allowing broader trust in carrier executables and potentially leading to arbitrary code execution.
Remediation
Users can upgrade to OpenClaw version 2026.3.28 or later to address this vulnerability.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
