CVE-2026-42423
OpenClaw before 2026.4.8 contains an approval-timeout fallback mechanism that bypasses strictInlineEval explicit-approval requirements on gateway and node exec hosts. Attackers can exploit this timeout fallback to execute inline eval commands that should require explicit user approval, circumventing the intended security boundary.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.7
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
- EPSS probability
- 0.32%
- CWE
- CWE-636
- Published
- 2026-04-28
- Last modified
- 2026-04-30
Affected products
- OpenClaw OpenClaw
- OpenClaw OpenClaw
Weakness type
Related vulnerabilities
- CVE-2026-81379 — Visual Studio Code Security Feature Bypass Vulnerability
- CVE-2026-86120 — APITable through 1.13.0-beta.1 Fail-Open Authorization in the Fusion API Node Permission Guard
- CVE-2026-85649 — (Holloway) Chew, Kean Ho's Actualizer v1.2.0 and earlier contains a fail-open password validation...
- CVE-2026-18329 — NGINX ngx_http_js_module vulnerability
- CVE-2026-82744 — Ash.Reactor change step fails open, skipping a change when its where guard raises
- CVE-2026-82018 — IGEL OS 12 / 11 Secure Boot Bypass via Unsigned igel.conf File
- CVE-2026-46482 — MyBB: Security Question insufficient validation
- CVE-2026-73421 — NextAuth.js: Configuration errors can cause existence-based auth checks to fail open (auth object populated with an error)