CVE-2026-42423

OpenClaw before 2026.4.8 contains an approval-timeout fallback mechanism that bypasses strictInlineEval explicit-approval requirements on gateway and node exec hosts. Attackers can exploit this timeout fallback to execute inline eval commands that should require explicit user approval, circumventing the intended security boundary.

Scoring

Severity
HIGH
CVSS base score
7.7
CVSS vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
EPSS probability
0.32%
CWE
CWE-636
Published
2026-04-28
Last modified
2026-04-30

Affected products

Weakness type

Related vulnerabilities

Markdown version · Browse all CVEs