Openclaw · Openclaw · CVE-2026-100599
**Name of the Vulnerable Software and Affected Versions**
OpenClaw versions 2026.5.1 through 2026.7.0
**Description**
The software fails to apply the configured execution approval path to Google Meet node commands. Specifically, the `googlemeet.chrome` command accepts caller-supplied audio command arrays and executes them on a paired node, bypassing the standard `system.run` approval flow. In environments where the Google Meet plugin is enabled, a paired Chrome node exists, and the `googlemeet.chrome` command is permitted, an agent with tool-invocation capabilities can execute arbitrary processes on the paired node. This can lead to the compromise of files, credentials, and browser profiles, as well as impact system availability.
**Recommendations**
Update to version 2026.7.1.
Remove `googlemeet.chrome` from the list of allowed node commands.
Disable the Google Meet plugin.